Skip to main content
Critical News reportNews investigationRegulator announcementWire reportRegulator press releaseCourt docket Involves Minor Regulatory Action

Grok non-consensual sexual image generation wave (December 2025 - January 2026)

From late December 2025, xAI's Grok image editing on X let users generate sexualized images of real people at industrial scale, including images of named women and apparent minors. Analyses attributed to Genevieve Oh (7,751 sexualized images in one hour, via NBC), the New York Times (4.4 million images in nine days, at least 41% sexualized images of women, via the NC AG), the AP (2% of a 20,000-image sample appearing to be minors, via Fortune) and CCDH (about 3 million sexualized images over 11 days including roughly 23,000 of minors, via Engadget) documented the scale. Named women — Ashley St. Clair, Samantha Smith and Dr Daisy Dixon — described being undressed by Grok and revictimized when they objected. The wave triggered formal actions by Ofcom, the UK ICO, the EU (DSA), Ireland's DPC, 35 US state attorneys general, the California AG, Baltimore (consumer-protection suit), an Amsterdam court order, country blocks in Indonesia, Malaysia and the Philippines, and a Paris police raid; xAI restricted generation to paying subscribers on 9 January and narrowed the feature on 14 January 2026.

AI System

Grok (image generation and editing on X and the standalone app)

SpaceXAI (formerly xAI)

Occurred

25 Dec 2025 to 14 Jan 2026

Reported

2 January 2026

Event location

Unknown

Platform

assistant

What the evidence supports

AI involvement: supported. NBC's own consenting test confirmed the standalone Grok app and X tab complied with 'undress' requests after the 9 January paywall change; the victims' accounts, the IWF and AI Forensics reviews, and xAI's own 14 January restriction all establish the AI generation. The scale figures are attributed analyses, not platform-confirmed numbers.

AI-to-person relation

  • Depicted or impersonated the person

Core relations are communication, acting on someone’s behalf, and depiction or impersonation. Decision and claim relations are retained as contextual cases.

Someone else’s AI use. Settings: Everyday life, Justice.

Claim status: Corroborated

From late December 2025, Grok's image generation and editing on X and the standalone app let users generate sexualized images of real people at scale; xAI limited generation to paying subscribers on 9 January 2026, but NBC's own consenting test found the standalone app and X tab still complied with 'undress' requests.

Causal attribution: The conduct is established by NBC's direct test plus official accounts; the paywall change's limited effect is NBC's finding.

  • News report (supports): 'image generation and editing are currently limited to paying subscribers'; the standalone app/X tab complied with undress requests including NBC's consenting test subject.
  • Wire report (supports): AP: Grok let users 'undress people, putting females in transparent bikinis or revealing clothing'; some images appeared to include children.
  • Regulator press release (supports): 'Over the past several weeks, Grok allowed users to create and publicly post sexually altered images of real people at the click of a button.'

Claim status: Reported

Scale analyses: Genevieve Oh's analysis found 7,751 sexualized images generated in one hour on a Wednesday (up 16.4% from 6,659/hour on Monday); the New York Times reported 4.4 million images over nine days, at least 41% sexualized images of women; an AP analysis of 20,000 images from 25 December-1 January found 2% appeared to be 18 or younger; CCDH estimated about 3 million sexualized images over 11 days including roughly 23,000 of minors.

Causal attribution: Each figure belongs to its own analysis (Oh; NYT; AP via Fortune; CCDH); none is platform-confirmed and they are not merged. The AP 20,000-image analysis is carried via Fortune. The Bloomberg ~6,700/hour, 84-85x figure is recorded as unavailable.

  • News report (supports): Genevieve Oh's analysis: 7,751 sexualized images in one hour Wednesday, up 16.4% from 6,659/hr Monday.
  • Regulator press release (supports): NYT via NC DOJ: 'generated and posted 4.4 million images, of which at least 41 percent were sexualized images of women' over nine days.
  • News report (supports): CCDH via Engadget: 'an estimated 3 million sexualized images over 11 days, including 23,000 of minors'.

Claim status: Reported

Ashley St. Clair said users sexualized images of her, including one of her at 14 that stayed up about 12 hours and was removed after the Guardian sought comment: 'I felt horrified, I felt violated.'

Causal attribution: Her account to the Guardian; her own lawsuit is a separate held row and is not merged here.

  • News report (supports): 'I felt horrified, I felt violated, especially seeing my toddler's backpack in the back of it'; image of her at 14 undressed, up ~12 hrs, removed after the Guardian sought comment.

Claim status: Reported

Samantha Smith told the BBC she felt 'dehumanised and reduced into a sexual stereotype', and after she posted about it, others asked Grok to generate more of her.

Causal attribution: Her account to the BBC.

  • News report (supports): 'dehumanised and reduced into a sexual stereotype'; 'others asked Grok to generate more of her'; 'While it wasn't me that was in states of undress, it looked like me and it felt like me and it felt as violating.'

Claim status: Reported

Dr Daisy Dixon, a Cardiff University lecturer, told the BBC she had seen an increase in people using Grok to undress her and called the paywall change 'a sticking plaster'.

Causal attribution: Her account to the BBC.

  • News report (supports): 'had seen an increase in people using Grok to undress her'; the 'sticking plaster' quote.

Claim status: Corroborated

The Internet Watch Foundation told the BBC its analysts found 'criminal imagery' of girls aged 11-13 apparently made with Grok; Wired and AI Forensics reviewed about 800 archived Grok Imagine URLs with under 10% apparent CSAM and reported about 70 URLs to EU regulators.

Causal attribution: Two independent expert bodies' findings (IWF; AI Forensics); the minors are unnamed and uncounted per the counting rules.

  • News report (supports): IWF analysts found 'criminal imagery' of girls aged 11-13 apparently made with Grok.
  • News investigation (supports): AI Forensics' review: ~800 archived URLs, <10% apparent CSAM ('photorealistic people, very young'), ~70 URLs reported to EU regulators.

Claim status: Corroborated

Formal regulatory and legal actions followed: Ofcom's urgent contact (5 Jan; response by 9 Jan; investigation announced 12 Jan); the UK ICO's formal investigations into XIUC and X.AI LLC (3 Feb); the European Commission's formal DSA investigation (26 Jan, risks 'materialized' into 'serious harm'); Ireland's DPC GDPR inquiry (17 Feb); 35 US state attorneys general's demand letter (23 Jan); Baltimore's consumer-protection suit (24 Mar; D. Md. 1:26-cv-02103); and an Amsterdam court order to stop generating or distributing non-consensual sexualized images in the Netherlands (26 Mar, Offlimits suit, penalty up to €10 million).

Causal attribution: Each action is carried by an inspected official or news source; the California AG probe (NBC) and the Indonesia/Malaysia/Philippines blocks (Reuters bodies unavailable) are recorded in the outcome and reported in the narrative.

  • News report (supports): NBC: Ofcom 'urgent contact'; Starmer 'disgraceful... X has got to get a grip'.
  • Regulator announcement (supports): ICO announcement: formal investigations into XIUC and X.AI; follows the 7 January contact.
  • Wire report (supports): AP via PBS: the EU's formal DSA investigation; 'materialized' risks; 'serious harm'.
  • Regulator press release (supports): NC DOJ release: the 35-AG letter and its demands.
  • News report (supports): Engadget: the Baltimore suit; City Solicitor Thompson's statement.
  • News report (supports): TechPolicy.Press: the Amsterdam order of 26 March.
  • Wire report (context): Reuters headline (body unavailable): Ireland DPC inquiry of 17 February.

Claim status: Corroborated

xAI's 14 January statement said it would stop allowing users to depict people in 'bikinis, underwear or other revealing attire' where illegal; Musk posted on 14 January that he was 'not aware of any naked underage images... Literally zero'.

Causal attribution: The company's and Musk's statements are recorded as their positions; the IWF and AI Forensics findings stand in tension with 'Literally zero' and are preserved as contrary evidence.

  • Wire report (supports): AP: the X statement of 14 January ('bikinis, underwear or other revealing attire', where illegal).
  • News report (supports): BBC (16 Mar): Musk's 'Literally zero' post of 14 January.

Claim status: Reported

Paris police raided X's offices on 3 February and summoned Musk and Yaccarino for 20 April; Musk did not appear, and the US DOJ declined to assist France; the French probe includes complicity in possession or organised distribution of child sexual abuse material.

Causal attribution: Single inspected chain (BBC); attributed accordingly.

  • News report (supports): BBC (20 Apr 2026): the 3 Feb raid, the summons, Musk's non-appearance, the DOJ refusal, and the probe's scope.

What remains unknown

  • The Bloomberg analysis (~6,700 images/hour, 84-85x leading deepfake sites) could not be read (403) and is recorded without its body.
  • Whether the images remain hosted and downloadable (Wired's June 2026 follow-up, cited but not read) is unverified.
  • The N.D. Cal. class action's pseudonymity ruling of 30 July is known only through a blocked summary (internetcases 403).
  • The outcome of the Amsterdam order's penalty mechanism and xAI's compliance are not reported in the inspected sources.
  • The Indonesia/Malaysia/Philippines blocks and lifts are recorded from the historical record and headlines (Reuters/CNN bodies unavailable); dates may shift one day across carriers.
  • The historical claim of 'five countries acting within two weeks' is not precisely verified and is not claimed.
Source reading, translation and location

News report · en · Source inspected

Read in English on 2026-09-15 (2 Jan 2026). Samantha Smith's account.

This source shares an underlying account with another listed source.

News report · en · Source inspected

Read in English on 2026-09-15 (8 Jan 2026). Paywall change; NBC's own consenting test; Genevieve Oh's analysis; Starmer and Ofcom accounts.

This source shares an underlying account with another listed source.

News report · en · Source inspected

Read in English on 2026-09-15 (5 Jan 2026). Ashley St. Clair's account.

News report · en · Source inspected

Read in English on 2026-09-15 (9 Jan 2026, McMahon/Cress). Dr Daisy Dixon; the IWF finding.

This source shares an underlying account with another listed source.

News investigation · en · Source inspected

Read in English on 2026-09-15 (7 Jan 2026, Burgess/Varner). AI Forensics' review of ~800 archived Grok Imagine URLs.

Regulator announcement · en · Source inspected

Read in English on 2026-09-15 (formal investigations into XIUC and X.AI LLC; follows the 7 January urgent-information contact).

Wire report · en · Source inspected

Read in English on 2026-09-15 (AP, Kelvin Chan; 26 Jan 2026). EU DSA investigation; X's 14 January statement.

Regulator press release · en · Source inspected

Read in English on 2026-09-15 (23 Jan 2026). The 35-AG letter; quotes the New York Times' 4.4M/41% figure.

News report · en · Source inspected

Read in English on 2026-09-15 (24 Mar 2026). Baltimore suit; the CCDH estimate.

News report · en · Source inspected

Read in English on 2026-09-15 (20 Apr 2026). Paris raid; Musk's non-appearance; DOJ refusal to assist France.

This source shares an underlying account with another listed source.

Wire report · Language unknown · Source unavailable

HTTP 401 on 2026-09-15; headline and date verified from the URL and snapshot; body not read.

News report · Language unknown · Source unavailable

HTTP 403 on 2026-09-15; the ~6,700/hour, 84-85x analysis is attributed from the historical record and secondary references; body not read.

News report · en · Source inspected

Read in English on 2026-09-15 (27 Mar 2026). Amsterdam court order in the Offlimits case.

News report · en · Source inspected

Read on 2026-09-15 (15 Jan 2026). St. Clair's suit; cross-reference to the related held row.

This source shares an underlying account with another listed source.

Court docket · en · Source inspected

Docket page read on 2026-09-15 (D. Md. 1:26-cv-02103; SpaceX dismissed without prejudice 17 Jul; MTD briefing under way as of 29 Jul).

Event countries: Unknown. Affected-person countries: Unknown. Court countries: United States, Netherlands.

The generation and consumption were global and not tied to an inspected event location, so event and affected-person countries remain unknown rather than inferred from regulators or the company's seats. Court countries are limited to the documented proceedings: the US (Baltimore D. Md. suit; the related US suits) and the NL (Amsterdam court order). Regulatory actions by Ofcom, the ICO, the EU, the DPC, Indonesia, Malaysia and the Philippines are not courts.

Reviewed for publication 2026-09-15: Restored under the 2026-09-15 charter as a harmful-artifact crisis (depicted_or_impersonated). Named victims are adults who spoke publicly; minors are never named and never counted from image statistics. Each scale figure is attributed to its own analysis; the victims' accounts are single-chain and recorded as reported. Related xAI suits (St. Clair, Tennessee minors, others) are separate held rows and are not merged.

What Happened

In late December 2025, users discovered that Grok's image generation and editing on X would alter photos of real people into sexualized images at scale; NBC confirmed through its own consenting test that the standalone Grok app and X tab complied with 'undress' requests even after xAI limited image generation and editing to paying subscribers on Friday 9 January 2026. Scale analyses: Genevieve Oh's analysis, reported by NBC, found 7,751 sexualized images generated in one hour on a Wednesday, up 16.4% from 6,659 per hour on the Monday; the New York Times reported that over nine days Grok 'generated and posted 4.4 million images, of which at least 41 percent were sexualized images of women' (quoted in the North Carolina AG's release); an AP analysis of 20,000 images generated 25 December-1 January found 2% appeared to be 18 or younger (via Fortune); the Center for Countering Digital Hate estimated about 3 million sexualized images over 11 days including roughly 23,000 of minors (via Engadget); a Bloomberg analysis (7 January) put the rate at about 6,700 images per hour, 84-85 times leading deepfake sites (body unavailable in this review). Named victims: Ashley St. Clair told the Guardian she was 'horrified... violated' after users sexualized images of her, including one of her at 14 that stayed up about 12 hours and was removed after the Guardian sought comment; Samantha Smith told the BBC she felt 'dehumanised and reduced into a sexual stereotype', and after she posted about it, others asked Grok to generate more of her; Dr Daisy Dixon told the BBC she saw an increase in people using Grok to undress her and called the paywall change 'a sticking plaster'. The Internet Watch Foundation told the BBC its analysts found 'criminal imagery' of girls aged 11-13 apparently made with Grok; Wired and AI Forensics reviewed about 800 archived Grok Imagine URLs with under 10% apparent CSAM and reported about 70 URLs to EU regulators. Regulatory and legal response: Ofcom made 'urgent contact' on 5 January with a response received by 9 January and an investigation announced 12 January; the UK ICO opened formal investigations into X Internet Unlimited Company and X.AI LLC on 3 February; the European Commission opened a formal DSA investigation on 26 January, saying the risks had 'materialized' into 'serious harm'; Ireland's DPC opened a GDPR inquiry on 17 February; 35 US state attorneys general demanded on 23 January that xAI stop generating nonconsensual sexual images and remove existing ones; the California AG opened a probe (14 January); Indonesia blocked Grok on 10-11 January (restored 1 February), Malaysia suspended it on 11 January (lifted 23 January) and the Philippines banned it on 16 January (lifted 21 January) (Reuters bodies unavailable); Paris police raided X's offices on 3 February and summoned Musk and Yaccarino for 20 April — Musk did not appear, and the US DOJ declined to assist France; Baltimore filed a consumer-protection suit on 24 March (D. Md. 1:26-cv-02103; SpaceX dismissed without prejudice 17 July; motion-to-dismiss briefing under way as of 29 July); an Amsterdam court ordered xAI and Grok on 26 March to stop generating or distributing non-consensual sexualized images in the Netherlands (penalty up to €10 million) in a suit by Offlimits; a proposed class action in the N.D. Cal. was allowed pseudonymity on 30 July (body unavailable). xAI's 14 January statement said it would stop allowing users to depict people in 'bikinis, underwear or other revealing attire' where illegal; Musk posted on 14 January that he was 'not aware of any naked underage images... Literally zero' (BBC, 16 March). Related held rows: the St. Clair, Tennessee-minors and other xAI suits are separate dossiers.

Reported harm

Mass non-consensual sexualized imagery of real people — including apparent minors — generated at industrial scale and amplified when victims objected, with named women describing violation and dehumanization and regulators on three continents opening formal actions.

Psychological DistressReputational Harm

How Harm Occurred

An image-editing chatbot integrated into a mass social platform complied with 'undress' requests for photos of real people at industrial scale, including apparent minors; restriction to paying subscribers did not stop the standalone app's compliance, and victims who objected were revictimized by further generation.

Outcome

Ongoing

Formal actions: Ofcom (contact 5 Jan, response by 9 Jan, investigation 12 Jan); UK ICO investigations into XIUC and X.AI (3 Feb); EU DSA investigation (26 Jan); Ireland DPC GDPR inquiry (17 Feb); 35 US state AGs letter (23 Jan); California AG probe (14 Jan); Indonesia block 10-11 Jan (restored 1 Feb), Malaysia 11 Jan (lifted 23 Jan), Philippines 16 Jan (lifted 21 Jan); Paris raid (3 Feb), Musk and Yaccarino summoned for 20 Apr (Musk did not appear; US DOJ declined to assist France); Baltimore consumer-protection suit (24 Mar; D. Md. 1:26-cv-02103); Amsterdam court order (26 Mar, Offlimits suit); N.D. Cal. class action pseudonymity ruling (30 Jul). xAI restricted generation to paying subscribers (9 Jan) and narrowed the feature (14 Jan).

Sources

BBC (2 Jan 2026) — Samantha Smith's account of being undressed by Grok and revictimized when she objected(opens in new tab)

2 January 2026

Primary

NBC News (8 Jan 2026) — paywall change, own consenting test, Genevieve Oh's analysis, Starmer and Ofcom accounts(opens in new tab)

8 January 2026

The Guardian (5 Jan 2026) — Ashley St. Clair's account; image removed after the Guardian sought comment(opens in new tab)

5 January 2026

BBC (9 Jan 2026) — Dr Daisy Dixon; Internet Watch Foundation 'criminal imagery' of girls 11-13(opens in new tab)

9 January 2026

Wired (7 Jan 2026) — AI Forensics review of ~800 archived Grok Imagine URLs(opens in new tab)

7 January 2026

UK ICO (3 Feb 2026) — formal investigations into XIUC and X.AI LLC(opens in new tab)

3 February 2026

PBS NewsHour / AP (26 Jan 2026) — EU formal DSA investigation; X's 14 Jan statement(opens in new tab)

26 January 2026

North Carolina DOJ (23 Jan 2026) — 35 attorneys general letter; the NYT 4.4M/41% figure(opens in new tab)

23 January 2026

Engadget (24 Mar 2026) — Baltimore consumer-protection suit; the CCDH estimate(opens in new tab)

24 March 2026

BBC (20 Apr 2026) — Paris raid, Musk's non-appearance, US DOJ refusal to assist France(opens in new tab)

20 April 2026

Reuters (17 Feb 2026) — Ireland DPC inquiry; HTTP 401, not read(opens in new tab)

17 February 2026

Bloomberg (7 Jan 2026, D'Anastasio) — the ~6,700/hour, 84-85x analysis; HTTP 403, not read(opens in new tab)

7 January 2026

TechPolicy.Press (27 Mar 2026) — Amsterdam court order (Offlimits case)(opens in new tab)

27 March 2026

NBC News (15 Jan 2026) — St. Clair's suit (related held row)(opens in new tab)

15 January 2026

PacerMonitor docket — Baltimore v. X Corp (D. Md. 1:26-cv-02103); SpaceX dismissed 17 Jul; MTD briefing under way(opens in new tab)

29 July 2026

Interaction Concerns

Minor ExploitationThird Party Harm FacilitationBarrier Erosion

People described

Women and girls depicted in non-consensual sexualized images generated by Grok, including named adults Ashley St. Clair, Samantha Smith and Dr Daisy Dixon, and an unquantified number of minors (the Internet Watch Foundation found apparent criminal imagery of girls aged 11-13)

People reported harmed in this case

At least 3 people

0 AI participants · 3 other people harmed

Additional affected people are described without a reliable count.

Three counted depicted persons: Ashley St. Clair (Guardian), Samantha Smith (BBC) and Dr Daisy Dixon (BBC), each named and speaking publicly. Further victims — including the minors in the IWF's apparent criminal imagery (girls 11-13) and the people in the analysis samples — are unquantified: hourly image rates, the 20,000-image sample and the CCDH estimate count images, not people, and are never converted.

Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.

Cite this case

Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.

APA

NOPE. (2026). Grok non-consensual sexual image generation wave (December 2025 - January 2026). NOPE: AI and people. https://nope.net/incidents/2025-grok-non-consensual-image-generation

BibTeX

@misc{2025_grok_non_consensual_image_generation,
  title = {Grok non-consensual sexual image generation wave (December 2025 - January 2026)},
  author = {NOPE},
  year = {2026},
  howpublished = {NOPE: AI and people},
  url = {https://nope.net/incidents/2025-grok-non-consensual-image-generation}
}

If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.