Technology intelligence for a changing world

About · Editorial standards

CyberProfi

ENGLISH EDITION

Italian regulator fines Character.AI $180K for privacy breaches

Italy’s privacy regulator fined Character.AI $180,500 for privacy violations, spotlighting GDPR compliance challenges for generative AI. Details inside.

Select the most newsworthy verified cybersecurity, AI, or technology development from the past 24 hours - CyberProfi

In a significant move highlighting regulatory scrutiny of generative artificial intelligence, Italy’s data protection authority has fined Character Technologies, the U.S. developer behind Character.AI, €158,000 (approximately $180,500) for violations of privacy law. The penalty, disclosed on September 16, 2026, is among the highest-profile enforcement actions against a generative AI service under Europe’s General Data Protection Regulation (GDPR).

This article examines the nature of the violations, the broader context for generative AI services in the EU, and implications for privacy compliance worldwide. The focus_keyword, Character.AI GDPR fine, is central to ongoing debates about the legal responsibilities of AI platforms.

Character.AI GDPR fine: what did the regulator find?

According to official statements from Italy’s Garante per la Protezione dei Dati Personali (Italian DPA), Character.AI was investigated in response to multiple user complaints. The regulator concluded that the platform failed to implement sufficient measures for informing users about the processing of their personal data, did not adequately verify users’ ages, and lacked clear mechanisms for data access and erasure requests, all required under the GDPR.

The Garante emphasized that privacy notices were incomplete or unclear, leaving users unaware of how their conversations with AI-generated characters could be stored, analyzed, or used for training machine learning models. The platform also failed to establish a straightforward process for users wishing to exercise their “right to be forgotten,” a cornerstone principle of the GDPR.

In addition, the DPA found insufficient protections to prevent minors under 13 from accessing the system, a requirement under both GDPR and the EU’s ePrivacy Directive.

Why the Character.AI GDPR fine matters beyond Italy

This enforcement arrives as generative AI tools, such as Character.AI, ChatGPT, and Gemini, are seeing explosive growth across Europe. Regulatory agencies face mounting pressure to clarify the legal boundaries for these platforms, especially as their outputs increasingly resemble human conversation and often invite users to share highly personal information.

The Italian regulator’s action follows earlier high-profile decisions—such as the temporary ban of ChatGPT in Italy in 2023—demonstrating that data protection authorities are willing to intervene quickly in response to compliance gaps. For global operators, this underlines the importance of embedding data privacy and user rights into system designs from day one.

GDPR requirements most relevant to generative AI

  • Clear, accessible privacy notices: Users must know what personal data is processed and how.
  • Age verification: Reasonable steps must be taken to prevent children from accessing adult-targeted services.
  • Data subject rights: Platforms must allow users to request access, correction, or deletion of their data.
  • Transparency and explainability: Users should understand how AI conversations may be stored and used for model training or other purposes.

The Garante’s decision confirmed that Character.AI fell short on several of these counts. The penalty was calculated based on the size of the company’s European user base and the scope of potential impact on individual privacy.

How Character.AI is responding

Character Technologies has not issued a detailed public statement on the ruling as of September 17, 2026. However, the company is expected to revise its privacy policies, strengthen age verification, and implement new workflows to address data subject requests for access and erasure—a process that may require significant engineering and compliance resources.

Failure to comply risks further sanctions, including even higher penalties or potential restrictions on providing services within the EU.

Context in the AI compliance landscape

The Character.AI GDPR fine sends a strong message to the broader AI industry: compliance with European privacy laws is not optional, nor is it achievable through token gestures. Regulators expect evidence of meaningful processes for user rights, robust controls for sensitive data, and clear explanations of how AI systems handle personal information.

Other generative AI firms—including OpenAI, Google, and Anthropic—face similar investigations across multiple EU jurisdictions. Some may soon see penalties or new restrictions if found non-compliant.

For more analysis of GDPR enforcement against AI, see CyberProfi’s cybersecurity coverage, or for technical implementation strategies, see our business technology section.

What companies can learn from Character.AI’s GDPR fine

  • Review and update privacy notices to ensure clarity and specificity regarding data use.
  • Implement robust age verification suited to your risk profile.
  • Ensure there are frictionless pathways for data subject access, correction, and deletion requests.
  • Train support and development teams on GDPR requirements and responsibilities.

While the financial impact of the fine is modest given the scale of many AI ventures, the reputational consequences and risk of escalated enforcement present ongoing challenges for service providers.

Frequently Asked Questions

What specifically did Character.AI do to violate the GDPR?
The regulator cited unclear privacy notices, lack of effective age verification, and an inadequate system for user data rights as central faults.
Could other generative AI platforms face similar fines?
Yes. Any platform serving EU users risks penalty if it lacks mechanisms to deliver GDPR rights or protect children’s data.
How quickly does the company have to remedy issues?
Character.AI is expected to make changes immediately, with ongoing regulatory monitoring and potential for additional sanctions if it fails to comply.
Where can businesses find guidance on bringing AI tools into GDPR compliance?
Refer to official EU GDPR guidance, consult legal counsel, and review recommendations from national DPAs such as Italy’s Garante.
Will this decision affect AI development or access in Europe?
Most likely, yes. It sets a precedent that may influence technical and policy choices for all AI platforms operating in the EU.

Sources