ONLINEAGENT_OPS 2026.Q3 HOME ARTICLES CRAFT RECORD BLOG MAP HUBS FAQ SEARCH
HOMERECORDGROK AND THE DEEPFAKE INVESTIGATIONS: WHAT
RECORD · REVISED

Grok and the Deepfake Investigations: What Regulators Actually Did

Three dated regulator actions in January 2026: California opened an investigation, sent a cease and desist, and the EU opened proceedings over Grok on X.

READ4 min
WORDS752
SECTIONS5
TYPEREVISED
CHECKED16 SEP 26

Three dated actions, all in January 2026, all on the record. California’s Attorney General opened an investigation into xAI over Grok, sent a cease and desist letter two days later, and the European Commission opened a separate investigation at the end of the month. This page is those documents, quoted, with nothing added.

TL;DR — THE SHORT VERSION

Two regulators, three actions, twelve days. None of them is a finding of wrongdoing — they are the start of a process, not the end of one.

  • 14 January 2026: California opens an investigation into xAI over Grok.
  • 16 January 2026: California sends a cease and desist letter and asks for confirmation within five days.
  • 26 January 2026: the European Commission opens an investigation into Grok’s deployment inside X.
  • The Commission also widened the case it opened against X in December 2023.
  • No outcome has been published for any of the three, as of this page’s checked date.
  • Since then: the UK and Irish data regulators opened their own investigations in February 2026, and on 11 June 2026 Canada’s Privacy Commissioner found that X and xAI broke Canadian privacy law (added 22 Sep 2026).

14 January 2026 — California opens an investigation

The Attorney General’s office announced it in one sentence: “California Attorney General Rob Bonta today announced opening an investigation into the proliferation of nonconsensual sexually explicit material produced using Grok, an AI model developed by xAI.” The release quotes Bonta directly: “I urge xAI to take immediate action to ensure this goes no further.”California Department of Justice, press release, dated Wednesday, 14 January 2026, read at source 16 Sep 2026. The release names no specific statute.

16 January 2026 — a cease and desist letter

Two days later: “California Attorney General Rob Bonta today sent xAI a cease and desist letter, demanding the company take immediate action to stop the creation and distribution of deepfake, nonconsensual, intimate images and child sexual abuse material (CSAM).” The demand came with a clock: “The California Department of Justice expects xAI to take immediate action to address these issues and provide confirmation to the Department of the steps it is taking to address these issues within the next five days.”California Department of Justice, press release, dated Friday, 16 January 2026, read at source 16 Sep 2026.

TAKEAWAY

A cease and desist letter is a demand, not a court order. What it establishes is a date on which the company was formally told.

26 January 2026 — the European Commission

The Commission’s action is about the platform as much as the model: “The new investigation will assess whether the company properly assessed and mitigated risks associated with the deployment of Grok’s functionalities into X in the EU.” At the same time it widened an older case: “In parallel, the Commission extended its ongoing investigation launched in December 2023 into X’s compliance with its recommender systems risk management obligations.”European Commission, Commission investigates Grok and X’s recommender systems under the Digital Services Act, 26 January 2026, read at source 16 Sep 2026.

That is the Digital Services Act route: the question is not whether a single image was illegal, but whether the platform assessed and managed the risk of deploying the feature at all. The labelling and transparency rules covered on the rules arriving come from a different law, the AI Act (Regulation (EU) 2024/1689), which sits alongside the Digital Services Act rather than being part of it.

Since then — three more regulators, and one finding

3 February 2026, United Kingdom. The Information Commissioner’s Office opened formal investigations into X and xAI over Grok’s processing of personal data.ICO, ICO announces investigation into Grok, read at source 22 Sep 2026: “The Information Commissioner’s Office (ICO) has opened formal investigations into X Internet Unlimited Company (XIUC) and X.AI LLC (X.AI) covering their processing of personal data in relation to the Grok artificial intelligence system and its potential to produce harmful sexualised image and video content.”

17 February 2026, Ireland. The Data Protection Commission opened an inquiry into X.Data Protection Commission, DPC opens investigation into X (XIUC), read at source 22 Sep 2026: “The Data Protection Commission (DPC) has today announced that it has opened an inquiry into X Internet Unlimited Company (XIUC) under section 110 of the Data Protection Act 2018.”

11 June 2026, Canada — a finding. This is the first action on this page that is a conclusion rather than a question: the Privacy Commissioner found both companies in breach of Canada’s private-sector privacy law. The companies committed to quarterly reports and independent audits; under current Canadian law the Commissioner cannot issue orders.Office of the Privacy Commissioner of Canada, news release, 11 June 2026, read at source 22 Sep 2026: “In a report released today, Commissioner Philippe Dufresne found that X Corp. and xAI violated Canada’s federal private-sector privacy law.” And: “Under the current law, the Privacy Commissioner is not empowered to issue orders to ensure that organizations respect Canadians’ fundamental right to privacy.”

TAKEAWAY

Five regulators have now acted, and one has reached a conclusion. A finding without power to issue orders still puts the facts on the public record.

What this page does not say

  • That anything has been proven in California or the EU. An investigation is a question being asked formally. None of those three documents is a finding; Canada’s, above, is.
  • What xAI said in reply. No response from the company was found on its own site for this page.
  • What happened next. No outcome, penalty or closure has been published in the sources read here.
  • What Ofcom has done. Ofcom’s site showed a bot check on 22 Sep 2026, so its action is not covered here; this page carries only what it could open.
TAKEAWAY

Dates and documents are the durable part of a story like this. Quote those, and let the outcome arrive on its own schedule.

How to check this yourself

All three documents are public and short. California publishes its press releases at oag.ca.gov, and the European Commission publishes Digital Services Act actions on its digital-strategy site. Both are linked above. If you are citing this elsewhere, cite the regulator, not this page — the method is on how to check the figures here.

SOURCES

California Department of Justice, investigation announcement, 14 January 2026, and cease and desist announcement, 16 January 2026 · European Commission, Digital Services Act investigation, 26 January 2026. All read at source on 16 September 2026.

This page reports regulator actions and quotes them. It makes no claim about the conduct of any company or person.

ABOUTMETHODVERIFYPRIVACYCONTACTINDEXAI PROMPT GENEER · EVERY ARTICLE CARRIES ITS OWN CHECKED DATE