A narrow, well-evidenced finding
Italy's data protection authority, the Garante per la protezione dei dati personali, closed a 20-month investigation into Character Technologies — the U.S. company behind the AI companion chatbot Character.AI — with a decision dated July 3, 2026 and made public July 9. The penalty: €158,000, plus a 120-day deadline to report compliance measures back to the regulator (Garante decision, doc. 10269571; Garante press release).
The substance is specific, not sweeping. The Garante's own technical testing found that Character.AI's self-declared birth-date age gate could be defeated by simply entering a false date — the regulator's testers registered an account as a 15-year-old despite the platform's nominal 16-and-up threshold for European users. That gap was live from April 8, 2024 through roughly April 8, 2025, a year-long window in which under-16 users could plausibly access the service (Garante decision). Layered on top: a data protection impact assessment that wasn't completed until November 14, 2024, months after the EU-facing product had launched; an EU representative (VeraSafe Ireland) not designated until May 31, 2025, with a non-functional contact address at first; and minor accounts defaulting to public visibility rather than private — a design choice the Garante called incompatible with data-protection-by-default principles for a vulnerable user base (Garante decision; ANSA).
The case for the fine
The strongest version of the Garante's position isn't hard to make. An AI companion product designed to sustain long, emotionally engaged conversations is a materially different risk than a static webpage, and regulators worldwide — including the U.S. Federal Trade Commission, which opened a child-safety inquiry into seven chatbot companies including Character.AI in September 2025 — have converged on the view that self-declared birth dates are not "age verification" in any meaningful sense; they are a formality a curious 13-year-old defeats in ten seconds. A public-by-default profile for a minor engaging with an AI companion compounds the exposure. The Garante's order doesn't ask for anything exotic — working age gates, a cooling-off period so a blocked minor can't just re-register with a new fake birthdate, private-by-default settings — and gave the company 120 days to show its work. That is proportionate, not punitive, process.
Why the number matters more than the finding
What makes this fine analytically interesting is its size relative to Italy's other headline AI enforcement action. In December 2024 the Garante fined OpenAI €15 million over ChatGPT's early data practices — nearly a hundred times Character.AI's penalty. On March 18, 2026, the Court of Rome annulled that fine entirely, but on jurisdictional grounds, not the merits: OpenAI had established an Irish subsidiary in March 2023, Ireland's DPC was recognized as lead authority under the GDPR's one-stop-shop mechanism by February 2024, and the court held Italy had no authority left to issue its decision by the time it acted in November 2024 (ppc.land). The substantive allegations against OpenAI were never actually tested.
Character.AI has no such EU subsidiary — only an Article 27 representative — so the Garante's jurisdiction here is comparatively bulletproof, and the fine reflects a genuinely bounded, evidenced failure rather than a maximalist opening bid. That's the right instinct: a €158,000 penalty tied to a specific, testable defect (an age gate the regulator's own staff walked through) is a more credible enforcement signal than a nine-figure number that later evaporates on a technicality. Companies can plan around clear, proportionate rules; they can't plan around regulators reaching for the largest number the statute allows and hoping it survives appeal.
The steeper test is still coming
The harder question hangs over the sector, not this ruling. The European Parliament's Internal Market Committee has already floated an EU-wide digital minimum age of 16 for AI companions and social media absent parental consent, with a floor of 13 for social media generally — a position debated in Parliament through late 2025 (European Parliament press release). Character.AI itself moved well past self-declared birthdates in the interim: on October 29, 2025 it announced it would remove open-ended chat for all under-18 users outright, with the restriction phased in by November 25, 2025 and paired with new age-verification technology and an independent AI Safety Lab (Character.AI). That change came after lawsuits tied to teen suicides and well before this month's Italian order — meaning the fine effectively certifies a defect the company had already moved to fix through a blunter instrument: banning the product for minors altogether rather than perfecting who counts as one.
That sequencing is the real lesson for regulators watching Italy. A narrowly evidenced, proportionate fine that lands after the underlying harm has already been substantially addressed by the market is a weaker deterrent than a credible enforcement threat issued while the defect is live. If the EU's forthcoming minimum-age framework is going to bind an entire product category rather than one company's stale age gate, it needs to move at the speed of the technology it's regulating — not two investigation cycles behind it.