In eleven days, Grok generated approximately 3 million sexualized images of women and children. An estimated 23,000 of those images depicted minors.
On February 16, 2026, Ireland’s Data Protection Commission (DPC) announced it had opened a formal investigation into X Internet Unlimited Company, the legal entity behind Elon Musk’s X platform, for potential violations of the General Data Protection Regulation (GDPR). Graham Doyle, the DPC’s Deputy Commissioner, confirmed the inquiry would examine whether X met its “fundamental obligations under the GDPR” regarding the processing of personal data of EU and EEA citizens, including children.
This is the second simultaneous EU investigation into Grok. In January, the European Commission launched a separate probe under the Digital Services Act (DSA), examining whether X properly assessed and mitigated the risks of Grok’s image generation capabilities. Two legal frameworks. Two investigating bodies. One platform.
How It Happened
The timeline tells the story. Between December 29, 2025 and January 9, 2026, Grok’s image generation feature allowed users to create realistic depictions of real people in sexualized contexts using simple text prompts. The Centre for Countering Digital Hate (CCDH), a British nonprofit, documented the scale: 3 million sexualized images generated in barely more than a week.
Users could type commands like “put her in a bikini” or “remove her clothes” and Grok would comply. It worked on public figures, private individuals, and minors.
X’s response was to restrict image generation to paying customers. Put another way, X put a price tag on the violation.
EU Tech Commissioner Henna Virkkunen called nonconsensual sexual deepfakes “a violent, unacceptable form of degradation.” European Commission President Ursula von der Leyen stated the EU would not “tolerate unthinkable behaviour, such as digital undressing of women and children.” X had already been fined €120 million ($140 million) in December 2025 for separate DSA violations.
The Enforcement Template
What makes this case structurally important is the dual-track approach. The GDPR investigation targets data protection. Every one of those 3 million images required processing someone’s personal data, their face, their likeness, their identity, without consent. The DSA investigation targets platform responsibility for content moderation and risk assessment.
If both investigations produce enforcement action, it creates a template that applies to every AI image generation tool operating in the EU. Meta’s AI tools, Midjourney, Stability AI, and every other platform with generative image capabilities would face the same scrutiny under both frameworks.
The pattern is consistent with how the EU has escalated its digital enforcement. When France banned American platforms from government use, it expanded the regulatory toolkit. When deepfake technology compromised remote hiring, it demonstrated the real-world harm that drives regulation forward.
The open question is whether the fines are large enough to change anything. €120 million is a rounding error for a platform valued in the tens of billions.
The Counter-Argument
X would argue that Grok’s image generation was an experimental feature, that restrictions were implemented quickly, and that paying-customer-only access limits misuse. The company could point to other AI platforms that have faced similar challenges with image generation guardrails. Every major generative AI tool has had content policy failures in its early stages.
That argument collapses under the numbers. Three million images. Eleven days. Twenty-three thousand involving children. This was not a guardrail failure. This was what the system was built to do.
This was a user acquisition play. The simplest way to drive engagement on a platform is to let users do things they cannot do anywhere else. For eleven days, X let millions of people generate explicit images of real women and children without consent. The surge in activity those numbers represent would appear in every growth metric X reports to investors and advertisers. Restricting it to paid users after the backlash does not undo the damage. It monetizes it.
What This Means for Everyday People
If your face is on the internet, it can be used to generate explicit images without your knowledge or consent. That was true before Grok. Grok industrialized it at a scale that made the problem impossible to ignore.
The EU is now testing whether existing law can contain AI-generated harm. If the GDPR and DSA can force platforms to build safety systems before launch rather than after scandal, it sets a global standard. If they cannot, the next episode will be larger. The technology only becomes more capable.
For inquiries and analysis contact laterstack@proton.me