ICO & Ofcom investigations into Grok — what they mean for AI regulation

We explore the legal issues under consideration by the ICO and Ofcom and what the case tells us about the UK's future regulation of AI-generated content.
Talk to us: 0333 004 4488 | hello@brabners.com | Contact us
AuthorsMaya TajuddinColin BellSara Ludlam

Grok, the AI chatbot developed by Elon Musk's xAI and integrated into X, is facing scrutiny from both the Information Commissioner's Office (ICO) and Ofcom over concerns relating to personal data, online safety and AI-generated imagery.
The investigations follow reports that Grok was used to create non-consensual sexualised and ‘nudified’ images of real people, including children, raising questions about the safeguards built into the technology and responsibilities of the platforms through which it operates.
The case sits at the intersection of data protection, online safety and the ever-evolving regulatory space.
Here, Maya Tajuddin, Colin Bell and Sara Ludlam from our specialist tech sector team explore why Grok is being investigated, the legal issues under consideration by the ICO and Ofcom and what the case tells us about the future regulation of AI-generated content in the UK.
Grok’s integration within X is central to both its appeal and the scrutiny that it now faces. Unlike many standalone AI assistants, Grok operates within — and draws relevance from — a live social media environment. While this creates opportunities for users to maximise the tool’s potential through full integration, it also magnifies the legal and ethical risks posed. Grok may draw on content that’s malicious, false, inaccurate, out of date, copyright- or IP-protected, infringing, stolen or private. As a result, any inaccuracies or legal issues within that content may be reflected in the AI's outputs, potentially leading to misinformation, unreliable results or the infringement of third-party rights.
On 3 February 2026, the ICO announced that it had opened formal investigations into xAI in relation to the processing of personal data by Grok following numerous reports that it had been used to generate non-consensual sexual imagery of individuals.
William Malcolm, the ICO’s Executive Director for Regulatory Risk and Innovation, said that the reports raised “deeply troubling questions” about whether necessary safeguards were in place and serious concerns under UK data protection law, presenting a risk of significant harm to the public.
Where AI systems are capable of generating content that relates to identifiable individuals, there’s a risk that such personal data may be repurposed in ways that those individuals neither expect nor consent to. The principle of data minimisation — together with obligations relating to purpose limitation and privacy by design — therefore become central to the lawful use of AI.
The UK GDPR and Data Protection Act 2018 (the DPA) define seven general principles that need to be complied with when processing any personal data:
In the context of AI-generated images, personal data may include a person’s likeness, image, name, identity and any other information that can identify them under the definition of ‘personal data’ set out in the DPA. If that data is used to create synthetic or manipulated content without consent, individuals may lose control over their personal information in a particularly intrusive way.
Therefore, the issue with the use of Grok is also whether:
On 12 January 2026, Ofcom announced a formal investigation into X under the Online Safety Act (the OSA). Ofcom’s investigation will examine whether X complied with its duties under this Act, including the duty to assess the risk of UK users encountering explicit content and carry out updated risk assessments before making significant changes to a service.
This investigation is still ongoing, with the latest update stating that:
“X has said it has implemented measures to prevent the Grok account from being used to create intimate images of people.
This is a welcome development. However, our formal investigation remains ongoing. We are working round the clock to progress this and get answers into what went wrong and what’s being done to fix it.”
The OSA presents a more complex and, at times, fragmented picture. Ofcom is able to investigate X as the platform through which harmful imagery may be created and shared, including whether it has taken sufficient steps to identify, assess and mitigate the risk of sexualised AI-generated content appearing on its platform and remove such material promptly where it arises. However, not all chatbot functionality falls squarely within the OSA’s framework, meaning that Ofcom may not always be able to directly investigate xAI despite it being the entity responsible for developing the technology that generates the content. The result is a regulatory gap where the spotlight falls heavily on the platform distributing the content while the technology generating it manages to slip through the cracks.
The OSA also identifies duties relating to children, including assessing risks and using highly effective age assurance to protect them from sexually explicit content. Ofcom, however, has reiterated that it’s not there to tell platforms what to post or take down, it’s there to identify and reiterate a platform’s legal obligations to its users, particularly where one falls short.
Regulatory scrutiny has been accompanied by legal action. In June 2026, MP Jess Asato filed a High Court claim against xAI, alleging that Grok had been used to create fake sexualised images of her, just like thousands of other girls and children who were digitally undressed.
Sir Keir Starmer supported her in this claim, stating that Ms Asato was "absolutely right" to take legal action against Elon Musk's xAI over "disgusting" images created of her. Shortly after this — and in response to the widespread concern over sexualised deepfakes — Elon Musk announced on X that Grok will no longer be able to edit photos of real people to show them in revealing clothing in jurisdictions where it’s illegal.
The ICO and Ofcom investigations illustrate how generative AI can sit at the intersection of multiple legislative and regulatory regimes. For the ICO, the issue is information rights: how personal data is collected, used, transformed and protected. For Ofcom, the issue is online safety: whether platforms have appropriate systems to reduce the risk of illegal and harmful content being created and/or disseminated.
This overlap is significant, showing that a single AI-generated image or video can raise questions of privacy, data protection, content moderation, child safety and platform design. A UNICEF report found that, across 11 countries, at least 1.2m children disclosed having had their images manipulated into sexually explicit deepfakes in the past year.
While the OSA amends the Sexual Offences Act (2003) to introduce new offences relating to online content, separate reforms have been introduced under the Data (Use and Access) Act 2025 (DUA). In particular, Section 138 of the DUA has amended the Sexual Offences Act (2003) to create a new offence covering the creation of deepfake intimate images without consent from the person depicted. This aims to close the loophole that previous legislation hasn’t addressed and deal with the growing risks associated with deepfakes and non-consensual imagery. While it was already illegal to share intimate, non-consensual images (including deepfakes), the DUA has now added a further restriction. Since Section 138 came into force on 6 February 2026, it has also been illegal to ask an AI tool to create these images.
The Crime and Policing Act (2026) will introduce similar improvements to protection, aiming to introduce additional offences relating to child sexual abuse material, intimate deepfakes and criminalising ‘nudification’ technologies, with Keir Starmer stating that “no platform gets a free pass”. Adding to earlier reforms, this Act also builds in protections around non-consensual imagery by introducing offences for taking intimate images without consent and enabling such conduct (for example, installing or deploying tools for that purpose).
The ICO and Ofcom’s investigations into Grok underline three critical issues for businesses that are considering deploying AI systems:
Ultimately, the Grok controversy raises a broader question for the future of generative AI: where should responsibility sit when an AI system is capable of producing harmful content?
As regulators continue to investigate, courts consider new legal claims and legislators seek to close existing gaps in the law, developers and platforms alike are likely to face greater scrutiny over the choices they make when designing and deploying AI systems. While innovation remains welcome, it must be accompanied by meaningful accountability, transparency and protection for the individuals whose rights may be affected.
With the online safety landscape continuing to evolve, legal compliance is becoming increasingly important and businesses need to stay up to date with changing regulatory requirements.
If your business develops or integrates AI solutions, now is the time to review your data protection practices, online safety processes and compliance frameworks.
Our specialist tech, data and regulatory lawyers help organisations to navigate the legal and commercial challenges associated with emerging technologies. We advise on AI governance, data protection, intellectual property, online safety, regulatory investigations and risk management, helping businesses to deploy AI compliantly.
We provide pragmatic, commercially focused advice tailored to each client's objectives and risk profile. We also have extensive experience working with regulators, including the ICO and Ofcom, helping you to respond to investigations, manage compliance issues and achieve positive outcomes.
Talk to our team by calling 0333 004 4488, emailing hello@brabners.com or completing our contact form.

Sara Ludlam
Sara is a Partner and Chartered Trade Mark Attorney in our commercial and intellectual property (IP) team.
Read more

Loading form...

We explore the legal issues under consideration by the ICO and Ofcom and what the case tells us about the UK's future regulation of AI-generated content.

What can we learn from the BrewDog shareholder emails? We outline key compliance risks and practical steps to consider before sending communications.

We explore the allegations against Roblox, wider challenges of protecting children online and steps that platforms are expected to take.

We explore what Stargate UK reveals about the hidden energy cost of AI and break down what this means in practice.

We explore the key insights shaping the future of games, digital creative and tech from this year’s FORMAT Group Summit.

Live from Old Trafford, we explored the realities of geopolitical risk, security threats, commercial sustainability and the growing role of technology.

We explore the tension between AI‑driven optimism and growing fears of an overinflated tech bubble.

We explain why uncontrolled use of public AI tools creates real confidentiality and data protection risks and outline how you can manage them safely.

We explore how scaleup policy, growth opportunities and local engagement help ambitious businesses to turn national strategy into practical support.

We explore the sector’s digital shift, from predictive repairs and income management to tenant engagement and the governance needed for responsible AI use.

We brought the retail sector together in London for a focused look at the risks, from physical threats, digital disruption and reputational challenges.

We explore how new parliamentary findings and the Government’s updated position are shifting the UK’s direction on AI and copyright.

We explain how AI patent applications are now being assessed and what this means for innovation and patent strategies.

We explore why retailers are particularly affected by deepfakes and the implications around data protection, IP, advertising compliance and more.

We explore how AI is transforming data protection, the risks that organisations now face and what effective compliance looks like today.

We break down the key insights from each panel, exploring AI's real-world impact and why it’s crucial to balance innovation with long‑term sustainability.

AI is enhancing performance and even scouting future talent in elite sport. Sports technology and data are key to success, but come with legal risks.

We discuss the key opportunities and considerations shaping the future of sustainable AI and quantum‑powered technology.

We break down what the ICO found and outline three key steps that UK businesses should take now.

We explore how the UK’s shift to clean power is reshaping industry, infrastructure and the future of energy security.

We break down the key proposed reforms in the Digital Omnibus Package and outline what businesses should do to prepare.

We explain where generative AI has the potential to damage individuals’ reputations and examine relevant case law from other jurisdictions.

We discuss the mounting dangers of AI-powered cybercrime across the world of sport with David Andrew — the Founder and Managing Partner of Tiaki.

We explain the importance of the Supreme Court decision and what it means for innovators looking to gain patent protection for computer-related inventions.

We outline the key takeaways from our Games Tech Connect session on how generative AI is being used in video game development.