Canadian privacy watchdog finds xAI’s Grok violated federal laws over deepfakes
The Canadian Privacy Commissioner’s report adds to a growing global regulatory crackdown on the Elon Musk-owned platform, coinciding with new domestic legislation aimed at digital safety.

xAI’s Grok has breached Canadian federal private sector privacy laws by launching an image generation tool capable of creating and sharing sexualised deepfake images without user consent, according to a report released by Privacy Commissioner Philippe Dufresne. The findings follow a probe conducted in January, which determined that the company failed to implement appropriate safeguards from the outset.
Dufresne stated that the violation occurred because the AI-powered tool was deployed without adequate protective measures in place. While the Commissioner acknowledged that xAI has committed to proactively monitoring for sexualised deepfakes rather than responding only after incidents are reported, he clarified that he lacks the authority to impose fines or mandate specific policy changes for the company.
The report was released on Thursday, coinciding with the rollout of changes by xAI designed to prevent users from editing images of real people into revealing clothing. The timing is significant as xAI, a subsidiary of SpaceX, is set to go public on United States markets on Friday in what is described as the biggest initial public offering in modern history.
The Canadian finding is part of a broader wave of international scrutiny regarding the platform’s handling of explicit content. In the United Kingdom, media regulator Ofcom launched an investigation in January, while British lawmaker Jess Asato filed a lawsuit earlier this month over deepfake images created of her. The European Commission also condemned the spread of explicit content on X in January, leading to a formal probe, and Spain launched a separate investigation into Grok in February.
Regulatory pressure has intensified globally, with a Dutch court ordering xAI in March to stop allowing the creation of nude images. In the United States, three teenage girls filed a class action lawsuit in California alleging the platform facilitated images depicting child sexual abuse, while the US Senate passed legislation in January allowing victims to sue creators for a minimum of $150,000. Additionally, Indonesia and Malaysia fully blocked Grok in January over sexually explicit AI images.
Domestically, the report emerges alongside a newly released digital safety bill that aims to ban social media use for children under 16. The proposed legislation would establish a digital regulator to enforce safety standards for AI chatbots, creating a framework that directly addresses the governance issues highlighted in the Privacy Commissioner’s findings.


