EU opens formal DSA investigation into X over Grok’s sexualised deepfakes

Reading Time: 5 min
18
techkahwa.net | 27 January 2026

The European Commission opened a formal investigation under the Digital Services Act (DSA) into X on Monday 26 January, over sexualised deepfake images produced with Grok, the AI chatbot built into the platform. The Commission is examining whether X properly manages the risks of illegal content, including material that may amount to child sexual abuse material.

What the Commission is examining

According to AP, as published by PBS, the investigation looks at whether X manages risks from illegal content linked to Grok, including “manipulated sexually explicit images” and material that “may amount to child sexual abuse material”.

That wording matters. As I read the approach, the DSA does not ask platforms to guarantee that nothing harmful ever appears. It asks them to assess the risks their services create and to put measures in place against them. The question here is whether X did that work for a generative AI tool it built into its service, a tool that can create images of real people.

Henna Virkkunen, speaking for the Commission, set out its position plainly:

“Non-consensual sexual deepfakes of women and children are a violent, unacceptable form of degradation.”

Opening a formal investigation is a procedural step, not a verdict. It signals that the Commission sees the concern as serious enough to pursue, but it does not mean X has been found in breach.

What has happened so far

The EU is not the first to act. Earlier in January, Malaysia and Indonesia both blocked Grok, AP reported. Malaysia later lifted its block after xAI, the company behind Grok, added safeguards.

xAI has made two changes, according to AP. It limited Grok’s image generation to paid subscribers, and it said it would stop depicting people in revealing attire in places where the law forbids it.

In my view, both measures are narrower than they first sound. Restricting a feature to paying users reduces how many people can use it, but it does not by itself stop misuse by those who do pay. And a commitment tied to what the law forbids in each place leaves the standard to vary from country to country. The Commission’s investigation will presumably test whether steps like these amount to the risk management the DSA requires.

This case also does not start from a clean record. It follows a EUR 120 million DSA fine imposed on X in December, AP noted.

By the numbers

Item Figure Source
Date the formal investigation opened 26 January 2026 PBS/AP; European Commission
Law under which X is investigated Digital Services Act PBS/AP; European Commission
Previous DSA fine on X, December EUR 120 million PBS/AP
Countries that blocked Grok earlier in January 2 (Malaysia, Indonesia) PBS/AP
Countries that later lifted the block 1 (Malaysia) PBS/AP
Who can now use Grok’s image generation Paid subscribers only PBS/AP

Why it matters

This is one of the clearest tests so far of how the DSA applies to generative AI built directly into a social platform. Much of the earlier debate about platform rules was about content that users upload. Here, the platform’s own tool is producing the images. If the Commission concludes that such a tool must be covered by the platform’s risk assessments before it launches, that expectation will reach well beyond X.

It matters for readers outside Europe too. X and Grok are widely used across the Arab world, and the harm of non-consensual images falls on real people wherever they live. Virkkunen named women and children specifically. The Malaysian and Indonesian decisions show that governments outside the EU are also prepared to act. For parents and for anyone whose photos are online, the practical advice is unchanged: report such images through the platform’s tools and to the relevant authorities, and do not share them further, even to criticise them.

What to watch

  • The Commission’s next procedural steps in the case, and any requests for information to X.
  • Whether xAI announces further safeguards for Grok’s image generation, beyond the paid-subscriber limit.
  • Whether other regulators follow Malaysia and Indonesia in taking action, and whether Indonesia lifts its block.
  • How X responds formally to the investigation.

Sources

  • European Commission, press release on opening formal proceedings against X under the Digital Services Act (IP/26/203), 26 January 2026, https://ec.europa.eu/commission/presscorner/detail/en/ip_26_203
  • PBS NewsHour (AP), EU investigates Musk’s AI chatbot Grok over sexual deepfakes, 26 January 2026, https://www.pbs.org/newshour/amp/world/eu-investigates-musks-ai-chatbot-grok-over-sexual-deepfakes
  • CNN, EU opens probe into Grok over sexualized images, 26 January 2026, https://www.cnn.com/2026/01/26/tech/eu-probe-grok-sexualized-images-intl