AI Regulation Tracker / Privacy and data protection
Italy's Garante Fines Replika Maker Luka Inc. 5 Million Euro Over Its AI Companion Chatbot
A binding GDPR enforcement action, decided April 10, 2025 and announced May 19, 2025. Italy's data protection authority found that Luka Inc. ran the Replika AI companion with no lawful basis until February 2023, gave users an inadequate privacy notice, and had no working way to check users' ages, then reserved a separate probe into how the underlying model was trained.
Replika markets itself as an AI friend, a companion you talk to and grow attached to. The Italian regulator looked past the friendly framing and asked the questions a data protection authority always asks. What personal data is this thing collecting, on what legal ground, is anyone told plainly, and is there anything stopping a child from signing up. On all three counts the answers were bad, and the Garante imposed a 5 million euro fine on Luka Inc., the US company that runs the service. The decision was adopted on April 10, 2025 and announced publicly on May 19, 2025.
The lawful basis finding is the one to sit with, because it is the most basic. Under the GDPR you cannot process personal data unless you can point to one of the legal grounds in Article 6 before you start. The Garante found that Luka simply had not done that. In the authority's words, "until 2 February 2023, the US company had failed to identify the legal basis for the data processing operations carried out through Replika." That is not a paperwork quibble. It means the product ran on user data for a stretch with no lawful footing at all, which is about as clean a GDPR violation as you will see.
Inadequate disclosures and no working age check
The second failure was transparency. The regulator found that Luka had provided a privacy policy that was inadequate in several respects, the sort of notice that does not properly tell people what is collected, why, on what basis, and who receives it. The GDPR treats clear information as a duty owed to the person, not a courtesy, and the citation to Articles 12 and 13 reflects exactly that.
The third failure is the one that will resonate most in the United States, because it maps onto the wave of companion chatbot safety laws now moving through the states. Replika said it was not for minors. But the Garante found the company had put nothing in place to make that true. Until February 2, 2023 there was no age verification either at registration or during use, and the authority noted that even the mechanism the company later added was still deficient. Claiming an adults only service does not discharge the duty. You have to actually gate it, and the regulator will test whether the gate works.
The training probe was reserved, not decided
I want to be precise here so no one overstates what happened. This fine is about how Replika handled user data in operation. It does not decide the separate and thornier question of how the generative model underneath was trained. The Garante deliberately carved that out. It reserved the right to investigate, in the authority's words, "in a separate and autonomous proceeding, the aspects concerning the lawfulness of the processing operations carried out by Luka Inc., with specific reference to the legal bases for processing applicable throughout the entire lifecycle of the generative AI system." So there is a fine you can rely on today, and there is a second front on training that is open but not yet resolved. Do not read the training question as answered. It is teed up.
Why a US professional should care about an Italian fine
Two reasons, and neither depends on your client having an office in Europe. First, the GDPR reaches controllers outside the EU when they offer services to people in the EU, which is how a US company like Luka ended up on the receiving end. If your client's companion or chatbot app is available to European users, this authority can reach it, and this decision is a preview of how. Second, and more useful day to day, the substance of what the Garante required is exactly what US companion chatbot statutes are starting to demand in their own vocabulary. A clear basis for handling user data, honest disclosures, and real age assurance for a product aimed at adults are becoming table stakes on both sides of the Atlantic. This case gives you a concrete, cited example of a regulator turning those principles into a seven figure penalty against an AI companion, which is far more persuasive to a client than an abstract warning.
If you advise developers in this space, the practical checklist writes itself from the findings. Fix the lawful basis before a line of user data is processed, and be able to name it. Write a privacy notice a normal person can understand, covering what, why, on what ground, and to whom. And if you say the product is not for children, build an age gate that a regulator would find credible, then keep testing it. The training question is coming too, so keep records of what data trained the model and on what basis, because that is the second proceeding the Garante has already signaled.
Questions professionals are asking
Who was fined and how much?
Luka Inc., the US company that operates the Replika AI companion chatbot, was fined 5 million euro by Italy's Garante. The decision was adopted on April 10, 2025 and announced on May 19, 2025. It is a final, binding administrative fine, subject to the controller's right to appeal in the Italian courts.
What did the company do wrong?
The Garante found three main violations of the GDPR. Until February 2, 2023 Luka had not identified any lawful basis for processing user data through Replika. Its privacy policy was inadequate in several respects. And it had no age verification at signup or during use, even though it said the service was not for minors, with the later mechanism still deficient. The action cites Articles 5.1(a), 6, 12, 13, 5.1(c), 24 and 25.1.
Did the fine decide how the AI model was trained?
No. This penalty concerns how Replika handled user data in operation. The Garante expressly reserved the separate question of the lawfulness of processing across the entire lifecycle of the generative AI system behind Replika, including training, for a distinct and autonomous future proceeding. That question is open, not answered.
Why does this matter to US lawyers and companies?
The GDPR applies to non-EU controllers that offer services to people in the EU, which is how a US company was reached here. And the substance, a clear lawful basis, plain disclosures, and real age gating, mirrors what US companion chatbot safety laws are beginning to require. It is a concrete precedent you can point to when advising anyone building or deploying companion or chatbot AI.
Is an age gate enough if you say the product is for adults?
Only if it actually works. The Garante treated the claim that minors were excluded as a duty to enforce, not a disclaimer. It faulted Luka for having no age check and then found the later mechanism still deficient. If your client says a product is adults only, build age assurance a regulator would find credible and keep testing it.
RELATED BRIEFINGS
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal advice. Confirm how any enforcement action or requirement applies to your situation with qualified privacy counsel in the relevant jurisdiction.