AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News
Enforcement2026-07-29

Italy's Garante Fines Character.AI Operator €158,000 for Data Protection and Age-Control Failures, Signaling Broader EU Enforcement Risk for Consumer AI Platforms

Source

Italy's data protection authority fined Character Technologies, the U.S.-based owner of generative AI platform Character.AI, 158,000

Italy data protection authority

Via Italy data protection authority

What happened

Italy's Garante per la protezione dei dati personali issued a €158,000 fine against Character Technologies, Inc., the U.S. company that operates Character.AI, following an investigation into the platform's data processing practices. The enforcement focused on failures in age-related access controls, insufficient lawful basis for processing personal data, and inadequate transparency disclosures to users, including minors. Character.AI is a consumer-facing generative AI platform that allows users to create and interact with AI-modeled personas, a format that regulators have flagged for heightened risk given its appeal to younger audiences. The action follows a pattern of EU regulators scrutinizing consumer AI services under the EU General Data Protection Regulation framework, with the Garante previously taking enforcement action against OpenAI in 2023 over similar concerns about ChatGPT. The fine applies to a non-EU company operating a service accessible to EU residents, reinforcing the extraterritorial reach of EU data protection enforcement for AI platforms regardless of where the developer is headquartered.

Why it matters

  • ·Any enterprise deploying or procuring consumer-facing generative AI services with EU users faces direct exposure to DPA enforcement if age verification, lawful processing bases, and transparency disclosures are not demonstrably in place, as this fine confirms that regulators will act against non-EU operators under existing GDPR powers without waiting for the EU AI Act's full implementation.
  • ·The enforcement highlights a specific control gap around age-appropriate design: organizations that have not built documented age-gating or parental consent workflows into their AI product intake and vendor assessment processes are carrying unquantified regulatory risk, particularly for platforms with broad consumer reach.
  • ·For compliance teams that use or distribute third-party generative AI tools to external users, this action reinforces the need for vendor due diligence programs that go beyond security reviews to include data minimization practices, lawful basis documentation, and minor-protection controls as standard procurement conditions.

Governance controls affected

What to do now

  • Audit all consumer-facing or broadly accessible generative AI tools in your portfolio for documented age-verification and minor-protection controls, and escalate any gaps to your data protection officer.
  • Review the lawful processing basis recorded for each AI service accessible to EU residents, ensuring consent or legitimate interest assessments are current and cover AI-specific data flows.
  • Update third-party AI vendor due diligence questionnaires to include explicit requirements for age-gating mechanisms, data minimization practices, and minor-user data handling policies.
  • Map your consumer-facing AI services against EU DPA enforcement patterns to assess which products share characteristics with platforms already subject to regulatory action, including persona-based or conversational formats.
  • Ensure your external complaints and redress mechanism for AI services is visible, functional, and logged, as regulators increasingly treat inadequate user recourse as a standalone compliance failure.

What to watch next

Compliance teams should monitor whether other EU data protection authorities follow Italy's Garante with parallel investigations into generative AI platforms, particularly those with minor-user exposure, as coordinated DPA enforcement across member states would substantially raise the cost of non-compliance for any non-EU AI operator. The European Data Protection Board is expected to issue further harmonized guidance on AI and children's data, which could formalize age-verification expectations across all member states. Organizations should also track whether the EU AI Act provisions on prohibited AI systems and transparency, which became applicable in February 2026, are cited alongside GDPR in future enforcement actions, as dual-framework liability could significantly increase financial exposure for consumer AI platforms.

Stay ahead of stories like this

Get every EU AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Corporate Policy2026-07-27

Claude Shared Chats Indexed by Google, Exposing Health Records and Children's Data in Employee-Generated AI Content

An undetermined number of Claude shared chats and Artifacts became publicly searchable on Google, with some conversations containing health records, private company documents, and children's personal information. Anthropic stated the exposure resulted from users choosing to share links rather than from a platform misconfiguration. The incident creates immediate compliance exposure for organizations whose employees use Claude for work involving sensitive or regulated data.

Enforcement2026-07-22

EU Binding DMA Measures Force Google to Open Android AI Access and Share Search Data by July 2027, Reshaping Enterprise AI Procurement Risk

The European Commission has finalized binding specification measures under the Digital Markets Act requiring Google to grant competing AI platforms the same system-level Android access currently held by Gemini, and to share search data with rival providers for a reasonable fee. AI chatbots are formally classified as search services for data-sharing purposes, with multilayered anonymization required. Search data sharing must begin by January 2027 and Android AI interoperability by July 2027.

Insight2026-07-16

Agentic Developer Tools Are the New Shadow IT, With a Larger Blast Radius

The Grok Build incident is not a data breach story. It is a category error story: organizations are applying shadow IT controls to a class of tools that bypasses those controls by design. Agentic coding assistants have codebase-level access, transmit code as part of their core function, and expose data in proportion to the developer's own privileges. The governance frameworks built for unauthorized SaaS subscriptions are not built for this.