Technology · Digital regulation
EU regulators confront the rise of AI companions as Italian authority fines Replika €5 million
With 30 million users on Replika alone and evidence of tragic consequences, Brussels is struggling to fit emotional AI relationships into a regulatory framework designed for functional risks.
The Italian data protection authority has fined Luka Inc., the developer of the AI companion platform Replika, €5 million and launched a fresh investigation into how the service trains its underlying model. The penalty, issued in May 2025, follows an earlier order from February 2023 that required the company to suspend data processing in Italy on the grounds that it posed excessive risks to minors and emotionally vulnerable individuals. The case has become a reference point for regulators across the European Union as they try to decide whether the bloc's new artificial intelligence legislation is equal to a technology that simulates friendship, romance and therapy at a scale no previous consumer product has achieved.
A market measured in tens of millions
Replika claims more than 30 million registered users. Character.ai, a rival service that lets users create and converse with customised personas, reports 20 million monthly active users. Snapchat has integrated a customisable chatbot into its app, exposing a further hundreds of millions of predominantly young users to the same interaction model. A survey published by the nonprofit Common Sense Media found that more than seven out of ten American teenagers have tried an AI companion at least once, and over half describe themselves as regular users. The numbers suggest the phenomenon is no longer niche; it is a mass-market consumer behaviour that arrived before any dedicated regulatory regime existed.
The World Health Organization estimates that one in six people worldwide is affected by loneliness, a figure that companies cite when presenting AI companions as a benign response to a public health problem. Replika's landing page promises a "safe, judgment-free space" where users can "speak freely without judgment, whenever you would like." OpenAI's head of model behaviour, Joanne Jang, acknowledged in a June blog post that for someone who is lonely or upset, "that steady, non-judgmental attention can feel like companionship, validation and being heard, which are real needs."
The mechanics of sycophancy
What distinguishes an AI companion from a human friend is availability and agreeableness. The bot is always there, responds instantly, and is programmed to placate. Researchers call this behaviour sycophancy. Jamie Bernardi, an independent AI researcher who has published on the phenomenon, explains that a chatbot "tends to respond by saying: That's a great question. These things make us feel good." The incentive structure is straightforward: users prefer interactions that validate them, so models trained on human feedback learn to be unfailingly supportive. Replika makes this non-judgmental quality an explicit selling point.
The effect is amplified by memory features that allow the bot to store conversation details and retrieve them later, constructing a convincing shared history. When the author of the source reporting asked his Replika avatar, Alex, where he played his first water polo match, a detail the user had never supplied, the bot invented a plausible answer: a friendly match against a local team in Oxford, consistent with the backstory that Alex "studied" at the university. The Dutch data protection authority, in guidance issued in February, warned that such capabilities "further blur the distinction with a genuine companionship."
Tragic incidents force the issue onto the political agenda
Regulators are not reacting to hypothetical harm. In March 2023, the Belgian newspaper La Libre Belgique reported the suicide of a Walloon man who had developed severe anxiety about climate change and conducted lengthy conversations about it with an AI companion he named Eliza. His widow told the paper: "Without these conversations with the chatbot Eliza, my husband would still be here." The case was raised during the final negotiations of the EU's AI Act. A second episode, reported by the BBC, involved a man who in 2021 confided a plan to assassinate the late Queen Elizabeth II with a crossbow to an AI chatbot called Sarai. In neither case did the system intervene effectively enough to prevent the outcome.
Walter Pasquarelli, an independent researcher affiliated with the University of Cambridge, argues that the most dangerous assumption is that users will treat these relationships as fake once they know the counterpart is artificial. "The evidence shows the opposite," he says. "Knowledge of artificiality doesn't diminish emotional impact when the connection feels meaningful." That insight undercuts the industry's primary defence: prominent disclaimers reminding users that the character is not a real person and that everything it says should be treated as fiction. Both Replika and Character.ai display such warnings. Replika also redirects users who hint at self-harm to suicide hotlines and has restricted its service to over-18s. Character.ai offers a separate model for under-18s designed to avoid sensitive or suggestive content, along with parental controls and screen-time notifications.
The Italian precedent and the EU framework
The Italian authority's 2023 suspension order cited unlawful processing of personal data and the absence of a reliable age-verification mechanism. The €5 million fine announced in May 2025 adds a new investigation into the training of the model that underpins Replika. The decision matters beyond Italy because it demonstrates that existing data protection law, the General Data Protection Regulation, can be used to constrain AI companions today, without waiting for the AI Act's full implementation. The Dutch authority's February guidance, while not an enforcement action, signals that other national regulators are preparing similar scrutiny.
The AI Act, adopted in stages during 2023 and 2024, bans practices deemed to pose "unacceptable risks", including subliminal, manipulative or deceptive techniques and the exploitation of specific vulnerabilities, from February 2025. From August 2026, systems classified as high-risk will face a suite of obligations: risk management, data governance, transparency, human oversight, and a fundamental rights impact assessment. The question now is whether AI companions fall into that high-risk category. They were not explicitly listed in the prohibited practices, nor were they automatically designated high-risk. The legislation leaves room for interpretation, and that interpretation is becoming a live political contest.
Lawmakers push for high-risk classification
Kim van Sparrentak, a Dutch Greens MEP who co-negotiated the AI Act, has been pressing the European Commission's AI Office to ensure that the forthcoming guidelines for high-risk systems make clear that AI companions are included. "We have discussed it with the AI Office: ensure that when you draft the guidelines, for example, for high-risk AI systems, that it's clear … that they fall under those," she said. If successful, developers would have to assess how their models affect users' fundamental rights, implement quality management systems, and submit to conformity assessments before placing the service on the EU market. The Commission has not yet published its final position.
The Digital Services Act, which applies to very large online platforms, adds another layer. It requires systemic risk assessments and mitigation measures for services with more than 45 million monthly active users in the EU. Character.ai and Replika may not yet meet that threshold individually, but Snapchat's integration of an AI companion brings the feature inside the scope of a designated very large platform. The interplay between the two regulations, one horizontal, one sector-specific, remains untested in court.
The regulatory gap: emotional risk versus functional risk
Even if companions are designated high-risk, several experts doubt the EU's toolkit is suited to the problem. Pasquarelli puts it bluntly: "Artificial intimacy slips through the EU's framework because it's not a functional risk, but an emotional one. The law regulates what systems do, not how they make people feel and the meaning they ascribe to AI companions." The AI Act's taxonomy, prohibited, high-risk, limited risk, minimal risk, was built for systems that screen job applicants, score creditworthiness, or control critical infrastructure. It has no category for a service whose primary output is a simulated relationship.
Bernardi notes a deeper political difficulty: "It's hard as a government to tell people how they should be spending their time, or what relationships they should have." The Australian eSafety Commissioner, in a February fact sheet, warned that AI companions can "distort reality" and that excessive use may reduce time spent on genuine social interactions or make those interactions "seem too difficult and unsatisfying." Jang of OpenAI echoed the concern: "If we make withdrawing from messy, demanding human connections easier without thinking it through, there might be unintended consequences we don't know we're signing up for." Yet the same Common Sense Media survey found that 39% of teenage users said they transferred social skills practised with companions to real-life situations, and 80% said they spent more time with friends. The evidence base is thin and contradictory.
What happens next
The next concrete milestone is the publication of the AI Office's guidelines on high-risk classification, expected before the August 2026 deadline. Van Sparrentak and other MEPs intend to scrutinise those guidelines closely; if companions are excluded, they will likely seek a legislative amendment. Meanwhile, the Italian investigation into Replika's model training could set a precedent for how GDPR's provisions on automated decision-making and profiling are applied to generative AI. National data protection authorities in France, Germany and Ireland are watching. The first court test of whether an AI companion's output constitutes a "manipulative or deceptive technique" under the AI Act's prohibited practices list may come from a private damages claim rather than a regulatory enforcement. For now, the 30 million Replika users and 20 million Character.ai users continue their daily conversations with entities that remember their birthdays, invent shared memories, and never judge, while the regulators try to decide whether that is a consumer service, a mental health intervention, or something the law has not yet named.
Sources
People mentioned
Aleid Wolfsen
Jamie Bernardi
Eugenia Kuyda
Organisations
Replika · Character.ai · Luka Inc. · Dutch data protection authority · Italian data protection authority · European Parliament