Irish DPC Opens Grok Inquiry Over Sexualised AI Images | TLY

AI Regulation Tracker  /  Data protection and GDPR

Ireland Opens a Formal GDPR Inquiry Into X Over Grok Image Generation

An inquiry, not a finding. On February 17, 2026, Ireland's Data Protection Commission announced it had opened a statutory inquiry into X Internet Unlimited Company under section 110 of the Data Protection Act 2018, over non-consensual sexualised images generated using the Grok AI on the X platform. It is an investigation into whether the GDPR was breached, not a ruling that it was.

The Leveraged Years AI Regulation News

Ireland's Data Protection Commission is the most consequential privacy regulator in Europe for one structural reason. Most of the largest US technology companies run their EU operations out of Dublin, which makes the DPC their lead supervisory authority under the GDPR one-stop-shop. When the DPC opens an inquiry, it is not a local matter. It reaches every EU and EEA user of the service. On February 17, 2026, the DPC did exactly that to X.

In its own words, the DPC "has today announced that it has opened an inquiry into X Internet Unlimited Company (XIUC) under section 110 of the Data Protection Act 2018." Section 110 matters because it is the own-volition power. The regulator does not need a complaint to act. It can commence an inquiry on its own initiative when it decides the public interest calls for it, and here it did.

What is the inquiry actually about?

Not model training. This inquiry is about output. The DPC says it concerns "the apparent creation, and publication on the X platform, of potentially harmful, non-consensual intimate and/or sexualised images, containing or otherwise involving the processing of personal data of EU/EEA data subjects, including children, using generative artificial intelligence functionality associated with the Grok large language model within the X platform." In plainer terms, the concern is that users could prompt the Grok feature to generate sexualised images of real people, and that this processed those people's personal data unlawfully.

Deputy Commissioner Graham Doyle framed the scope directly. He said the DPC "has been engaging with XIUC since media reports first emerged a number of weeks ago concerning the alleged ability of X users to prompt the @Grok account on X to generate sexualised images of real people, including children," and that "as the Lead Supervisory Authority for XIUC across the EU/EEA, the DPC has commenced a large-scale inquiry which will examine XIUC's compliance with some of their fundamental obligations under the GDPR."

Which GDPR duties are in play?

The DPC named four. The inquiry will look at Article 5, the core principles of processing; Article 6, the lawfulness of processing; Article 25, data protection by design and by default; and Article 35, the requirement to carry out a data protection impact assessment. That combination is worth reading closely. Article 25 and Article 35 are not about a single bad output. They are about whether the company built and assessed the feature responsibly before it shipped. A regulator invoking design-by-default and DPIA duties is signalling that it will ask what safeguards existed at the design stage, not just whether harmful images appeared.

What does this mean for US companies?

Even though this is an Irish inquiry into X, the operational lesson is general and it lands on any US company shipping generative image or avatar features into the EU. First, a lead EU regulator now treats AI-generated images of identifiable people as personal-data processing that has to have a lawful basis and a design story behind it. If your product lets users generate images of real people, you should be able to show your Article 6 basis, your Article 25 safeguards, and your Article 35 impact assessment on demand. Second, the DPC can act on its own volition, so the absence of a complaint is not protection. Third, this is still an inquiry. Nothing has been decided, no penalty has issued, and it would be wrong to describe X as having been found in breach. The correct read is that the design and safeguards around user-prompted AI image generation are now squarely a GDPR enforcement question in Europe, and the time to have your documentation in order is before a regulator asks for it.

Questions professionals are asking

Has the DPC found that X broke the GDPR?

No. The DPC has opened an inquiry, which is an investigation into whether X complied with its GDPR obligations. It is not a finding of infringement and not a penalty. Any decision would come only at the end of the statutory process.

Is this inquiry about training Grok on user posts?

No. This February 17, 2026 inquiry is about output, specifically the creation and publication of non-consensual intimate or sexualised images of real people, including children, using the Grok generative-AI feature on X. It is distinct from questions about training data.

Why can the Irish regulator investigate an EU-wide service?

Because X's EU entity, XIUC, is based in Ireland, the DPC is its Lead Supervisory Authority under the GDPR one-stop-shop. It also used its own-volition power under section 110 of the Data Protection Act 2018, so it did not need a complaint to act.

What should US companies with image-generation features take from this?

Treat AI-generated images of identifiable people as personal-data processing under the GDPR. Be able to show your lawful basis under Article 6, your data-protection-by-design safeguards under Article 25, and a completed impact assessment under Article 35. A lead EU regulator can open an inquiry on its own initiative, so waiting for a complaint is not a safe strategy.

RELATED BRIEFINGS

Browse the full AI Regulation News tracker

Informational analysis for working professionals, not legal advice. Confirm how any inquiry or GDPR obligation applies to your situation with qualified counsel in the relevant jurisdiction.