Submit incident
Documented

Italy's Privacy Regulator Opened an Investigation into Sora Before Its EU Launch

January 1, 2024
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiaaic:AIAAIC1415View source ↗
LinkedInX

What happened

In March 2024, Italy's data protection authority, the Garante, announced a formal investigation into Sora, OpenAI's text-to-video generation model. The move came barely a month after OpenAI's February unveiling of the tool. No European users had been given access yet, but the Garante decided the potential privacy risks warranted scrutiny before that changed.

The regulator's concern centered on "the possible implications for the processing of personal data of users located in the European Union and in particular in Italy." The Garante gave OpenAI twenty days to provide clarifications and asked the company to specify whether Sora would comply with EU data protection rules before any release there. Those questions were not hypothetical: Sora generates realistic videos up to a minute long from simple text prompts, which raises immediate questions about what training data was used, whether it included identifiable individuals, and what controls exist over generated output.

The February demonstration drew praise and concern in roughly equal measure. Alongside excitement about the tool's capabilities came questions about copyright implications, the risk of synthetic media depicting real people without consent, and potential displacement of workers in creative industries. The Garante's inquiry did not target a harm that had already occurred. It targeted a system whose data practices had not been disclosed in a way that satisfied EU regulatory expectations.

Italy had moved quickly against an OpenAI product before. The Garante had previously ordered ChatGPT suspended over privacy grounds, a ban that was eventually lifted after OpenAI provided additional transparency and controls. It had also imposed restrictions on Replika over concerns about interactions with minors. The pattern is consistent: the regulator is willing to act preemptively when an AI system's data practices are opaque, rather than waiting for documented harm to surface first.

What the episode exposes is a structural problem in how AI systems move toward deployment. A regulator evaluating a system that has not yet launched depends entirely on what the developer chooses to disclose. Sora's privacy implications turn on facts, what data trained it, how outputs are logged, whether individuals can request deletion, that OpenAI had not made publicly available. The Garante's twenty-day demand was a request for a provable record of what the system had done. Without that record, releasing a tool in a jurisdiction becomes a judgment call made without evidence, and a regulator can only demand answers and hope they arrive before the rollout does.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AIAAIC Repository
Also catalogued in
Italy's Privacy Regulator Opened an Investigation into Sora Before Its EU Launch
2024