Ireland's Data Protection Commission (DPC) has opened a formal investigation into Grok, X's AI chatbot, over the processing of personal data and its potential to produce harmful sexualized images and video, including content involving minors.
The "Spicy Mode" scandal
Grok featured a function called "Spicy Mode" that allowed users to prompt the chatbot into "undressing" images of women and posing them in bikinis, creating deepfakes without consent and without any safeguards.
Even worse: media investigations found that Grok often complied when users prompted it to generate sexually suggestive images of minors, including one of a 14-year-old actress.
What Ireland is investigating
The DPC will examine whether X Internet Unlimited Company (X's EU subsidiary) complied with core GDPR obligations, including:
- Principles of lawful data processing
- Data protection by design
- Requirement to conduct data protection impact assessments
Ireland has jurisdiction because X's European headquarters are based there, and it can levy fines of up to 4% of global revenue under the GDPR.
Not the only investigation
The Irish probe joins a cascade of legal actions against Grok across Europe:
- European Commission: Investigation under the Digital Services Act (DSA) since January
- France: Prosecutors raided X's Paris offices over possible CSAM generation and Holocaust denial
- Spain: Ordered criminal investigation into X alongside Meta and TikTok
- Brazil and Canada: Filed formal complaints over illegal content distribution
Why it matters
This case sets a crucial precedent: AI companies are responsible for what their models generate, not just for content users post. If Grok can produce sexual deepfakes without consent, the liability falls on X and Musk's xAI company.
What you can do
- Never use AI tools to create sexual content of other people — it's illegal in many countries
- If you discover a deepfake of yourself, report it to your data protection authority
- Review whether your personal photos are set to public on social media
- Support legislation that criminalizes non-consensual deepfake creation