Italy Italy Garante GDPR AI enforcement

Character.AI's Fine Shows GDPR Enforcement Now Turns on Where You Incorporate, Not What You Did

Italy fined Character.AI €158,000 for GDPR lapses months after a Rome court voided a €15M OpenAI fine on pure jurisdictional grounds.

Italy's AI Chatbot Fines: A Widening Gap People of Internet Research · Italy €158K Character.AI fine Garante decision issued July 3, 20… €5M Replika fine Italy fined Luka Inc. in April 202… €15M OpenAI fine, annulled Rome's court voided this fine in M… ~4 years Violations to decision Garante traces Character.AI's brea… peopleofinternet.com
Italy's AI Chatbot Fines: A Widening G… People of Internet Research · Italy €158K Character.AI fine €5M Replika fine €15M OpenAI fine, annulled ~4 years Violations to decision peopleofinternet.com

Key Takeaways

Italy's data protection authority, the Garante per la protezione dei dati personali, fined Character Technologies Inc. — the U.S. company behind the companion chatbot app Character.AI — €158,000 on July 3, 2026. The decision, published July 9, cites violations dating back to September 2022: deficient privacy notices (Articles 12, 13, 14 GDPR), a late data protection impact assessment (Article 35), inadequate security and privacy-by-design measures (Articles 24, 25), a delayed EU representative appointment (Article 27), and — the headline concern — insufficient age verification for minors on a platform where users can carry on unlimited, emotionally intimate conversations with AI personas. The company now has 120 days to report the fixes it has made: working age checks, a cooling-off mechanism so blocked minors can't simply re-register, and private-by-default profiles for underage users.

The steelman for the fine

The Garante's concern is not manufactured. Character.AI has been named in multiple wrongful-death lawsuits in the United States, including the widely covered case brought by Megan Garcia in Florida after her 14-year-old son died by suicide following months of conversation with one of the platform's chatbots. The U.S. Federal Trade Commission opened an inquiry into seven companion-chatbot operators, Character.AI among them, in September 2025 over exactly this kind of harm. A platform that lets a 13-year-old open an account with no functioning age gate and no limit on how long or how intensely they engage with a simulated relationship is not a hypothetical risk — it is a demonstrated one. Regulators asking whether privacy-by-design obligations were actually met before minors were exposed to that risk are asking a fair question, and a DPIA finished late is a DPIA that arrived after, not before, the product went live to children.

A fine that is oddly small for the pattern it fits

Set against Italy's own enforcement record, though, €158,000 looks less like a proportionate penalty and more like a footnote. The Garante fined Luka Inc., maker of the companion chatbot Replika, €5 million in April 2025 for nearly identical failures — no valid legal basis for processing, no working age verification — after having provisionally blocked the app outright in February 2023. It fined OpenAI €15 million in November 2024 over ChatGPT's training-data legal basis, transparency gaps, an unreported 2023 data breach, and its own age-verification shortfalls. Character.AI's conduct, as described in the Garante's own decision, tracks closely with both predecessor cases. The gap in the fine isn't a gap in the violations. It's a gap in exposure.

Why OpenAI's fine disappeared and Character.AI's didn't

Here is the part of the story that matters more than the €158,000 figure itself. On March 18, 2026, Rome's Tribunale Ordinario annulled the Garante's €15 million ChatGPT fine — not because the underlying GDPR violations weren't real, but because of timing. GDPR's "one-stop-shop" mechanism (Articles 55–56) assigns lead-authority status to whichever national regulator sits where a company's main EU establishment is located. Ireland's Data Protection Commission recognized OpenAI Ireland Ltd. as that establishment on February 15, 2024. The Garante didn't finalize its ChatGPT decision until nine months later, in November 2024 — by which point, the court held, jurisdiction had already passed to Dublin. The substantive violations were never actually adjudicated; the case just evaporated on a technicality of corporate structure.

Character.AI has no equivalent escape route, because it has no EU subsidiary — only the Article 27 representative it was, per the Garante's own findings, late in appointing. Without an EU establishment, there is no lead authority to shop to; every national DPA where the app is used can act on its own. That is precisely the asymmetry legal scholars flagged after the Rome ruling: a company that never sets up shop in the EU remains exposed to fragmented, uncoordinated enforcement from all 27 member states, while a company that formalizes an EU presence — even belatedly, even strategically — can consolidate proceedings under one regulator and potentially outrun them on the clock. The company with the weaker EU footprint faces the more direct enforcement. That is backwards incentive design for a privacy regime that is supposed to reward good-faith compliance infrastructure, not corporate domicile timing.

The faster fix came from liability, not regulation

It's also worth noting what the Garante's decision does not claim credit for. Character.AI banned under-18 users from open-ended chats entirely, effective November 25, 2025 — eight months before this fine landed — rolling out age-verification tools and capping, then eliminating, unsupervised minor access. That move came in direct response to the wrongful-death lawsuits and the FTC inquiry, not the Italian proceeding, whose underlying facts date back to at least September 2022. The market and litigation pressure produced the safety change faster than the regulatory process did.

None of this argues against holding AI companies to real privacy and child-safety standards — the underlying obligations are sound, and the Garante's findings on stale privacy notices and late impact assessments are well within its mandate. But a regime where the size of your fine depends on whether your lawyers filed the right incorporation paperwork before a court deadline, rather than on the severity of the harm, is not protecting anyone consistently. The EDPB should move to close the incorporation-timing gap the Rome ruling exposed — clarifying that one-stop-shop transfer applies prospectively, not retroactively to conduct predating the establishment — before more AI companies learn that the fastest way to shrink GDPR exposure is a Dublin filing, not a safer product.

Sources & Citations

  1. Garante — Character.AI sanction press release
  2. EDPB — Italian authority fines Replika (Luka Inc.)
  3. Euronews — Character.AI bans under-18s after teen suicide lawsuit
  4. PPC Land — Rome court annuls OpenAI's €15M Garante fine
  5. European Law Blog — one-stop-shop and the AI enforcement gap