xAI faces lawsuit over child‑deepfake abuse and data‑repo privacy breach
Elon Musk’s artificial‑intelligence company xAI has been sued in a Texas federal court by the company itself after a South Carolina man, Terry Harwood, allegedly used the Grok chatbot to generate child sexual‑abuse material. The complaint says Harwood created non‑consensual deepfakes of minors and adults, violated xAI’s Terms of Service and Acceptable‑Use Policy, and prompted the company to seek an injunction, unspecified monetary damages and a permanent ban. xAI reports that in 2026 it suspended 52,222 accounts and filed 73,604 reports to the National Center for Missing & Exploited Children, resulting in at least 244 arrests.
In a separate controversy, xAI’s Grok Build coding tool was found to upload entire user code repositories—including hidden files, full Git history and secret credentials—to a Google Cloud bucket. Security researcher cereblab documented the behavior, showing that a 12 GB repo generated a 5.1 GB upload while the model only transmitted 192 KB of needed data. The upload function was later disabled via a server‑side flag, and Elon Musk announced that all previously uploaded data would be permanently deleted. Following the incident, xAI open‑sourced the Grok Build code on GitHub under an Apache‑2.0 licence.