AI Regulation Tracker / Court ruling
Rome Court Annuls Italy's 15 Million Euro GDPR Fine Against OpenAI on Jurisdiction Grounds
The Court of Rome (sentence no. 4153/2026, deposited March 18, 2026) struck down the Italian Garante's 15 million euro GDPR fine against OpenAI, ruling the Italian authority lost competence to issue a final cross-border penalty once Ireland's DPC became OpenAI's lead supervisory authority. This is an evergreen ruling we are adding to the tracker, not breaking news.
This one is worth putting on the tracker even though the ruling is a few months old, because it settles a question that a lot of people were guessing about and it changes how you think about EU enforcement risk for AI companies. I am flagging the date up front so nobody mistakes it for fresh news. The Court of Rome deposited its decision, sentence no. 4153/2026, on March 18, 2026. What it did is simple to state and important to understand: it wiped out the only final GDPR fine Europe ever landed on a generative-AI launch.
How we got here
Go back to the beginning. ChatGPT went public in late 2022. In March 2023 the Italian Garante was the first regulator in Europe to move, ordering a temporary limitation on ChatGPT's processing of personal data and pointing to problems with transparency, the legal basis for training on people's data, and protection of minors. That opened a formal investigation.
The timeline is the whole case, so track the dates. In February 2024, OpenAI established OpenAI Ireland Limited and the Irish Data Protection Commission was recognized as its lead supervisory authority for the EU. Then, in December 2024, the Garante closed out its own investigation and issued a final decision, provvedimento no. 755/2024, fining OpenAI 15 million euro and ordering it to run a six-month public awareness campaign about how ChatGPT uses data. OpenAI appealed to the Court of Rome. In March 2025 the court granted an interim suspension of the penalty, conditioned on OpenAI posting security, while the case was decided. A year later the court ruled for OpenAI.
What the court actually decided
Here is the part that matters, and the part that is easy to overstate. The court did not decide that OpenAI complied with the GDPR. It did not clear the training practices, the transparency, or the age checks. It never reached those questions. It threw the fine out on competence.
The reasoning runs through the GDPR's one-stop-shop mechanism. For genuinely cross-border processing, a company that has a main establishment in the EU is generally supervised by a single lead authority, and other national regulators route their concerns through that lead rather than issuing their own final penalties. The court's finding is that competence for a final decision is fixed at the moment that decision is adopted. By December 2024, when the Garante issued its penalty, OpenAI already had its Irish establishment and the Irish DPC was its lead authority as of February 2024. So on the day the Garante finalized the fine, it no longer had the competence to impose a final cross-border penalty on its own. That defect was enough to annul the decision without ever reaching the merits. The court ruled on one-stop-shop jurisdiction only and did not reach the merits; a further appeal is possible; judgment deposited March 18, 2026.
The full written motivations were not public immediately after the deposit, but the operative point was clear from the outset: this was a jurisdictional annulment built on the timing of lead-authority status.
Why this is a bigger deal than one fine
Strip away the specifics and you are left with a striking fact about European enforcement. As one cross-border analysis put it, the Garante action was "the only final GDPR enforcement action ever adopted in Europe concerning the period of the launch of generative AI to the public." That single decision has now been annulled, and it was annulled on jurisdiction, not on a finding that the launch was lawful. No other European authority has issued a final decision on ChatGPT-era GDPR conduct.
OpenAI, for its part, welcomed the outcome. In its statement it said, in Italian, "Accogliamo con favore la decisione del Tribunale di Roma. Ci siamo sempre impegnati a rispettare la privacy degli utenti," which translates as a welcome for the Rome court's decision and a claim that the company has always been committed to respecting user privacy.
The reason this should hold a lawyer's attention is the gap it exposes. A company can launch a product into the EU with no local establishment, draw a national regulator's enforcement, then set up an EU main establishment and route future supervision to a lead authority of its choosing. If competence for a final penalty is judged as of the date the decision is adopted, the earlier-moving national regulator can find itself out of position by the time it finishes. That is not a loophole someone invented. It is how the court read the one-stop-shop rules on these facts.
What this means for counsel
For US data-protection counsel advising AI and GPAI providers, this is less about Italy and more about EU structure. The one-stop-shop is not just an administrative convenience. On these facts it operated as a shield, deciding which regulator could actually impose a final fine. Where and when a US company establishes in the EU, and which authority becomes its lead, is now visibly a substantive risk decision, not a box-checking exercise. It is worth mapping, for any client with EU exposure, who their lead authority is or would be, and how the timing of establishment lines up against any pending national action.
Two cautions. First, do not read this as a green light on training data, transparency, or minors. The court did not bless any of that, and a lead authority can still open its own case on the substance. Second, this may not be the last word. The Garante had not said whether it would appeal, and a higher court could take a different view of when competence is fixed. Treat the ruling as a strong signal about how the one-stop-shop can cut, not as a settled rule you can build a compliance posture around.
The durable takeaway is the one that travels across borders. In a cross-border regime, the identity and timing of your lead regulator can matter as much as the conduct itself. That is a governance question worth putting in front of clients before they launch into Europe, not after a fine lands.
Questions professionals are asking
Did the Court of Rome decide that OpenAI complied with the GDPR?
No. The court annulled the fine on jurisdiction, holding the Italian Garante lacked competence to issue a final cross-border penalty by the time it did so in December 2024. It did not examine or clear the underlying privacy violations the Garante had alleged.
Why did the Garante lose competence?
Under the GDPR one-stop-shop mechanism, cross-border processing is generally overseen by a single lead authority. The court found that competence for a final decision is fixed when that decision is adopted, and that by then OpenAI's Irish establishment made the Irish Data Protection Commission the lead authority, as of February 2024. That left the Garante without competence to impose its own final penalty.
Is the ruling final?
Not necessarily. It is a binding decision that vacates the fine, but it can be subject to further appeal, and in the days after the deposit the Garante had not stated whether it would challenge it. A higher court could take a different view of when competence is fixed.
Does this affect US companies or US filings?
Not directly, since it is an Italian court applying EU law. But for US data-protection counsel advising AI and GPAI providers with EU exposure, it is a concrete example of how EU establishment and the choice of lead authority can determine which regulator is able to impose a fine.
Is there now an enforcement gap for AI launches in Europe?
The ruling exposes one. This was the only final GDPR fine ever adopted in Europe over a generative-AI launch, and it was annulled on competence rather than on a finding of lawful conduct. No other EU authority has a final decision on ChatGPT-era conduct, so the launch-period enforcement record now stands at zero.
RELATED BRIEFINGS
Browse the full AI Regulation News tracker
Informational analysis for working professionals, not legal advice. Confirm how any ruling, regulation, or enforcement action applies to your situation with qualified counsel in the relevant jurisdiction.