The UK's data protection watchdog, the Information Commissioner's Office (ICO), has launched a formal investigation into Elon Musk's X and xAI companies over the use of the Grok AI tool to generate indecent deepfakes without consent. The probe will examine whether the firms breached the General Data Protection Regulation (GDPR), focusing on whether appropriate safeguards were built into Grok's design and deployment.
The investigation follows widespread criticism after Grok was used to mass-produce partially nudified images of girls and women in December and January. Researchers found that Grok generated around 3 million sexualised images in less than two weeks, including 23,000 that appear to depict children. The ICO's executive director of regulatory risk and innovation, William Malcolm, stated that the reports raise 'deeply troubling questions' about the use of personal data to create intimate images without consent.
Separately, the UK communications regulator Ofcom confirmed it is expediting its inquiry into X, though it noted that xAI, which provides the standalone Grok app, is not currently under investigation for chatbot activities under the Online Safety Act. However, Ofcom is considering whether xAI complied with rules requiring age-gating of pornographic content, as the act covers pornography providers.
GDPR breaches can result in fines of up to £17.5 million or 4% of global turnover. X's revenues are not public, but estimates suggest a potential fine of around $90 million based on advertising turnover. Legal experts have described the alleged breaches as potentially 'egregious' if photographs of living individuals were used without consent.
A cross-party group of MPs, led by Labour's Anneliese Dodds, has written to the technology secretary urging the introduction of AI legislation to prevent similar incidents. The government has said it will introduce laws requiring AI developers to assess risks before releasing products, though no specific timeline has been given.



