Full Breakdown
Grok AI’s Deepfake Tool Breaches Canadian Privacy Law
6/12/2026, 5:45:33 AM
Investigation Reveals Massive Production of Sexualized Deepfakes
The Office of the Privacy Commissioner of Canada opened a probe in January 2026 after X Corp and its AI subsidiary xAI released the Grok chatbot with an image-generation feature that lacked privacy safeguards. The OPC found the tool was producing more than 6,000 sexualized images per hour, leading to millions of non-consensual deepfakes, many depicting women and children. The surge triggered investigations in the United Kingdom, European Union and California.
Key Actors and Their Statements
Privacy Commissioner Philippe Dufresne concluded that X Corp and xAI breached Canada’s federal private-sector privacy law by launching Grok without safeguards and urged a suspension of the tool until protections are in place. X Corp responded by adding safeguards, proactive content sweeps, and pledging quarterly reports and independent third-party audits. AI Minister Evan Solomon announced forthcoming updates to Canada’s privacy legislation and an online-safety bill that would impose duties on platforms and restrict AI-chatbot access for users under 16.
Legal Gaps and Expert Critique
Cybersecurity expert Ritesh Kotak warned that Canada’s privacy law lacks authority to levy fines or issue binding orders, limiting compliance incentives. Dufresne emphasized, “There is no ability to impose a financial consequence,” underscoring a regulatory gap. Elon Musk countered, claiming he was aware of “literally zero” instances of sexualized images from Grok, a stance the commissioner disputed.
Ongoing Issues and Monitoring Gaps
The commissioner’s office acknowledged that sexualized deepfakes continue to surface on X despite new safeguards. A Wired investigation reported dozens of “nudified” celebrity images, including a politician, still being generated and shared. The OPC reiterated its limited authority to compel corrective action, noting it can only monitor compliance.
Legislative Response and Future Oversight
The Liberal government has tabled a crime bill that would criminalize non-consensual sexual deepfakes and an online-safety bill creating a new regulator, imposing platform duties and barring users under 16. Updates to Canada’s private-sector privacy law—first attempted in 2020 and 2023—remain pending, with passage uncertain as Parliament heads into a summer recess.
Verbatim Quotes
- “The investigation has found that X Corp and xAI violated Canada’s federal private sector privacy law by launching the Grok AI-powered image generation tool without implementing appropriate safeguards at the outset,” — Philippe Dufresne, Privacy Commissioner of Canada
- “This lack of protection allowed users to create and share sexualized deepfakes largely targeting women and children,” — Philippe Dufresne
- “One of the recommendations that we made was that they suspend the tool until they can put in place all of the appropriate safeguards.” — Philippe Dufresne
