Updated September 6, 2026. Article 5 has grown since this was written. The Digital Omnibus added two prohibitions in July 2026, applying from December 2, 2026, and wrote an express intent test into the article. Both are below, along with corrections to the case law and to the guidelines citation.
There’s a moment, and if you work in compliance or risk you’ve either had it or it’s coming, when someone in a meeting turns to you and says: “So, the AI Act. What do we need to do?”
And you sit there thinking, I barely finished the DORA implementation.
The regulation is long. The guidance documents keep stacking up. Every law firm in Europe has published an “alert” that somehow manages to create more questions than it answers.
And you, the person who already handles GDPR, maybe DORA, maybe NIS2, maybe all three on a good day, just got handed another regulation to figure out.
Because apparently regulatory compliance is like a hotel room minibar: there’s always room for one more.
The instinct is to start reading from Article 1 and work your way through. Don’t.
Start with Article 5. Start with the prohibited practices.
Not because they’re the most complex. They aren’t. But because they carry the highest fines in the entire regulation: up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher. And because Chapters I and II, which include Article 5, were the first parts of the AI Act to take effect, on February 2, 2025.
Just be aware that the prohibitions applied from February 2025. The penalties regime applied from August 2025, which is when Member States were meant to have national penalty rules in place. The market surveillance machinery that supervises any of it arrived in August 2026. Applicable, finable and supervised are three different things, and I keep a running record of which is which.
Article 99(6) reverses the formula for SMEs and start-ups: for them the cap is whichever figure is lower, not higher.
If any of your AI systems are doing something on this list, it doesn’t matter how far along you are with risk classification or documentation or conformity assessment. You have a problem that outranks all of those.
That’s the logic. Start with the biggest exposure. Work down from there.
What the Commission Said — and What It Didn’t
The European Commission guidelines on prohibited practices are often cited as “the February 2025 guidelines”. But they were not adopted in February 2025.
On February 4, 2025 the Commission approved the content of a draft, C(2025) 884 final. The instrument actually adopted is C(2025) 5052 final, dated July 29, 2025, running to around 135 pages.
They are non-binding, which means the Court of Justice of the European Union has the final word on interpretation. But they are the Commission’s view of what each prohibition means, and they will shape how enforcement authorities approach these cases.
They clarify definitions, give examples, and take positions on ambiguous questions. They’re useful. They are also, in a way that is becoming familiar with the AI Act, incomplete in exactly the places where you most need clarity. And they predate the Digital Omnibus on AI by a year, so they say nothing at all about the two newest prohibitions.
Intent Is Not Required, For Two of Them
Article 5(1)(a) and (b) use a specific formulation: “with the objective or the effect of.”
That “or” is quite important. Intent is not required. If an AI system has the actual effect of materially distorting someone’s behavior, the prohibition applies even if no one designed it to do that, even if the deployer didn’t know it was happening, even if the system passed every internal review.
The guidelines say it directly: the prohibition applies
“even if the material distortion of a person’s behaviour occurs without the intent of the provider or deployer.”
The EU borrowed the approach from the Unfair Commercial Practices Directive. An effects-based standard, deliberately low, designed to protect people regardless of what the company thought it was building.
So for manipulation and exploitation: “we didn’t mean to” is not a defense.
“We had a governance framework” is not a defense.
“Our vendor assured us it was compliant” is not a defense.
That formulation appears nowhere else in the article. Predictive policing is purposive: the system has to be used to assess or predict. Emotion recognition catches systems deployed for that specific purpose. Biometric categorization turns on systems that categorize to deduce or infer. Untargeted scraping is conduct-based, with no mental element at all. You either scraped or you didn’t.
Ten prohibitions, and the effects standard reaches two of them.
Then the Digital Omnibus on AI wrote the point into the Regulation. The two prohibitions added in July 2026 carry an express intent-and-foreseeability gate in the new Article 5(1a), which is the clearest possible demonstration that Article 5 has never had one test. It has a different test per practice.
Knowing which one you are under is the first question, not the last.
The Ten Prohibited Practices
Eight have applied since February 2, 2025. Two were added by the Digital Omnibus on AI and apply from December 2, 2026.
1. Subliminal, manipulative, and deceptive AI techniques
Article 5(1)(a). An AI system deploying subliminal techniques beyond a person’s consciousness, or purposefully manipulative or deceptive techniques, with the objective or effect of materially distorting behavior, appreciably impairing their ability to make an informed decision, causing them to take a decision they would not otherwise have taken, in a manner that causes or is reasonably likely to cause significant harm.
“Subliminal techniques” means imperceptible influences. Visual content flashed too fast for the conscious mind to catch. Audio below the threshold of awareness.
“Material distortion,” borrowed from consumer protection law, means a substantial impact on behavior. Not mere influence. Manipulation.
The grey zone is enormous. Personalized advertising based on user preferences? The guidelines say that is not inherently prohibited. An AI system that dynamically hides cancellation buttons, generates artificial urgency, or adjusts scroll behavior in ways the user can’t perceive? Closer. Much closer. An adaptive checkout flow that increases pressure when it detects hesitation is the territory where personalization starts looking like manipulation, and the only thing separating them is whether the effect materially distorts the decision.
The Digital Services Act already targets manipulative design. Article 5(1)(a) extends the prohibition to AI-driven manipulation specifically. If your company has AI touching customer-facing products, this is the one that deserves the longest look in the mirror.
2. Exploitation of vulnerabilities
Article 5(1)(b). An AI system that exploits vulnerabilities due to age, disability, or a specific social or economic situation. Same objective-or-effect standard, same requirement of material distortion and significant harm.
Three categories of vulnerability:
Children and elderly people.
Physical or mental disability.
Financial desperation or socio-economic disadvantage.
The guidelines give one interesting example: AI systems creating “personalized and unpredictable rewards through addictive reinforcement schedules.” Targeting the underdeveloped impulse control of children. Targeting cognitive decline in the elderly. Designed, or merely having the effect of, exploiting the people least equipped to resist.
There is a limit here though. The AI system has to distort behavior. A model that treats vulnerable people worse without changing what they do falls outside this point, and may well land on the next one instead.
3. Social scoring
Article 5(1)(c). An AI system that evaluates or classifies natural persons based on social behavior or personal characteristics, resulting in detrimental treatment that is either in social contexts unrelated to where the data was collected, or unjustified or disproportionate to the behavior assessed.
This is the one that gets waved away. We don’t do social scoring.
However, the prohibition isn’t about building China’s social credit system. It’s about what happens when a score travels.
A credit score based on financial behavior, used for lending decisions? Not social scoring under Article 5. That same score leaking into housing eligibility, school enrollment, or employment screening? Now you’re in Article 5 territory. A customer loyalty score from a retail platform used to set insurance premiums? Same problem.
For compliance teams the question isn’t “do we score people?” Almost everyone does. The question is: where does the score travel? If the answer is “only within the context it was designed for, with proportionate consequences,” you’re likely fine. If the answer is “we’re not sure,” that’s the assessment you need to do.
Two European cases sit here.
France’s CAF. Since 2010 the national family benefits agency has used a risk-scoring algorithm to flag welfare fraud, covering over 13 million households. Parameters that raise your score: low income, unemployment, living in a disadvantaged neighborhood, having a disability while working. Source code obtained by investigators in 2023 exposed the design. In October 2024, fifteen organizations including La Quadrature du Net and Amnesty International challenged the system before the Conseil d’État. Ten more joined in January 2026. The claim is pleaded as social scoring. No ruling yet.
The Netherlands, and it is two systems rather than one. SyRI, a risk-indication system for welfare fraud, was struck down by the Hague District Court on February 5, 2020 for breaching Article 8 of the European Convention on Human Rights. Separately, the tax administration’s childcare benefits risk model used nationality as a risk indicator and wrongly accused tens of thousands of parents of fraud. That one was never struck down by any court. It drew a EUR 2.75 million fine from the Dutch data protection authority in December 2021 for discriminatory and unlawful processing, and the political fallout brought down the government.
Merging the two is common, but one is a human rights ruling and the other is a data protection fine. Neither was decided under the AI Act, which didn’t exist at that time. What they show is that European governments, well funded and democratically accountable, built exactly the systems Article 5(1)(c) now describes.
4. Predictive policing
Article 5(1)(d). An AI system that assesses or predicts the likelihood of a person committing a criminal offense, based solely on profiling or on assessing personality traits and characteristics.
“Solely” makes this a partial ban rather than an absolute one. And the system has to be used to assess or predict. This one is purposive, not effects-based.
“Personality traits and characteristics” gets a broad reading in the guidelines: gender, race, ethnicity, address, income, health, preferences, behavior, financial status. Non-exhaustive. AI systems supporting human assessment based on objective, verifiable facts directly linked to criminal activity remain permitted, provided the human decision-maker actually relies on the assessment. Rubber-stamping an algorithmic output doesn’t count.
Geographic crime mapping, identifying high-crime areas from historical data, is not prohibited. It targets patterns, not people.
Which is exactly where Geolitica belongs. The system deployed by the Plainfield Police Department in New Jersey generated 23,631 predictions between February and December 2018. When The Markup analyzed them in October 2023, fewer than 100 corresponded to a reported crime in the predicted category. Under half a percent.
Those were location predictions, not person predictions, so the system sits on the permitted side of Article 5(1)(d). The AI Act bans predicting whether you will commit a crime. It doesn’t ban predicting whether a crime will happen near you. Same underlying data, different framing, different legal outcome. And the accuracy figure suggests the permitted side isn’t obviously the safer one for the people being policed.
5. Untargeted facial image scraping
Article 5(1)(e). An AI system that creates or expands facial recognition databases through untargeted scraping of facial images from the internet or CCTV footage.
The hardest line in Article 5. An absolute ban, with no exceptions and no law enforcement carve-out. Of the three prohibitions that law enforcement actually runs into, this is the one with no door at all. It is also purely conduct-based. No objective, no effect, no purpose. You either scraped or you didn’t.
“Untargeted” means indiscriminate mass collection not focused on specific individuals.
“Scraping” means automated extraction using crawlers and bots.
And the detail that matters: consent to posting images on social media is not consent to a facial recognition database. You put your photo on LinkedIn. That doesn’t mean a company can feed it into a face-matching system. The guidelines are clear on this.
One more. Multiple targeted scrapes that incrementally build the same database still count as untargeted scraping. You can’t slice an ocean into cups and call each one a glass of water.
Clearview AI defines this category. A US company that scraped the internet to build a database it says now exceeds 60 billion facial images. Four EU authorities have fined it: Italy EUR 20 million in February 2022, Greece EUR 20 million in July 2022, France EUR 20 million in October 2022, and the Netherlands EUR 30.5 million announced on September 3, 2024. EUR 90.5 million in total. France added a further EUR 5.2 million in May 2023 for ignoring the original order. Austria’s authority found the processing unlawful in May 2023 and issued no fine at all.
Under the AI Act, Clearview’s entire model is now a prohibited practice rather than only a data protection violation.
The enforcement gap tells its own story. Those fines landed on a US company with no EU establishment. Collection has been, let’s call it aspirational. noyb took a different route and filed a criminal complaint against Clearview executives in Austria, which if it succeeds means personal liability for anyone who travels to Europe.
The AI Act doesn’t solve cross-border enforcement. It raises the ceiling on what happens when enforcement catches up.
6. Emotion recognition in workplace and education
Article 5(1)(f). An AI system intended to infer emotions of natural persons in a workplace or educational institution. Purposive again. What the system is for is the question.
“Workplace” covers any setting where work is performed, including recruitment, hiring, temporary work and remote work. The prohibition applies from the moment someone is a job candidate, not from day one on the job.
“Educational institutions” means public and private, all levels, in person and online, including admissions.
There are two exceptions:
Medical, but only CE-marked medical devices for genuine therapeutic purposes. Monitoring employee stress because HR wants a wellness dashboard is not medical.
Safety, but only for concrete risks to life or health. Construction workers at height. Pilots. Truck drivers on long shifts. A general interest in employee wellbeing doesn’t meet the threshold.
If you’ve evaluated, or already deployed, video interview analysis tools, employee engagement monitoring, classroom attention tracking, or proctoring that analyzes facial expressions, this is the prohibition with your name on it. Remember the person who asked “So, the AI Act, what do we need to do?” This is what I’d tell them to check first, because these products were actively marketed to companies until very recently. Some still are.
Be aware of AI systems tracking behavioral signals like cursor hesitation, typing cadence and mouse movement, without calling the output “emotion.” A product labeled “engagement scoring” or “confidence assessment” instead. The guidelines focus on purpose, on inferring emotions. But when the function is analyzing human behavior to deduce internal states, the label on the output starts to look like a distinction without a difference. That’s my reading, not the law but I wouldn’t want to be the test case.
7. Biometric categorization by sensitive characteristics
Article 5(1)(g). Biometric categorization systems that categorize individual natural persons based on their biometric data to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation.
The prohibition
“does not cover any labelling or filtering of lawfully acquired biometric datasets, such as images, based on biometric data or categorizing of biometric data in the area of law enforcement.”
Two things. Labeling and filtering lawfully acquired datasets, which is how you ensure ethnic diversity in medical imaging training data. And categorizing biometric data in the law enforcement context. Using categorization operationally, against real people in a commercial or public setting, is the prohibition.
“Deduce or infer” is deliberately broad. A confidence score correlated with race triggers the prohibition. The system doesn’t need to output a categorical label. A probability is enough. A security system that wasn’t designed to infer race but whose outputs happen to correlate with it? Still caught. The question isn’t what you built the system to do.
It’s what the system does.
8. Real-time remote biometric identification by law enforcement
Article 5(1)(h). The use of real-time remote biometric identification systems in publicly accessible spaces for law enforcement purposes, unless and insofar as strictly necessary for one of three objectives (see below). The most politically charged prohibition in the AI Act, and the only one where the EU built a detailed exception framework directly into the article. Which tells you something about the lobbying pressure behind it.
“Real-time” means simultaneous with data capture. Analyzing recorded footage after the fact is a different legal category, classified as high-risk rather than prohibited. That distinction sounds clean. In practice the boundary is blurry. If you analyze CCTV footage ten minutes after capture, is that real-time? An hour? The guidelines don’t draw the line.
The three objectives:
Targeted search for specific victims of abduction, trafficking in human beings or sexual exploitation, as well as the search for missing persons.
Prevention of a specific, substantial and imminent threat to the life or physical safety of natural persons, or a genuine and present or genuine and foreseeable threat of a terrorist attack.
Localization or identification of a person suspected of an offense listed in Annex II and punishable in the Member State concerned by a custodial sentence or detention order for a maximum period of at least four years. Note what that measures. It is the maximum sentence available for the offense, not the sentence anyone expects to receive.
Article 5(2) adds a balancing test before any of that: the seriousness, probability and scale of the harm if the system isn’t used, against the consequences for the rights and freedoms of everyone affected. Plus a fundamental rights impact assessment under Article 27 and registration in the EU database under Article 49.
Article 5(3) requires prior authorization by a judicial authority or an independent administrative authority whose decision binds. In duly justified urgency, use may begin without it, provided authorization is requested without undue delay and at the latest within 24 hours. If it is then refused, use stops and the data is deleted.
However, these derogations don’t exist by default. A Member State has to provide for them in national law and lay down the detailed rules. In a Member State that hasn’t, there is no lawful route to real-time remote biometric identification at all, whatever the three objectives say.
Hungary is the live example. Amendments rushed through in March 2025, in force from April 15, 2025, extended police facial recognition from serious offenses to all infraction procedures, which reaches minor violations and attendance at banned demonstrations. A joint legal analysis published on April 28, 2025 by the Hungarian Civil Liberties Union, Liberties, EDRi and the European Center for Not-for-Profit Law argues this breaches Article 5(1)(h).
For most corporate readers this prohibition matters if you’re a vendor selling biometric identification to law enforcement, or if you’re thinking about the national security exemption. Article 2(3) exempts AI systems used exclusively for national security purposes. A real-time biometric system reframed as national security escapes Article 5 entirely. The guidelines don’t close that door.
9 and 10. The two the Omnibus added
Point (ba) covers AI systems that generate or manipulate realistic images, video, audio or comparable material of an identifiable natural person’s intimate parts, or that person engaged in sexually explicit conduct, without their freely given, specific, informed, unambiguous and explicit consent.
Point (bb) covers child sexual abuse material within the meaning of Directive 2011/93/EU, with a narrow exception where the conduct is lawful under national law, which is how legitimate law enforcement work stays out of scope.
The material has to be realistic. The person has to be identifiable. The consent standard is active consent, not the absence of an objection, so consent to publishing the original photograph is not consent to what a model does with it. And the new Article 5(1b) narrows it further: manipulation that neither increases exposure nor alters the nature of the activity depicted is not manipulation for these purposes.
The origin story is recent enough to remember. In early January 2026 Grok was generating large volumes of near-nude images of real people, including minors. The Commission called it illegal within two days and ordered X to preserve the relevant documents and data on January 8. The prohibition entered the omnibus negotiation in the months that followed.
Which is why the drafting reaches further than purpose-built nudify apps. Under new Article 5(1a), a provider is caught where generating that material is the system’s intended purpose, or where the system’s design, training, architecture, capabilities or user-facing functionality make it a reasonably foreseeable and reproducible outcome and the provider has no reasonable and adequate technical safety measures capable of reliably preventing it. The duty doesn’t stop at launch either: it extends to correcting misuse once observed or reported.
Deployers get a different test entirely. Purely intentional. Caught only where they use the system for the purpose of generating that material, including by circumventing the provider’s safeguards. Accidental output isn’t caught.
Notice that Article 5 speaks to AI systems, not to models. A general-purpose model provider is caught in its capacity as the provider of a system it places on the market, not by virtue of having a model.
So the same prohibition asks two questions. Of a provider: what does your system reliably prevent, and what do you do when someone reports that it didn’t? Of a deployer: what did you use it for?
While everything else in the omnibus gave industry more time, this went the other way.
The Patterns To See Behind the Text
Ten practices, one article. It’s tempting to treat them as a flat list. They’re not.
Not all prohibitions are created equal. There are three tiers:
Absolute bans with no exceptions at all, where untargeted facial scraping sits.
Near-absolute bans, covering manipulation, exploitation, social scoring and predictive policing, where the path through is so narrow it barely exists.
And conditional bans, emotion recognition and real-time biometric identification, where exceptions are real but come with procedural safeguards heavy enough to deter most uses.
Knowing which tier you’re in changes the conversation from “are we allowed to do this?” to “what would we need to do to be allowed?”
The two newest ones don’t fit the tiers cleanly, and that’s the point. For a deployer they’re close to absolute: use the system for that purpose and you’re in breach. For a provider they’re conditional on safeguards. Same prohibition, different shape depending on which side of it you sit.
Every prohibition has its own test. Two are effects-based, (a) and (b). Four are purposive, (c), (d), (f) and (g), where what the system is for decides it. Two turn on conduct alone, (e) and (h), where the act of scraping or of switching the system on is the breach. And two carry an express foreseeability gate, (ba) and (bb). Reading Article 5 as a single standard is the most common way to get it wrong, and getting the test wrong means assessing the wrong thing thoroughly.
Context determines everything for social scoring. The prohibition isn’t about scoring. It’s about spillover. Where does the score travel? Who sees it? What decisions does it touch? A score that stays in its lane is fine. A score that leaks into unrelated contexts, or produces disproportionate consequences, triggers Article 5.
Three prohibitions involve law enforcement, at three different levels of restriction. Predictive policing is a partial ban, because of “solely.” Facial scraping is absolute. Real-time biometric identification is conditional, and the conditions only exist where a Member State has legislated for them. The EU drew lines even for law enforcement. It drew them differently each time. And the national security exemption in Article 2(3) sits behind all three.
What the Guidelines Leave Open
Around 135 pages of guidance, and the hardest questions are left for another day.
The “solely” threshold. How much additional objective data allows AI use in criminal risk assessment? No standard.
How to identify vulnerability. Where does “specific socio-economic situation” begin? Is a single parent on minimum wage vulnerable? A recent graduate with student debt? No line drawn.
“Reasonably likely to cause significant harm.” What probability? How significant? No quantitative threshold.
National security versus law enforcement. A real-time biometric system reframed as national security escapes the prohibition entirely. The boundary isn’t defined.
Untargeted scraping circumvention. Multiple targeted scrapes building the same database. How many? Over what timeline? The principle is stated, the mechanics aren’t.
Where “real-time” ends. If you analyze CCTV footage an hour after capture, is that real-time? A day? The line between prohibited real-time identification and permitted retrospective analysis isn’t drawn.
Generative AI and manipulation. How Article 5(1)(a) applies to foundation models and large language models. The guidelines don’t address it.
GDPR and Digital Services Act interplay. The prohibited practices overlap with both. How the obligations interact, or conflict, is unresolved.
The “material distortion” threshold. How much behavior change triggers the prohibition? The standard says material. It doesn’t say what that means in practice.
The two newest prohibitions, entirely. The guidelines were adopted in July 2025, a year before points (ba) and (bb) existed. Nothing has been published on what “reasonably foreseeable and reproducible” means, or on what makes a safeguard reasonable and adequate. The most operationally demanding test in Article 5 currently has no guidance at all.
These aren’t academic gaps. They’re the questions that land on someone’s desk the moment a real AI system has to be assessed, and there won’t be a clear answer.
What to Do
Having no clear answer is fine. Having no answer is not. You need something better than “it’s complicated.”
Start with what you have, not with the law. You cannot map systems against Article 5 that no one has written down, and the inventory is reliably harder than the regulation. IT has a security list, procurement has a vendor list, and the business teams have tools no one else knows about. That gap is where the Article 5 exposure hides.
Then map, with the technical team in the room. For each AI system: could it deploy manipulative techniques, even unintentionally? Could it exploit vulnerable users through its design, targeting or effects? Does any scoring or classification travel across context boundaries? Does anything in the workplace or education space infer emotions, even under a different label? If it generates images, video or audio of people, what does it refuse, and how do you know?
Match each AI system to the right test. For manipulation and exploitation, the question is “does the system do this,” not “did we intend this.” For social scoring, predictive policing, emotion recognition and biometric categorization, read the verb: purpose is the trigger. For the two new prohibitions, the provider question is foreseeability plus safeguards.
Trace where your scores go. If you score, classify or categorize people, and most AI systems do somewhere in the pipeline, follow the output. Who consumes it. What decisions it touches. If a score generated for one purpose influences decisions in another context, you have an Article 5(1)(c) question that needs an answer.
Check your vendors. If you’re using third-party AI tools, video interview platforms, employee monitoring, customer analytics, proctoring, ask what they do under the hood. If a vendor’s product turns out to be prohibited, the vendor isn’t the only one with a problem. Your exposure runs through use, and through putting a system into service under your own name or for your own purposes. “We bought it from someone else” is not a defense.
Document your reasoning. For every system where you conclude “this isn’t a prohibited practice,” write down why. Element by element. Not because a regulator has asked. Because when enforcement starts, a documented assessment is the difference between a defensible position and an assumption you can’t explain.
No AI Act fine for a prohibited practice has been issued yet. It’s September 2026. But the machinery exists now. Chapter IX applied from August 2, 2026, and national market surveillance authorities began supervising then. Where they exist, at least. As of mid-2026 fewer than half of Member States had designated both a market surveillance authority and a notifying authority, so which country you’re in still decides whether any of this reaches you.
And the map changed in July. The omnibus moved enforcement competence for certain systems away from national authorities entirely: the AI Office now has exclusive supervision over AI systems built on general-purpose models within the same undertaking, and over systems integrated into very large online platforms and search engines under the Digital Services Act. A prohibited generative practice running on a general-purpose model is likely an AI Office matter, not one for your national regulator. Complaints have been filed elsewhere too. France’s CAF. Clearview’s criminal exposure in Austria. GDPR enforcement against the same conduct has already cleared EUR 90 million against one company.
So if someone turns to you in a meeting and asks what you need to do about the AI Act, you probably don’t need a full answer by Friday. But you need to know three things: the prohibitions exist, they’re already in force, and the test that applies depends on which one you’re under.
Start there. High-risk classification, documentation, conformity assessment, that all comes next. But it comes after this.
You don’t build a house from the roof down.
Scope is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.





This is exactly where it becomes difficult in practice.
The regulation is effect-based - but most implementations still rely on documentation, intent, or post-hoc assessment.
So even if a system ends up violating Article 5, the only thing we can prove is that it happened - not prevent it structurally.
I’ve been working on a different approach where the constraint doesn’t sit at the level of policy, but at the level of when a system is allowed to act at all.
Not limiting outcomes, but limiting action under epistemically insufficient conditions.
Still early — but it seems like the only way to actually bridge that gap.