The Red Lines by Kai London
The AI Act's prohibitions read as though they concern only extreme cases. In practice, ordinary commercial systems — personalisation, workforce analytics, engagement optimisation, biometric features bought in from a vendor — can drift towards them without anyone intending it. This book is about noticing that early.
What the book covers
Reading the prohibitions
What each category actually bans, the qualifying conditions and the narrow exceptions.
Where commercial systems get close
Behavioural personalisation, workplace monitoring, inferred attributes and biometric features shipped inside third-party products.
Screening method
A repeatable triage that product and procurement teams can apply before a system is built or bought.
Borderline cases
Worked examples showing how to reason to a defensible conclusion when the answer is not obvious.
Escalation and record
Who decides, what gets documented, and how to evidence that a system was assessed and cleared.
Redesign options
Changes that move a use case back to permissible territory without abandoning the business goal.
This book provides general guidance and is not legal advice; prohibited-practice questions turn on specific facts and should be put to qualified counsel. It is independent and carries no endorsement by or affiliation with any regulator or standards body.
Who it is for
AI governance and compliance leads, product managers and designers, legal and privacy teams, procurement, and boards overseeing AI-enabled products and services.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.