
Character.AI's €181K Garante Fine: A Case Study in What Regulators Now Consider an AI Privacy Violation
On July 9, 2026, Italy's data protection authority (the Garante) published its decision fining Character Technologies roughly €158,000 (reported variously as ~$181K) for a stack of GDPR violations. The fine itself is modest. The remedial order attached to it is not. If you ship an AI product that touches European users, this enforcement action is a privacy checklist written in regulatory ink, and you should read it as one. Below, we walk through exactly what the Garante flagged, why each item matters operationally, and how to audit your own product against the same criteria before a regulator does it for you.
Key Takeaways
- The Garante cited Character.AI for inadequate transparency notices, a late Data Protection Impact Assessment (DPIA), failure to appoint an EU representative, weak age verification, and missing safeguards for minors. Each of these is a discrete, auditable item you can check in your own product today.
- The DPIA and EU representative failures are cheap to fix and appear in nearly every recent Garante AI enforcement action. If you haven't done both, they are the highest-ROI compliance tasks you can complete this quarter.
- The remedial order goes beyond the fine: working age-gate mechanisms, a "cooling-off period" to prevent re-registration by blocked minors, private-by-default profiles for minors, and a 120-day reporting deadline. These are now the de facto standard the Garante expects.
- The Replika precedent (a €5 million fine for similar violations) shows the Garante escalates penalties when it sees repeat patterns across the sector. The Character.AI fine is a warning shot, not a ceiling.
- The training-data question (whether conversation logs can lawfully be reused to train models) was explicitly split off in the Replika case and may be the next vector of enforcement. Fixing your onboarding flow does not close your exposure.
What Exactly Did the Garante Flag?
The Garante identified five categories of violation. We list them in the order that matters for a technical founder conducting a self-audit, not in the order the regulator happened to write them up.
1. Transparency and Data-Processing Notices
The regulator found shortcomings in the information provided to users about how their personal data is processed. In GDPR terms, this means the Articles 13/14 notices were either incomplete, unclear, or not surfaced at the right moment. For a conversational AI product, this is particularly consequential because the data being processed includes the content of conversations, which can be intimate, health-related, or otherwise sensitive. A privacy policy buried three clicks deep, written in dense legalese, and failing to explain what happens to chat logs at inference versus at training time, does not satisfy the Garante's standard.
Concretely: your notice needs to explain, in language a user can actually parse, what data you collect from conversations, how long you keep it, whether it feeds back into model training, and who (which processors or sub-processors) can access it. Generic boilerplate about "improving our services" is exactly the kind of language regulators treat as insufficient.
2. Late DPIA
Character Technologies was found to have been late in conducting a Data Protection Impact Assessment. A DPIA is required under Article 35 whenever processing is "likely to result in a high risk" to individuals. A conversational AI product that stores user messages and generates persona-based responses clearly qualifies. Being "late" means the company launched or continued operating the service in the EU before completing the assessment. The Garante treats this as a substantive violation, not a paperwork oversight, because a DPIA shows how a company weighs risks in its data handling, and without one, the regulator has no evidence that risks were weighed at all.
3. No EU Representative
Character Technologies, a U.S. company, failed to appoint an EU representative in a timely manner. Under Article 27, a non-EU controller that processes EU residents' data must designate a representative in the Union. This gives regulators a local point of accountability. Skipping it does not save you anything meaningful in cost, and it signals to the regulator that you are not set up to respond to their inquiries, which tends to make those inquiries more aggressive.
4. Age Verification
The Garante found the platform lacked robust mechanisms to prevent young minors from registering or being exposed to unsuitable content. eWeek reported "critical issues" in protections for minors and in age-verification systems. This is not about having zero age gate. It is about having one that does not actually work. A self-declared date-of-birth field, with no verification layer and no friction for a 12-year-old who types "1999," is exactly the kind of mechanism regulators now reject.
5. Minor-Specific Safeguards
Beyond the gate itself, the Garante looked at what happens to minors who do get through. The remedial order specifies that minors' profiles must be set to private by default, and the platform must implement a "cooling-off period" to prevent blocked minors from immediately creating a new account. These are product-level controls, not policy statements. The regulator is telling you what your code needs to do.
How Does This Compare to the Replika Fine?
The Replika case is the obvious precedent, and the comparison is instructive. The Garante fined Replika's developer €5,000,000 for violations of Articles 5(1)(a), 5(1)(c), 6, 12, 13, 24, and 25(1) GDPR, covering unlawful processing, transparency failures, and inadequate age verification. The Character.AI fine is roughly 3% of that amount. The difference likely reflects the scope and severity of findings, the company's cooperation posture, and the specific articles cited. But the trajectory is clear: the Garante fines in this sector are getting more frequent, and the Replika action in 2025 established the template that the Character.AI action follows.
One detail from the Replika case deserves special attention. The Garante deliberately split off the training-data question into a separate track. The lawful basis for reusing conversation data to train a model is a distinct, harder question than the basis for running the chat in real time. An operator that fixed its consumer notice has not necessarily fixed its training-data basis. This means the Garante may return to Character.AI on exactly this issue.
Why Is the Fine Amount Almost Irrelevant?
€158,000 is a small number for a company valued in the billions. Most coverage fixates on the amount. The amount is not the point. The remedial order is the point. The Garante specified concrete technical and procedural changes with a 120-day reporting deadline. Failure to comply with a remedial order escalates enforcement significantly. And the specific remedies listed in this order are now precedent: the next AI company the Garante investigates will be measured against these same expectations from day one, not given the grace of a first offense.
The escalation pattern is also worth noting. At the end of 2024, the Garante issued a €15 million fine in the first generative-AI-related GDPR case against a separate chatbot maker. The numbers are trending in one direction.
What Should You Actually Audit in Your Own Product?
Here is a concrete checklist derived from the Character.AI remedial order and the Replika precedent. These are not hypotheticals; each item maps to a specific regulatory finding.
DPIA: Is Yours Done, Current, and Dated Before Launch?
The Garante flagged "late" completion. Your DPIA needs to be completed before you process EU user data, not after a regulator asks for it. If you have already launched without one, complete it now and document when it was done. A DPIA is not a one-time document; it needs updating when your processing changes materially (new model, new data flows, new retention policy). If you are routing requests to a frontier provider at inference, that data flow needs to appear in the DPIA. If you are using conversation data for fine-tuning or training, that is a separate processing activity and needs its own risk assessment.
EU Representative: Is Yours Appointed and Contactable?
This is a solved problem. Third-party services will act as your Article 27 representative for a few thousand euros per year. The cost of not having one, as Character.AI discovered, is orders of magnitude higher. Your representative's contact details need to appear in your privacy notice. This is a half-day task at most.
Transparency Notices: Do They Actually Describe Your Data Flows?
A generic privacy policy template does not satisfy the Garante. Your notice needs to cover, at minimum: what categories of personal data you collect from conversations, the legal basis for each processing purpose (consent, legitimate interest, contractual necessity), retention periods stated concretely (not "as long as necessary"), whether conversation data is used for model training and under what legal basis, the identity of sub-processors or categories of recipients (including inference providers), and how users can exercise their rights (access, deletion, portability). If you use conversation content at inference time and a slice of that content reaches a third-party provider, that needs to be disclosed. Vagueness is what gets flagged.
Age Verification: Does Yours Actually Prevent Minors from Registering?
A date-of-birth dropdown is not age verification. The Garante is looking for mechanisms that create real friction. Options that regulators have treated as more credible include ID-based verification for account creation, credit card verification (imperfect, but adds friction), integration with national digital identity systems where available, and AI-based age estimation (itself raising privacy questions, but increasingly accepted as a supplementary layer). The specific mechanism matters less than whether it actually works. If a 13-year-old can bypass your age gate in under 30 seconds by lying about their birth year, the Garante will treat it as if you have no age gate at all.
Re-registration Prevention: Do You Have a Cooling-Off Period?
The Garante specifically ordered Character.AI to implement a cooling-off period to stop minors who were previously blocked from simply making a new account. This is a product engineering problem. You need to be able to identify re-registration attempts (by device fingerprint, email domain pattern, phone number, or other signals) and enforce a waiting period before a blocked user can create a new account. The exact implementation is up to you, but "we delete the account and they sign up again five minutes later" is the specific failure mode the Garante is targeting.
Default Settings for Minors: Are Minor Profiles Private by Default?
If your product allows any users under 18 (and in some EU member states, the relevant age is 16 or even 14 depending on the Article 8 derogation), their profiles and interaction histories need to be private by default. Not "we recommend setting your profile to private." Private by default, in the code, at account creation. Public must be an opt-in, not an opt-out.
Content Safeguards: Can Minors Access Adult or Harmful Content?
The Garante found that Character.AI's platform could expose minors to potentially adult or unsuitable content. If your AI product generates open-ended text, you need content filtering that is age-appropriate. For accounts identified as belonging to minors, the filtering threshold needs to be meaningfully different from the default. This is not a moderation nicety. It is a regulatory requirement that the Garante is actively enforcing.
What About the Training-Data Question?
This is the item most likely to generate the next wave of enforcement, and it was not fully resolved in either the Character.AI or Replika actions. The core question: under what legal basis can you use the content of user conversations to train or fine-tune your models?
Consent is one option, but GDPR consent needs to be freely given, specific, informed, and unambiguous. A blanket clause in your terms of service is unlikely to qualify. Legitimate interest is another option, but requires a balancing test documented in your DPIA, and the intimate nature of conversational data makes that balance harder to strike. The Replika case explicitly reserved this question for a separate proceeding, meaning the Garante has signaled it will return to it.
If you are currently using conversation data for training and your legal basis for doing so is "we haven't really thought about it," you have a live compliance gap. This is true regardless of whether you anonymize or aggregate the data before training, because the Garante will ask whether the anonymization is truly irreversible and whether the original collection was lawful in the first place.
How Does Garante Enforcement Fit into the Broader EU Pattern?
The Garante has been among Europe's most active regulators in policing AI-related privacy issues. It temporarily restricted a major chatbot service before fining it. It fined Replika's developer. It issued the €15 million fine at the end of 2024. The Character.AI action continues that pattern.
For founders, this means Italy is the jurisdiction most likely to act first, but not the only jurisdiction that matters. The GDPR's consistency mechanism means other EU data protection authorities are watching the Garante's reasoning and may adopt similar positions. The eWeek analysis noted that for AI developers operating in Italy and the wider European market, age checks are no longer just a UX feature. Regulators increasingly treat them as part of a broader compliance system including transparency, privacy risk assessments, child safety controls, and local representation.
The EU AI Act adds another layer. Conversational AI systems that interact with natural persons are subject to transparency obligations under the AI Act, on top of GDPR requirements. The two regulatory frameworks are interrelated but not identical, and compliance with one does not guarantee compliance with the other.
What Does a "Lifecycle" Compliance Approach Look Like?
The pattern across Garante enforcement actions suggests that treating GDPR compliance as a one-time onboarding-screen fix is the single most common mistake AI companies make. The lifecycle has at least four stages, and each has distinct compliance requirements.
Collection. What data do you collect, under what legal basis, and did you tell the user clearly before collecting it? This is the transparency-notice issue from the Character.AI decision.
Training. If conversation data feeds back into model training, you need a separate legal basis for that processing purpose. The training-data question is live and unresolved in Garante case law.
Deployment. When a user sends a message and your system processes it at inference, what data reaches which processor? If content transits to a frontier provider, your privacy notice and your DPIA both need to account for that. If you store conversation history for context continuity, your retention policy needs to specify how long and why.
Retention and Deletion. When a user deletes their account, what actually happens to their data? Is conversation history purged from your primary datastore? From backups? From any training datasets it was incorporated into? The Garante has not yet explicitly litigated the "delete means delete" question for training data in the AI context, but the direction of travel is obvious.
How We Think About This at Selina
We build an AI assistant with persistent memory, so every issue in this enforcement action is directly relevant to our architecture decisions. A few specifics on how we handle the items the Garante flagged.
On data protection by design: user content is encrypted at rest. Memory is NOT end-to-end encrypted, because a slice of each request reaches a frontier provider at inference. We state this plainly because regulators (and users) deserve to know. Files and transfers via SelinaSEND are zero-knowledge encrypted end-to-end. The account itself is protected, not encrypted. We think the honest distinction matters more than a marketing claim.
On retention: we keep non-content operational metadata for a short retention window, not indefinitely. Content data follows user-controlled retention settings. When a user deletes something, it is gone. Actually gone.
On the DPIA and EU representative: these were completed before we processed our first EU user's data. The DPIA is a living document updated when our data flows change. This is not heroic. It is table stakes, and the Character.AI decision confirms that regulators agree.
On age verification and minor safety: we take this seriously as a product design constraint, not a compliance checkbox. The specifics of our implementation are bounded automatically, but the principle is that friction for minors is a feature, not a bug.
On training data: we route requests to a stack of frontier models, routed per task. We do not train on user conversations. We think the training-data lawful-basis question is the hardest open problem in AI privacy compliance, and we would rather design around it than litigate it.
What Should You Do This Week?
If you are a technical founder or privacy lead at an AI company with EU users, here is the minimum viable response to this enforcement action, ordered by effort-to-impact ratio.
- Check whether you have a completed, dated DPIA that covers your current data flows. If not, start one today. Template resources exist from most EU supervisory authorities.
- Confirm you have an appointed Article 27 EU representative whose contact details appear in your privacy notice. If not, engage one this week. This is a vendor selection task, not a legal research project.
- Review your privacy notice against the specific deficiencies cited in the Character.AI decision: does it explain what happens to conversation data, who processes it, how long it is retained, and whether it is used for training?
- Audit your age-verification mechanism. Have someone on your team try to register as a minor. If they succeed in under a minute, your mechanism does not meet the Garante's standard.
- If you allow minors on your platform, verify that their profiles are private by default in your codebase, not just in your policy documentation.
- Document your legal basis for any use of conversation data in model training. If you do not have a defensible answer, stop using that data for training until you do.
None of these items require retraining a model or rebuilding your inference stack. Most can be completed in days. The Garante's 120-day remediation deadline for Character.AI is generous by enforcement standards. You do not need to wait for your own enforcement action to start.
If you want to see how we built these principles into an AI assistant from the start, start a free 7-day trial, no card required.
Frequently Asked Questions
What did the Garante fine Character.AI for?
The Garante fined Character Technologies about €158,000 (reported as ~$181K) for inadequate transparency notices, a late DPIA, failure to appoint an EU representative, weak age verification, and missing safeguards for minors.
Why does the article say the fine amount matters less than the remedial order?
The €158,000 fine is small for a billion-dollar company, but the remedial order requires specific technical and procedural changes, working age-gates, a cooling-off period, private-by-default minor profiles, within a 120-day reporting deadline, and failure to comply escalates enforcement significantly.
How does the Character.AI fine compare to the Replika case?
Replika's developer was fined €5,000,000, about 33 times larger than Character.AI's fine, for similar violations including unlawful processing, transparency failures, and inadequate age verification, showing the Garante escalates penalties for repeat sector patterns.
What is a DPIA and why was Character.AI cited for it?
A Data Protection Impact Assessment (DPIA) is required under GDPR Article 35 when processing is likely to pose high risk, and Character.AI was cited for completing it late, meaning it operated in the EU before assessing the risks of its data handling.
What unresolved issue from the Replika case might affect Character.AI next?
The Garante separated out the question of whether conversation logs can lawfully be reused to train AI models, a distinct legal basis issue from real-time chat processing, suggesting this could be the next area of enforcement against Character.AI.
Sources & References
- Italy fines Character.AI over age verification failures
- Italy's Garante Fines Character AI Owner €158,000 for GDPR Breaches - TechNadu
- Italy privacy watchdog fines Character.AI owner over age-check failures - AOL
- Garante Fines Character.AI $181,000 for Privacy Violations
- Italy Fines Character.AI Owner over AI Age-Check, Privacy Failures
- Italy Fines Character.AI Owner Over Age-Check and Privacy Failures
- Italy Penalizes Character.AI Owner Over Child Safety and Privacy Controls | PYMNTS.com
- Italy Fines Character.AI Parent Over Age-Check Failures | eWeek
- Italy privacy watchdog fines Character.AI owner over age-check failures
- Press room - Garante privacy en - Garante Privacy
- News & Analysis as of
- Children's Data | Topics | DataGuidance
- Italy's DPA reaffirms ban on Replika over AI and children's privacy concerns | IAPP
- How to Process Children’s Data in AI Apps in a Compliant Way
- Generative AI and GDPR Enforcement in Europe: A Lot of Noise, One Fine, Zero Survivors – Cross-Border Data Forum
- AIR-2026-006: Garante v Luka: Italy's €5M fine on the Replika chatbot for processing without a legal basis | AI Agent Incident Register
- AI and GDPR Compliance: A Practical Guide
- EU AI Act: Mapping the Interplays with the GDPR | IAPP
- Fines for GDPR violations in AI systems and how to avoid them - DPO Europe
- AI Meets the GDPR (Chapter 7) - The Cambridge Handbook of the Law, Ethics and Policy of Artificial Intelligence
- Emotional AI Company Fined for Privacy Violations | Buchanan Ingersoll & Rooney PC
- Garante per la protezione dei dati personali (Italy) - 10130115 - GDPRhub
- Replika’s €5 Million GDPR Fine: Key Takeaways for AI Developers - Captain Compliance
- Italy Slaps $5.6M Fine on Replika AI for Data Privacy Violations - Technology Org
- US-Based AI Developer Fined €5 million for GDPR Violations: Key Takeaways | The CommLaw Group
- Replika massively violates GDPR: Luka Inc. must pay a fine of millions in Italy - Ailance
- Italy Just Fined Replika €5 Million. Privacy UX Enforcement ...
- Replika's €5M GDPR Fine: What It Means for Your Data (2026)
