What is social scoring under the AI Act?
Social scoring is the evaluation or classification of natural persons over a period of time based on their social behaviour or on known, inferred or predicted personal characteristics. The EU AI Act (Regulation (EU) 2024/1689) treats it as a prohibited practice under Article 5 where the resulting score leads to (a) detrimental treatment in social contexts unrelated to the context in which the data was generated or collected, or (b) treatment that is unjustified or disproportionate to the behaviour. The ban has applied since 2 February 2025 and binds public and private actors alike — it is not a state-scoring rule only.
What falls inside the ban — and what does not
The prohibition turns on the two limbs, not on the word “score”:
- Credit scoring on financial data used for a credit decision is not social scoring, but it is high-risk under Annex III, which brings the high-risk AI system regime and, for some deployers, a fundamental rights impact assessment (FRIA);
- Fraud scoring that stays within the same transactional context generally survives;
- The ban bites when scores travel across contexts: using social media behaviour to price insurance is the classic example, and cross-context data enrichment is where products drift into the prohibition without anyone deciding to build a “social score”.
The legal dimension
Article 5 violations sit at the top of the AI Act’s penalty scale: fines reach €35M or 7% of global turnover, whichever is higher. The ban already applies; no transition period is left. Fintech, insurtech and marketplace trust-and-safety teams should map every scoring model against the two limbs — where does the input data come from, and is the treatment proportionate to the scored conduct? A model that fails either limb cannot be cured with transparency notices; it has to be redesigned or withdrawn. The wider Article 5 catalogue is covered under prohibited AI practices.
Turkish context
Türkiye has no AI Act equivalent in force, so there is no domestic ban phrased in these terms. Scoring models that process personal data are instead governed by KVKK: lawful basis, purpose limitation and the rules on profiling and automated decisions do much of the same work, and cross-context reuse of data will usually fail the purpose-limitation test. Turkish companies whose products reach EU users fall within the Article 5 ban directly.
Do: inventory every scoring model, record the context its input data comes from, and test both limbs before launch. Don’t: enrich scores with data from unrelated contexts on the assumption that “this is not a state social credit system” — the ban covers private actors too.
Related guides: Already Illegal.
Sources. Regulation (EU) 2024/1689 (AI Act).