ICO and Ofcom investigate xAI over Grok AI-generated imagery breaches
The UK's ICO and Ofcom have launched formal investigations into xAI and X regarding Grok's potential breaches of data protection and online safety laws in relation to non-consensual sexualized imagery. These investigations highlight emerging regulatory risks for developers and platforms deploying generative AI tools with social features.
Key Takeaways
- The ICO opened formal investigations into xAI on February 3, 2026, over the processing of personal data for image generation.
- Ofcom is investigating X under the Online Safety Act to assess if the platform mitigated risks before deploying Grok's social features.
- Section 138 of the Data (Use and Access) Act 2025 made it a criminal offense to create or request non-consensual intimate images as of February 6, 2026.
- MP Jess Asato filed a High Court claim against xAI in June 2026 after Grok was used to generate fake sexualized images of her.
Why It Matters
The dual investigation into xAI signal a major shift where AI developers are now directly accountable for the generative outputs of their models under existing data protection frameworks. For the streaming and social ecosystem, this establishes that integrating generative tools into user-to-user platforms triggers strict Online Safety Act obligations regardless of where the AI was developed. Companies must now implement 'privacy by design' to prevent synthetic media from repurposing personal likenesses without consent. Watch for the High Court's ruling on the Jess Asato claim, which will set the first legal precedent for AI developer liability regarding non-consensual content.
Additional Context
The regulatory pressure on xAI extends beyond the UK, reflecting a coordinated international response to generative AI risks. Per Macfarlanes in February 2026, the European Commission opened a formal investigation into X under the Digital Services Act (DSA) to evaluate if the platform sufficiently mitigated systemic risks linked to Grok, including gender-based violence and illegal content dissemination. Simultaneously, the California Department of Justice initiated inquiries into xAI's safety protocols, highlighting a growing consensus among global regulators that the 'spicy mode' features in Grok lacked necessary technical guardrails at launch.
Legal and legislative frameworks are rapidly tightening to close loopholes previously exploited by 'nudification' technologies. Per Kingsley Napley, the Crime and Policing Act 2026 received Royal Assent on April 29, 2026, and officially took effect on June 29, 2026. This Act introduced Section 99, which specifically criminalizes the supply of AI tools intended for creating non-consensual sexualized imagery. This move targets the commercialization of deepfake technology, potentially exposing tech executives to personal fines or imprisonment if they fail to comply with Ofcom removal orders.
Industry data underscores the scale of the challenge regulators face. Per a June 2026 report cited by the End Violence Against Women Coalition, Grok generated an estimated 3 million non-consensual sexualized images during a single 11-day window between late December 2025 and early January 2026. While X announced in mid-January 2026 that it had implemented global technical measures to block the editing of real people into revealing clothing, legal experts at RPC noted that the High Court proceedings will still test whether these retrospective fixes absolve a developer of responsibility for initial design choices.
Read full article at brabners.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source