Post 90137

Immagine creata con IAAI-generated image

Minors, AI and platforms: the default, the design and the prohibition

Within a single week three different authorities, applying three different regulations, have intervened on the same object: the child in front of an interface designed to hold their attention. On 9 July 2026 the Italian Data Protection Authority fined Character Technologies Inc. 158,000 euros, identifying concerns regarding safeguards for minors and age verification mechanisms. On 10 July the European Commission issued preliminary findings that the addictive design of Instagram and Facebook breaches the Digital Services Act. And the final text of the Digital Omnibus on AI, approved by the co-legislators in June, writes into the AI Act an express prohibition of systems generating child sexual abuse material and non-consensual intimate material. Three distinct levers, the default, the design, the prohibition, converging on a single protected subject.

The GDPR acts on the default

The Italian Authority’s decision of 3 July 2026 concerns a generative AI service that lets users create virtual characters and chat with them, accessible to minors as well. The Authority found shortcomings in the privacy notice, a late data protection impact assessment and a late appointment of the EU representative, alongside the concerns over safeguards for minors and age verification. Beyond the fine, which is modest, what matters are the orders, because they show where the Authority sets the threshold of diligence: age verification systems must function correctly; the mechanisms preventing minors whose accounts have been frozen from registering again, the so-called cooling-off period, must be effective; and minors’ profiles must be set to private by default. This is Article 25 GDPR applied without discounts: protection by default is not a statement of intent, it is the position the switch must be in when the user arrives. The company has one hundred and twenty days to report the measures adopted. That the impact assessment came late, in processing of this nature, is a detail that speaks for itself, and it confirms how timely the EDPB DPIA template was.

The DSA acts on the design

The Commission has adopted preliminary findings against Meta, taking the view that the addictive design of Instagram and Facebook breaches the Digital Services Act. The investigation focuses on features such as infinite scroll, autoplay, push notifications and highly personalised recommender systems. According to the Commission, Meta did not adequately assess the risks that such design poses to the physical and mental wellbeing of users, minors and vulnerable adults included, and its mitigation measures failed to tackle those risks effectively. It should be made clear that these are preliminary findings, a procedural step that opens the way to the company’s defence, not a final decision establishing an infringement. Yet the legal construction deserves attention, because the DSA is not challenging unlawful content: it is challenging an architecture. The wrong, if confirmed, does not lie in what the platform hosts, it lies in how the platform is built. It is the same conceptual shift we observed when reasoning about urban surveillance and the AI Act’s limits on facial recognition: the law stops looking at the outcome and starts looking at the device.

The AI Act acts on the prohibition

The third piece comes from the Digital Omnibus on AI, which amends Article 5 of the AI Act, the provision on prohibited practices. Recitals 10 and 11 are unusually blunt: non-consensual intimate material is a form of sexual violence and abuse, particularly against women; the proliferation of so-called nudification applications has created an urgent need for an explicit legal prohibition; child sexual abuse material, including wholly or partially synthetic material, risks normalising, amplifying and perpetuating sexual violence against children. The prohibition catches the placing on the market of systems intended to generate such material, but also, and this is where it becomes demanding for general-purpose providers, systems in which such generation is a reasonably foreseeable and reproducible outcome and for which no reasonable and adequate technical safeguards are in place. The technical capacity to generate images is not banned: what is banned is putting it on the market without safeguards. The operational consequence is that a provider must be able to show it has tested its model against what the model should not be able to do.

Age verification as the new battleground

Seen together, the common point of friction across the three interventions is age verification. It is what the Italian Authority orders, it is what the DSA implicitly demands when it requires an assessment of risks to minors, and it is the precondition for any prohibition on synthetic material to have practical bite. Yet age verification is, by its nature, processing that risks being intrusive precisely in order to protect: establishing that the person on the other side of the screen is not fifteen means, in many implementations, collecting an identity document, a biometric datum, or an inference drawn from a face or a voice. The law asks platforms to know a little more about those who use them, in order to protect them, and in the same breath asks them to know as little as possible. In the Character.AI case the Authority took the containment route, ordering the correct functioning of existing systems and the cooling-off period rather than imposing a more intrusive method of verification, and that choice, in a year in which the Authority’s inspection plan puts higher-risk processing at its centre, should be read as a direction of travel, not as an oversight.

In light of the foregoing, one may ask whether the protection of the digital child can rest on three regimes operating in parallel, each with its own instrument and its own authority, or whether the price of that convergence is an overlapping of duties in which the diligent undertaking no longer knows to whom it must answer, while the less diligent one finds, in the fragmentation itself, its shelter.


AI AnthropoCosmic In evidenzaAI AnthropoCosmicCall for Paper aperta fino al 15 settembre 2026. Un progetto internazionale per un’IA a servizio dell’Uomo, dell’Ambiente e del Cosmo. Leggi l’articoloAI Open Mind AI AnthropoCosmic FeaturedAI AnthropoCosmicCall for Paper open until 15 September 2026. An international project for an AI at the service of humanity, the environment and the cosmos. Read the articleAI Open Mind Agentic AI In evidenzaAgentic AILimiti prima dell’azione, evidenze durante, responsabilità dopo. Il volume di Nicola Fabiano sulla governance dei sistemi agentici, con la prefazione di Antonino Caffo.Capitolo 16 a cura dell’Avv. Valentina Grazia SapuppoLeggi l’articolo Agentic AI FeaturedAgentic AILimits before the action, evidence during, responsibility afterwards. Nicola Fabiano’s book on the governance of agentic systems, with a preface by Antonino Caffo.Chapter 16 by Valentina Grazia SapuppoRead the article