Europe’s first big fines against generative AI did not come from the AI Act. They came from GDPR — and from one regulator in particular: Italy’s Garante per la protezione dei dati personali (the Italian data protection authority, the national body that enforces GDPR in Italy).
This is the registry of the Garante’s AI-related GDPR enforcement: what each company did, the exact GDPR articles cited, the amount, and — critically — what happened to the decision afterwards. One of these two fines has already been struck down by a court. Every amount, date and article below links to the regulator, the court record, or editorial press.
Why the first AI fines run through GDPR, not the AI Act
The AI Act does not replace GDPR. The two laws run in parallel and overlap constantly: GDPR governs how personal data is handled inside an AI system (what data, on what legal basis, with what transparency), while the AI Act governs how the AI system itself is built, tested and supervised (risk class, conformity assessment, market surveillance). A chatbot can be perfectly compliant with one and breach the other.
In practice the first wave of headline AI penalties in Europe arrived through GDPR, because GDPR was already in force with mature enforcement machinery while the AI Act’s obligations were still phasing in. The common thread in both Italian cases below is the same GDPR failure: training or running an AI service on people’s personal data without a valid legal basis (a “legal basis” is the specific lawful ground — consent, contract, legitimate interest, etc. — that GDPR’s Article 6 requires before any personal data may be processed). Neither was decided under the AI Act.
1. OpenAI — ChatGPT — €15,000,000 — December 2024 — ANNULLED IN COURT
What happened. Following its March 2023 temporary block of ChatGPT in Italy and the cross-border EDPB ChatGPT Task Force it co-coordinated, the Garante concluded its own investigation and announced a €15 million fine against OpenAI, made public on 20 December 2024.
GDPR violations. Per the regulator, OpenAI processed users’ personal data to train ChatGPT without first identifying an adequate legal basis, breached the transparency and information obligations owed to users, had no age-verification mechanism capable of keeping under-13s out, and failed to notify the Garante of a March 2023 data breach (case summary, Lewis Silkin).
Corrective measure. Beyond the €15 million, OpenAI was ordered to run a six-month institutional communication campaign across Italian radio, TV, press and the internet, explaining how ChatGPT works, how it collects data for training, and the rights — objection, rectification, erasure — that data subjects can exercise (Euronews). OpenAI called the decision “disproportionate” and appealed.
Status — ANNULLED. OpenAI appealed to the ordinary court (the Tribunale di Roma, the Rome civil court that hears challenges to Garante sanctions). The court first temporarily suspended the fine in March 2025 pending a ruling on the merits, then annulled it in full with judgment no. 4153/2026, filed on 18 March 2026 (ANSA). The Garante removed the decision from its website following the ruling; the court’s full written reasoning was not yet public at the time of reporting. The €15 million is, as of this writing, not owed.
2. Luka Inc. — Replika — €5,000,000 — April 2025
What happened. Replika is an AI “virtual companion” app — users create a chatbot that plays the role of friend, therapist, romantic partner or mentor. After press reports about the service, the Garante investigated its US operator, Luka Inc., and on 10 April 2025 fined the company €5 million.
GDPR violations. Per the official EDPB summary of the Italian decision, the Garante found breaches of Articles 5(1)(a), 6, 12, 13, 5(1)(c), 24 and 25(1) of the GDPR: until 2 February 2023 Luka had not identified any legal basis for the processing carried out through Replika; its privacy notice was inadequate in several respects; and it had implemented no age-verification mechanism at sign-up or in use, despite declaring that minors were excluded from its users.
Corrective measure and a second front. Beyond the €5 million, the Garante ordered Luka to bring its processing into compliance with the Regulation, and expressly reserved a separate, autonomous investigation into the lawfulness of Luka’s use of user data to train the Replika AI model itself — a distinct question from running the service (EDPB). That separate proceeding is, at the time of writing, ongoing.
What the two cases have in common
Strip away the AI framing and both decisions reduce to one GDPR failure pattern, repeated across the AI lifecycle: personal data used to build or run the service before anyone established a lawful basis for it, compounded by weak transparency and absent age checks on services plainly reaching minors. The €15M OpenAI matter shows the second half of the story too — a large generative-AI fine can be issued and then fall apart in court on the procedure and substance, exactly as happened to the €746 million Amazon fine in Luxembourg. A headline number is not the same as a final, collected penalty.
If you build or deploy AI
- If you train models on personal data: the legal-basis question is decided before training, not after launch. “We’ll figure out the basis later” is precisely what cost OpenAI a fine at first instance — the court fight came later and is the exception, not the plan.
- If your AI service can be reached by minors: a sign-up checkbox is not age verification. Both cases turned partly on the absence of any real age-gating despite the terms excluding minors.
- If you operate from outside the EU: Luka (US) and OpenAI (US) were both reached. Establishment in Ireland later routed OpenAI into the one-stop-shop (the GDPR mechanism that gives a company one lead regulator for cross-border cases) — but the conduct before EU establishment was judged by the national authority directly.
- Watch the appeal track. Italian Garante sanctions are challenged before the Tribunale di Roma. The OpenAI annulment shows first-instance fines are not the end of the matter — for either side.
Sources and method
Figures, dates and article numbers are taken from the Italian supervisory authority’s published decisions as summarised by the EDPB, the Rome court record (judgment 4153/2026 reporting, Altalex), Italy’s national news agency ANSA, and editorial/legal coverage by Euronews and Lewis Silkin. This is a living registry — it is updated when a decision’s court status changes. Related: the GDPR pillar, the AI Act pillar, and the AKI fines registry for the same pattern in Estonia.