AI Governance Institute
← News
Enforcement2026-07-29

Italy's Garante Fines Character.AI Operator €158,000 for Data Protection and Age-Control Failures, Signaling Broader EU Enforcement Risk for Consumer AI Platforms

Source

Italy's data protection authority fined Character Technologies, the U.S.-based owner of generative AI platform Character.AI, 158,000

Italy data protection authority

Via Italy data protection authority

What happened

Italy's Garante per la protezione dei dati personali issued a €158,000 fine against Character Technologies, Inc., the U.S. company that operates Character.AI, following an investigation into the platform's data processing practices. The enforcement focused on failures in age-related access controls, insufficient lawful basis for processing personal data, and inadequate transparency disclosures to users, including minors. Character.AI is a consumer-facing generative AI platform that allows users to create and interact with AI-modeled personas, a format that regulators have flagged for heightened risk given its appeal to younger audiences. The action follows a pattern of EU regulators scrutinizing consumer AI services under the EU General Data Protection Regulation framework, with the Garante previously taking enforcement action against OpenAI in 2023 over similar concerns about ChatGPT. The fine applies to a non-EU company operating a service accessible to EU residents, reinforcing the extraterritorial reach of EU data protection enforcement for AI platforms regardless of where the developer is headquartered.

Why it matters

  • ·Any enterprise deploying or procuring consumer-facing generative AI services with EU users faces direct exposure to DPA enforcement if age verification, lawful processing bases, and transparency disclosures are not demonstrably in place, as this fine confirms that regulators will act against non-EU operators under existing GDPR powers without waiting for the EU AI Act's full implementation.
  • ·The enforcement highlights a specific control gap around age-appropriate design: organizations that have not built documented age-gating or parental consent workflows into their AI product intake and vendor assessment processes are carrying unquantified regulatory risk, particularly for platforms with broad consumer reach.
  • ·For compliance teams that use or distribute third-party generative AI tools to external users, this action reinforces the need for vendor due diligence programs that go beyond security reviews to include data minimization practices, lawful basis documentation, and minor-protection controls as standard procurement conditions.

Governance controls affected

What to do now

  • Audit all consumer-facing or broadly accessible generative AI tools in your portfolio for documented age-verification and minor-protection controls, and escalate any gaps to your data protection officer.
  • Review the lawful processing basis recorded for each AI service accessible to EU residents, ensuring consent or legitimate interest assessments are current and cover AI-specific data flows.
  • Update third-party AI vendor due diligence questionnaires to include explicit requirements for age-gating mechanisms, data minimization practices, and minor-user data handling policies.
  • Map your consumer-facing AI services against EU DPA enforcement patterns to assess which products share characteristics with platforms already subject to regulatory action, including persona-based or conversational formats.
  • Ensure your external complaints and redress mechanism for AI services is visible, functional, and logged, as regulators increasingly treat inadequate user recourse as a standalone compliance failure.

What to watch next

Compliance teams should monitor whether other EU data protection authorities follow Italy's Garante with parallel investigations into generative AI platforms, particularly those with minor-user exposure, as coordinated DPA enforcement across member states would substantially raise the cost of non-compliance for any non-EU AI operator. The European Data Protection Board is expected to issue further harmonized guidance on AI and children's data, which could formalize age-verification expectations across all member states. Organizations should also track whether the EU AI Act provisions on prohibited AI systems and transparency, which became applicable in February 2026, are cited alongside GDPR in future enforcement actions, as dual-framework liability could significantly increase financial exposure for consumer AI platforms.

Stay ahead of stories like this

Get every EU AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Corporate Policy2026-09-07

Gemini 3.8 Flash Cyber Variant Creates a Two-Tier Procurement Compliance Problem

Google DeepMind released Gemini 3.8 Flash and a restricted companion model, Gemini 3.8 Flash Cyber, in September 2026. The two variants carry separate access eligibility requirements, acceptable-use terms, and logging obligations. Enterprises must evaluate each variant independently rather than treating them as a single procurement decision.

Corporate Policy2026-09-03

Meta's 95% API Discount Creates a Data Classification Forcing Function

Meta is offering enterprise customers roughly a 95% reduction in Muse Spark API costs in exchange for consent to use their prompts and model outputs as training data. The structure creates a direct financial incentive to share workflow data with a model provider, raising compliance questions about which data enterprises can lawfully contribute. Organizations without a mature data classification policy face meaningful exposure before they can make an informed procurement decision.

Corporate Policy2026-08-29

OpenAI's Zero Data Retention Option Shifts Audit Log Burden to Enterprise

OpenAI has introduced a zero data retention option for eligible API customers using frontier models, under which prompts and model responses are not stored after processing. The offering resolves a data minimization concern but transfers responsibility for audit-trail capture entirely to the enterprise customer. Regulated organizations must now ensure their own logging infrastructure compensates for the absence of vendor-side retention.