Italy Italy Garante GDPR AI enforcement

Italy's €158,000 Character.AI Fine Shows GDPR's Age-Verification Gap, Not Its Enforcement Muscle

Garante's fine over weak minor safeguards is dwarfed by its €15M OpenAI penalty — proportionality, not just severity, will decide if AI child-safety rules work.

Italy's AI Child-Safety Enforcement, By the Numbers People of Internet Research · Italy €158,000 Character.AI fine Imposed by the Garante on July 9, … €15M OpenAI fine, 2024 Same regulator's penalty for train… 120 days Compliance deadline Time given to report adopted age-v… peopleofinternet.com
Italy's AI Child-Safety Enforcement, B… People of Internet Research · Italy €158,000 Character.AI fine €15M OpenAI fine, 2024 120 days Compliance deadline peopleofinternet.com

Key Takeaways

Italy's data protection authority, the Garante per la protezione dei dati personali, fined Character Technologies Inc. €158,000 on July 9, 2026, for failing to adequately verify the ages of users on Character.AI, the generative AI platform that lets people converse with AI-generated personas. The decision, issued July 3 and published six days later, followed an ex officio investigation and found deficient privacy notices, a late Data Protection Impact Assessment, a delayed EU representative appointment, and — the core of the order — age-verification systems that didn't reliably keep minors out or stop blocked minors from simply re-registering.

The Case for Intervention

The strongest version of the Garante's case doesn't need embellishing. Character.AI is not a hypothetical risk case: it is the company behind Garcia v. Character Technologies, the wrongful-death suit brought after 14-year-old Sewell Setzer III died by suicide in February 2024 following months of an emotionally and sexually charged relationship with a chatbot on the platform. Character Technologies and Google settled that suit in January 2026 without disclosing terms — an acknowledgment, however implicit, that the underlying safety failures were real. Against that backdrop, a regulator insisting that age gates actually function, and that minors who are blocked can't simply create a new account minutes later, is not reaching for a novel or speculative harm. It is responding to a documented one. The remedies the Garante ordered — working age verification, an effective "cooling-off" barrier against re-registration, and private-by-default profiles for minors, to be reported within 120 days — are narrow, specific, and directly responsive to that failure mode. This is what proportionate enforcement is supposed to look like: not a platform ban, not a data-processing shutdown, but a fix demanded of the exact control that broke.

Why the Number Undercuts the Message

And yet the fine itself tells a different story than the violation does. €158,000 is a rounding error for Character Technologies, whose valuation has been reported in the billions since Google's 2024 licensing-and-hire deal with the company's founders. For comparison, the same regulator fined OpenAI €15 million in December 2024 for unlawful training-data processing and failure to follow prior corrective orders — a case that also involved inadequate under-13 protections. The GDPR's own ceiling for infringements of this kind runs to the higher of €20 million or 4% of global annual turnover. Whatever the Garante's internal calculus on Character.AI's Italian revenue and cooperation, a five-figure-into-six-figure penalty for a company already the subject of a fatal-outcome lawsuit reads less like deterrence than like a procedural marker. It signals that the Garante is watching; it does not obviously signal that ignoring an age-verification order costs more than fixing one.

An Emerging Playbook, Not a One-Off

What makes this fine worth tracking is the pattern it extends, not its size in isolation. The Garante briefly banned ChatGPT outright in April 2023 over training-data legality and the absence of age checks, before OpenAI restored access by adding a birth-date gate and an under-13 block. Ireland's Data Protection Commission has since opened its own large-scale inquiry into X's Grok over AI-generated sexualized images of children. Read together, these cases show European regulators converging on a specific theory of AI harm: not the model's outputs in the abstract, but the absence of working guardrails between those outputs and minors. That is a defensible and comparatively narrow theory — it targets an access-control failure rather than the technology's existence — and it gives AI companies operating in the EU a clear, replicable compliance target: verify age, block re-registration by evaders, default minors to the most restrictive settings.

The Innovation Case, Held Honestly

None of this argues against enforcement. It argues for enforcement that is calibrated to actually change incentives rather than merely to generate a press release. A regulator that fines a company implicated in a minor's death the same order of magnitude it might levy for a late DPIA filing blurs the line between paperwork violations and safety failures — and blurring that line is bad for both goals. Companies building conversational AI products aimed at, or accessible to, teenagers should read the Garcia settlement and the Garante's order as the same signal: age-gating is not a compliance checkbox, it is the product's core safety mechanism, and getting it wrong now carries legal, reputational, and — eventually, if regulators calibrate fines to match the OpenAI precedent rather than this one — genuine financial exposure. The Garante's 120-day compliance deadline is a reasonable, proportionate mechanism. Its fine schedule, so far, is not yet the deterrent that mechanism needs.

Sources & Citations

  1. Garante Privacy — official decision announcement
  2. Megan Garcia v. Character Technologies — Tech Policy Press case tracker
  3. CBS News — Character.AI, Google settle teen suicide lawsuit
  4. Lewis Silkin — OpenAI faces €15 million Garante fine
  5. Euronews — Ireland DPC investigates X's Grok over child-safety images