ICO investigates Grok over sexual deepfake reports
UK regulators have opened investigations following reports that the Grok artificial intelligence system has been used to create and share non-consensual sexualised images of real people, including children.
The Information Commissioner’s Office confirmed it has launched formal investigations into X Internet Unlimited Company and X.AI to assess whether personal data was processed lawfully, fairly and transparently in the development and deployment of Grok, and whether adequate safeguards were in place to prevent harmful manipulated imagery.
The ICO said it has not yet reached a view on whether data protection law has been breached, but will take enforcement action if obligations are found to have been unmet.
Separately, Ofcom said it is continuing its investigation into X under the Online Safety Act. The regulator said it contacted X on 5 January and opened a formal investigation on 12 January to examine whether the platform had done enough to mitigate the risk of such content spreading at scale and to remove it quickly when identified.
However, Ofcom said not all AI services fall within the scope of the Act. Where chatbot interactions are one-to-one, do not involve search, and do not allow content to be shared with other users, image generation may fall outside the legislation unless the content is pornographic.
Together, the parallel investigations highlight increasing regulatory scrutiny of generative AI systems capable of producing harmful content involving real people, while also exposing gaps between data protection law and online safety regulation as current frameworks struggle to keep pace with rapidly evolving AI tools.
The BBC has also reported that the French offices of Elon Musk's X have been raided by the Paris prosecutor's cyber-crime unit, as part of an investigation into suspected offences including unlawful data extraction and complicity in the possession of child pornography. The prosecutor's office said both Musk and former X chief executive Linda Yaccarino had been summoned to appear at hearings in April.
The company said in a statement, external that it was "disappointed" but "not surprised," and accused the Paris Public Prosecutor's office of an "abusive act."
X also denied any wrongdoing and said the raid "endangers free speech."
We want your views:
- Where, in practical terms, should responsibility sit when AI systems generate harmful sexualised content involving real people?
- Is this primarily a data protection issue or an online safety issue, and what does that distinction change in real-world enforcement?
- Does the current legal split between one-to-one AI interactions and user-to-user platforms still make sense?
- What safeguards should regulators reasonably expect to be built into generative AI systems capable of producing intimate imagery?
- What would proportionate regulation look like here without freezing AI development altogether?





