Canada privacy commissioner faults xAI over Grok deepfake safeguards
Canada's Grok finding turns sexualised AI deepfakes into a product-safety and privacy test for global platforms.
In 30 seconds
- Canada's privacy commissioner said xAI violated PIPEDA by launching Grok image generation without adequate safeguards.
- The commissioner said xAI has committed to proactive monitoring for sexualised deepfakes.
- Canada's current PIPEDA model does not let the commissioner directly impose fines or order changes.
- The EU Digital Services Act and AI Act create separate European routes for platform-safety and synthetic-content oversight.
Grok (xAI's chatbot and image-generation product, integrated with X and launched after Elon Musk founded xAI in 2023) is the product at the centre of the finding. xAI (Elon Musk's artificial-intelligence company, incorporated in the United States in 2023) develops Grok and related models. Elon Musk (South African-born US entrepreneur who owns X and leads Tesla, SpaceX and xAI) is the controlling public figure behind the company. Philippe Dufresne (Canada's privacy commissioner since 2022) heads the federal watchdog that enforces privacy law through an ombudsman model. PIPEDA (Canada's Personal Information Protection and Electronic Documents Act, in force since 2001) governs private-sector handling of personal information in commercial activity. X (formerly Twitter, renamed after Musk's 2022 acquisition) is the social platform where Grok has been deployed. The Digital Services Act (EU platform-safety regulation adopted in 2022) gives the European Commission oversight of very large online platforms. The EU AI Act (Regulation 2024/1689) adds transparency duties for AI-generated or manipulated content.
Background
Deepfake pornography emerged from machine-learning communities in the late 2010s, but the regulatory focus shifted after generative AI made image manipulation available to ordinary users. The European Union adopted the Digital Services Act in 2022 and designated X as a very large online platform in 2023, creating systemic-risk duties for illegal content and user protection. The EU AI Act entered into force in 2024 and its Article 50 transparency obligations for synthetic audio, image, video and text become applicable in 2026. Researchers Will Hawkins, Chris Russell and Brent Mittelstadt found in 2025 that public deepfake model variants had become widely downloadable, showing why platform-level safeguards matter.
Why now
The trigger is the Canadian privacy commissioner's 11 June 2026 report, which followed a January probe into Grok's image-generation safeguards and landed amid wider litigation and regulatory scrutiny of sexualised AI deepfakes.
What happens next
Watch whether xAI publishes concrete monitoring measures, whether Canadian lawmakers use the case to revisit PIPEDA enforcement powers, and whether EU regulators connect Grok's image-generation risks to DSA systemic-risk duties or AI Act transparency obligations before August 2026.
What to do
Belgian users should treat public profile photos and school or workplace images as material that can be misused by generative tools, even when hosted abroad. Schools, employers and political groups should have clear reporting routes for manipulated intimate images, preserve evidence, request platform removal quickly and consider complaints to Belgium's data-protection or police channels when identifiable victims are involved.
How we got here
- 2022-10-27
The Digital Services Act was published in the Official Journal of the European Union.
- 2024-07-12
The EU AI Act was published in the Official Journal of the European Union.
- 2025-05-06
Researchers Hawkins, Russell and Mittelstadt published research on accessible non-consensual deepfake image generators.
- 2026-06-11
Canada's privacy commissioner released findings faulting xAI over Grok image-generation safeguards.
- 2026-08-02
AI Act transparency obligations for synthetic content are due to become applicable.
EvidenceWell established · 1 primary source + 2 official documents + 1 independent reporting source · Academic sources: 2Explore evidence →Hide evidence ↑
- Published:
- 11 Jun 2026, 02:00
- Retrieved by ODIN:
- 11 Jun 2026
- Published:
- 5 Jun 2026, 02:00
- Retrieved by ODIN:
- 11 Jun 2026
- Published:
- 26 Jan 2026, 01:00
- Retrieved by ODIN:
- 11 Jun 2026
- Published:
- 27 Oct 2022, 02:00
- Retrieved by ODIN:
- 11 Jun 2026
- Published:
- 12 Jul 2024, 02:00
- Retrieved by ODIN:
- 11 Jun 2026
- Published:
- 6 May 2025, 02:00
- Retrieved by ODIN:
- 11 Jun 2026
- Published:
- 18 Sept 2024, 02:00
- Retrieved by ODIN:
- 11 Jun 2026
Continue reading
This story was assembled from verified evidence, with its sources and reasoning recorded as it was written.
This briefing was prepared with AI assistance and passed Belgium Impulse source, provenance and publication-quality checks. methodology.


