EU opens formal probe into X over Grok deepfakes and platform risk controls
European Union regulators launched a formal investigation into Elon Musk’s platform X after its AI chatbot Grok generated nonconsensual sexualized deepfake images, including material that may involve children. The probe examines whether X complied with the Digital Services Act requirement to assess and reduce systemic risks tied to illegal and harmful content. Regulators also widened scrutiny of X’s recommendation systems as the company moves to integrate Grok more deeply into how posts are surfaced.
- PUBLISHED
- UPDATED

A Digital Services Act test for AI-generated abuse
The European Union opened a formal investigation into X on Monday, focusing on Grok’s role in creating and spreading nonconsensual sexualized deepfake images. EU officials said the case will examine whether X met its obligations under the Digital Services Act, which requires large platforms to identify, assess, and mitigate systemic risks—especially risks connected to illegal content and real-world harms.

Why Grok triggered a rapid regulatory response
The backlash intensified after users demonstrated how the AI tool could manipulate images to “undress” people or place them into revealing outfits. A key accelerant, regulators and researchers argue, is that Grok’s outputs on X can be publicly visible and quickly redistributed, which increases the likelihood that harmful content spreads faster than moderation systems can keep up.
Recommender systems now part of the scrutiny
Alongside the deepfake investigation, the EU expanded an earlier inquiry into X’s recommendation systems. The widening comes as X seeks to use Grok-related models more broadly to decide what content users see. Regulators have repeatedly signaled that amplification mechanics—how content is ranked, boosted, and recommended—can be as consequential as the content rules themselves.
Possible outcomes and next steps
- X can pledge specific product and policy changes to address the identified risks
- The EU can require behavioral remedies related to risk assessments and mitigation
- Penalties remain on the table if regulators determine X failed DSA obligations
- The case timeline is open-ended; there is no fixed deadline for resolution
X has said it has zero tolerance for child exploitation and nonconsensual nudity, but the EU’s central question is whether X’s safeguards were adequate and timely given the scale and severity of the harm.