Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsYes—the UK has opened a formal investigation involving X after reports that Grok was used to create and circulate sexualised images of real people, including apparent children. Ofcom has not found that X created or distributed child sexual abuse material (CSAM), and neither Ofcom nor the Information Commissioner’s Office (ICO) had announced a final decision by 18 August 2026. The regulators are examining whether X and xAI met their separate online-safety and data-protection duties. Elon Musk called the scrutiny censorship; Ofcom says it is assessing platform systems, not choosing which lawful posts to remove.
The short version
- Ofcom opened its investigation on 12 January 2026 into X Internet Unlimited Company under the Online Safety Act.
- The inquiry followed reports that Grok on X could generate or share undressed or sexualised images, including images of apparent children. Ofcom said the material “may amount to” intimate-image abuse, pornography or CSAM—an allegation requiring evidence, not a final legal finding.
- The ICO opened separate investigations on 3 February 2026 into X and xAI over the lawful, fair and transparent processing of personal data and safeguards in Grok’s development and deployment.
- X said it added measures to stop intimate-image generation on 15 January and later described automated detection, human review and guardrails to Parliament. Those are company claims whose effectiveness regulators must assess.
- Possible outcomes range from remedial orders and fines to, in serious continuing cases, court-backed measures affecting UK access. No fine, ban or shutdown had been announced in the official material available by 18 August 2026.
What happened and when
| Date | Event |
|---|---|
| 5 January 2026 | Ofcom urgently contacted X about safeguards around Grok and requested information. |
| 9 January | X and xAI replied by Ofcom’s deadline. The government said Grok still appeared to allow intimate-image generation for paying users. |
| 12 January | Ofcom formally opened an investigation into X. In a House of Commons statement, the government said the Internet Watch Foundation had reported criminal imagery involving children as young as 11. Read the government statement. |
| 15 January | X said it had introduced measures intended to prevent the Grok account from creating intimate images. Ofcom said its investigation continued. Ofcom’s launch notice. |
| 3 February | Ofcom explained the investigation’s scope and the Online Safety Act’s limits around standalone chatbot use. The ICO announced parallel investigations into X and xAI. Ofcom’s scope update and ICO announcement. |
| February–March | Ofcom said it was researching X and Grok on X-managed accounts and devices while analysing evidence obtained through legally binding information requests. Its transparency notices are published here. |
| 24 April | X submitted written evidence to Parliament describing its moderation systems and claimed Grok guardrails. Read X’s submission. |
What Ofcom is actually investigating
Ofcom’s case is primarily about X’s institutional safeguards and compliance, not a criminal trial of Musk or a determination that every image reported online was illegal. The regulator is examining whether X:
- assessed the risk that illegal content would appear on its service;
- updated that assessment before significant product changes;
- took proportionate measures to prevent UK users encountering priority illegal content;
- removed illegal content promptly after becoming aware of it;
- considered privacy risks and risks to children; and
- used highly effective age assurance to keep children away from pornography.
Ofcom must gather evidence, allow the company to respond and then decide whether statutory duties were breached. An opened investigation is not a provisional or final finding.
What “may amount to CSAM” means
Ofcom’s wording matters. Saying material may amount to CSAM, intimate-image abuse or pornography signals a regulatory question about particular content and conduct, not a conclusion that all Grok outputs fit one offence.
#1 Best Overall
UK law prohibits possession and sharing of sexual images of children, including artificially created images, according to Ofcom’s explanation. Sharing or threatening to share a non-consensual intimate image of a person of any age is also illegal. Ofcom said that from 6 February 2026, creating or requesting creation of such non-consensual intimate images would be covered by the new offence described in its guidance.
The classification of an AI image depends on what it depicts, the apparent age shown, whether a real person’s photograph was manipulated, what the user did with the output and which offence applies. An AI-generated image is not automatically evidence that a real child was photographed; conversely, the fact that a source photograph was publicly available does not establish consent to sexual manipulation.
What X says it changed
X said on 15 January that it had implemented measures to stop the Grok account being used to create intimate images. In its 24 April parliamentary submission, X described:
- machine-learning models, heuristics and large-language-model checks;
- confidence scores and thresholds for automated action;
- human review of lower-confidence cases;
- monitoring of false positives, appeals, overturned decisions and anomalies; and
- rules prohibiting child sexual exploitation, non-consensual nudity and unwanted sexual content.
These statements show what X says its systems are designed to do. They do not independently establish that safeguards worked in practice. Ofcom’s key questions include whether controls existed before the reported abuse, whether they blocked generation and distribution, how quickly reports were acted on, and whether repeat offenders could continue.
Free tools Windows power users keep installed
One-click scans. No signup required.
The separate ICO investigation into privacy
The ICO’s inquiry is distinct from Ofcom’s Online Safety Act case. It concerns X and xAI LLC, the Grok provider, and asks whether personal data was processed lawfully, fairly and transparently and whether privacy safeguards were built into the model and its deployment.
The ICO is examining the legal basis for processing, notice to individuals, data-protection rights, protection of children and vulnerable people, and whether Grok enabled harmful manipulation of identifiable people. The ICO said it had not reached a view on whether data-protection law was infringed. Its possible tools include information and assessment notices, enforcement notices and monetary penalties.
Rank #3
Why X and xAI must not be conflated
| Entity | Regulatory focus |
|---|---|
| X Internet Unlimited Company | Ofcom’s investigation of the X platform’s risk assessments, moderation, reporting, removal, privacy and age-assurance systems. |
| xAI LLC | The ICO’s investigation into Grok’s personal-data processing and safeguards. Ofcom said it was considering whether some Online Safety Act provisions applied to xAI, but could not at that stage investigate illegal-image creation by standalone Grok under the relevant Part 3 framework. |
This is why it is inaccurate to say that the UK has “charged Musk’s AI company with CSAM.” The official material describes regulatory investigations of named corporate entities, not criminal charges against Musk.
What Musk’s “censorship” claim means
Musk characterized the scrutiny as an attempt to find any excuse for censorship
, according to contemporary reporting by Ars Technica. His argument is political and constitutional: government pressure on a major platform could become an indirect way to control lawful speech.
Ofcom’s position is narrower. It says it does not select individual posts or accounts for removal. Platforms decide whether content breaches UK law; Ofcom evaluates whether their systems and processes meet statutory duties. The factual issue is therefore not whether a regulator dislikes a viewpoint, but whether X’s product design, moderation, reporting, age checks and risk management were legally adequate.
Rank #4
Both over-removal and under-removal create risks. X’s own submission discusses balancing false positives against false negatives. That trade-off does not answer whether the controls were effective, but it explains why the investigation must examine evidence rather than slogans.
The legal gap around standalone chatbots
Ofcom’s 3 February explanation limits what readers should infer from the case. A private, one-to-one interaction with a standalone chatbot may fall outside some Part 3 Online Safety Act duties unless content is user-generated, shared or encountered through search. That does not make private conduct lawful: separate criminal and data-protection rules may still apply. It means the Online Safety Act does not automatically cover every Grok product or every generation pathway.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What penalties are possible?
| Regulator | Potential consequences | Maximum stated figure |
|---|---|---|
| Ofcom | Compliance or remedial measures; in serious ongoing cases, a court application for proportionate business-disruption measures, potentially affecting payment providers, advertisers or UK access. | £18 million or 10% of qualifying worldwide revenue, whichever is greater. |
| ICO | Information or assessment notices, enforcement notices and monetary penalties under the UK GDPR and Data Protection Act 2018. | £17.5 million or 4% of annual worldwide turnover, whichever is higher. |
These are statutory ceilings, not predictions of a fine. The sequence matters: investigation, possible provisional finding, company representations, final decision, and then any enforcement notice or penalty. A court order affecting access would require a separate court process and must be appropriate and proportionate.
What remains unknown
- Whether Ofcom will find that X’s risk assessments, controls or removal systems breached the Online Safety Act.
- How widespread or repeatable the reported generation and sharing was, and how quickly flagged material was removed.
- Whether safeguards differed for UK users, paying users, public posts, reposts, search and recommendations.
- Whether the ICO will conclude that personal-data processing or model safeguards breached data-protection law.
- What evidence X and xAI provide about false positives, false negatives, appeals and repeat offenders.
What victims and users should do
Do not download, save, quote-post, archive or deliberately search for suspected abusive material. Reporting it can create further copies and harm.
- Under-18s: Ofcom points to Childline’s Report Remove service for images of themselves or peers.
- Adults: The Revenge Porn Helpline offers support for intimate images shared without consent.
- Suspected CSAM: Ofcom directs people to report it to the Internet Watch Foundation, without redistributing the material.
Use X’s reporting tools where safe, preserve only information needed by investigators, and contact police if there is an immediate threat or extortion.
What to watch next
The meaningful milestones are an Ofcom provisional view, X’s representations, a final Ofcom decision and any resulting enforcement notice or fine. Separately, the ICO may issue notices or reach a data-protection decision. Until those steps occur, the accurate description is that the UK is investigating whether X and xAI met their legal duties after reported misuse of Grok—not that the regulators have already proved a CSAM offence or ordered a ban.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.




