Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy prohibits using Stability AI technology to perform social scoring, criminal risk profiling based solely on personal traits, unauthorized facial recognition database creation, emotion inference in workplaces or schools, biometric-based categorization to infer protected characteristics, and real-time biometric identification in public spaces for law enforcement.
This analysis describes what Stability AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a set of prohibited AI use cases that closely track the prohibited practices listed in the EU AI Act, creating a contractual prohibition layer that applies to all users globally, including those outside EU jurisdiction. Operators building applications on Stability AI infrastructure must ensure their downstream use cases do not fall within these categories, or risk account suspension or termination.
Under this clause, any use of Stability AI technology to classify individuals based on biometric data, social behavior, or personal characteristics for discriminatory or enforcement purposes is prohibited. The agreement applies these restrictions to all users, including those accessing the technology through third-party platforms.
Cross-platform context
See how other platforms handle Biometric Data Categorization and Social Scoring Prohibition and similar clauses.
Compare across platforms →Monitoring
Stability AI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"evaluating or classifying persons based on their social behavior, personal characteristics, or the use of social scoring leading to detrimental or unfavorable treatment. assessing or predicting the risk of a person committing a crime, based solely on profiling or personal traits. creating or expanding facial recognition databases without consent. inferring emotions in the workplace or education institution, except for medical or safety reasons. categorizing people based on their biometric data to infer their race, political opinion, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. using real-time biometric identification systems in public spaces for law enforcement purposes.Excerpt from Stability AI's Acceptable Use Policy
(1) REGULATORY LANDSCAPE: This provision engages the EU AI Act's prohibited practices provisions, which ban social scoring by public authorities, real-time remote biometric identification in public spaces for law enforcement, and biometric categorization to infer protected characteristics. It also engages GDPR provisions on special category data processing, including biometric and health data. The FTC may also have jurisdiction over deceptive or unfair AI practices in the United States. Specific EU AI Act articles are not cited in the document; the alignment is substantive rather than explicit. (2) GOVERNANCE EXPOSURE: High. Operators deploying Stability AI in any context involving biometric data, access control, HR analytics, or public safety applications must affirmatively verify that their use case does not trigger these prohibitions. A violation could result in account termination, and depending on jurisdiction, regulatory enforcement action under the EU AI Act or GDPR. (3) JURISDICTION FLAGS: EU and EEA users face the highest exposure, given direct applicability of the EU AI Act and GDPR to the prohibited categories listed. California operators should also evaluate CCPA obligations around biometric data. Illinois operators should note BIPA implications for facial recognition database creation. The policy applies globally, but regulatory consequences for violations vary by jurisdiction. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise licensees and API integrators should review whether their downstream product functionality implicates any of the listed prohibited categories. Procurement teams onboarding Stability AI as a vendor should assess whether the AUP's prohibitions are adequately reflected in their own vendor contracts and end-user terms. The policy does not specify indemnification obligations for downstream violations. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should conduct a use-case audit against the specific prohibited categories listed in this provision, particularly for any HR, public safety, healthcare, or identity verification applications. Organizations subject to the EU AI Act should map this provision against their AI system classification and conformity assessment obligations.
Regulatory citations, enforcement risk, and due diligence action items.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes a set of prohibited AI use cases that closely track the prohibited practices listed in the EU AI Act, creating a contractual prohibition layer that applies to all users globally, including those outside EU jurisdiction. Operators building applications on Stability AI infrastructure must ensure their downstream use cases do not fall within these categories, or risk account …
Under this clause, any use of Stability AI technology to classify individuals based on biometric data, social behavior, or personal characteristics for discriminatory or enforcement purposes is prohibited. The agreement applies these restrictions to all users, including those accessing the technology through third-party platforms.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Stability AI.