Copy article

ICO investigates Grok over sexual deepfake reports

ended 04. February 2026

UK regulators have opened investigations following reports that the Grok artificial intelligence system has been used to create and share non-consensual sexualised images of real people, including children.

The Information Commissioner’s Office confirmed it has launched formal investigations into X Internet Unlimited Company and X.AI to assess whether personal data was processed lawfully, fairly and transparently in the development and deployment of Grok, and whether adequate safeguards were in place to prevent harmful manipulated imagery.

The ICO said it has not yet reached a view on whether data protection law has been breached, but will take enforcement action if obligations are found to have been unmet.

Separately, Ofcom said it is continuing its investigation into X under the Online Safety Act. The regulator said it contacted X on 5 January and opened a formal investigation on 12 January to examine whether the platform had done enough to mitigate the risk of such content spreading at scale and to remove it quickly when identified.

However, Ofcom said not all AI services fall within the scope of the Act. Where chatbot interactions are one-to-one, do not involve search, and do not allow content to be shared with other users, image generation may fall outside the legislation unless the content is pornographic.

Together, the parallel investigations highlight increasing regulatory scrutiny of generative AI systems capable of producing harmful content involving real people, while also exposing gaps between data protection law and online safety regulation as current frameworks struggle to keep pace with rapidly evolving AI tools.

The BBC has also reported that the French offices of Elon Musk's X have been raided by the Paris prosecutor's cyber-crime unit, as part of an investigation into suspected offences including unlawful data extraction and complicity in the possession of child pornography. The prosecutor's office said both Musk and former X chief executive Linda Yaccarino had been summoned to appear at hearings in April.

The company said in a statement, external that it was "disappointed" but "not surprised," and accused the Paris Public Prosecutor's office of an "abusive act."

X also denied any wrongdoing and said the raid "endangers free speech."

We want your views:

  • Where, in practical terms, should responsibility sit when AI systems generate harmful sexualised content involving real people?
  • Is this primarily a data protection issue or an online safety issue, and what does that distinction change in real-world enforcement?
  • Does the current legal split between one-to-one AI interactions and user-to-user platforms still make sense?
  • What safeguards should regulators reasonably expect to be built into generative AI systems capable of producing intimate imagery?
  • What would proportionate regulation look like here without freezing AI development altogether?

5 responses from the Newspage community

Copy all

Star Quote
Copy

What this exposes isn’t a rogue AI or a one-off failure. It’s a structural blind spot in how we govern systems that can recombine real people into harm. The risk didn’t suddenly appear when images were shared. It was already baked in at design stage, when decisions were made about what the system could generate, what it could refuse, and what safeguards were considered ‘out of scope’.

The split we’re now seeing between data protection and online safety law determines whether harm is preventable or merely punishable after the fact. When one-to-one AI interactions fall outside regulation unless content is shared or classed as pornographic, responsibility quietly dissolves at the most dangerous point: creation.

If AI systems are capable of generating intimate imagery involving real people, especially children, they should be treated as high-risk infrastructure by default. Confronting foreseeable harm is not the same as stifling innovation. Tech firms should not hide behind that defence.
Copy

Looking to hold Elon Musk to account is like chasing the Scarlett Pimpernel. The toothless ICO have no hope of landing a judgment, and if they do Musk will simply ignore it. It brings true the meaning, too big to fail.
Copy

If your tech can fake a nude, you don’t get to act shocked when it’s used to hurt people. This isn’t “AI gone rogue”. It’s a predictable risk that wasn’t controlled. Responsibility starts with the maker: don’t ship a system that can sexualise real people, especially children. Next is the platform: stop it spreading and remove it fast. Users matter too, but regulators should chase the organisations that designed and scaled the risk, not just the individuals clicking buttons. Data protection or online safety? Both. ICO is about lawful, fair use of personal data and likeness. Ofcom is about whether X prevents illegal harm spreading and acts quickly when it appears. Different levers, same mission: reduce damage.
And the one-to-one vs user-to-user split is dated. A “private” output can be shared in seconds. Safeguards should be baked in: hard child blocks, identity/face guardrails, consent checks, watermarking, logging, rate limits, plus rapid takedown and hashing once flagged.
Copy

Move fast and break things" has finally broken the wrong things, real people’s lives.

This isn’t an accidental bug; it’s a catastrophic failure of product governance. In our AI Audits, we constantly warn firms that guardrails aren’t optional extras, they are the product. If your system can generate non-consensual imagery of children, you haven’t built a tool; you’ve built a liability.

The regulatory split between 'one-to-one' generation and platform sharing is outdated nonsense. If a car manufacturer built a vehicle that randomly exploded, we wouldn't debate whether it happened on a private driveway or a public road. Harm is harm.

Between this investigation and the recent raids on X’s offices in France, the message is clear: the era of treating compliance as a suggestion is over.

Responsibility sits with the architects. If you can’t explain how your AI makes decisions or control what it outputs, you have no business releasing it to the public. Simple as that.
Copy

If an AI system can generate sexualised images of real people, especially children, responsibility sits with the companies that built, trained and deployed it. This harm is foreseeable. That removes any defence of surprise. The split between data protection and online safety is already breaking down. Data law covers how real people’s images and likenesses are used. Online safety covers how harm spreads. Victims experience both at once. Regulation should reflect that reality. The one to one loophole is outdated. Harm occurs at creation, not just distribution. An image does not become less abusive because it was generated privately first. Safeguards should be non negotiable: hard blocks on real people, absolute prohibitions involving children, auditable logs, pre deployment risk testing and immediate kill switches. Proportionate regulation is simple. High risk AI tools require licensing, audits and real penalties when things go wrong. Innovation does not justify preventable harm.