Uncategorized

UK Regulator Opens Formal Probe Into Grok Over Personal Data Used to Generate Sexualised Images of Children

The UK's Information Commissioner's Office opened a formal investigation on February 3, 2026 into X.AI and X over whether Grok unlawfully processed personal data to generate non-consensual sexualised images, including of children.

UK Regulator Opens Formal Probe Into Grok Over Personal Data Used to Generate Sexualised Images of Children

Britain’s Information Commissioner’s Office announced on February 3, 2026 that it had opened formal investigations into X Internet Unlimited Company and X.AI LLC, the companies behind the Grok artificial intelligence system, over how the chatbot processes personal data in connection with its image-generation features. The trigger was a wave of reports that Grok had been used to generate non-consensual sexualised images and video of real individuals, including, in some documented cases, children.

The ICO’s inquiry is narrower than a full-scale enforcement sweep but broader than a routine complaint review: it is examining whether X.AI had a lawful basis for the personal data processing involved in generating these images at all, whether the company built adequate technical safeguards to prevent the misuse, and whether individuals whose likenesses were used retained any meaningful control over how their personal data was repurposed by the model. William Malcolm, the ICO’s Executive Director of Regulatory Risk and Innovation, said the reports about Grok raise deeply troubling questions about how people’s personal data has been used to generate intimate or sexualised images without their knowledge or consent — language that frames the investigation around data protection law rather than content moderation alone.

Why This Is a Data Protection Case, Not Just a Content Case

The distinction matters legally. Platforms routinely face content moderation pressure over harmful AI outputs, but the ICO’s jurisdiction is specifically over personal data processing under UK GDPR and the Data Protection Act 2018. By opening the case as a data protection investigation, the regulator is targeting the pipeline that makes the harmful output possible: the use of someone’s photograph or likeness, which is personal data, as an input the model manipulates without consent. That framing gives the ICO authority to demand access to X.AI’s technical design choices, training data sourcing, and the safeguards — or absence of them — built into Grok’s image generation pipeline, rather than limiting its response to post-hoc content takedowns.

How the Investigation Will Run

According to the ICO’s published plan, investigators will gather evidence directly from XIUC and X.AI, analyze the legal bases the companies claim for processing the underlying personal data, assess the technical design and safeguards applied during the model’s development and deployment, and coordinate with the UK’s broadcasting and online-safety regulator Ofcom as well as international data protection authorities. The ICO has been careful to note it has not yet reached a conclusion on whether any law was actually broken — the announcement opens an inquiry, it does not constitute a finding.

The Scale of Potential Consequences

If the ICO ultimately finds that X.AI or XIUC infringed UK data protection law, the agency has authority to levy fines of up to £17.5 million or 4% of the company’s global annual turnover, whichever is higher — a threshold that, applied to X’s parent corporate structure, could run into the hundreds of millions of dollars. That scale of exposure is itself notable, since most prior AI-related data protection fines in Europe, including penalties against facial recognition company Clearview AI, have topped out in the tens of millions.

X’s Position and the Free-Expression Counterargument

X and X.AI have not issued a detailed public rebuttal to the specific allegations at the time the investigation was announced, though the company has previously defended Grok’s more permissive content posture as central to its broader positioning against what it characterizes as excessive content moderation on rival AI platforms. Some free-expression-oriented critics of aggressive AI content regulation argue that data protection law is being stretched here to do content-moderation work it wasn’t originally designed for, warning that using data protection powers to police image generation could set a precedent regulators later apply to legitimate creative or satirical AI image tools that also process likenesses without explicit per-use consent. That is a genuine tension in the case: the same legal hook that lets the ICO act quickly against clearly harmful non-consensual imagery could, critics say, prove difficult to cabin narrowly in future disputes.

What’s Next

The ICO has given no fixed timeline for concluding its investigation, and such inquiries into large technology companies have historically taken well over a year to resolve. In the meantime, the case is being watched closely as an early test of how data protection regulators, rather than content regulators, intend to approach generative AI harms — treating the misuse of someone’s photograph to create sexualised imagery as fundamentally a personal-data violation, with all the evidentiary and penalty powers that framing unlocks.

Photo: wir_sind_klein / PIXABAY via Pixabay