TL;DR: Italy's Garante fined Character Technologies Inc. -- the company behind Character.AI -- 158,000 euros ($181,000) on July 9, 2026, for inadequate age verification, late GDPR compliance work, and weak protections for minor users. The regulator ordered a cooling-off period preventing blocked minors from immediately re-registering, private-by-default profiles for minors, and a 120-day remediation report. The case is Europe's clearest enforcement statement yet on what companion AI operators owe minor users under GDPR, and the ordered remedies map almost exactly onto Colorado's HB 26-1263 requirements taking effect January 1, 2027.
Character.AI is designed for frictionless engagement. No credit card required, minimal friction at sign-up, a product model built on keeping users in conversation. For adult users, that's the value proposition. For the 14-year-old Italian girl whose conversations with a Character.AI persona preceded her death by suicide in late 2023, it was also the entry point for a two-and-a-half-year investigation that concluded with Italy's data protection authority issuing the clearest enforcement template yet for companion AI age verification.
On July 9, 2026, the Garante per la protezione dei dati personali fined Character Technologies Inc. 158,000 euros and issued a set of mandatory operational orders. The fine amount -- modest relative to GDPR's maximum of 4% of global annual turnover -- understates the significance. What matters is what the Garante found and what it specifically ordered, because those findings now constitute public regulatory guidance on the minimum compliance floor for any company running a companion AI platform with European users.
The five violations the Garante documented
The investigation identified five distinct GDPR failures. Each represents a gap operators in this space routinely rationalize rather than fix.
Inadequate age verification. Character.AI's onboarding did not effectively prevent minors from accessing the platform. Users could register without meaningful restriction -- age fields were present but not verified against any reliable signal. The platform relied on users to self-declare accurate ages, which is not age verification; it is age theater.
No cooling-off period. This is the failure that goes beyond inadequate gatekeeping into active evasion of gatekeeping. The Garante found that minors who were blocked or suspended could immediately re-register using a new email address. There was no system to detect that a previously blocked minor was creating a second account. The Garante named this specifically and ordered a cooling-off period as a required remedy -- the first time a European DPA has used that phrase as an operational requirement for a companion AI platform.
Inadequate user information. GDPR Articles 13 and 14 require controllers to provide clear, accessible information about how personal data is processed at the time it is collected. The Garante found Character.AI's disclosure to users about their data processing was insufficient -- the standard failure mode of dense terms of service replacing the layered, user-facing notices the regulation actually demands.
Late DPIA. GDPR Article 35 requires a Data Protection Impact Assessment before processing likely to result in high risk to individuals' rights and freedoms. Processing personal data of minors at scale through an AI system that actively cultivates parasocial relationships plainly meets that threshold. The Garante found the company completed its DPIA late rather than before the relevant processing began.
Late EU representative appointment. GDPR Article 27 requires non-EU controllers offering services to EU residents to appoint an EU representative. Character Technologies is a US company. The Garante found this appointment was made late.
What the Garante ordered
The fine came with specific operational requirements. These are enforceable orders, not recommendations. Failure to comply can trigger additional fines, and the 120-day reporting deadline creates a monitored accountability mechanism.
Age verification must actually work. The Garante did not specify which technology to use, but the functional standard is unambiguous: an age gate a 14-year-old can defeat by entering a false birth year does not meet it. The order implies some combination of technical controls, behavioral signals, authenticated third-party age verification, or other means that produce a genuine probability assessment of user age rather than a checkbox.
Implement a cooling-off period. Previously blocked minors cannot be permitted to immediately re-register under a new account. The specific implementation is left to the operator, but the functional requirement -- preventing evasion of a prior block -- is explicit. Acceptable mechanisms include device fingerprinting, phone number verification at re-registration, or email domain restrictions that detect the same user returning under a different identity.
Set minor profiles to private by default. Accounts identified as belonging to minors must default to private settings. This is not a content restriction -- it is a data visibility default. It mirrors requirements in both the UK Age-Appropriate Design Code and Colorado's HB 26-1263 chatbot safety law, which takes effect January 1, 2027.
Report remediation within 120 days. Character Technologies must report to the Garante within 120 days on what measures it has adopted. This creates an accountability mechanism and signals that enforcement is not concluded by the fine -- continued monitoring is expected.
Why the fine amount understates the significance
158,000 euros is a rounding error relative to Character Technologies' revenue. The fine amount alone would not move a product roadmap.
The significance is elsewhere. Three points stand out.
First, the Garante specifically called out the re-registration gap by name. Regulators often find abstract "inadequate age verification" without identifying the specific failure mode. The Garante's naming of the cooling-off period gap tells operators exactly what the compliance bar now is: it is not enough to have an age gate that a motivated minor can defeat in thirty seconds by creating a second account. The gate must have memory of who it previously excluded.
Second, this investigation ran for nearly three years and produced a detailed public enforcement decision. Every European data protection authority -- including the Irish DPC, which functions as lead authority for most US-based platforms under GDPR's one-stop-shop mechanism -- now has a template. An operator that knows this case exists and makes no changes has documentary evidence of willful non-compliance if another EU authority opens proceedings.
Third, the DPIA and EU representative failures have nothing to do with AI -- they are standard GDPR hygiene that any EU-facing data controller should have completed before going live. Finding both failures at Character Technologies suggests the company treated GDPR compliance as a later-stage concern. For any companion AI platform that went to market in the past two years and hasn't formally completed its GDPR DPIA, this is the clearest possible signal to stop waiting.
Where US chatbot law is going on the same issues
The Garante's remedial orders -- age verification, cooling-off periods, private-by-default for minors -- map almost exactly onto what Colorado enacted in HB 26-1263, signed May 29, 2026.
Colorado requires chatbot operators to implement "reasonable measures" to estimate whether a user is under 18, prohibit emotional dependency tactics targeting minor users, and provide privacy controls that minor account holders and parents of under-13 users can exercise. The January 1, 2027 effective date makes this the most imminent US companion AI compliance deadline.
The Garante case answers a question Colorado's law leaves open: what does "reasonable" age verification actually look like in enforcement practice? Based on the Italian findings, reasonable means at minimum:
- An age gate that is not trivially bypassable by entering a false birth year
- A re-registration control that prevents previously blocked minors from creating new accounts
- Private-by-default profiles for accounts identified as minors
The Colorado Chatbot Safety Act compliance guide covers the specific US requirements in detail. Georgia's SB 540 and Rhode Island's AI therapy chatbot law impose similar minor-specific requirements. The Garante's enforcement decision now provides a European data point for what happens when operators get these wrong.
See also the state chatbot disclosure laws tracker for the full picture across US jurisdictions.
Compliance checklist for companion AI operators
1. Complete your GDPR DPIA before you process -- not after. If your platform processes personal data of EU users through an AI system with high engagement or emotional-relationship dynamics, you are likely required to complete a DPIA under Article 35 before that processing begins. "We haven't gotten to it yet" is the documented failure mode the Garante just issued a fine for.
2. Appoint an EU representative if you're a non-EU company. Article 27 is not optional for non-EU operators offering services to EU residents. This is a checklist item -- find a designated EU representative, document the appointment, and make the contact information publicly available in your privacy policy.
3. Audit your age verification for the re-registration gap. Does your platform have any mechanism to prevent a previously blocked minor from creating a new account? If not, the Garante's July 9 order is now public regulatory guidance that this gap constitutes a GDPR violation. Fix it before a European DPA asks you directly.
4. Review your user information notices against Articles 13 and 14. The disclosure must be readable at the time personal data is collected -- not buried in a 6,000-word terms of service document. For platforms used heavily by minors, this means layered notice in plain language, delivered at the right moment in the user journey.
5. Set identified minor accounts to private by default. If your platform can detect that an account belongs to a minor, that account's privacy settings must default to private. This is now required under Colorado HB 26-1263 and was specifically ordered by the Garante. It is the least controversial item on this list to implement.
6. Map your exposure to the Irish DPC. If your platform offers services to users in the EU and you're based outside the EU, your likely lead supervisory authority is the Irish DPC under GDPR's one-stop-shop mechanism. The Irish DPC has historically taken several years to conclude major investigations but has issued substantial fines when it does. The Garante's case shortens the discovery window for any Irish DPC investigation of a similar platform.
See the GDPR AI enforcement tracker for the broader pattern of GDPR fines against AI-adjacent products and what they signal for 2026 enforcement priorities.
What comes next
Character Technologies has 120 days from July 9, 2026 to report its remediation to the Garante. That deadline falls in early November 2026. If the report is inadequate, the Garante can impose additional sanctions.
More consequentially for the industry, this case is now part of the regulatory record that other European data protection authorities will cite. The Irish DPC and the UK ICO have both indicated companion AI platforms are an enforcement priority for 2026 and 2027. The Garante's detailed findings -- specifically the cooling-off period gap and the late DPIA -- give those investigations a documented benchmark for what inadequate compliance looks like.
For operators in this space, the relevant question is not whether your platform is identical to Character.AI. It is whether the five violations the Garante documented -- inadequate age verification, no re-registration barrier, insufficient user information, late DPIA, late EU representative -- describe any part of your own compliance posture. If the answer is yes to any of them, the enforcement window for fixing it before a regulator asks is closing.
Related Reading
- Colorado Chatbot Safety Act (HB 26-1263): Compliance Guide 2027
- GDPR AI Fines 2026: Enforcement Cases and What Small Teams Must Know
- State Chatbot Disclosure Laws 2026: SaaS Compliance Guide
- AI Data Privacy for Small Teams: GDPR and CCPA Essentials
- DeepSeek and Chinese AI Models: GDPR Compliance Guide
Sources: Italy Fines Character.AI Owner Over Age-Check and Privacy Failures, Italy's Garante Fines Character AI Owner €158,000 for GDPR Breaches, Italian Privacy Authority Fines Character.AI for Data Protection and Child Safety Failures, Character.AI fined in Italy over child privacy failures
