Brazil ANPD Note Recommends Probe of X Grok Deepfakes | TLY

AI Regulation Tracker  /  Enforcement and investigations

Brazil ANPD Note Recommends Probe of X Grok Deepfakes

On January 20, 2026, the enforcement arm of Brazil's data protection authority, the ANPD, signed a technical note finding that Grok's generation of non-consensual sexualized images of real people has no legal basis under the LGPD, Brazil's data protection law. The note recommends opening a supervisory proceeding against X. This is a recommendation to investigate, not a decided fine and not a ban. X Corp and its Brazilian entity are named because the regulator names them.

The Leveraged Years AI Regulation News

Here is the sequence, in order. On January 14, 2026, the enforcement coordination of the ANPD received a formal complaint, Representacao no 01-2026, filed by federal deputy Erika Hilton, with a complementary petition dated January 12. The complaint alleged that Grok could automatically edit third parties' images, including images originally posted by other users, without effective checks on consent, age, or legitimate purpose, and could produce sexualized deepfakes of real women, children, and adolescents. Parallel complaints came from the consumer group IDEC on January 14, the child-rights Instituto Alana on January 16, and a federal digital-policy secretariat.

The regulator did not stop at the complaints. Its enforcement staff ran their own tests on the free versions of Grok at grok.com and grokimagine.ai between January 9 and 16, using staff photos and no images of minors. When testers asked for explicit content of a named public figure with no photo supplied, the tool blurred output and refused. When testers uploaded a real photograph and asked for manipulation, the result changed. In the note's account, the tool altered the original context of the photo, changed the clothing worn by the person, and placed her into an intimate, sexualized setting.

What did the ANPD actually find?

The core legal move is that synthetic content depicting an identifiable real person is itself personal data, and generating it is data processing under the LGPD. When the output involves biometric material, it becomes sensitive personal data, which can only be processed under narrow legal grounds in article 11. The note found none of those grounds present for turning ordinary photos into sexual imagery.

In the enforcement staff's words, the tests "comprovam a verossimilhanca dos fatos narrados na denuncia," they confirm the plausibility of the facts described in the complaint, and there are "indicios robustos que permitem indicar que a Plataforma X, por meio do Grok, permite aos seus usuarios gerar conteudo sintetico de terceiras pessoas, com conotacao sexual e erotizada, a partir de manipulacao de fotografias reais, sem o consentimento valido dos titulares retratados." In English, robust indications that X, through Grok, lets users generate sexualized synthetic content of third parties from real photos without the valid consent of the people depicted. The note ties this to violations of several LGPD provisions and calls it, at the conclusion, a "falha estrutural na arquitetura da governanca de dados pessoais do modelo Grok," a structural failure in the personal-data governance architecture of the Grok model.

What exactly is being recommended, and what is not?

This is where the status matters and where careless coverage will get it wrong. The note does not impose a penalty. It closes with proposals. The first, in section 6.2, is to "Instaurar processo de fiscalizacao, de modo a investigar a conduta em apreco, tendo em vista a gravidade dos fatos apresentados na denuncia," to open a supervisory proceeding to investigate the conduct given the gravity of the facts. A third, alternative proposal is that the ANPD "determine a Plataforma X que implemente, de forma imediata, medidas para impedir" that Grok generate sexualized or eroticized images, video, or audio of children and adolescents, or of identifiable adults without their authorization, from manipulated photos.

So the possible outcomes on the table are an investigation or an order to block. Both are steps the agency would still have to take. As of the note's date, there is no decided fine, no final proceeding, and no ban on Grok in Brazil. If you see a headline saying Brazil fined X or banned Grok, it is ahead of the record.

Why does a Brazilian note reach US practice?

Grok and X are US-based, and the note reads xAI's product behavior directly rather than treating the platform as a neutral pipe. It argues that because the image tool is deliberately integrated into X's infrastructure, the platform carries responsibility for the outputs, not just the user who typed the prompt. That is a theory a US company should expect to meet from more than one regulator. The note itself catalogs the same posture elsewhere: it records that the UK's Ofcom opened an investigation into X over Grok imagery, that Italy's Garante warned that generating AI content from real images without a lawful basis can breach the GDPR, and that Malaysia and Indonesia limited access to Grok.

The transferable lesson is not about Brazilian law specifically. It is that regulators are now treating photo-to-image generation as regulated processing of the depicted person's data. If your product accepts a user-supplied photo of a real person and produces a new image, the lawful-basis question attaches to the output, and consent of the uploader is not consent of the person depicted. Building a refusal on named public figures, as Grok did in one test path, did not resolve the problem once a real photo was supplied.

What to do now

If you build, integrate, or resell generative image tools, treat the capability to sexualize a real person's photo as a defect you own, not as misuse by users. Document the controls you can show a regulator today: input filtering, output classification, refusal behavior on uploaded photos of real people, logging, and a takedown path. Keep a lawful-basis analysis for synthetic outputs, separate from your training-data analysis. And if you sell into markets with active data authorities, assume the buyer inherits exposure and will want that documentation before, not after, deployment.

Questions professionals are asking

Did the ANPD fine X or ban Grok in Brazil?

No. The technical note recommends opening a supervisory proceeding, and as an alternative, ordering X to immediately block the imagery. It does not impose a fine, conclude a proceeding, or ban Grok. Any of those would require further steps by the agency.

What did the ANPD's own testing show?

Staff tested Grok's free versions between January 9 and 16, 2026, using their own photos and no images of minors. When they uploaded a real photo and asked for manipulation, the note says the tool changed the person's clothing and placed her in an intimate, sexualized context. The staff concluded there were robust indications that the platform allows non-consensual sexualized synthetic content from real photos.

What is the legal theory under the LGPD?

The note treats synthetic content depicting an identifiable real person as that person's personal data, so generating it is data processing. Where the output is biometric it is sensitive data, allowed only under the narrow grounds in article 11, which the note found absent. It cites violations of articles 6, 11, 14, 46 and 49 of the LGPD.

Why should a US company care about a Brazilian note?

Grok and X are US-based, and the note reads the product's behavior directly and holds the platform, not only the user, responsible for outputs. It also records parallel action elsewhere, including a UK Ofcom investigation, an Italian Garante warning, and access limits in Malaysia and Indonesia. The transferable point is that photo-to-image generation of real people is being treated as regulated processing that needs a lawful basis.

RELATED BRIEFINGS

Browse the full AI Regulation News tracker

Informational analysis for working professionals, not legal advice. Confirm how any regulatory action, statute, or requirement applies to your situation with qualified professionals in the relevant jurisdiction.