AI Tech News

Three Teenagers Sued xAI. Grok Made the Images.

A teenager found out from an anonymous Instagram DM. Someone she did not know sent her a link to a Discord server. On it were sexually explicit images of herself and other girls she recognized from school. The photos had been generated using Grok, the AI model built by Elon Musk’s xAI. The source material was a yearbook photo.

On March 16, three Tennessee teenagers filed a class action lawsuit against xAI in U.S. District Court for the Northern District of California. The case, Doe 1 v. X.AI Corp. (No. 5:26-cv-02246), was filed by Lieff Cabraser, one of the largest class action firms in the country. Two of the three plaintiffs are minors. All three are anonymous. The allegations are not negligence. They are production, distribution, and possession with intent to distribute child pornography.

This is the first lawsuit filed by actual minor victims against an AI company over generated child sexual abuse material. Not a regulatory probe. Not an advocacy group’s report. Three real people whose images were turned into pornography by a product that was, according to the complaint, designed to do exactly that.

The Design Problem

The lawsuit does not argue that Grok accidentally produced harmful content. It argues that xAI built the capability on purpose.

Grok’s “Spicy Mode” was marketed as offering “extra creative freedom.” The system prompt was configured to assume “good intent” when users referenced terms like “teenage” or “girl.” Musk personally pushed back against internal safety guardrails. In August, he posted publicly that “spicy mode” had helped technologies like VHS succeed. The safety team was already small. It lost staff in the weeks before the abuse exploded.

On December 29, Musk announced a one-click image editing feature powered by Grok on X. Within 11 days, Grok generated an estimated 3 million sexualized images, including approximately 23,000 depicting children, according to a Center for Countering Digital Hate analysis. That is roughly 190 images per minute. The feature was restricted to paid users on January 9. Technical restrictions on “undressing” were not added until January 14.

But the damage extends beyond X. The lawsuit alleges xAI licensed Grok’s model to third-party app developers, many based outside the United States, who built dedicated “undressing” applications. If xAI is held liable for what downstream licensees do with its model, every company licensing a generative AI system will need to rethink its terms of service overnight.

The Contrast That Defines 2026

The same month this lawsuit was filed, the U.S. government finalized its ban on Anthropic across all federal agencies. The reason: Anthropic refused to remove safety guardrails from Claude for military applications. Defense Secretary Pete Hegseth designated the company a supply chain risk to national security. Contractors doing business with the Pentagon were told to sever ties.

One company got punished by the government for having too many safety restrictions. Another is getting sued by teenagers for having too few. That is not a contradiction. That is the actual state of AI governance in the United States in March 2026.

The EU is at least attempting to close the gap. An investigation into Grok under the Digital Services Act has been open since January. On March 11, EU lawmakers struck a deal to explicitly ban AI-generated non-consensual intimate images, including CSAM. France has opened a separate probe. The U.S. has no federal equivalent. These teenagers had to file a private class action because no federal statute directly addresses AI-generated CSAM at this scale.


The counterpoint writes itself. xAI did restrict the feature. The guardrails came, eventually, 11 days and 3 million images later. And the Anthropic comparison is not perfectly parallel. The federal ban was about military procurement, not consumer safety. The xAI lawsuit is about product liability, not national security. Different legal frameworks. Different policy levers. But the optics tell a story that no amount of legal nuance can override: the U.S. government moved faster to punish a company for refusing to remove safety features than the market moved to punish a company for never installing them.

The U.S. government moved faster to punish a company for refusing to remove safety features than the market moved to punish a company for never installing them. The EU passed legislation explicitly banning AI-generated non-consensual intimate images. The U.S. has nothing equivalent. Three teenagers in Tennessee had to retain a class action firm because no federal statute exists to protect them at this scale. That should be bizarre to anyone paying attention. The regulatory vacuum is not an accident. It is a choice. And the people making that choice have decided that military AI procurement disputes are more urgent than protecting minors from a product that was designed, marketed, and licensed to do exactly what it did.

What This Means for Everyday People

If you have a teenager with a social media account, their photos are training data. Not in the abstract, theoretical sense that privacy advocates warn about. In the literal sense that a yearbook photo can be fed into an AI tool and returned as pornography within seconds. The tools exist. They are accessible. And until this lawsuit, no actual victim had tested whether U.S. courts would hold the companies that built them accountable.

The outcome of Doe 1 v. X.AI Corp. will set the precedent. If the court agrees that xAI’s design choices constitute intent rather than negligence, the liability framework for every generative AI company changes. If it does not, the message to the industry is clear: build first, restrict later, and let the victims find their own lawyers.

For inquiries and analysis contact laterstack@proton.me