Investigative Journalism
Unclessify — Journal of Investigation and Declassification, Founded by Graziano Costantino
Unclessify — Journal of Investigation and Declassification, Founded by Graziano Costantino
Conversational AI Under European Regulatory Scrutiny: The Regulatory Examination of Large Language Model Governance and Minor Safeguards
Acquired Record: garanteprivacy.it

Conversational AI Under European Regulatory Scrutiny: The Regulatory Examination of Large Language Model Governance and Minor Safeguards

garanteprivacy.itItalia2026public
#intelligenza-artificiale#protezione-dati#privacy-minori#modelli-linguistici#garante-privacy

Verified Primary Investigative Source: garanteprivacy.it — Italia

Share:

Editorial Transparency & Fair Use Notice

Investigative dossier curated and structured by the Unclessify editorial team based on official disclosures, court filings and declassified records published by garanteprivacy.it. Historical context, analytical synthesis, and editorial commentary are provided by Unclessify under Public Interest, Freedom of the Press, and Fair Use principles.

Read Full Editorial Policy & Source Transparency →

Official Records & Declassified Dossier

Public Interest and Emerging AI Regulatory Enforcement

The regulatory oversight of generative conversational models in the European digital space represents a defining frontier in digital governance. As interactive agents powered by proprietary large language models interface directly with diverse demographic segments, administrative inquiries have shifted from theoretical risks to rigorous structural audits of model training, user transparency, and dedicated safeguards for underage users.

Documentary records from data protection oversight proceedings establish how technical architectures, corporate compliance mechanisms, and cross-border targeting criteria interact under statutory data protection frameworks. The tension between rapid product deployment and procedural obligations forms a central challenge for emerging artificial intelligence developers targeting European audiences.

Examining these primary administrative findings illuminates how European authorities evaluate legitimate interest assessments, data protection impact analyses, and the practical enforcement of transparency mandates when proprietary models process continuous user interaction data.

Historical and Regulatory Context

The rapid evolution of conversational artificial intelligence platforms transformed consumer technology between 2021 and 2026. Character was formally incorporated on November 3, 2021, and subsequently initiated a phased deployment of its synthetic conversational service. The entity introduced its web-based beta framework on September 16, 2022, followed by a dedicated mobile application release on May 23, 2023.

A major structural transition occurred on April 8, 2024, when the provider retired its beta environment in favor of a definitive consumer platform accessible via the primary domain www.character.ai, explicitly featuring an Italian language interface. This deployment brought the platform squarely within the scope of European data protection regulations under the targeting criterion of Article 3(2)(a) of Regulation (EU) 2016/679, as goods and services became directly accessible to users residing across the European Union.

As conversational platforms expanded, the technical reality of proprietary large language models (LLMs) relying on user dialogue for iterative model refinement drew formal regulatory review. In November 2024, the entity introduced an ad hoc architecture dedicated to underage users, alongside platform restrictions designed to limit open access to synthetic personas and prevent minors from publishing custom personas publicly.

Formal regulatory inquiries commenced in late 2024. On December 20, 2024, supervisory officials granted an extension request (protocol no. 150217/24) following an application submitted the same day (protocol no. 150737/24) due to the substantial evidentiary scope and logistical constraints over the year-end holiday period.

The procedural timeline progressed through structured submissions. On January 21, 2025, the company filed its initial response (protocol no. 6935/25), submitting copies of its Data Protection Impact Assessment (DPIA) under Article 35 of the General Data Protection Regulation (GDPR) and its Legitimate Interest Assessment (LIA) pursuant to Article 6(1)(f). This filing documented the November 2024 deployment of an LLM specifically trained for users under eighteen years of age.

Follow-up inquiries required further technical details regarding DPIA security measures and formal documentation of the legal representative designated under Article 27 of the Regulation. On September 30, 2025, the organization lodged updated compliance documentation (protocol no. 129329/25), including an updated privacy policy dated August 27, 2025, a DPIA revised on September 30, 2025, an LIA revised on September 29, 2025, and formal documentation designating its European representative.

On December 9, 2025, the company submitted formal communication (protocol no. 171362/25) confirming structural changes to minor interactions, verifying the termination of open conversational access with synthetic characters for users under eighteen in the United States starting November 24, 2025, with an equivalent cessation slated for Italy by late February 2026.

Key Entities and Corporate Actors

The regulatory inquiry centres on specific corporate entities, legal representatives, and public authorities engaged across the administrative timeline:

  • Character Inc.: A digital technology corporation incorporated on November 3, 2021, operating the synthetic conversational intelligence platform character.ai.
  • Garante per la protezione dei dati personali: The Italian national supervisory authority responsible for enforcing European and national data protection standards.
  • VeraSafe: The designated legal entity acting as the statutory representative within the European Union under Article 27 of Regulation (EU) 2016/679, whose registered address was formally entered into the administrative record.
  • Corporate Legal Representation: The General Counsel of the operating company, who represented the organization during formal hearing proceedings held pursuant to Article 166(6) of the Italian Privacy Code.

Critical Analysis of the Documentary Record

The evidentiary record submitted throughout the proceedings provides critical insights into the operational friction between commercial generative artificial intelligence development and European privacy frameworks. A central issue revolves around the legal basis for continuous model optimization. The company utilizes proprietary large language models refined through user interaction, though administrative records confirm that as of April 30, 2026, data from users in the European Economic Area (EEA) is excluded from model training interactions.

The Article 3(2)(a) targeting criterion applies directly when synthetic conversational services are intentionally offered and localized for data subjects within the European Union, triggering compliance with transparency, security, and representation mandates.

On March 31, 2026, the company submitted a comprehensive defense brief (protocol no. 49636/26) requesting a formal hearing under Article 166(6) of the Code. In its pleadings, the enterprise invoked the statutory exemption under Article 14(5) of the Regulation, claiming disproportionate effort in direct communications. The defense asserted that notice requirements had been fulfilled through publication across official blog posts, the platform Help Center, and third-party hosted community forums, noting policy revisions in February 2025 and September 2025.

From a subjective legal standpoint, the defense maintained that the regulatory initiation document failed to establish intentional misconduct or actionable negligence, citing the jurisprudential standard articulated by the European Court of Justice in its December 5, 2023 ruling (Case C-807/21). The defense also submitted certified documentation regarding its global annual turnover for the 2025 financial year.

During the formal oral hearing convened on April 15, 2026 (recorded under protocol no. 60939/26), the organization’s General Counsel presented technical and commercial context, arguing that the enterprise retains startup characteristics facing high operational and infrastructure costs in a hyper-competitive market. Following reservations entered during the hearing, the company filed supplementary disclosures on April 30, 2026 (protocol no. 71632/26), including the verified physical address of VeraSafe and historical copies of its February 2023 privacy policy.

The documentation highlights notable governance timelines: an updated privacy policy and regional supplement were scheduled for formal entry into force on July 1, 2026. However, the record leaves open broader structural questions regarding the retrospective transparency provided to European users prior to localized policy revisions, as well as the qualitative methods used to verify age limits before conversational restrictions took effect across jurisdictions.

Transparency, Statutory Framework, and Legal Basis

The evidentiary material underlying this investigation derives from formal public administrative acts issued by the national data protection supervisory authority, specifically under administrative reference Provvedimento del 3 luglio 2026 [10269571]. The full official record is maintained on the institutional repository at garanteprivacy.it.

Under Article 5 of Italian Law no. 633/1941 (L. 633/1941, art. 5), official texts of the state and public administrations are exempt from copyright protection and fall within the public domain. This publication reproduces and analyzes official administrative actions in compliance with statutory public interest standards, documenting the application of Articles 12, 14, 27, 35, and Recital 58 of Regulation (EU) 2016/679 to frontier artificial intelligence platforms.

What this piece rests on

The text was checked against the facts listed below, extracted from the act above. It does not yet carry corroboration from independent sources.

The 20 facts verified in the text
  1. Character, società costituita in data 3 novembre 2021, ha lanciato la versione beta del Servizio in modalità web in data 16 settembre 2022 ed in modalità app in data 23 maggio 2023.
  2. In data 8 aprile 2024 la versione beta è stata sostituita dalla versione definitiva, reperibile al dominio di primo livello www.character.ai ed offerta anche in lingua italiana.
  3. Nel novembre 2024 è stata lanciata una versione ad hoc del Servizio riservata ai soggetti minorenni.
  4. Character utilizza un sistema di intelligenza artificiale generativa basato su modelli linguistici di grandi dimensioni (Large Language Model, di seguito anche “LLM”) proprietari, perfezionati dall’interazione degli utenti con il Servizio (alla data del 30 aprile 2026 gli utenti dell’area SEE non sono compresi).
  5. In data 20 dicembre 2024 l’Ufficio accoglieva (prot. n. 150217/24) una richiesta di proroga del termine, per fornire riscontro, avanzata dalla Società in pari data (prot. n. 150737/24), in ragione dell’ampiezza della richiesta e della difficoltà a reperire le informazioni necessarie nel corso del periodo natalizio.
  6. In data 21 gennaio 2025 la Società rispondeva alla richiesta di informazioni (prot. n. 6935/25), producendo copia della valutazione di impatto (in seguito anche “DPIA”) ai sensi dell’art. 35 del Regolamento e della valutazione del legittimo interesse (in seguito anche “LIA”) di cui all’art. 6, par. 1, lett. f) del Regolamento.
  7. Riferiva altresì di aver implementato, sempre nel mese di novembre 2024, una versione separata del Servizio basato su di un LLM specificamente addestrato per gli utenti di età inferiore ai diciotto anni e di aver impedito agli stessi di accedere indiscriminatamente a tutti i Personaggi e di rendere pubblici i propri Personaggi.
  8. L’Ufficio chiedeva, inoltre, chiarimenti in merito ad alcune delle misure di sicurezza indicate nella DPIA, nonché la trasmissione di copia dell’atto con cui era stato designato il rappresentante ex art. 27 del Regolamento.
  9. In data 30 settembre 2025 la Società forniva riscontro alla seconda richiesta di informazioni (prot. n. 129329/25), nel rispetto dei termini concessi, producendo copia della privacy policy aggiornata al 27 agosto 2025, copia della DPIA aggiornata al 30 settembre 2025, copia della LIA aggiornata al 29 settembre 2025 e copia dell’atto di designazione del rappresentante ex art. 27 del Regolamento.
  10. La Società rispondeva con nota del 9 dicembre 2025 (prot. n. 171362/25) con cui, quanto al profilo relativo agli utenti minorenni, confermava la veridicità della notizia relativa al progetto di eliminare la possibilità per i minori di 18 anni di partecipare a conversazioni aperte con i Personaggi del Servizio a partire dal 24 novembre 2025 negli Stati Uniti ed entro la fine di febbraio 2026 in Italia.
  11. Difese della Parte (art. 166, co. 6, del Codice) In data 31 marzo 2026 (prot. n. 49636/26), la Società Character ha prodotto una memoria difensiva con richiesta di essere sentita, ai sensi dell’art. 166, co. 6 del Codice.
  12. Ha, inoltre, riferito che nel caso di specie sarebbe applicabile l’eccezione di cui all’art. 14, par. 5, del Regolamento (impossibilità o sforzo sproporzionato nella comunicazione delle informazioni) e, in ogni caso, di aver rispettato gli obblighi di cui all’art. 14 del Regolamento mediante la pubblicazione di aggiornamenti sul proprio blog, nell’Help Center e su forum ospitati da siti web di terze parti (ad es.
  13. Il documento è stato successivamente aggiornato nel febbraio 2025 e nel settembre 2025.
  14. Sotto il profilo soggettivo, nella memoria difensiva, Character ha affermato che l’atto di avvio del procedimento non dimostra che le presunte violazioni siano state commesse con dolo o colpa, come richiesto dalla Corte di Giustizia UE nella sentenza del 5 dicembre 2023, causa C-807/21.
  15. Character ha inoltre fornito gli elementi richiesti in ordine al fatturato mondiale annuo relativo all’anno 2025.
  16. In occasione dell’audizione, richiesta ai sensi dell’art. 166, co. 6, del Codice e tenutasi in data 15 aprile 2026 (v. verbale prot. n. 60939/26), il General Counsel della Società ha illustrato le caratteristiche del Servizio ed ha precisato che Character deve ancora essere considerata una start-up in quanto impiega … OMISSIS persone e si pone in un mercato fortemente competitivo con alti costi di gestione.
  17. Con nota trasmessa in data 30 aprile 2026 (prot. n. 71632/26), a scioglimento della riserva presa in sede di audizione, il Titolare ha fornito l’indirizzo esatto di VeraSafe e copia della privacy policy del febbraio 2023.
  18. L’ultima versione della privacy policy ed il relativo supplemento regionale entrano in vigore il 1° luglio 2026. 3.
  19. In particolare, nel caso di specie, è applicabile il criterio del targeting di cui all’art. 3, par. 2, lett. a), del Regolamento, ovverosia l’offerta di beni o servizi ad interessati nell’Unione, in quanto il servizio Character AI è liberamente fruibile da utenti situati nel territorio europeo e, segnatamente, in Italia, a far data dall’8 aprile 2024.
  20. L’art. 12 ed il considerando 58 del Regolamento prescrivono che le informazioni destinate al pubblico o all'interessato debbano essere concise, facilmente accessibili e siano rese in un linguaggio semplice e chiaro.
Click to switch theme:

Comments (0)