Brussels targets AI-enabled deepfakes on a major platform
The European Union opened a formal investigation on Monday, January 26, 2026, into X, the social media platform owned by Elon Musk, focusing on Grok’s role in generating and distributing sexually explicit deepfake images. The inquiry centers on whether X complied with the EU’s Digital Services Act (DSA), which requires large platforms to identify and reduce the risks posed by illegal content and harmful systemic behavior.

The controversy intensified as Grok’s image tools were used to alter photos of real people without consent—such as “undressing” subjects or placing them into revealing outfits—and as the results spread quickly across the network. Because Grok’s responses on X can be visible to others, the manipulated images could circulate beyond the original prompt, raising concerns about scale and the speed of amplification. Researchers and regulators also flagged the possibility that some content could involve minors, elevating the issue from harmful speech into potentially criminal territory.
Digital Services Act scrutiny expands to recommendations
EU officials said the probe will examine whether X had effective safeguards, reporting mechanisms, and risk mitigation steps in place as required under the DSA. Regulators are also widening attention to X’s recommendation systems after the company indicated it would integrate Grok more deeply into content curation. That linkage matters because recommender systems determine what spreads fastest and who sees it, making them central to the “systemic risk” analysis the DSA demands for very large online platforms.
X has stated that it has a zero-tolerance policy for child exploitation and nonconsensual nudity, and it has said it is restricting certain image manipulations in places where they are illegal. Even so, EU regulators argue that once harms materialize at scale, platforms must demonstrate that they can prevent recurrence—not only react after public outcry. The investigation will focus on Grok’s use inside X, rather than standalone services, because the DSA’s scope is tied to the largest platforms’ influence on public information flows.
Potential outcomes: remedies, commitments, or fines
The EU has not set a deadline to conclude the case, and the outcome could range from formal commitments to change product design and safety controls to financial penalties if regulators find serious violations. The case also signals a broader regulatory direction: European authorities are treating generative AI features as part of platform risk, not as optional add-ons. For the tech industry, the probe may become a benchmark for what “reasonable” safeguards look like when image generation and editing tools can be used for abuse.