Canada Finds xAI and X Corp Violated Privacy Laws
Privacy Commissioner Philippe Dufresne determined xAI and X Corp violated federal law by allowing Grok to generate sexualized deepfakes without adequate safeguards.
Canada's Privacy Commissioner Philippe Dufresne announced Thursday that xAI and X Corp violated federal private sector privacy laws by launching the Grok AI image generation tool without appropriate safeguards. An investigation initiated in January revealed that the tool enabled users to create and share non-consensual, sexualized deepfakes primarily targeting women and children, with output peaking at over 6,000 such images per hour.
While xAI implemented some restrictions on editing images of real individuals and agreed to third-party audits and quarterly reports, the companies rejected a recommendation to suspend the tool. Dufresne stated that the companies remain in non-compliance and highlighted a critical legislative gap, as his office currently lacks the authority to issue binding orders or financial penalties without lengthy court proceedings.
In response to these findings, Artificial Intelligence Minister Evan Solomon announced plans to introduce updated privacy legislation to modernize 25-year-old laws and combat deepfakes. This move coincides with the government's introduction of the Safe Social Media Act, which includes a ban on social media accounts for users under 16, and Bill C-16, which seeks to criminalize the distribution of non-consensual deepfake intimate images. The ruling reflects a global regulatory trend, following similar scrutiny of Grok in the United Kingdom, Italy, and the European Union.