Alongside this institutional development, the Garante issued a 14 May 2026 provvedimento addressing workplace AI systems that analyse workers' emotional or psychological states, explicitly invoking the AI Act's ban on emotion-inference systems in the employment context. This signals that the Garante is already applying AI Act principles operationally, ahead of the national implementing decree's formal enactment, through its existing enforcement and guidance powers.
Other Developments
Two concrete enforcement sanctions this cycle. The Garante sanctioned Poste Italiane/PostePay for unlawful monitoring of applications installed on users' Android devices, a security-of-processing and accountability matter recorded in Provvedimento n. 237 of 17 April 2026. Separately, the Garante's 29 July 2026 newsletter recorded a EUR 280,000 fine against Altroconsumo Edizioni for a marketing-related violation, though this finding rests on a single source this cycle and should be read with appropriate caution.
Expanded inspection programme shifting toward AI systems. The Garante's inspection plan for the second half of 2026 identifies at least 35 inspections across August to December, with scope shifting away from schools and toward municipalities, local health authorities, geomarketing, neuromarketing, dynamic pricing, and DPO-supplier relationships. AI-system checks feature prominently in this expanded programme, consistent with the broader pattern of the Garante extending its practical enforcement attention into algorithmic and AI-adjacent processing this cycle.
Biometric and generative-AI matters affecting vulnerable groups. The Garante called for an express prohibition, within a pending criminal-procedure reform introducing a new Article 359-ter biometric-identification framework, on the use of databases obtained through indiscriminate scraping or otherwise in violation of data-protection law. Separately, in a 3 July 2026 provvedimento, the Garante examined the character.ai generative-AI companion service, noting the existence of a dedicated version for minor users launched in November 2024, a matter with direct relevance to the treatment of children and vulnerable groups in generative-AI contexts.
Cross-Monitor Connections
The AI Act implementing-decree development and the workplace-AI provvedimento both carry relevance for the artificial-intelligence monitor, which tracks the substantive AI-governance dimension of these same instruments in more depth; readers following Italy's AI Act transposition in full should refer there. The biometric-identification framework under the pending Article 359-ter criminal-procedure reform also touches law-enforcement and surveillance themes that may be of interest to the financial-integrity monitor's enabler-jurisdiction and compliance-technology tracking, though no direct financial-integrity nexus was identified in the sources reviewed this cycle.
Outlook
The central item to watch is the fate of the draft AI Act implementing decree: the Garante's favourable opinion is a significant procedural milestone, but the decree has not yet been enacted, and its final text and enactment date remain open. Once enacted, it would formally extend the Garante's market-surveillance remit into high-risk AI systems in justice, law-enforcement, immigration and democratic-process contexts, a substantial expansion of institutional scope. Separately, the character.ai provvedimento and the biometric-scraping advocacy both point to a continuing pattern of the Garante using its existing GDPR powers to address AI-adjacent harms ahead of AI Act enactment, a pattern likely to continue through the remainder of 2026 as the expanded H2 inspection programme proceeds.
1 earlier update not shown here.
Standing brief · as of 25 August 2026
Written before the update above. Where they differ, the update is the more recent position.
Lead Signal
The Garante's decision of 17 April 2026 to fine Poste Italiane EUR 6,624,000 and PostePay EUR 5,877,000 — a combined EUR 12.5 million — over device-surveillance software development kits embedded in the companies' banking applications is the dominant enforcement event of this cycle. The Garante found violations across GDPR Articles 5, 6, 13, 25, 26, 28, 32 and 35, together with Article 122 of the Italian Privacy Code, and explicitly rejected Poste Italiane's argument that PSD2 fraud-prevention obligations justified the intrusive processing, finding that less invasive alternatives existed. The decision sets a financial-sector precedent that PSD2-based fraud-prevention justifications do not automatically legitimise device-level surveillance under GDPR.
Other Developments
Judicial reversal of the OpenAI fine. The Court of Rome annulled, on 18 March 2026, the Garante's EUR 15 million fine originally imposed against OpenAI on 20 December 2024, a landmark reversal that signals judicial pushback against the regulator's AI-enforcement approach and introduces new uncertainty into how far the Garante's AI-related GDPR enforcement will be sustained on appeal.
Character.AI fined over privacy and child-protection lapses. The Garante fined Character Technologies Inc. approximately EUR 158,000 for privacy and child-protection lapses, a decision that also implicates age-verification failures in a generative-AI chatbot context and sets an early marker for scrutiny of interactive AI platforms used by minors.
New opt-in rules for email tracking pixels. In April 2026 the Garante introduced guidelines requiring email tracking pixels to move to an opt-in consent model, with a six-month compliance window for businesses to adjust, placing a concrete compliance deadline on the adtech and commercial-privacy landscape.
Cross-Monitor Connections
The Poste Italiane/PostePay decision's rejection of a PSD2-based justification for device surveillance is directly relevant to the world-payments monitor's conduct and safeguarding coverage, given the decision concerns banking-application security tooling deployed by a licensed payment-services provider. The Character.AI and OpenAI enforcement actions are relevant to the artificial-intelligence monitor's coverage of generative-AI governance in Italy, particularly on the question of how durable Garante enforcement against AI providers proves to be following the Court of Rome's reversal.
Outlook
Two threads are worth tracking into the next cycle: whether the Garante appeals the Court of Rome's annulment of the OpenAI fine, which would clarify whether this cycle's reversal is a one-off procedural correction or a more durable check on the regulator's AI-enforcement approach; and whether Poste Italiane and PostePay's appeal of the EUR 12.5 million fine succeeds in disturbing the Garante's rejection of the PSD2 fraud-prevention defence, a precedent that other financial-sector controllers deploying similar device-surveillance tooling will be watching closely. The six-month compliance window for the new email-tracking-pixel opt-in rules, running to around October 2026, is a concrete near-term deadline for adtech-adjacent controllers operating in Italy.