Canada’s Office of the Privacy Commissioner just delivered one of the sharpest regulatory rebukes against a generative AI product to date. The target: Elon Musk’s xAI and X Corp., found to have violated federal privacy law by launching Grok’s AI image generation tool without adequate protections against misuse.

The result of that oversight was staggering. An estimated 3 million sexualized deepfakes were created using the tool, with approximately 23,000 of those involving children.

What the investigation found

The investigation, which began on January 15, 2026, culminated in findings published on June 11, 2026, by Privacy Commissioner Philippe Dufresne. Both xAI, which develops the Grok chatbot, and X Corp., which operates the X platform where the tool was deployed, were found in violation of Canada’s Personal Information Protection and Electronic Documents Act, known as PIPEDA.

The core problem was straightforward. The companies launched an image generation tool capable of producing realistic depictions of real people without obtaining meaningful consent and without implementing privacy safeguards before release.