The decision
On July 3, 2026, Italy's data protection authority, the Garante per la protezione dei dati personali, fined Character Technologies Inc. — the U.S. company behind the AI companion app Character.AI — €158,000 for a string of GDPR violations. The regulator announced the sanction on July 9 in a press release accompanying the full decision.
The findings are specific and, on the facts the Garante cites, hard to dismiss. Character's privacy notices failed to meet the transparency standard in GDPR Articles 12–14. The company had not completed a Data Protection Impact Assessment before launching a service that lets anyone, including children, converse at length with AI-generated personas — a DPIA is meant to precede exactly this kind of high-risk processing under Article 35. Age verification did not reliably screen out under-16 users, and minors' profiles were not private by default, both cutting against the privacy-by-design obligations in Articles 24 and 25. Character also appointed its EU representative — required under Article 27 for any non-EU company processing European users' data — late.
Steelmanning the Garante
The case for taking this seriously is straightforward. Character.AI is not a search engine or a shopping app; it is a product explicitly designed to sustain long, emotionally intimate conversations, and it has attracted a large teenage user base. That combination has already produced tragedy in the United States: Megan Garcia sued Character Technologies and Google in October 2024 after her 14-year-old son, Sewell Setzer III, died by suicide following months of conversation with a Character.AI chatbot. Google and Character.AI agreed to settle that case and related suits from Colorado, Texas and New York on January 8, 2026, according to court filings reported by Jurist. Against that backdrop, a regulator that finds a broken age gate and public-by-default child profiles is not manufacturing a problem. GDPR's DPIA and privacy-by-design requirements exist precisely to force this kind of risk assessment before deployment, not after a wrongful-death suit.
Where the fine undercuts itself
The trouble is proportionality — and the Garante's own record supplies the yardstick. In May 2025, the same regulator fined Replika's developer, Luka Inc., €5 million for a strikingly similar profile: no valid legal basis for processing user data and no functioning age verification on an AI companion app, as confirmed by Global Banking & Finance, which also notes the Garante's history of suspending Replika in 2023 over child-safety concerns. Character.AI is comparable in scale and user base to Replika, and its violations — an age gate that did not work, defaults that exposed minors — are not obviously milder. Yet the fine here is roughly 3% of the Replika penalty.
A sanction that size functions less as a deterrent than as a compliance memo with a price tag attached. Character Technologies is a company that, following the U.S. litigation, has already rolled out parental controls and barred under-18 users from open-ended chat — commercially costly product changes made under the threat of tort liability, not GDPR enforcement. Next to that, a six-figure fine plus a 120-day deadline to report fixes to Rome reads as symbolic. If the Garante wants fines to actually shape how AI companion products are built for minors, it needs to apply the penalty scale it has already shown it is willing to use.
The regulatory pile-up
There's a second, structural problem: this fine did not land in isolation. On August 2, 2026, the EU's AI Act transparency rules came into force across the bloc, requiring chatbots to disclose that users are talking to a machine, with penalties up to €15 million or 3% of global turnover for noncompliance, per Help Net Security. Character.AI is now navigating GDPR enforcement from a national regulator and AI Act enforcement from the EU's AI Office simultaneously, with different legal tests, different remedies and different deadlines, all aimed at overlapping harms.
That overlap is a genuine cost, and not just for Character Technologies. A well-resourced U.S. company can absorb parallel compliance tracks; a smaller EU-based startup building safety-focused companion AI cannot as easily. Coherent, risk-proportionate enforcement — one clear signal about what "safe enough for minors" means, backed by penalties that actually track the harm — would do more for both child safety and a competitive European AI sector than two regulators independently re-litigating the same underlying facts. The Garante was right to act. It should not mistake a modest fine for a solved problem.