Viral Wire

Canada rules xAI's Grok Imagine violated privacy law with 3M deepfakes

Over 23,000 sexualized images of children generated before any privacy review

Deep Dive

Canada's Privacy Commissioner Philippe Dufresne ruled on Thursday that Elon Musk's X Corp and xAI violated the Personal Information Protection and Electronic Documents Act (PIPEDA) by launching Grok Imagine in July 2025 without a proper privacy impact assessment. The investigation, prompted by a Center for Countering Digital Hate report, found that between December 29, 2025 and January 8, 2026, Grok Imagine generated roughly three million non-consensual sexualized deepfakes—including 23,000 depicting children—at a peak rate of over 6,000 images per hour. X Corp itself shared at least 1.8 million of these images on its platform. The OPC concluded that the companies did not take reasonable steps to prevent foreseeable harm and that the belated privacy assessment completed in March 2026 failed to capture actual risks.

The ruling names both X Corp and xAI as jointly responsible, reflecting how Grok is trained on X data and surfaced through X’s interface—a finding that European and Australian regulators may cite. However, the remedies are limited: Canada’s privacy commissioner has no power to levy fines or suspend the tool; enforcement requires a lengthy Federal Court process. In lieu of penalties, X and xAI committed to quarterly reporting on content-moderation safeguards and independent third-party audits—voluntary undertakings the OPC can publicize but not compel. The ruling lands as Musk became the world’s first trillionaire via SpaceX’s IPO, highlighting a stark contrast between wealth creation and child-safety enforcement.

📬 Get the top 10 AI stories daily