Skip to main content

Talk to us: 0333 004 4488 | hello@brabners.com | Contact us

ICO & Ofcom investigations into Grok — what they mean for AI regulation

AuthorsMaya TajuddinColin BellSara Ludlam

A row of people seated on a bench along a canal walkway, each focused on their smartphones, wearing casual jackets and ripped jeans as daylight glints off wet pavement.

Grok, the AI chatbot developed by Elon Musk's xAI and integrated into X, is facing scrutiny from both the Information Commissioner's Office (ICO) and Ofcom over concerns relating to personal data, online safety and AI-generated imagery.

The investigations follow reports that Grok was used to create non-consensual sexualised and ‘nudified’ images of real people, including children, raising questions about the safeguards built into the technology and responsibilities of the platforms through which it operates.

The case sits at the intersection of data protection, online safety and the ever-evolving regulatory space.

Here, Maya Tajuddin, Colin Bell and Sara Ludlam from our specialist tech sector team explore why Grok is being investigated, the legal issues under consideration by the ICO and Ofcom and what the case tells us about the future regulation of AI-generated content in the UK.

 

Why the ICO is investigating xAI

Grok’s integration within X is central to both its appeal and the scrutiny that it now faces. Unlike many standalone AI assistants, Grok operates within — and draws relevance from — a live social media environment. While this creates opportunities for users to maximise the tool’s potential through full integration, it also magnifies the legal and ethical risks posed. Grok may draw on content that’s malicious, false, inaccurate, out of date, copyright- or IP-protected, infringing, stolen or private. As a result, any inaccuracies or legal issues within that content may be reflected in the AI's outputs, potentially leading to misinformation, unreliable results or the infringement of third-party rights.

On 3 February 2026, the ICO announced that it had opened formal investigations into xAI in relation to the processing of personal data by Grok following numerous reports that it had been used to generate non-consensual sexual imagery of individuals. 

William Malcolm, the ICO’s Executive Director for Regulatory Risk and Innovation, said that the reports raised “deeply troubling questions” about whether necessary safeguards were in place and serious concerns under UK data protection law, presenting a risk of significant harm to the public.

 

How UK data protection law applies to Grok

Where AI systems are capable of generating content that relates to identifiable individuals, there’s a risk that such personal data may be repurposed in ways that those individuals neither expect nor consent to. The principle of data minimisation — together with obligations relating to purpose limitation and privacy by design — therefore become central to the lawful use of AI. 

The UK GDPR and Data Protection Act 2018 (the DPA) define seven general principles that need to be complied with when processing any personal data:

  1. Lawfulness, fairness and transparency: Process data legally, fairly and in a clear way that people expect.
  2. Purpose limitation: Collect data only for clear, stated reasons and do not use it later for unrelated tasks.
  3. Data minimisation: Keep the data you collect adequate, relevant and limited to what you actually need.
  4. Accuracy: Ensure personal data is correct and updated, fixing or deleting mistakes right away.
  5. Storage limitation: Keep data in a form that identifies people no longer than necessary for your stated purpose.
  6. Integrity and confidentiality: Protect data securely against loss, damage, theft or unauthorised access.
  7. Accountability: Take responsibility for these rules and be able to prove your compliance with clear records.
     

In the context of AI-generated images, personal data may include a person’s likeness, image, name, identity and any other information that can identify them under the definition of ‘personal data’ set out in the DPA. If that data is used to create synthetic or manipulated content without consent, individuals may lose control over their personal information in a particularly intrusive way. 

Therefore, the issue with the use of Grok is also whether: 

  • The personal data in question has been processed lawfully, fairly and transparently.
  • It has been used in accordance with the original purpose for which it was collected.
  • Appropriate safeguards were built into the design of the system from which the images were taken.

 

Ofcom's investigation into X & the Online Safety Act 

On 12 January 2026, Ofcom announced a formal investigation into X under the Online Safety Act (the OSA). Ofcom’s investigation will examine whether X complied with its duties under this Act, including the duty to assess the risk of UK users encountering explicit content and carry out updated risk assessments before making significant changes to a service. 

This investigation is still ongoing, with the latest update stating that: 

“X has said it has implemented measures to prevent the Grok account from being used to create intimate images of people.

This is a welcome development. However, our formal investigation remains ongoing. We are working round the clock to progress this and get answers into what went wrong and what’s being done to fix it.”

The OSA presents a more complex and, at times, fragmented picture. Ofcom is able to investigate X as the platform through which harmful imagery may be created and shared, including whether it has taken sufficient steps to identify, assess and mitigate the risk of sexualised AI-generated content appearing on its platform and remove such material promptly where it arises. However, not all chatbot functionality falls squarely within the OSA’s framework, meaning that Ofcom may not always be able to directly investigate xAI despite it being the entity responsible for developing the technology that generates the content. The result is a regulatory gap where the spotlight falls heavily on the platform distributing the content while the technology generating it manages to slip through the cracks. 

The OSA also identifies duties relating to children, including assessing risks and using highly effective age assurance to protect them from sexually explicit content. Ofcom, however, has reiterated that it’s not there to tell platforms what to post or take down, it’s there to identify and reiterate a platform’s legal obligations to its users, particularly where one falls short. 

 

Legal action adds to pressure on xAI 

Regulatory scrutiny has been accompanied by legal action. In June 2026, MP Jess Asato filed a High Court claim against xAI, alleging that Grok had been used to create fake sexualised images of her, just like thousands of other girls and children who were digitally undressed

Sir Keir Starmer supported her in this claim, stating that Ms Asato was "absolutely right" to take legal action against Elon Musk's xAI over "disgusting" images created of her. Shortly after this — and in response to the widespread concern over sexualised deepfakes — Elon Musk announced on X that Grok will no longer be able to edit photos of real people to show them in revealing clothing in jurisdictions where it’s illegal. 

 

What the Grok investigations reveal about AI regulation 

The ICO and Ofcom investigations illustrate how generative AI can sit at the intersection of multiple legislative and regulatory regimes. For the ICO, the issue is information rights: how personal data is collected, used, transformed and protected. For Ofcom, the issue is online safety: whether platforms have appropriate systems to reduce the risk of illegal and harmful content being created and/or disseminated. 

This overlap is significant, showing that a single AI-generated image or video can raise questions of privacy, data protection, content moderation, child safety and platform design. A UNICEF report found that, across 11 countries, at least 1.2m children disclosed having had their images manipulated into sexually explicit deepfakes in the past year.

While the OSA amends the Sexual Offences Act (2003) to introduce new offences relating to online content, separate reforms have been introduced under the Data (Use and Access) Act 2025 (DUA). In particular, Section 138 of the DUA has amended the Sexual Offences Act (2003) to create a new offence covering the creation of deepfake intimate images without consent from the person depicted. This aims to close the loophole that previous legislation hasn’t addressed and deal with the growing risks associated with deepfakes and non-consensual imagery. While it was already illegal to share intimate, non-consensual images (including deepfakes), the DUA has now added a further restriction. Since Section 138 came into force on 6 February 2026, it has also been illegal to ask an AI tool to create these images.

The Crime and Policing Act (2026) will introduce similar improvements to protection, aiming to introduce additional offences relating to child sexual abuse material, intimate deepfakes and criminalising ‘nudification’ technologies, with Keir Starmer stating that “no platform gets a free pass”. Adding to earlier reforms, this Act also builds in protections around non-consensual imagery by introducing offences for taking intimate images without consent and enabling such conduct (for example, installing or deploying tools for that purpose). 

 

Key takeaways

The ICO and Ofcom’s investigations into Grok underline three critical issues for businesses that are considering deploying AI systems:

  1. The need to consider more carefully the consequences of potential GDPR breaches and build in more robust, privacy-by-design measures when deploying AI tools that can interact with personal data.
  2. The importance of proactive platform compliance with the Online Safety Act, particularly around protecting children from harmful content.
  3. The closing legislative gaps, such as offences introduced under the DUA and Crime and Policing Act, which points towards a much tougher legal landscape for developers and platforms alike.

 

Looking ahead

Ultimately, the Grok controversy raises a broader question for the future of generative AI: where should responsibility sit when an AI system is capable of producing harmful content? 

As regulators continue to investigate, courts consider new legal claims and legislators seek to close existing gaps in the law, developers and platforms alike are likely to face greater scrutiny over the choices they make when designing and deploying AI systems. While innovation remains welcome, it must be accompanied by meaningful accountability, transparency and protection for the individuals whose rights may be affected.

 

Talk to us

With the online safety landscape continuing to evolve, legal compliance is becoming increasingly important and businesses need to stay up to date with changing regulatory requirements.

If your business develops or integrates AI solutions, now is the time to review your data protection practices, online safety processes and compliance frameworks.

Our specialist techdata and regulatory lawyers help organisations to navigate the legal and commercial challenges associated with emerging technologies. We advise on AI governance, data protection, intellectual property, online safety, regulatory investigations and risk management, helping businesses to deploy AI compliantly.

We provide pragmatic, commercially focused advice tailored to each client's objectives and risk profile. We also have extensive experience working with regulators, including the ICO and Ofcom, helping you to respond to investigations, manage compliance issues and achieve positive outcomes.

Talk to our team by calling 0333 004 4488, emailing hello@brabners.com or completing our contact form.

Maya Tajuddin

Maya is a Paralegal in our real estate team.

Read more
MAYA TAJUDDIN HEADSHOT PHOTO

Sara Ludlam

Sara is a Partner and Chartered Trade Mark Attorney in our commercial and intellectual property (IP) team.

Read more
Sara Ludlam

Colin Bell

Colin is a Partner and leads our intellectual property and technology teams.

Read more
Colin Bell

Talk to us

Loading form...

Related insights