Italy Fines Character AI €158K for Privacy, Child Protection Lapses
In a significant move signaling heightened scrutiny over artificial intelligence, Italy's data protection authority, the Garante per la protezione dei dati personali, has levied a €158,000 fine against Character Technologies Inc. The enforcement action, dated July 9, 2026, targets the company's generative AI service for critical data protection violations, specifically citing inadequate privacy notices and significant issues concerning child protection and age verification. This decision not only carries a substantial financial penalty but also mandates further corrective measures, sending a clear message to AI developers operating within the European Union.
What's changing
This enforcement action by the Garante is a stark reminder that innovative AI services are not exempt from fundamental data protection principles, particularly those enshrined in the General Data Protection Regulation (GDPR) and Italy's evolving national AI framework. The core of Character Technologies Inc.'s violations revolved around two critical areas: transparency and safeguarding minors.
Firstly, the Garante found the company's privacy notices to be inadequate. Under GDPR, organizations must provide clear, concise, and easily accessible information about how personal data is collected, used, stored, and shared. For an AI service that processes user inputs to generate responses, this transparency is paramount. Users need to understand what data fuels the AI, how their interactions contribute to its learning, and what rights they have over their data. Inadequate notices suggest a failure to meet these foundational transparency requirements, leaving users potentially unaware of the implications of using the service.
Secondly, and perhaps more critically, the Garante identified issues with child protection and age verification. Generative AI services, by their nature, can be highly engaging and accessible. Without robust age verification mechanisms, minors can easily access services intended for adults, potentially exposing them to inappropriate content or leading to the processing of their personal data without parental consent. The Garante's focus on this aspect aligns with the GDPR's specific protections for children's data and reflects a growing global concern about the impact of AI on younger users. The order for corrective measures indicates that the Garante expects Character Technologies Inc. to implement concrete changes to address these deficiencies, likely involving more stringent age verification protocols and clearer communication regarding the suitability of its service for different age groups.
This action also sits within the broader context of Italy's proactive approach to AI regulation. Law 132/2025, which governs Italy's AI landscape, aligns with the overarching principles of the EU AI Act while introducing national specificities, such as criminal penalties for deepfakes and strict localization requirements for public sector AI. While the specific provisions of Law 132/2025 may not have been directly cited in this GDPR-focused enforcement, the Garante's action reflects the same regulatory intent: to ensure AI development and deployment are responsible, ethical, and compliant with existing data protection and emerging AI governance standards. The involvement of authorities like AgID and ACN in Italy's AI governance further underscores the multi-faceted regulatory environment AI companies must navigate.
Who is affected
This enforcement action has broad implications for a range of entities, extending beyond just Character Technologies Inc. and the generative AI sector:
- Generative AI Developers and Providers: Any company offering AI services that interact with users, particularly those that process personal data or could be accessed by minors, must take note. This includes chatbots, content generators, virtual assistants, and other interactive AI platforms. The Garante's decision sets a precedent for how privacy notices, age verification, and child protection will be scrutinized.
- Companies Operating in Italy and the EU: While the fine was issued by the Italian Garante, the underlying principles are rooted in the GDPR, which applies across the entire European Economic Area. Companies targeting or serving users in Italy, or any EU member state, must ensure their data protection practices, especially for AI services, are up to standard. This includes both EU-based companies and those outside the EU offering services to EU residents.
- Any Organization Handling User Data: The emphasis on clear privacy notices is a universal data protection requirement. This case serves as a general reminder for all organizations to regularly review and update their privacy policies to ensure they are transparent, comprehensive, and easily understandable for their users, especially when new technologies like AI are introduced into their services.
- Companies with Services Accessible to Minors: Organizations whose products or services could potentially be used by children must implement robust age verification and child protection measures. This is not limited to AI but is particularly pertinent for engaging digital services.
Three things to do this week
In light of the Garante's action against Character Technologies Inc., organizations, especially those developing or deploying AI services, should take immediate steps to review and bolster their compliance posture:
- Review and Enhance Privacy Notices for AI Services: Conduct a thorough audit of your privacy policies and notices, particularly those related to AI-driven features. Ensure they clearly and explicitly detail how personal data is collected, processed, and used by your AI models. Explain the logic involved in automated decision-making (if applicable) and how users can exercise their data rights. Use plain language, avoid jargon, and make the information easily accessible and understandable, especially for the average user. This transparency is a cornerstone of GDPR compliance.
- Implement Robust Age Verification and Child Protection Protocols: If your AI service could potentially be accessed by minors, develop and deploy effective age verification mechanisms. This might involve technical solutions, clear age gates, or requiring parental consent for users below a certain age. Beyond verification, assess the content and interactions of your AI to ensure it is appropriate for the intended audience and does not pose risks to children. Proactively design your service with child safety and data protection in mind from the outset.
- Conduct Data Protection Impact Assessments (DPIAs) for AI: For any new or significantly modified AI service that involves high-risk data processing, perform a comprehensive Data Protection Impact Assessment. A DPIA helps identify and mitigate data protection risks before deployment. This includes evaluating the necessity and proportionality of data processing, assessing the risks to individuals' rights and freedoms, and outlining measures to address those risks, such as data minimization, pseudonymization, and security controls. This proactive approach can help uncover potential compliance gaps before they lead to enforcement actions.
Related context
The Garante's fine against Character Technologies Inc. is not an isolated incident but part of a broader trend of increased regulatory scrutiny over AI and data protection in Italy and across the EU. The Italian authority has consistently demonstrated its commitment to enforcing data protection principles in the face of emerging technologies.
For instance, in 2024, the Garante fined Cappello Giovanni & Figli S.r.l. €120,000 and banned its X-Face 380 facial-recognition system for employee attendance control, citing a lack of legal basis for such intrusive processing. This highlights the Garante's willingness to take strong action against technologies deemed disproportionate or non-compliant. Furthermore, in October 2025, the Garante ordered an immediate stop to the Clothoff app, which used AI to 'undress' people in images, citing serious ethical and data protection concerns. These actions collectively paint a picture of a proactive regulator determined to curb the misuse of AI and protect individual rights.
This Italian enforcement also aligns with the broader European regulatory push. Italy's national AI framework, particularly Legge n.132 del 23 settembre 2025 - Disposizioni e deleghe al Governo in materia di intelligenza artificiale (/regulations/RAI-IT-NA-LND2SXX-2025), and the preceding Disegno di legge n.1146 - Disposizioni e deleghe al Governo in materia di intelligenza artificiale (/regulations/RAI-IT-NA-DDLNDXX-2025), demonstrate a comprehensive effort to regulate AI. These national efforts complement the upcoming EU AI Act, creating a robust and complex regulatory environment. Other EU member states, like Spain, are also developing their own AI regulation frameworks (/regulations/RAI-ES-NA-SUMMARY-2026), indicating a continent-wide commitment to responsible AI governance. Companies must therefore consider not just national laws but also the harmonized and sometimes divergent requirements across the EU.
Note: this article was drafted by AI - Google Gemini