A modest fine, a pointed finding
On July 3, 2026, Italy's data protection authority, the Garante per la protezione dei dati personali, fined Character Technologies Inc. — parent of the companion chatbot Character.AI — €158,000 (about $181,000) for a cluster of GDPR violations (Garante press release; full ruling). Measured against the GDPR's ceiling of up to 4% of global turnover, the penalty is trivial for a company that raised billions in AI funding rounds. What matters is not the number but what the Garante's technical testing actually found, and the design change it is now forcing.
According to the ruling, when Garante investigators tested Character.AI's age gate on April 8, 2025, they were able to register an account claiming to be 15 years old — despite the platform's own stated minimum of 16 for European users. The authority also found that minor accounts defaulted to public profiles, with no parental controls switched on, which it deemed incompatible with the GDPR's data-protection-by-design principle (Articles 24(1) and 25(2)) for a vulnerable user base. On top of the age-verification failure, the Garante cited unclear privacy notices (Articles 12–14), a Data Protection Impact Assessment that should have preceded the service's 2022 launch but wasn't filed until November 14, 2024, and an EU representative — VeraSafe Ireland — who wasn't designated until May 31, 2025, well after the company's April 2024 official Italian rollout.
Steelmanning the regulator
The case for intervention here is genuinely strong, not manufactured. Character.AI is a chat product built around open-ended, emotionally responsive conversation, marketed to and demonstrably used by teenagers. The company has separately faced wrongful-death and product-liability suits in the US — including a Texas case brought on behalf of children aged 11 and 17, alleging the chatbot encouraged self-harm and produced sexual content — that were resolved in a January 2026 settlement with Character Technologies and Google (CNN). Against that backdrop, a regulator finding that a self-declared age gate could be defeated by simply typing a false birth year, on a platform whose default setting exposed minors' profiles publicly, is not bureaucratic nitpicking. Age-of-majority self-attestation has been a known weak point in consumer platforms for two decades; GDPR's data-protection-by-design requirement exists precisely to force companies to catch that kind of gap before regulators do it for them. The Garante is not asking Character.AI to solve the unsolved problem of AI companionship's mental-health effects — it is asking for privacy-by-default settings and a working DPIA, which is squarely inside a data protection authority's lane.
Where the proportionality argument holds up
Even granting all of that, the enforcement here is a reasonable model of what GDPR-based AI oversight should look like — precisely because it stayed narrow. The Garante did not ban Character.AI, as it briefly did to ChatGPT in 2023, nor did it impose a fine anywhere near the €5 million it levied on the companion app Replika in April 2025 for a near-total absence of age verification (EDPB summary). That gap in penalty size is itself informative: Character.AI had built some age-gating and had eventually filed a DPIA and named an EU representative, however late. The Garante's order — fix the age gate, default minors to private, add a real cooling-off period so blocked minors can't just re-register with a new fake birthdate, and report back within 120 days — is a specific, auditable remedy rather than an open-ended compliance obligation or a ban that would have deprived Italian adults of a lawful product over a minors-only failure.
That is the model worth generalizing as the EU AI Act's own age-assurance and minor-protection provisions come into force over the next two years: enforcement that targets a demonstrated, testable failure — a 15-year-old getting past a 16+ gate — rather than speculative harms from the underlying model architecture. A regime that fined companies for the mere existence of a companion-chatbot product, rather than for specific, reproducible safety-control failures, would chill exactly the kind of consumer AI experimentation that has made Europe a laggard in AI deployment, not just AI research. Where Italian and EU regulators have stuck to the narrower path — proving the safeguard doesn't work, then ordering a fix — the enforcement has been credible rather than performative. The test now is whether Character Technologies' 120-day report shows an age gate that actually holds, or whether the Garante ends up back at the same table in another year.
What to watch
The compliance deadline falls in early November 2026. If the company's report to the Garante is accepted without a further order, this becomes a template for proportionate AI enforcement. If Italian regulators find the fix cosmetic, expect a larger fine on the next pass — Replika's own trajectory from a 2023 precautionary ban to a €5 million fine two years later is the cautionary comparison Character Technologies should be reading closely.