Public Interest and Emerging AI Regulatory Enforcement
The regulatory oversight of generative conversational models in the European digital space represents a defining frontier in digital governance. As interactive agents powered by proprietary large language models interface directly with diverse demographic segments, administrative inquiries have shifted from theoretical risks to rigorous structural audits of model training, user transparency, and dedicated safeguards for underage users.
Documentary records from data protection oversight proceedings establish how technical architectures, corporate compliance mechanisms, and cross-border targeting criteria interact under statutory data protection frameworks. The tension between rapid product deployment and procedural obligations forms a central challenge for emerging artificial intelligence developers targeting European audiences.
Examining these primary administrative findings illuminates how European authorities evaluate legitimate interest assessments, data protection impact analyses, and the practical enforcement of transparency mandates when proprietary models process continuous user interaction data.
Historical and Regulatory Context
The rapid evolution of conversational artificial intelligence platforms transformed consumer technology between 2021 and 2026. Character was formally incorporated on November 3, 2021, and subsequently initiated a phased deployment of its synthetic conversational service. The entity introduced its web-based beta framework on September 16, 2022, followed by a dedicated mobile application release on May 23, 2023.
A major structural transition occurred on April 8, 2024, when the provider retired its beta environment in favor of a definitive consumer platform accessible via the primary domain www.character.ai, explicitly featuring an Italian language interface. This deployment brought the platform squarely within the scope of European data protection regulations under the targeting criterion of Article 3(2)(a) of Regulation (EU) 2016/679, as goods and services became directly accessible to users residing across the European Union.
As conversational platforms expanded, the technical reality of proprietary large language models (LLMs) relying on user dialogue for iterative model refinement drew formal regulatory review. In November 2024, the entity introduced an ad hoc architecture dedicated to underage users, alongside platform restrictions designed to limit open access to synthetic personas and prevent minors from publishing custom personas publicly.
Formal regulatory inquiries commenced in late 2024. On December 20, 2024, supervisory officials granted an extension request (protocol no. 150217/24) following an application submitted the same day (protocol no. 150737/24) due to the substantial evidentiary scope and logistical constraints over the year-end holiday period.
The procedural timeline progressed through structured submissions. On January 21, 2025, the company filed its initial response (protocol no. 6935/25), submitting copies of its Data Protection Impact Assessment (DPIA) under Article 35 of the General Data Protection Regulation (GDPR) and its Legitimate Interest Assessment (LIA) pursuant to Article 6(1)(f). This filing documented the November 2024 deployment of an LLM specifically trained for users under eighteen years of age.
Follow-up inquiries required further technical details regarding DPIA security measures and formal documentation of the legal representative designated under Article 27 of the Regulation. On September 30, 2025, the organization lodged updated compliance documentation (protocol no. 129329/25), including an updated privacy policy dated August 27, 2025, a DPIA revised on September 30, 2025, an LIA revised on September 29, 2025, and formal documentation designating its European representative.
On December 9, 2025, the company submitted formal communication (protocol no. 171362/25) confirming structural changes to minor interactions, verifying the termination of open conversational access with synthetic characters for users under eighteen in the United States starting November 24, 2025, with an equivalent cessation slated for Italy by late February 2026.
Key Entities and Corporate Actors
The regulatory inquiry centres on specific corporate entities, legal representatives, and public authorities engaged across the administrative timeline:
- Character Inc.: A digital technology corporation incorporated on November 3, 2021, operating the synthetic conversational intelligence platform character.ai.
- [[Garante per la protezione dei dati personali|Q3758885]]: The Italian national supervisory authority responsible for enforcing European and national data protection standards.
- VeraSafe: The designated legal entity acting as the statutory representative within the European Union under Article 27 of Regulation (EU) 2016/679, whose registered address was formally entered into the administrative record.
- Corporate Legal Representation: The General Counsel of the operating company, who represented the organization during formal hearing proceedings held pursuant to Article 166(6) of the Italian Privacy Code.
Critical Analysis of the Documentary Record
The evidentiary record submitted throughout the proceedings provides critical insights into the operational friction between commercial generative artificial intelligence development and European privacy frameworks. A central issue revolves around the legal basis for continuous model optimization. The company utilizes proprietary large language models refined through user interaction, though administrative records confirm that as of April 30, 2026, data from users in the European Economic Area (EEA) is excluded from model training interactions.
The Article 3(2)(a) targeting criterion applies directly when synthetic conversational services are intentionally offered and localized for data subjects within the European Union, triggering compliance with transparency, security, and representation mandates.
On March 31, 2026, the company submitted a comprehensive defense brief (protocol no. 49636/26) requesting a formal hearing under Article 166(6) of the Code. In its pleadings, the enterprise invoked the statutory exemption under Article 14(5) of the Regulation, claiming disproportionate effort in direct communications. The defense asserted that notice requirements had been fulfilled through publication across official blog posts, the platform Help Center, and third-party hosted community forums, noting policy revisions in February 2025 and September 2025.
From a subjective legal standpoint, the defense maintained that the regulatory initiation document failed to establish intentional misconduct or actionable negligence, citing the jurisprudential standard articulated by the European Court of Justice in its December 5, 2023 ruling (Case C-807/21). The defense also submitted certified documentation regarding its global annual turnover for the 2025 financial year.
During the formal oral hearing convened on April 15, 2026 (recorded under protocol no. 60939/26), the organization’s General Counsel presented technical and commercial context, arguing that the enterprise retains startup characteristics facing high operational and infrastructure costs in a hyper-competitive market. Following reservations entered during the hearing, the company filed supplementary disclosures on April 30, 2026 (protocol no. 71632/26), including the verified physical address of VeraSafe and historical copies of its February 2023 privacy policy.
The documentation highlights notable governance timelines: an updated privacy policy and regional supplement were scheduled for formal entry into force on July 1, 2026. However, the record leaves open broader structural questions regarding the retrospective transparency provided to European users prior to localized policy revisions, as well as the qualitative methods used to verify age limits before conversational restrictions took effect across jurisdictions.
Transparency, Statutory Framework, and Legal Basis
The evidentiary material underlying this investigation derives from formal public administrative acts issued by the national data protection supervisory authority, specifically under administrative reference Provvedimento del 3 luglio 2026 [10269571]. The full official record is maintained on the institutional repository at garanteprivacy.it.
Under Article 5 of Italian Law no. 633/1941 (L. 633/1941, art. 5), official texts of the state and public administrations are exempt from copyright protection and fall within the public domain. This publication reproduces and analyzes official administrative actions in compliance with statutory public interest standards, documenting the application of Articles 12, 14, 27, 35, and Recital 58 of Regulation (EU) 2016/679 to frontier artificial intelligence platforms.

