In eleven days, Grok generated approximately 3 million sexualized images of women and children. An estimated 23,000 of those images depicted minors.

On February 16, 2026, Ireland’s Data Protection Commission (DPC) announced it had opened a formal investigation into X Internet Unlimited Company, the legal entity behind Elon Musk’s X platform, for potential violations of the General Data Protection Regulation (GDPR). Graham Doyle, the DPC’s Deputy Commissioner, confirmed the inquiry would examine whether X met its “fundamental obligations under the GDPR” regarding the processing of personal data of EU and EEA citizens, including children.

This is the second simultaneous EU investigation into Grok. In January, the European Commission launched a separate probe under the Digital Services Act (DSA), examining whether X properly assessed and mitigated the risks of Grok’s image generation capabilities. Two legal frameworks. Two investigating bodies. One platform.

How It Happened

The timeline tells the story. Between December 29, 2025 and January 9, 2026, Grok’s image generation feature allowed users to create realistic depictions of real people in sexualized contexts using simple text prompts. The Centre for Countering Digital Hate (CCDH), a British nonprofit, documented the scale: 3 million sexualized images generated in barely more than a week.

Users could type commands like “put her in a bikini” or “remove her clothes” and Grok would comply. It worked on public figures, private individuals, and minors.

X’s response was to restrict image generation to paying customers. Put another way, X put a price tag on the violation.

EU Tech Commissioner Henna Virkkunen called nonconsensual sexual deepfakes “a violent, unacceptable form of degradation.” European Commission President Ursula von der Leyen stated the EU would not “tolerate unthinkable behaviour, such as digital undressing of women and children.” X had already been fined €120 million ($140 million) in December 2025 for separate DSA violations.

The Enforcement Template

What makes this case structurally important is the dual-track approach. The GDPR investigation targets data protection. Every one of those 3 million images required processing someone’s personal data, their face, their likeness, their identity, without consent. The DSA investigation targets platform responsibility for content moderation and risk assessment.

If both investigations produce enforcement action, it creates a template that applies to every AI image generation tool operating in the EU. Meta’s AI tools, Midjourney, Stability AI, and every other platform with generative image capabilities would face the same scrutiny under both frameworks.

The pattern is consistent with how the EU has escalated its digital enforcement. When France banned American platforms from government use, it expanded the regulatory toolkit. When deepfake technology compromised remote hiring, it demonstrated the real-world harm that drives regulation forward.

The open question is whether the fines are large enough to change anything. €120 million is a rounding error for a platform valued in the tens of billions.

The Counter-Argument

X would argue that Grok’s image generation was an experimental feature, that restrictions were implemented quickly, and that paying-customer-only access limits misuse. The company could point to other AI platforms that have faced similar challenges with image generation guardrails. Every major generative AI tool has had content policy failures in its early stages.

That argument collapses under the numbers. Three million images. Eleven days. Twenty-three thousand involving children. This was not a guardrail failure. This was what the system was built to do.

This was a user acquisition play. The simplest way to drive engagement on a platform is to let users do things they cannot do anywhere else. For eleven days, X let millions of people generate explicit images of real women and children without consent. The surge in activity those numbers represent would appear in every growth metric X reports to investors and advertisers. Restricting it to paid users after the backlash does not undo the damage. It monetizes it.

What This Means for Everyday People

If your face is on the internet, it can be used to generate explicit images without your knowledge or consent. That was true before Grok. Grok industrialized it at a scale that made the problem impossible to ignore.

The EU is now testing whether existing law can contain AI-generated harm. If the GDPR and DSA can force platforms to build safety systems before launch rather than after scandal, it sets a global standard. If they cannot, the next episode will be larger. The technology only becomes more capable.

For inquiries and analysis contact laterstack@proton.me

Consider the audacity. A deepfake candidate applied for a security researcher position at Evoke, an AI security company whose entire business is threat modeling for artificial intelligence systems. The CEO, Rebholz, has spent years researching deepfakes. He has used them in presentations. He has built a career on understanding synthetic media.

And he almost hired the deepfake.

“Everything in me, everything I know about deepfakes was screaming at me: this is a deepfake,” Rebholz told The Register last week. “But there was something blocking me, the one percent chance that I’m wrong, this is actually a good candidate, and he’s going to think poorly of me if I confront him.”

This is the moment when an emerging threat becomes a systemic crisis. When a deepfake expert, interviewing for his own security company, experiences “inner turmoil” about whether to trust his expertise, the verification systems that underpin remote work have failed. The question is no longer whether deepfakes will compromise hiring processes. The question is what comes next.

The Anatomy of the Attack

The incident began ordinarily. Rebholz posted job openings on LinkedIn. Within hours, someone he did not know messaged him, recommending a candidate for the security researcher role. The referral itself was not suspicious. People refer candidates. Networks operate through introductions.

The first red flag was the candidate’s profile picture: not a photograph but something resembling an anime character. In the security community, this is not automatically disqualifying. Privacy concerns lead many professionals to avoid displaying their real faces online. Aliases and stylized avatars are common.

Rebholz gave the candidate the benefit of the doubt.

When the video interview began, the candidate sat in front of a virtual background. His face appeared “a bit blurry and plastic.” There was a greenscreen reflection visible in his glasses. At one point, dimples appeared on his face and then disappeared as he moved. The “softness of his face” came and went.

Rebholz noticed behavioral indicators as well. The candidate repeated interview questions back before answering them, a technique that buys processing time for systems generating responses. Many of his answers were nearly word-for-word quotes of things Rebholz himself had said or written publicly.

“It was almost an out-of-body experience where I felt like I was talking to myself,” Rebholz said.

Despite all of this, the deepfake expert experienced doubt. The candidate might be real. The visual artifacts might be compression issues. The familiar answers might be coincidence or good research. The social pressure not to accuse someone of being fake competed with the technical evidence that something was wrong.

After the interview, Rebholz sent video clips to a colleague at Moveris, which develops deepfake detection technology. The analysis confirmed what his expertise already told him: the candidate was synthetic.

The Implications for Remote Work

The remote work revolution that accelerated during the pandemic created enormous value. Talent could be hired from anywhere. Geographic constraints on labor markets loosened. Companies accessed skills that were previously unavailable in their local markets. Workers gained flexibility that many describe as transformational for their quality of life.

The same structural changes that enabled remote work also created vulnerabilities that are now being exploited.

Remote hiring relies on video interviews conducted over platforms that were not designed with identity verification in mind. Zoom, Teams, and Google Meet assume that the person on the video feed is who they claim to be. There is no cryptographic proof of identity. There is no biometric verification. There is trust, backed by the assumption that creating a convincing synthetic identity is difficult.

That assumption is no longer valid.

Experian’s fraud forecast for 2026 identified deepfake job candidates as a top threat. Nearly every major technology company, from Amazon to small startups, has encountered fake IT workers applying for positions. Some have been hired. Some have passed background checks. Some have gained access to internal systems before being detected.

The underlying threat is not merely fraudulent employment. It is infiltration. An attacker who passes an interview, receives credentials, and gains access to internal systems can exfiltrate data, compromise code repositories, establish persistent access, or conduct espionage. Remote work and global hiring widen talent pools, but they also weaken the signals of identity verification that previously protected organizations.

The Scale of the Problem

Industry data suggests the problem is larger than isolated incidents.

A 2024 survey found that 15% of high school students had encountered explicit deepfake imagery of their peers. The same technology that creates fake intimate images creates fake job candidates. The underlying models are general-purpose.

Challenger, Gray & Christmas, the employment consulting firm, has documented cases of synthetic candidates at scale. North Korean operatives have been identified using fake identities to obtain remote IT positions at American companies, earning salaries that fund the regime while potentially conducting espionage.

The FBI has documented cases where deepfake extortion, using synthetic intimate imagery created from social media photographs, has led to self-harm among victims, including minors. The same technology ecosystem enables job fraud, identity theft, and targeted harassment.

What makes the Evoke incident notable is not that a deepfake attempted to infiltrate a company. It is that the target was a company specifically focused on AI security threats, the interviewer was a deepfake expert, and the attack nearly succeeded anyway.

If experts cannot reliably detect deepfakes in real-time video interviews, what hope do ordinary hiring managers have?

The Emerging Response

The market is responding with verification technologies, but adoption lags threat development.

Companies like Moveris and others offer deepfake detection as a service. The technology analyzes video feeds for artifacts: inconsistent lighting, unnatural facial movements, audio-visual synchronization errors, and other indicators of synthetic generation. These tools can be integrated into hiring workflows.

Biometric verification services offer alternatives to video interviews for identity confirmation. A candidate can be required to verify their identity through a trusted third party before an interview begins. This does not prevent the interview itself from using deepfakes, but it establishes that the person claiming the identity is who they claim to be.

Some organizations are returning to in-person interviews for sensitive positions. The geographic flexibility of remote hiring is sacrificed for the security of physical presence. A deepfake cannot shake your hand.

Others are implementing multi-stage verification: initial video screening, followed by live coding exercises observed in real-time, followed by reference checks conducted through established professional networks rather than provided contacts. The friction increases. The security improves. The talent pool shrinks.

There is no costless solution. Remote work created value by reducing friction. The friction was also security. Restoring security means restoring friction.

The Policy Dimension

This is not merely a corporate security problem. It is a labor market problem with policy implications.

Employment verification systems, background check infrastructure, and credential validation processes were designed for a world where identity documents were difficult to forge and video communication did not exist. The entire apparatus assumes that physical presence or documented history establishes identity.

Deepfakes undermine these assumptions systematically. A synthetic candidate can provide fake credentials, appear convincingly in video interviews, and pass initial screening processes. The verification happens after hiring, when access has already been granted.

Policymakers face difficult tradeoffs. Mandating biometric verification raises privacy concerns. Requiring in-person verification restricts labor market flexibility. Imposing liability on employers for deepfake infiltration may be unfair when detection is genuinely difficult.

The honest answer is that no policy solution currently exists that preserves the benefits of remote hiring while eliminating the risks of synthetic candidates. Technology created this problem. Technology may eventually solve it. In the interim, organizations must make risk decisions with imperfect information and imperfect tools.

What This Means for Everyday People

For job seekers, the deepfake threat creates a new burden: proving that you are real. Legitimate candidates may face increased scrutiny, additional verification steps, and suspicion that would have been absent in earlier eras. The friction imposed by security measures falls on everyone, not just attackers.

For workers in remote positions, the question is whether their employers can distinguish them from synthetic impostors. If not, what prevents an attacker from impersonating a current employee, attending meetings in their place, or redirecting their communications?

For society broadly, the erosion of identity verification extends beyond employment. If you cannot trust that the person on a video call is who they claim to be, the implications ripple through every domain that relies on remote communication: telemedicine, legal proceedings, financial services, family relationships.

The Evoke incident is a warning. The CEO of an AI security company, an expert in exactly this threat, experienced doubt about whether to trust his own expertise. He almost hired a synthetic candidate because the social pressure not to accuse someone of fraud competed with the technical evidence that something was wrong.

This is the future of identity in the age of generative AI. The signals we relied upon to verify that people are who they claim to be are failing. What replaces them remains uncertain.

For inquiries and analysis contact laterstack@proton.me

Frequently Asked Questions

What happened with the deepfake job applicant at Evoke?

A synthetic identity using deepfake video technology applied for a security researcher position at Evoke, an AI security company. The CEO, who has years of experience researching deepfakes, conducted the video interview and noticed multiple red flags including visual artifacts and answers that quoted his own public statements. Despite his expertise, he experienced doubt about confronting the candidate and later confirmed through third-party analysis that the applicant was a deepfake.

How widespread is the deepfake job applicant problem?

Nearly every major technology company has encountered fake IT workers applying for positions. North Korean operatives have been identified using synthetic identities to obtain remote positions at American companies. Experian’s 2026 fraud forecast identifies deepfake job candidates as a top threat. The problem extends beyond tech: any organization using remote video interviews is potentially vulnerable.

How can companies protect against deepfake job candidates?

Emerging solutions include deepfake detection services that analyze video feeds for artifacts, biometric identity verification through trusted third parties, multi-stage verification processes combining video screening with live exercises and reference checks through established networks, and returning to in-person interviews for sensitive positions. No solution is costless; all involve tradeoffs between security and hiring flexibility.