grok ai

Serious Allegations Against Elon Musk’s AI: Irish Data Protection Authority Opens Proceedings Against X

Dublin/San Francisco – Ireland’s Data Protection Commission (DPC) is stepping up its action against the social media platform X (formerly Twitter). At the center of the investigation is the AI chatbot “Grok.” The allegation: the system is said to enable the creation of abusive, intimate images and to massively violate European data protection standards.

The Irish data protection authority DPC, which serves as the lead supervisory body for US tech corporations’ compliance with the General Data Protection Regulation (GDPR) in the EU, has officially launched an investigation into X. The trigger is reports about the workings of the AI model Grok, which was developed by Elon Musk’s company xAI and deeply integrated into the platform X.

Suspicion of Deepfakes and Inadequate Child Protection

Specifically, there is a suspicion that Grok can be used to create so-called “deepfakes” – deceptively realistic, sexualized images of real people without their consent. Of particular concern to the authorities: according to initial indications, minors are among the affected individuals.

Graham Doyle, Deputy Commissioner of the DPC, stated that the authority has already been in intensive contact with the company for several weeks. Initial media reports had shown that users were able to bypass the chatbot’s safety filters through targeted prompts in order to generate non-consensual intimate content.

Reviewing GDPR Compliance

The DPC’s proceedings now aim to examine the fundamental architecture of Grok. The focus is on three central aspects of the GDPR:

  1. Lawfulness of processing: On what legal basis is the personal data of EU citizens used for training and operating the AI?
  2. Privacy by Design: Did the company ensure, already during the development of the software, that the protection of privacy is technically guaranteed?
  3. Data Protection Impact Assessment (DPIA): Was a comprehensive risk analysis carried out before the introduction of the AI features, as EU legislation requires for technologies posing a high risk to the rights of data subjects?

Background: What Is Grok?

Grok is a Large Language Model (LLM) developed by xAI and available exclusively to paying premium users on the platform X. Unlike competing products such as ChatGPT, Grok is marketed as “rebellious” and has access to real-time data from the platform X. Critics have long accused the system of deliberately keeping its safety barriers (guardrails) low compared to other models in order to offer an “unfiltered” user experience.

Possible Consequences

Should the DPC find violations, the company faces significant penalties. The GDPR provides for fines of up to 20 million euros or up to 4 percent of worldwide annual turnover – whichever amount is higher. In addition, the authority could order the suspension of the relevant AI services in the European Union.

X has so far not commented in detail on the ongoing proceedings. It is not the first conflict, however: back in August, X had to temporarily give assurances that it would not use user data from the EU to train Grok without explicit consent, after the DPC had initiated legal action.

Mastodon
Scroll to Top