In this article (4)
Character.AI Age Assurance Analysis: Safety by Design
Key Takeaways
- Design age assurance before launch, not after moderation failures appear.
- Tie minor safeguards to onboarding and account state, not only to content filters.
- Complete DPIA and EU representation work early when serving European users.
Italy’s Garante treated access control, privacy notices, and DPIA timing as part of the same safety system.
The compliance lesson from Italy’s latest AI enforcement action is not subtle: a chatbot cannot moderate its way out of an onboarding problem. If minors can use the product, regulators are increasingly asking what happens before the first prompt, not just what happens after the model replies. Italy’s data protection authority, the Garante, fined Character Technologies, the U.S. based owner of Character.AI, €158,000 ($180,500), according to a Reuters report carried by AOL. The service lets users, including minors, chat with AI generated virtual characters. That makes it a useful case study for AI companion products, where intimacy, personalization, and data collection meet the least fun sentence in product management: show me the age gate.
What Italy actually found According to
the Reuters report carried by AOL, the Garante found several privacy violations, including shortcomings in the information provided to users about personal data processing. The authority also raised concerns about safeguards for minors and the effectiveness of age verification procedures, saying further protections were needed beyond those already in place. Character Technologies did not immediately respond to a request for comment, according to the same report. The regulator also said the company was late in conducting a Data Protection Impact Assessment, or DPIA, and late in appointing an EU representative, Reuters reported via AOL. Put in product terms, this is not merely a content policy issue. The cited failures sit across the whole service lifecycle: explain the data use, identify the user’s age with enough confidence, assess risk before or during deployment, and have the required EU accountability contact in place. The notable move is the grouping. A weak privacy notice is not the same defect as a weak age check, and a late DPIA is not the same defect as a missing child safety control. But the Garante treated them as related evidence of whether the service had been designed for lawful, safe use by the people who could actually get into it.
Age assurance is no longer
an afterthought WTVB’s Reuters copy reports the same core point: the Garante questioned safeguards for minors and the effectiveness of age verification, while saying further protections were needed beyond measures already in place. That wording matters because it does not say, politely, add a banner and move on. It says the access layer is part of the safety design. For builders, the plain obligation is boring and therefore important. If minors may use the product, onboarding needs to collect or infer age in a way that matches the product’s risk, privacy notices need to explain what happens to personal data, and child safety controls need to be tied to the account state rather than pasted onto the moderation queue. Content filters still matter, but they are downstream controls. The regulator is looking upstream, at who is allowed through the door. This is where AI companion products have less room for the usual evasions. A virtual character service is not just a search box with a friendlier font. It invites repeated, personalized conversation, which means age, consent, profiling, and retention questions arrive early. If your launch checklist says model safety but not age assurance, the checklist is doing theater.
The ChatGPT precedent is
the warning label The Reuters report carried by AOL notes that the Garante has been one of Europe’s more proactive AI regulators and briefly banned OpenAI’s ChatGPT in 2023 over age check and data collection issues. That precedent does not mean every chatbot is one enforcement notice away from suspension. It does mean Italy has already shown that generative AI access controls can become a privacy enforcement issue, not a public relations footnote. This is where LinkedIn will overstate the case by sunset. The law does not say AI companions are categorically unlawful, at least not from the facts reported here. It says the basics still apply when the interface is charming: tell users how their data is processed, assess high risk processing before it becomes a habit, put EU representation in place when required, and do not wave children through a product whose safeguards depend on guessing later. There is also a jurisdictional headache hiding in plain sight. The company is U.S. based, while the enforcement came from Italy’s data protection authority, according to Reuters via AOL. Consumer AI services that scale across borders inherit local privacy expectations whether or not the product team staffed for them. The internet remains annoyingly available in Europe.
What builders should change now OECD.AI classified
the matter as an AI incident involving data protection and child safety failures, and The News International reported that the Garante highlighted violations under the EU’s GDPR data privacy framework. Those labels are useful because they place the fine in the governance bucket, not merely the trust and safety bucket. Regulators are treating age access, privacy information, and internal risk assessment as parts of one operating system. The practical takeaway is straightforward. Before launch, teams building AI companions should map whether minors can access the service, decide what age assurance is proportionate, write privacy information that a normal user can understand, and complete the DPIA before the risk has already shipped. Vendor contracts and internal ownership should also cover who maintains the age check, who reviews child safety controls, and who handles EU representative obligations where they apply. The €158,000 fine is not the largest number in privacy enforcement, but that is the wrong metric. The better metric is architectural cost. Retrofitting age assurance into an AI companion after regulators ask questions is slower, messier, and more lawyer intensive than designing the access layer with the model layer. Watch whether other European regulators follow Italy’s framing, because the next enforcement notice may read less like a warning and more like a product requirements document.
