AIR-2026-008 · AI Agent Incident Register
Garante v Character Technologies: Italy fines Character.AI's maker €158,000 over age assurance and pre-training transparency
Incident: 2026-07-03 · Parties: Garante per la protezione dei dati personali (Italian DPA); Character Technologies, Inc. (US provider of Character.AI)
Liability locus: Deployer-carried. the organisation that deployed the agent answers for its output.
Legal analysis by Michael K. Onyekwere, CIPP/E · Janus Compliance · Published 2026-07-27 · Last reviewed 2026-07-27. Analysis of public facts. Not legal advice.
What happened
On 3 July 2026 the Italian data protection authority (the Garante) adopted provvedimento n. 487, fining Character Technologies, Inc., the US company behind Character.AI, €158,000, and ordering corrective measures with a 120-day compliance report. The decision was announced on 9 July 2026.
Character.AI lets users create and chat with AI personas. The service launched in beta in 2022, released an official Italian-language version on 8 April 2024, and is used heavily by teenagers. The Garante's findings fall into three groups.
Age assurance that did not work. The service declared itself off-limits to under-16s in the EEA, but its age gate was a neutral self-declaration. The decision records the Authority's own verification test: on 8 April 2025, a tester declaring an age of fifteen was able to register and use the service, and minors' profiles defaulted to public. The Garante found the technical and organisational measures inadequate for the risk (Articles 24(1) and 25(2)), engaging the accountability principle (Article 5(2)) as well.
Transparency failures reaching the model itself. The privacy notice was in English only for an Italian-market service, unclear on retention and on which legal basis covered which operation (Articles 12(1), 13(1)–(2)). The finding with the widest reach: Character had used personal data scraped from public internet sources to pre-train its LLM and had not informed the people concerned, users or not. The company argued the data was incidental, that Article 14(5)(b)'s disproportionate-effort exception applied, and that forum posts and blog updates were notice enough. The Garante rejected each argument and found Article 14(1)–(2) violated.
Late structural compliance. Character designated its EU representative (VeraSafe Ireland Ltd) only on 31 May 2025, after more than a year of offering the service in Italy, with a contact link that did not work (Article 27), and its first data protection impact assessment came in November 2024, after launch and incomplete (Article 35(1)).
The corrective orders require working age assurance, a cooling-off mechanism to stop a blocked minor simply re-registering, private-by-default profiles for minors, and a report on the measures adopted within 120 days.
The duty engaged
Transparency to people who never used the service (Article 14). Article 14 covers data not collected from the data subject, which is what scraped pre-training data is. The Garante held that the duty applies to pre-training, that "we posted about it on our blog" does not discharge it, and that the disproportionate-effort exception is not a general pass for web-scale collection. The reasoning treats notice as something owed to the public whose data went into the model, and it applies to any provider whose training corpus includes personal data. The Authority drew a careful line on the dates: it found the Article 14 notice duty engaged, but declined to find a right-to-object (Article 21) violation for the pre-training, because that processing predated the EDPB's December 2024 opinion setting out how opt-outs must be honoured.
Child protection as an engineering duty (Articles 24, 25). As in the Replika decision (AIR-2026-006), the Garante treated age assurance as a design obligation. A self-declaration gate that a fifteen-year-old defeats on the regulator's own test is, in the Authority's analysis, an absent control. The decision's standard is risk-based: the technical and organisational measures must be adequate to the innovative technology and to the underage, vulnerable users the service processes. That asks more of AI services aimed at or reachable by minors.
The structural duties that travel with market entry (Articles 27, 35). A non-EU provider offering a service to people in the EU owes an EU representative from day one and a DPIA completed before the processing begins. Both findings are about sequence: the compliance scaffolding has to exist when the service arrives, and bolting it on after the regulator writes is itself the violation.
The liability chain
Character Technologies carries it all, as controller. The same merged shape as Replika: the model's maker is also the consumer service's operator, so provider and deployer are one entity and the liability does not divide. (The register tags this entry deployer because the consumer-facing operation is where the duties bit; the pre-training finding shows the same entity answering in its provider capacity too.)
The pre-training finding shifts where exposure starts. For the service-layer findings, exposure began at Italian market entry. For the Article 14 finding, the processing at issue happened before any Italian user signed up: the scraping and pre-training themselves. A provider cannot fence off its model-building as pre-market activity beyond European reach once the resulting service is offered to people in the EU.
The penalty is minor next to the corrective orders. €158,000 against the €5 million in Replika reflects the Garante's calibration, and the money is the least of it. The corrective orders compel engineering: rebuilt age assurance, a cooling-off barrier so a blocked minor cannot just re-register, changed defaults for minors, and a report proving it, on a 120-day clock. For an operator, the ordered work costs more than the penalty.
What would have prevented it
- Test the age gate the way a regulator will. The Garante registered as a fifteen-year-old and got in. Any control that has never been adversarially tested should be assumed to fail that test.
- Write the Article 14 notice for the people in the training data. If pre-training used scraped personal data, publish notice addressed to the people concerned — what was collected, the basis, the rights — and make it findable. Blog posts about model updates were held not to count.
- Private by default for minors. Article 25(2) is literal: the protective setting is the default, and disabling it takes a deliberate opt-out.
- Stand up the EU scaffolding before market entry. Representative appointed, DPIA done, notice localised — the day the service is offered in the EU, all three exist. Each was found late here, and late was enough for a violation.
- One legal basis per operation, named. The same failure as Replika, one product over: a notice that does not map a basis to each processing operation identifies none.
Mapped controls
- OWASP Top 10 for Agentic Applications 2026: no category applies; the failures are legal-duty events, working as built. With Moffatt, Ayinde and Garante v Luka, this is the register's fourth entry that no security taxonomy indexes — the class the liability layer exists for.
- NIST AI RMF: a GOVERN failure in the compliance scaffolding (representative, DPIA timing, notice ownership) and a MEASURE failure in the one control that existed: the age gate was deployed but never tested against the obvious adversary, a minor willing to lie.
- Singapore IMDA Model AI Governance Framework for Agentic AI (v1.5, May 2026): a partial fit, flagged as such: "Enable end-user responsibility" is the nearest dimension — users, including the youngest, given accurate information about what the system is and what happens to their data. The pre-training transparency failure belongs to data-protection law, outside the agentic-security frameworks' scope.
- The general rule the decision stands for: transparency obligations follow the data into the model. A provider that trains on scraped personal data owes Article 14 notice to the people in the corpus, and "it would be disproportionate to tell them" was rejected as the answer. Together with AIR-2026-006, the Garante's line on companion AI is now explicit: the service layer and the model layer each carry their own duties.
Sources
- Garante per la protezione dei dati personali, provvedimento n. 487 of 3 July 2026 against Character Technologies, Inc. (docweb 10269571) — the decision text; the reasoning finds violations of Articles 5(2), 12(1), 13(1)–(2), 14(1)–(2), 24(1), 25(2), 27 and 35(1), and expressly declines to find an Article 21 violation for the pre-training; the operative part and the sanction figure are redacted in the published version — checked 27 July 2026 [primary]
- Garante press release, "Intelligenza artificiale: il Garante privacy sanziona Character.ai", 9 July 2026 (docweb 10269594) — states the €158,000 fine and the corrective orders (age verification, a cooling-off measure against re-registration by blocked minors, private-by-default profiles, 120-day report) — checked 27 July 2026 [primary]
- ANSA, "Il Garante Privacy sanziona Character.AI per 158mila euro", 9 July 2026 — Italian national-agency corroboration of the fine and the minors-protection orders — checked 27 July 2026 [corroborating]
Cite this entry as AIR-2026-008 (https://companyscope.io/register/air-2026-008). Entry IDs are stable; corrections publish as dated addenda on this page.
Talk to Michael about your agent deployment — or your AI vendor governance more broadly
CompanyScope's public profiles cover the general picture. Michael runs Janus DPO-as-a-Service for businesses that need ongoing AI vendor governance, and writes one-off CIPP/E-reviewed Vendor Risk Notes for specific procurement decisions. Tell him what you're actually trying to clear.
Your context goes only to Michael. We don't share with the vendor or anyone else. Privacy notice.
Subscribe to the AI Agent Incident Register
Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.
Subscribe — freeDelivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.
This analysis is the work Janus Compliance does for clients before the incident. For a fixed-scope read of your own EU AI Act Article 50 exposure, see the Article 50 teardown; for ongoing agent governance, Janus DPO-as-a-Service. New entries are delivered free through Compliance Engineering on Substack. Browse the full register or the vendor compliance index.