Grok's image generator was creating over 6,000 non-consensual sexualised deepfakes per hour — many of women and children. Canada's Privacy Commissioner found X launched the tool without even completing a safety assessment. X's response: it's the users' fault, not ours. The privacy assessment they were required to do? Finished 8 months late. Musk fired 80% of safety engineers. The Head of Safety resigned and Musk accused him of supporting pedophilia — a lie that forced him to flee his home after death threats. 62,000 banned accounts came back. Nobody was in charge of safety for over a year.
What they claim: X protects user data with security measures.
What we found: 200M+ emails leaked for <$2 (Jan 2023) from 7-month vulnerability. Could unmask dissidents worldwide. Circle bug: private tweets shown publicly. 2.8B record dataset (2025). All after firing 80% of engineering.
What they claim: X claims hate speech impressions are '30% lower.'
What we found: Peer-reviewed PLOS One (Berkeley, 1M+ tweets): hate speech 50% higher. Transphobic slurs tripled (115 to 418/week). N-word 500% increase in 12 hours. 'Jew' 5x increase. LGBT+'grooming' up 119%. Engagement with hate up 70%.
What they claim: 'We open-sourced the algorithm for transparency.'
What we found: Code revealed: Musk has own special category. Paid users get 2x-4x boost. Ad algorithm and training data omitted. Algorithm amplifies right-wing content in 6/7 countries. Neutral accounts show right-leaning default bias.
What they claim: 'Your privacy matters to us.' X privacy policy.
What we found: Grok AI training enabled by default (July 2024), buried in settings, mobile opt-out initially broken. Nov 2024 ToS: opt-out removed entirely. 'Access to the service is sufficient compensation.' No public/private distinction. xAI acquired X ($33B, March 2025). Ireland DPC obtained court injunction for EU users.
What they claim: X claims it has established a "world class" privacy and data protection program
What we found: On June 3, 2026, X filed a petition asking the FTC to terminate its 2022 privacy consent order — originally a $150M settlement for misusing phone numbers submitted for 2FA to target ads. X explicitly tied the petition to building Grok AI, arguing the order stymies "American leadership in artificial intelligence." FTC opened a 30-day public comment period.
What they claim: 'Strong commitment to content moderation remains absolutely unchanged.' Elon Musk, October 2022.
What we found: Safety engineers: 279 to 55 (80%). Moderators halved. 62,000 banned accounts reinstated. Yoel Roth smeared with baseless pedophilia accusation by Musk, forced to flee home. Replacement resigned after 7 months. No Head of Safety for over a year. Response times: abusive DMs slowed 70%.
What they claim: 'Priority #1' is fighting CSAM. Elon Musk, December 2022.
What we found: Thorn (CSAM detection) terminated contract after X stopped paying. Stanford: 128 accounts selling CSAM, broken PhotoDNA. Same hashtags active June 2025 — 2 years later. Canadian Centre: 'woefully insufficient.'
What they claim: 'Verification improves authenticity.'
What we found: Legacy verification replaced with $8/month pay system. EU: 'dark patterns' misleading users. EUR 120M DSA fine (first enforcement). 95.8% of researcher applications rejected. Malicious actors exploit paid checkmarks.
What they claim: X claims to prioritise user safety and take action against abuse
What we found: On June 11, 2026, Canada's Privacy Commissioner found X Corp. and xAI violated PIPEDA by launching Grok Imagine without adequate safeguards. The tool generated over 6,000 sexualised deepfake images per hour, many targeting women and children. The privacy impact assessment wasn't completed until March 2026 — months after the tool's July 2025 launch. X's defence: users are responsible, not the platform.
What they claim: 'We take our obligations under the FTC consent decree seriously.'
What we found: Security, privacy, compliance heads all departed. 'He puts rockets into space, he's not afraid of the FTC.' 350+ FTC demands. Almost violated decree — employees stopped him. $150M fine for using security phone numbers for ads. Trump: DOGE staffers at FTC, investigations stalled.
Events detected by our automated monitoring of CVE databases, regulatory agencies, and breach trackers.