AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News
Enforcement2026-07-29

Italy's Garante Fines Character.AI Operator €158,000 for Data Protection and Age-Control Failures, Signaling Broader EU Enforcement Risk for Consumer AI Platforms

Source

Italy's data protection authority fined Character Technologies, the U.S.-based owner of generative AI platform Character.AI, 158,000

Italy data protection authority

Via Italy data protection authority

What happened

Italy's Garante per la protezione dei dati personali issued a €158,000 fine against Character Technologies, Inc., the U.S. company that operates Character.AI, following an investigation into the platform's data processing practices. The enforcement focused on failures in age-related access controls, insufficient lawful basis for processing personal data, and inadequate transparency disclosures to users, including minors. Character.AI is a consumer-facing generative AI platform that allows users to create and interact with AI-modeled personas, a format that regulators have flagged for heightened risk given its appeal to younger audiences. The action follows a pattern of EU regulators scrutinizing consumer AI services under the EU General Data Protection Regulation framework, with the Garante previously taking enforcement action against OpenAI in 2023 over similar concerns about ChatGPT. The fine applies to a non-EU company operating a service accessible to EU residents, reinforcing the extraterritorial reach of EU data protection enforcement for AI platforms regardless of where the developer is headquartered.

Why it matters

  • ·Any enterprise deploying or procuring consumer-facing generative AI services with EU users faces direct exposure to DPA enforcement if age verification, lawful processing bases, and transparency disclosures are not demonstrably in place, as this fine confirms that regulators will act against non-EU operators under existing GDPR powers without waiting for the EU AI Act's full implementation.
  • ·The enforcement highlights a specific control gap around age-appropriate design: organizations that have not built documented age-gating or parental consent workflows into their AI product intake and vendor assessment processes are carrying unquantified regulatory risk, particularly for platforms with broad consumer reach.
  • ·For compliance teams that use or distribute third-party generative AI tools to external users, this action reinforces the need for vendor due diligence programs that go beyond security reviews to include data minimization practices, lawful basis documentation, and minor-protection controls as standard procurement conditions.

Governance controls affected

What to do now

  • Audit all consumer-facing or broadly accessible generative AI tools in your portfolio for documented age-verification and minor-protection controls, and escalate any gaps to your data protection officer.
  • Review the lawful processing basis recorded for each AI service accessible to EU residents, ensuring consent or legitimate interest assessments are current and cover AI-specific data flows.
  • Update third-party AI vendor due diligence questionnaires to include explicit requirements for age-gating mechanisms, data minimization practices, and minor-user data handling policies.
  • Map your consumer-facing AI services against EU DPA enforcement patterns to assess which products share characteristics with platforms already subject to regulatory action, including persona-based or conversational formats.
  • Ensure your external complaints and redress mechanism for AI services is visible, functional, and logged, as regulators increasingly treat inadequate user recourse as a standalone compliance failure.

What to watch next

Compliance teams should monitor whether other EU data protection authorities follow Italy's Garante with parallel investigations into generative AI platforms, particularly those with minor-user exposure, as coordinated DPA enforcement across member states would substantially raise the cost of non-compliance for any non-EU AI operator. The European Data Protection Board is expected to issue further harmonized guidance on AI and children's data, which could formalize age-verification expectations across all member states. Organizations should also track whether the EU AI Act provisions on prohibited AI systems and transparency, which became applicable in February 2026, are cited alongside GDPR in future enforcement actions, as dual-framework liability could significantly increase financial exposure for consumer AI platforms.

Stay ahead of stories like this

Get every EU AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Corporate Policy2026-08-12

Twitch's Default Opt-In for AI Training Exposes Consent Design Risks

Twitch has introduced a privacy toggle allowing streamers to opt out of having their content used to train Amazon's generative AI models, but the setting defaults to opted-in and covers only future data collection. The opt-out does not apply to content already collected, and a streamer's chat activity on another channel remains subject to that channel owner's preference. The move illustrates how platform-level training data consent is being operationalized at scale, and why the design choices matter for enterprise governance teams.

Research2026-08-15

Exposed MCP Bridge in Ruflo Enables Command Execution and API Key Theft

Check Point Research's August 3 threat intelligence report documents a critical vulnerability in the Ruflo AI agent platform, where an exposed Model Context Protocol bridge allowed attackers to execute commands, steal API keys, access conversations, and tamper with agent memory. The same report flags a privacy issue in Anthropic's Claude sharing feature, noting that shared conversation content became indexable by search engines. Both incidents carry direct compliance implications for enterprises deploying AI agents or using Claude as a business tool.

Corporate Policy2026-08-14

OpenAI's Computer History Feature Brings Keylogging and Prompt Injection Into Enterprise Scope

OpenAI has introduced an opt-in feature called Computer History for ChatGPT Pro, Business, and Enterprise users on macOS that records keystrokes, clicks, and app context to build AI memories over time. Interaction data is stored unencrypted locally for up to 48 hours before being transmitted to OpenAI servers for summarization, with resulting memory files potentially retained for longer periods. The feature is unavailable in the EEA, Switzerland, and the UK, and requires admin approval before Business and Enterprise users can enable it.