Skip to content

Character.AI age verification: Italy's Garante fines €158,000

Filip LuchianencoUpdated 4 min read

Last updated: 2026-10-03

On July 9, 2026, Italy's data protection authority, the Garante per la protezione dei dati personali, announced a fine of €158,000 on Character Technologies, Inc., "a US company that operates Character.AI, a generative artificial intelligence service that enables users, including minors, to create and chat with virtual characters." The decision of July 3, 2026 (doc. web 10269571) finds five GDPR infringements, one of them on Character.AI age verification. It orders fixes to the age gate and the "cooling-off period" for refused minors, and private profiles for minors by default. The Garante opened the inquiry on its own initiative in November 2024, into a service offered in Italy "tramite applicazione mobile e piattaforma web" (through a mobile app and a web platform).

What did the Garante find against Character.AI?

The decision lists five infringements (my translation):

Finding GDPR articles Period or document
Privacy notice not clear, intelligible or complete 12(1), 13(1)–(2), 14(1)–(2) Policies of October 2023 and August 27, 2025
No adequate notice to Italian data subjects of pre-training of the proprietary LLMs 14(1)–(2) Pre-training
No adequate technical and organizational age verification measures by default 24(1), 25(2) April 8, 2024 to November 2024; for Italian users under 16, April 8, 2024 to April 8, 2025
Data protection impact assessment adopted late 5(2), 35(1) First DPIA November 14, 2024
EU representative designated late 27(1) VeraSafe Ireland Ltd. designated May 31, 2025

Source: Garante decision, sections 3.2–4.

Two charges failed: Article 21, because, the Garante held, the unconditional opt-out before training that EDPB Opinion 28/2024 recommends does not apply to pre-training done before its adoption on December 17, 2024; and Article 27(4), where the Garante held a broken contact link to be a clerical error.

How does Character.AI verify age, according to the decision?

The decision (section 3.4) records these measures as the company described them:

  • October 2023: a self-declared date of birth at registration; in the EEA, a user under 16 cannot create an account.
  • November 2024: the same gate applied to accounts created earlier, and a separate under-18 service on a dedicated LLM.
  • November 2025 (February 2026 in Italy): open-ended chats closed to users under 18.
  • November 2025: an in-house model predicts age from interaction signals on accounts self-declared as adult and moves a likely minor to the under-18 service. If the user contests the result, Persona Identities, Inc. checks age with a selfie, then with an identity document if the selfie does not settle it. Selfie and document are kept seven days, per the company.

The Garante tested account creation on the web version on April 8, 2025. A user declaring an age under 13 was sent back to the homepage. A user declaring 15 could register, and that minor's profile was public by default. The decision calls the company's defense on these results "prettamente giuridica" (purely legal). The Garante accepted that Articles 24 and 25 require no specific age verification method, but held that they require adequate measures. It found the November 2025 measures adequate to the risks; the infringement covers the earlier period. The decision reports a web test only and does not say where the Persona step runs on Android or iOS.

What must Character.AI change, and by when?

The decision (section 5) orders the company to make the age-16 gate work for Italian users, to make the cooling-off period block repeat sign-ups by minors refused at their first attempt, and to set minors' profiles to private by default. It also orders privacy policy fixes, among them the legal basis for age checks during use, retention criteria for chats and age verification data, and whether EEA users' chats are used for post-training. Data on Italian users collected for pre-training must be deleted unless a compatible purpose under Article 6(4) applies. The company must comply, and report the measures to the Garante, within 120 days of notification.

How was the €158,000 fine set, and can it be appealed?

One fine covers all five infringements under Article 83(3), with transparency as the most serious. The Garante rated gravity "medio" (medium), called the company a start-up and credited three mitigating factors, the age assurance measures among them (section 6). The company must pay within 30 days of notification; under art. 166(8) of the Italian Privacy Code, it can instead settle by paying half the fine within the appeal period. An appeal lies to the ordinary court within 30 days of communication, or 60 days for an appellant resident abroad. As of October 3, 2026, the Garante's pages for this case carry no appeal notice; its May 2025 release on the €5 million Replika fine carries one. I did not search court records.

What a CITT scan and capture show for an AI companion app

Persona offers native Android and iOS verification SDKs; the Android library is com.withpersona.sdk2:inquiry. When I scan an app, the report lists the ad, analytics, attribution and session-replay SDKs found in the binary, any OpenAI, Anthropic or Google Gemini API host in the code, every URL host in the code and resources, and every declared permission, camera included. An age verification vendor's host in that list shows the build references the vendor; only a capture shows a check ran. The capture on the test device records the age and consent screens on first launch, what the app sends at the date-of-birth screen, when an age check fires (a web-embedded check included), and where chat text is sent. Every static finding cites its file and line; every traffic finding cites its capture. See what a scan checks and the limits of a scan.

For the EU disclosure duty on chatbots and AI companions, see AI Act Article 50; for US rules, see app store age verification laws and the amended COPPA Rule.

I run age gate and AI chat app investigations for lawyers and for researchers working with lawyers. Sign up for a CanITrustThat (CITT) account to run your own research, let us run an investigation for you, or browse the scanned apps.

App privacy law, applied to real apps.

Posts on new laws, fines and studies, and teardowns of the apps those laws apply to.

How we use your address: privacy notice. Prefer a feed reader? Use the RSS feed.