Character Technologies has been fined €158,000 ($180,500) in Italy over a raft of infringements on European data protection law, with the country’s data protection authority finding the U.S. Owner of Character.AI, which allows users to communicate with AI virtual companions, has inadequate measures to protect underage users on the platform. The Italian privacy authority, Garante, ordered the company to adjust its privacy practices in light of the “numerous violations of European regulations.” Character.AI has rapidly gained popularity, particularly among younger users and is “particularly used by minors,” according to Garante, prompting concern over the collection of their personal data and how they are protected from harmful content.
The Italian regulator concluded that Character Technologies lacked adequate procedures to prevent underage individuals from accessing the platform and noted that the measures currently in place were insufficient to prevent children from easily using the service.
In addition to concerns regarding age verification, Garante cited other problems with Character Technologies’ service, including insufficient information provided to users on the collection and use of their personal data, the company’s failure to timely conduct a required Data Protection Impact Assessment (DPIA), and its tardiness in appointing a representative in the EU, all violations of GDPR. Character Technologies did not respond immediately to a request for comment on the ruling. The penalty highlights Europe’s increasingly assertive stance on regulating AI, and in particular, Italian authorities have been on the forefront of enforcing privacy laws regarding AI applications. Italy’s privacy watchdog previously issued a ban on ChatGPT over data concerns, and the operator of an AI chatbot companion called Replika was penalized over issues including lack of transparency and protection of children.
These regulatory actions have underscored the expectation that AI platforms are subject to the same rigorous data protection standards as other online services.
The case also brings into focus the potential risks to children engaging with generative AI, such as the possibility of harmful interactions, disclosure of private data, and the potential for these technologies to unduly influence young or vulnerable users in the absence of proper safeguards. The European Commission has indicated it would work with member states to consider regulating AI-driven age verification. As companies in Europe continue to embrace AI, regulators expect to see more enforcement activities to ensure that consumer AI platforms are more transparent in their data processing, implement robust governance, and comply with privacy legislation.
Italy’s ruling reinforces the message that the growth of artificial intelligence must not come at the expense of fundamental user rights, and especially the rights and safety of children.