Protecting Young People in the Age of Conversational AI

Italy’s Action on Character.AI

As generative artificial intelligence becomes increasingly embedded in young people’s everyday lives, the debate around AI governance is moving beyond questions of innovation and technological performance towards a more fundamental issue: how should societies protect young users when AI systems are designed not simply to provide information, but to interact, converse and build increasingly personalised relationships with them?

A decision by the Italian Data Protection Authority, the Garante per la Protezione dei Dati Personali, brings this question sharply into focus.

According to the Authority’s published materials, in 2026 the Garante imposed an administrative fine of €158,000 on Character Technologies Inc., the US company operating Character.AI, a service that allows users to create and interact through chat with virtual characters. The Authority’s proceedings concerned the processing of personal data in connection with the service, including issues relevant to users under 18. This made age assurance, privacy and safeguards for younger users important elements of the case.

The case is particularly relevant to the YouthGovAI project because it demonstrates how debates around youth participation in AI governance are becoming increasingly concrete. Young people are no longer simply encountering artificial intelligence through recommendation algorithms or conventional digital services. They are interacting directly with generative systems capable of producing personalised, conversational and potentially highly engaging experiences. As these technologies become more sophisticated, ensuring that younger users understand the environments they are entering — and that companies provide appropriate protections — becomes an essential component of responsible AI governance.

What did the Italian Authority find?

The Garante’s published decision indicates that the proceedings began in November 2024 and examined several aspects of Character.AI’s processing of personal data in Italy.

The Authority identified shortcomings concerning the information provided to users about the processing of their personal data. It also addressed the timing of the company’s Data Protection Impact Assessment and the appointment of a representative within the European Union.

Of particular significance were the findings concerning minors and age assurance.

The Authority found that, during the periods examined, the company had not implemented adequate technical and organisational measures to verify users’ ages by default. The decision should not be read as establishing that every aspect of the service was unlawful, or that age verification alone resolves the risks associated with conversational AI. Rather, it illustrates the Garante’s view that age-assurance measures are relevant to the protection of minors where a service processes personal data and offers highly interactive generative-AI functionality.

The Authority also required the company to adopt or strengthen measures relating to age verification and the prevention of immediate re-registration by minors whose accounts had been blocked. The published materials further refer to privacy protections for minor users, including making their profiles private by default. These requirements should be understood as measures imposed or required in the context of the Authority’s proceedings, rather than as a general technical standard applicable in identical form to every AI service. The decision is significant because it illustrates a broader shift in the governance of digital technologies: protecting young people cannot depend exclusively on young users understanding and managing risks themselves. Responsibility must also be embedded into the design, governance and default settings of the technologies they use.

From access to meaningful protection

Age assurance has become one of the most complex questions in contemporary digital governance. Regulators face a difficult balance: mechanisms must be sufficiently effective to protect minors without introducing disproportionate forms of identification, surveillance or collection of personal data.

The Character.AI case illustrates why this balance matters.

Generative AI platforms can provide young people with opportunities for creativity, exploration and learning. Conversational AI, in particular, can offer highly personalised interactions that differ substantially from more traditional forms of digital content. Yet the same characteristics that make these systems engaging can create new forms of vulnerability when users are children or adolescents.

The Italian proceedings therefore raise a question that extends far beyond a single company: what does an AI environment genuinely designed with young people’s rights in mind look like?

Privacy-by-default, proportionate age assurance, transparent information and appropriate risk assessments provide part of the answer. However, technological safeguards alone cannot address the entire challenge.

Young people also need the knowledge and critical capacities required to understand what happens when they interact with an AI system: what information they are providing, how their data may be processed, why an artificial agent responds in a particular way, what limitations its outputs may have, and where the boundaries between simulated interaction and human relationships lie.

AI literacy is becoming a question of rights

This is where the case intersects particularly strongly with the objectives of YouthGovAI.

AI literacy is sometimes understood primarily as the ability to use artificial intelligence effectively: knowing how to formulate prompts, recognise AI applications or make productive use of generative tools. Yet the rapid development of conversational AI demonstrates why this definition is insufficient.

Being AI-literate also means understanding rights, risks, responsibilities and power.

Young people need opportunities to ask who designs the systems they use, what data those systems collect, what incentives guide their development, how algorithms influence the interactions they experience, and what mechanisms exist when something goes wrong. In this sense, AI literacy becomes closely connected to digital citizenship. The findings emerging from YouthGovAI activities in Italy reinforce precisely this point. Young people are already frequent users of artificial intelligence, but familiarity with AI tools does not automatically translate into a comprehensive understanding of their functioning or their societal implications. The challenge for education is therefore not simply to increase exposure to AI, but to transform widespread exposure into informed, critical and responsible engagement.

Governance should include young people, not only protect them

There is another important dimension to this debate.

Policies concerning minors and artificial intelligence understandably emphasise protection. Children and adolescents require specific safeguards, particularly where personal data, persuasive technologies and potentially harmful content are concerned.

Yet a governance model that sees young people exclusively as vulnerable users would remain incomplete.

Young people are also among the groups with the most direct experience of emerging digital technologies. They use generative AI for education, creativity, communication and entertainment, and their everyday experiences can reveal risks, opportunities and patterns of use that may not be immediately visible to policymakers or technology developers.

Protecting youth and empowering youth should therefore be understood as complementary objectives.

Meaningful youth participation can help institutions understand how AI systems are actually being used, which forms of interaction young people perceive as beneficial or problematic, what safeguards they consider understandable and effective, and what kind of information they need in order to make informed choices. This is precisely the transition promoted by YouthGovAI: moving from a model in which young people are simply the subjects of digital policies towards one in which they can become informed participants in AI governance.

A broader lesson for Europe

The Character.AI proceedings form part of a wider European debate about the implications of generative AI for minors, education, privacy and digital rights. Italy is also developing a broader institutional response to artificial intelligence, while national authorities are examining issues ranging from AI in schools to disinformation, deepfakes, transparency and the protection of minors.

The Character.AI case therefore represents more than an isolated enforcement action. It provides a tangible example of how established principles such as data protection, accountability, privacy by design and the protection of children must be applied in an environment where artificial intelligence is becoming increasingly interactive and personalised.

For educators, youth workers and policymakers, the message is equally important. Regulation can establish safeguards and responsibilities, but young people must also be equipped to navigate these environments critically. AI governance and AI education cannot develop along separate tracks.

The future of responsible artificial intelligence will depend on our capacity to combine effective regulation, responsible technological design, critical AI literacy and meaningful youth participation.

Young people should be protected when interacting with artificial intelligence. But they should also understand the systems surrounding them, be able to question them and, ultimately, have opportunities to contribute to the decisions that determine how those systems are governed. That distinction — between simply being protected from technology and being empowered to participate in shaping it — lies at the heart of the challenge that projects such as YouthGovAI seek to address.

Leave a Reply

Your email address will not be published. Required fields are marked *

toggle icon