Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • COPYRIGHT—S.D.N.Y.: Smut film screencap is protected as fair use
    • COPYRIGHT—N.D. Cal.: Photographer wins infringement ruling but not damages
    • PATENT—1st Cir.: Tech company’s malpractice and fiduciary-duty claims against patent law firm revived on appeal
    • PATENT—Fed. Cir.: Sharing of content with a unique identifier was an unpatentable abstract idea
    • STRATEGIC PERSPECTIVES: Grok’s sexual deepfakes draw scrutiny from U.S., European enforcers
    • TRADEMARK—N.D. Cal.: Motion to dismiss declaratory judgment action regarding HELIOS trademark denied
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    IP Law Daily, STRATEGIC PERSPECTIVES: Grok’s sexual deepfakes draw scrutiny from U.S., European enforcers, (Feb 5, 2026)

    Organizations Mentioned:SpaceX

    By Thomas Long, J.D.

    Authorities in the U.K. and France join over 35 state attorney generals in launching investigations of potentially unlawful practices by Elon Musk’s AI company.

    Rapid advances in generative artificial intelligence technology have introduced new ...

    By Thomas Long, J.D.

    Authorities in the U.K. and France join over 35 state attorney generals in launching investigations of potentially unlawful practices by Elon Musk’s AI company.

    Rapid advances in generative artificial intelligence technology have introduced new capabilities for analyzing and processing information, but along with the positive aspects of the emerging tech have come significant problems. One of the most well-publicized negative consequences of AI’s proliferation has been the rise in the use of AI tools to generate realistic imitations (frequently called “deepfakes”) of people’s likeness. Deepfakes of actors, athletes, and other prominent individuals have led to disputes over publicity (or “name, image, and likeness”) rights, while even more serious concerns have stemmed from AI-generated nonconsensual sexual or intimate images (NCII) of real people, including children. In recent weeks, these types of activity being carried out on the social media platform X, owned by billionaire Elon Musk, have drawn widespread attention.

    X (formerly known as Twitter) is operated by Musk’s X Corp. As of March 2025, X Corp. has been a subsidiary of Musk’s artificial intelligence startup, X.AI Corp. (doing business as xAI), which produced and operates Grok, both as a component of the X platform and in a standalone subscription-based format. According to news reports, Musk’s aerospace company SpaceX acquired xAI on February 2.

    According to numerous reports and complaints, X users have successfully prompted the integrated generative artificial intelligence chatbot called Grok to produce NCII, including child sexual abuse material (CSAM). These images reportedly have often been created and disseminated as part of efforts to harass women and girls. After a flurry of negative media attention, X imposed guardrails to limit the ability of Grok to create NCII on the social media platform, although these limitations reportedly do not restrict a standalone version of the Grok chatbot.

    While efforts by X and xAI to mitigate the harms of sexual deepfakes have been welcomed, many regulators and enforcers are not satisfied and have begun launching investigations into the social media giant, hinting at the possibility of future enforcement actions.

    State AGs take the initiative to address Grok deepfakes

    While the U.S. government has not taken or announced the intention to take action against xAI over sexual deepfakes, attorneys general of a majority of states and territories have initiated either formal investigations or less formal requests for information.

    California opens investigation. The attorney general of California was the first to act. On January 14, California Attorney General Rob Bonta announced the opening of an investigation into the “proliferation” of nonconsensual sexually explicit material produced through Grok. According to Bonta, “xAI appears to be facilitating the large-scale production of deepfake nonconsensual intimate images that are being used to harass women and girls across the internet, including via the social media platform X.”

    On January 16, Bonta’s office said he had sent xAI a cease and desist letter, demanding the company stop the creation and distribution of deepfake, nonconsensual, intimate images and CSAM. “The creation of this material is illegal,” Bonta said. “I fully expect xAI to immediately comply. California has zero tolerance for child sexual abuse material.” Specifically, Bonta’s office asserts that xAI’s actions violate California Civil Code section 1708.86, California Penal Code sections 311 et seq. and 647(j)(4), and California Business & Professions Code section 17200.

    The letter demands that xAI immediately cease and desist from creating, disclosing, or publicizing, or facilitating the creation of, digitized sexually explicit material when the depicted individual did not consent to its creation or disclosure or was a minor when the material was created. It also demands that xAI stop activities related to images involving or depicting a person under 18 years of age or what appears to be a person under 18 years of age engaging in or simulating sexual conduct.

    Thirty-five state AGs demand information, curative action

    A letter from a bipartisan group of 35 state attorneys general, dated January 23, calls on xAI to take action to address the problem of NCII generated through Grok. While the letter notes that problems with CSAM and deepfakes aren’t limited to Grok, it said that Grok was being singled out because of “evidence that it both (1) promoted and facilitated the production and public dissemination of such images, and (2) made it all as easy as the click of a button.” The AGs expressed concern that xAI’s measures to curb abuses via Grok have not solved the problems, and they requested that xAI take “additional steps to protect the public and users of your platforms, especially the women and girls who are the overwhelming target of NCII.”

    Connecticut AG William Tong, who is leading the investigative effort, said, “Elon Musk and xAI unleashed this monster, and it’s on them to immediately pull down abusive content, decisively disable Grok’s ability to produce these images, and to hold bad actors on their platform accountable. Bipartisan attorneys general representing a majority of states across the country are united in this demand, and are prepared to pursue all available legal remedies should this online abuse continue.”

    Information sought by AGs. The AGs’ letter called on xAI to “promptly” tell them how the company intends to:

    • take all necessary measures to ensure that Grok is no longer capable of producing NCII and child sexual abuse material;

    • eliminate such content that has already been produced;

    • suspend users that have created these materials;

    • where applicable, report these creators and users to the relevant authorities;

    • grant X users control over whether their content can be edited by Grok; and

    • ensure that recently announced safeguards actually mitigate production of NCII throughout X and the Grok platform.

    TAKE IT DOWN Act. Along with citations to applicable state laws, the letter mentions one new federal statute aimed at deepfakes—Section 223 of the Communications Act of 1934 (47 U.S.C. § 223), which was amended in 2025 by the Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks (TAKE IT DOWN) Act (S. 146). That law amended Section 223 to provide for the prohibition of the nonconsensual online publication of intimate visual depictions of individuals, both authentic and computer-generated. Covered platforms are required to remove nonconsensual intimate visual depictions within 48 hours of notification from the individual depicted. Although criminal penalties for publishing NCII were effective immediately, platforms will not be required to implement the 48-hour notice-and-takedown process until May 19, 2026.

    Enforcers in the United Kingdom and France launch probes

    Musk’s companies are not only facing scrutiny in the United States. Overseas enforcers, including those of the United Kingdom and France, have begun scrutinizing Grok and xAI for possible violations of communications safety laws and other offenses.

    ICO. The United Kingdom’s Information Commissioner’s Office (ICO) announced on February 3 that it has launched a formal investigation into X Internet Unlimited Co. (XIUC) and xAI in connection with Grok’s potential to produce “harmful sexualized image and video content.” Based in Dublin, XIUC is the data controller for the X platform in the European Union and the European Economic Area. Reports of Grok being used to generate non-consensual sexual imagery of individuals, including children, “raises serious concerns under UK data protection law and presents a risk of significant potential harm to the public,” the ICO said. According to the ICO, the concerns relate to whether personal data has been processed lawfully, fairly, and transparently, and whether appropriate safeguards were built into Grok’s design and deployment to prevent the generation of harmful manipulated images using personal data. The launch of the investigation follows a January 7 public statement in which the ICO said it had contacted XIUC and xAI to seek information about these reports.

    Ofcom. The U.K. Office of Communications (Ofcom)—an independent regulator of communications services—said on February 3 that it is not investigating xAI or the standalone Grok service. Ofcom is, however, investigating X with respect to “concerning reports of the Grok AI chatbot account on X being used to create and share demeaning sexual deepfakes” and potential violations of the Online Safety Act through the social media platform. Although xAI’s activities are part of Ofcom’s inquiries, it said that limitations of the Online Safety Act with respect to chatbots preclude it from investigating “the creation of illegal images by the standalone Grok service in this case.” Ofcom’s press release notes that it is in close communication with the ICO. “The ICO’s investigation into X and xAI will cover both the development and deployment of Grok,” Ofcom said, “and look into whether personal data has been processed lawfully, fairly and transparently, and whether appropriate safeguards were implemented to prevent the generation of harmful manipulated images using personal data.”

    France. News media reported on February 3 that French police—specifically, the cybercrime unit of the Paris prosecutor’s office—had raided X’s Paris offices as part of an investigation in CSAM being produced using Grok. Prosecutors have summoned Musk and former X Corp. CEO Linda Yaccarino for voluntary questioning at an April 20 court appearance, according to a press release. A machine translation of the release indicates that the investigation concerns criminal offenses including complicity in possession, distribution, offering, or making available CSAM materials as well as violating personal and privacy rights through sexually oriented deepfakes. Musk has asserted that the French investigation is a political attack.

    Conclusion—What comes next?

    Next steps taken by enforcers will depend on responses by xAI and Musk to requests for information and cooperation. If regulators are satisfied that xAI is taking sufficient action to address problems posed by Grok, that could be the end of it. If not, however, European and U.K. authorities have a variety of data protection and communications safety laws at their disposal, and U.S. states can pursue their own enforcement actions under laws criminalizing the creation and dissemination of CSAM and NCII, and possibly under state consumer protection and unfair business practices laws. They could also take action against payment processors to interfere with Grok’s revenue stream. When the requirements of the TAKE IT DOWN Act become enforceable later this year, we could see federal action. And legislatures at both the state and federal levels are likely to explore statutory means of dealing with sexual deepfakes.

    MainStory: AINews PublicityRights TechnologyInternet

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use