
Start here
In March 2023, the case for treating an AI chatbot as ordinary software met a data protection regulator that disagreed. Italy's Garante per la protezione dei dati personali ordered an immediate stop to processing Italian users' data through ChatGPT, and the sequence that followed shows what a regulator can require before a consumer AI product resumes service in a market.
What the documents say
The Garante's own announcement of the order, dated 31 March 2023, states that the authority imposed a temporary limitation of processing against OpenAI with immediate effect and opened a formal inquiry. It cites four reasons: no notice informing users and other people whose data is collected, no legal basis for the large-scale collection and retention of personal data used to train the algorithms, inaccurate information the service could return about real people, and no age-verification system despite terms setting a minimum age of 13. OpenAI had 20 days to report steps taken, under threat of a fine up to twenty million euros or four percent of global turnover. The Garante's follow-up announcement, dated 28 April 2023, records what OpenAI changed before the authority allowed the service to resume: an expanded privacy notice shown before registration, an online form letting anyone in Europe object to their data being used for algorithm training, a welcome screen on reactivation linking to the new notice, an age-declaration gate for existing Italian users, and a birth-date field at sign-up blocking registration under 13.
Check this
The concrete check is to compare a company's general privacy promises against what a regulator's order specifically required it to add. Here, the order named a notice, a legal basis for training data, an accuracy problem, and an age gate as deficiencies; the reopening document lists a matching change for each one. That one-to-one structure is worth looking for in any regulator dispute: does the fix map onto the stated problem, or address something else while leaving the cited defect unmentioned?
What holds and what fails
What holds is narrow and specific: the Garante's documents record a named set of problems and a named set of fixes, and the authority says it hopes OpenAI continues further steps, including age verification, not yet complete as of 28 April. What this does not establish is a general verdict on ChatGPT's compliance everywhere; the Garante's own text frames this as an ongoing inquiry, not a closed case. Readers should treat the order as evidence of what one regulator required in one jurisdiction at one time, not a finding about every similar service.
- Look up whether your own AI provider offers a similar opt-out for training on your data.
- Check whether an age-verification step exists for services also used by teenagers.
- Read a regulator's order and a company's response to it as a matched pair, not separately.
A blocked launch is a strong headline; the more durable lesson sits in the gap between an order's stated defects and a company's documented fixes, because that gap is what a reader can actually check for any other product.
Sources & reading trail
Records the immediate limitation order against OpenAI, the four cited reasons, and the 20-day compliance deadline.
Source published: 31 March 2023 · Retrieved: 16 September 2026
Records the specific measures OpenAI implemented, such as the training opt-out form and age gate, that led the Garante to allow ChatGPT to resume in Italy.
Source published: 28 April 2023 · Retrieved: 16 September 2026
Documentation, regulator guidance and studies establish the record; the checks and the boundary are AI Use Field Guide editorial analysis. This retrospective draft does not imply the site published on the event date.