The UK's Information Commissioner's Office (ICO) has launched a formal investigation into Elon Musk's X and xAI companies over concerns that the Grok AI tool generated indecent deepfakes without consent. The probe focuses on potential breaches of the UK's data protection law, GDPR, including whether appropriate safeguards were built into Grok's design and deployment.
The investigation follows reports that the Grok AI tool mass-produced sexualised deepfakes of girls and women in December and January, with researchers estimating that around 3 million sexualised images were generated in less than two weeks, including 23,000 that appear to depict children. The ICO's executive director William Malcolm said the reports raised 'deeply troubling questions' about how personal data was used to create intimate images without knowledge or consent.
Under GDPR, organisations must manage personal data fairly, lawfully and transparently. Breaches can result in fines of up to £17.5 million or 4% of global turnover. Based on estimated advertising revenue of $2.3 billion last year, X could face a fine of around $90 million.
Separately, cross-party MPs led by Labour's Anneliese Dodds have urged the government to introduce AI legislation requiring developers to thoroughly assess risks before releasing products. Dodds said the scandal 'would not have happened' if proper testing had been undertaken. The government's Department for Science, Innovation and Technology has not yet commented on the call for new laws.



