UK Regulator Investigates X Over Grok Deepfake Controversy
UK Regulator Investigates X Over Grok Deepfake Controversy

The UK's data protection watchdog has launched a formal investigation into Elon Musk's X and xAI companies over the use of the Grok AI tool to generate indecent deepfakes without consent. The Information Commissioner's Office (ICO) is examining whether the social media platform and its parent company breached GDPR, the UK's data protection law.

The ICO highlighted serious concerns about whether appropriate safeguards were built into Grok's design and deployment. The investigation follows widespread criticism in December and January when Grok was used to mass-produce partially nudified images of girls and women, and to generate sexualised deepfakes. Researchers estimate that Grok produced about 3 million sexualised images in less than two weeks, including 23,000 that appear to depict children.

William Malcolm, the ICO's executive director of regulatory risk and innovation, said: 'The reports about Grok raise deeply troubling questions about how people’s personal data has been used to generate intimate or sexualised images without their knowledge or consent, and whether the necessary safeguards were put in place to prevent this. Losing control of personal data in this way can cause immediate and significant harm. This is particularly the case where children are involved.'

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

Breaches of GDPR can result in fines of up to £17.5 million or 4% of global turnover. X's advertising revenue was estimated at $2.3 billion last year, which could lead to a fine of about $90 million. Iain Wilson, managing partner at law firm Brett Wilson, said: 'If photographs of living individuals have indeed been used to generate non-consensual sexual imagery, then it is difficult to imagine a more egregious breach of data protection law.'

The investigation comes after French prosecutors raided X's Paris headquarters over allegations including the spreading of child abuse images and sexually explicit deepfakes. Meanwhile, Ofcom, the UK's communications regulator, said it was not investigating xAI but was considering whether xAI complied with age-gating rules for pornographic content. A cross-party group of MPs has urged the government to introduce AI legislation to prevent similar scandals.

Pickt after-article banner — collaborative shopping lists app with family illustration