Italy's Garante Fines Character.AI Operator €158,000 for Data Protection and Age-Control Failures, Signaling Broader EU Enforcement Risk for Consumer AI Platforms
Source
Italy's data protection authority fined Character Technologies, the U.S.-based owner of generative AI platform Character.AI, 158,000
Italy data protection authority
What happened
Italy's Garante per la protezione dei dati personali issued a €158,000 fine against Character Technologies, Inc., the U.S. company that operates Character.AI, following an investigation into the platform's data processing practices. The enforcement focused on failures in age-related access controls, insufficient lawful basis for processing personal data, and inadequate transparency disclosures to users, including minors. Character.AI is a consumer-facing generative AI platform that allows users to create and interact with AI-modeled personas, a format that regulators have flagged for heightened risk given its appeal to younger audiences. The action follows a pattern of EU regulators scrutinizing consumer AI services under the EU General Data Protection Regulation framework, with the Garante previously taking enforcement action against OpenAI in 2023 over similar concerns about ChatGPT. The fine applies to a non-EU company operating a service accessible to EU residents, reinforcing the extraterritorial reach of EU data protection enforcement for AI platforms regardless of where the developer is headquartered.
Why it matters
- ·Any enterprise deploying or procuring consumer-facing generative AI services with EU users faces direct exposure to DPA enforcement if age verification, lawful processing bases, and transparency disclosures are not demonstrably in place, as this fine confirms that regulators will act against non-EU operators under existing GDPR powers without waiting for the EU AI Act's full implementation.
- ·The enforcement highlights a specific control gap around age-appropriate design: organizations that have not built documented age-gating or parental consent workflows into their AI product intake and vendor assessment processes are carrying unquantified regulatory risk, particularly for platforms with broad consumer reach.
- ·For compliance teams that use or distribute third-party generative AI tools to external users, this action reinforces the need for vendor due diligence programs that go beyond security reviews to include data minimization practices, lawful basis documentation, and minor-protection controls as standard procurement conditions.
Governance controls affected
What to do now
- ☐Audit all consumer-facing or broadly accessible generative AI tools in your portfolio for documented age-verification and minor-protection controls, and escalate any gaps to your data protection officer.
- ☐Review the lawful processing basis recorded for each AI service accessible to EU residents, ensuring consent or legitimate interest assessments are current and cover AI-specific data flows.
- ☐Update third-party AI vendor due diligence questionnaires to include explicit requirements for age-gating mechanisms, data minimization practices, and minor-user data handling policies.
- ☐Map your consumer-facing AI services against EU DPA enforcement patterns to assess which products share characteristics with platforms already subject to regulatory action, including persona-based or conversational formats.
- ☐Ensure your external complaints and redress mechanism for AI services is visible, functional, and logged, as regulators increasingly treat inadequate user recourse as a standalone compliance failure.
What to watch next
Compliance teams should monitor whether other EU data protection authorities follow Italy's Garante with parallel investigations into generative AI platforms, particularly those with minor-user exposure, as coordinated DPA enforcement across member states would substantially raise the cost of non-compliance for any non-EU AI operator. The European Data Protection Board is expected to issue further harmonized guidance on AI and children's data, which could formalize age-verification expectations across all member states. Organizations should also track whether the EU AI Act provisions on prohibited AI systems and transparency, which became applicable in February 2026, are cited alongside GDPR in future enforcement actions, as dual-framework liability could significantly increase financial exposure for consumer AI platforms.
Stay ahead of stories like this
Get every EU AI governance development like this one, plus the rest of the week's developments. Every Thursday.
