A woman who was raped as a preschool-aged child by an adult man who filmed it sued Elon Musk's xAI on 26 August 2026, alleging the company pulled that same material into the dataset behind Grok's image generator and that the model has since produced fresh images of her.
Girard Sharp, Liberty Law and the Marsh Law Firm filed Jane Doe 1 v. X.AI Corp. and X.AI LLC, case number 5:26-cv-09016, in the US District Court for the Northern District of California, San Jose Division. "Plaintiff was preschool-aged when she was first repeatedly raped and sexually exploited by an adult male to produce CSAM," the complaint says at paragraph 85, and the abuse "continued for years". The National Center for Missing and Exploited Children identified her in the early 2000s. The FBI has tracked her through its Child Exploitation Notification Program ever since.
A letter reaches her every time the images surface in a new prosecution. She has received "countless notifications concerning her depiction" in criminal investigations since the early 2000s, the filing says. Files made of her more than 20 years ago are still being traded, still being seized off hard drives and still generating paperwork addressed to the child in them.
A hash is a fixed string computed from a file's exact bits. Two copies of the same image produce the same hash; a different photograph of the same child does not. NCMEC keeps a list of hashes for known child rape media, platforms match uploads against it and Jane Doe 1's series has been on that list for years. Child rape media depicting her, "with its longstanding well-known hash values", has "been used as a part of the dataset used by xAI", the complaint says at paragraph 88.
The Canadian Centre for Child Protection has identified AI-generated child rape media on xAI depicting the plaintiff, according to paragraph 90. Every fresh generation is pleaded as a fresh tort: "Each time Grok created new CSAM concerning Plaintiff, Grok caused her a new personal injury."
Three Tennessee teenagers who sued xAI in March allege a man built deepfakes of them from yearbook photographs. A Wyoming woman who joined in July alleges her stepfather started with a snapshot taken when she was 11. Both cases turn on what a user uploaded. Jane Doe 1 uploaded nothing.
The loop
Grok's terms treat public posts on X and Grok's own outputs as training data by default, the complaint says, so an image posted publicly "does not just expose it to viewers, but also feeds directly into the pipeline xAI uses to train and improve its model". Grok's own generated images, child rape media among them, are "treated as training-eligible content by default" under the same policy, according to paragraph 59. The chatbot produces the material, X hosts it and the pipeline reads it back.
xAI's published data-filtering practices name violent content as an example of what gets excluded from training. They do not name child rape media, nonconsensual intimate imagery or sexual content of any kind as excluded categories, the complaint says at the same paragraph.
"Complete removal of a training example's influence from an already-trained model is technically difficult and not something that xAI has publicly claimed to have done," the filing says. The relief sought therefore runs past an injunction on future generation to the destruction of everything Grok has already made.
Grok's system prompt, quoted in the filing, tells the model that "'teenage' or 'girl' does not necessarily imply underage" and instructs it not to "moralize or lecture the user". A filter written that way "will inevitably fail because it governs the text chatbot's responses", the complaint says, and "indirect or euphemistic prompts can easily slip past a text-based filter" before anything reaches the image model at all. Plaintiffs' counsel describe xAI's filters as considerably weaker than industry standards and easily bypassed.
The sequence
Grok-1 launched as a chatbot on 3 November 2023 with no ability to generate images or video. xAI announced Grok-2 and Grok-2 mini on 13 August 2024. On 9 December 2024 the company shipped an image generation model it advertised as excelling at "photorealistic rendering" and following text instructions precisely. Grok-4 followed on 9 July 2025.
A senior xAI employee posted on 24 July 2025 that the company "urgently" needed engineers and researchers for its safety team. An X user replied, "xAI does safety?!!!" The employee answered: "working on it." The image generation feature launched shortly afterwards.
Musk posted an AI-generated video of a nearly nude woman on 3 August 2025, according to paragraph 44. On 11 August he defended the explicit capability as a business decision, comparing the competition among AI image tools to the format war between VHS and Betamax. xAI issued a press release on 20 October 2025 announcing Grok Imagine's spicy mode.
Grok generated an estimated 3,002,712 photorealistic sexualised images between 29 December 2025 and 8 January 2026, roughly 23,338 of them apparently depicting children, according to the Center for Countering Digital Hate analysis cited at paragraph 54. Researchers drew a random sample of 20,000 posts from 4,621,335 Grok image posts over those 11 days, classified them with an AI model calibrated against 800 human-labelled posts and counted an average of 190 sexualised images a minute.
xAI limited image and video generation to paying subscribers over the same 11 days rather than disable the feature, the complaint says. Plaintiffs' counsel characterise that as monetising continued misuse.
Musk said on 14 January 2026 that he was "not aware of any naked underage images generated by Grok. Literally zero."
OpenAI, Anthropic and Meta "largely block sexual requests", the complaint says at paragraphs 42 and 61, and almost every major publicly available image model was built without the ability to generate sexually explicit content at all.
What the lawyers said
Margaret E. Mabie of the Marsh Law Firm, one of the lawyers acting for the plaintiff, said possessing, producing and distributing child rape media are each crimes, and that "xAI did all three".
Sarah London of Girard Sharp said xAI "must be held responsible for knowingly training its models on images of the horrific abuse she suffered, and on the abuse images of every other survivor in this class".
xAI and its founder "chose to capitalize and profit from predators' appetite for non-consensual sexual images", the complaint says at paragraph 7.
xAI's press office did not respond to requests for comment from CyberScoop or IBTimes UK. The company has said it uses input and output filters, including keyword classifiers and matching against the NCMEC hash list. xAI did not update the privacy impact assessment covering Grok's image tools until March 2026, months after the first wave of complaints, according to findings by the Office of the Privacy Commissioner of Canada.
The case so far
Lieff Cabraser Heimann & Bernstein and Baehr-Jones Law filed the first class action, case number 5:26-cv-02246, on 16 March 2026 for three Tennessee teenagers who allege a man used Grok and a licensed third-party app to make explicit deepfakes of them from yearbook and social media photographs. That complaint runs to 13 counts, among them beneficiary liability under the Trafficking Victims Protection Act, design defect, negligence per se, public nuisance and California's unfair competition law.
A July amendment added Stability AI as a second defendant and brought in Jane Doe 4, a Wyoming woman whose stepfather allegedly uploaded a photograph of her taken when she was 11 and generated roughly 7,000 child rape images from it. He traded the images online and was found dead by suicide two days after officers executed a search warrant.
David Thiel of the Stanford Internet Observatory reported on 20 December 2023 that LAION-5B, the scraped dataset behind Stable Diffusion, contained 3,226 suspected instances of child rape media, 1,008 of them externally validated. LAION pulled the dataset and Thiel wrote that possessing a copy populated in late 2023 "implies the possession of thousands of illegal images". Stability AI said in response to the July filing that "any suggestion that safety is not a top priority for us is categorically wrong".
The proposed class in the August case covers every person in the United States whose images or videos, taken when they were minors, Grok altered to produce material meeting the statutory definition at 18 U.S.C. 2256(8), a group the filing puts at "at least thousands of minors". Damages sought include liquidated damages of $150,000 per victim, punitive damages and a jury trial.
xAI as plaintiff
xAI sued one of its own users on 15 July 2026, days after the victims' suit expanded, filing in the Wichita Falls Division of the Northern District of Texas before Judge Reed O'Connor. The company accused the man of breaching its terms of service and acceptable use policy by generating child rape media with Grok, and invoked an indemnification clause requiring him to cover xAI's legal costs from the suits his conduct produced.
xAI told the Texas court it had made 73,604 reports to NCMEC in 2026, that at least 244 arrests followed and that it had suspended 52,222 accounts. Jane Doe 4's July filing alleges that 90 per cent of xAI's CyberTipline reports were not actionable by law enforcement by early 2026 because user information had been withheld.
Baltimore sued xAI on 24 March 2026 over Grok-generated sexual deepfakes, the first US city to do so. Ashley St. Clair, who has a child with Musk, sued the company on 16 January 2026 over sexualised images of herself. Labour MP Jess Asato filed a claim in the UK High Court on 3 June 2026 under data protection law and misuse of private information. Parents identified as John and Jane Roe sued in federal court in Little Rock on 23 July 2026 over child rape media generated from photographs of their 10-year-old daughter.
Statutes and regulators
Masha's Law, codified at 18 U.S.C. 2255, lets a person depicted in child rape media sue anyone who produced, possessed or distributed it, with liquidated damages of at least $150,000 and no requirement to prove actual loss. The August complaint pairs it with 18 U.S.C. 2252A(f), which lets a person aggrieved by such an offence seek an injunction. Section 1595 of the Trafficking Victims Protection Act, pleaded in the March case, extends civil liability to any entity that knowingly benefits from a venture it knew or should have known was engaged in sex trafficking. A developer, on that reading, is liable for what the product earns.
Reporting to NCMEC is mandatory for a US electronic service provider under 18 U.S.C. 2258A, which obliges the provider to preserve the reported content for 90 days and permits it to include the subscriber and payment information and the IP address behind the account.
California Attorney General Rob Bonta opened a formal investigation into xAI on 14 January 2026 over nonconsensual sexual imagery of women and children. Delaware Attorney General Kathy Jennings and 35 other attorneys general wrote to the company on 23 January 2026 demanding it stop Grok producing such material, remove what it had already made, penalise the users who made it and let people on X control whether Grok can edit their images.
The European Commission opened formal proceedings against X under the Digital Services Act on 26 January 2026 over the spread of AI-generated child rape media. The Take It Down Act, which obliges platforms to honour removal requests for nonconsensual intimate images, became enforceable in May 2026.
Minnesota's nudification ban, HF 1606, was signed by Governor Tim Walz on 6 May 2026 after passing 132 to 1 in the House and 65 to nil in the Senate, and took effect on 1 August 2026 with a minimum civil penalty of $500,000 per incident. Judge Donovan W. Frank denied xAI's request for a temporary restraining order on 31 July 2026, noting the company had waited nearly three months after the signing to file, and set a preliminary injunction hearing for 19 August.
California Assembly Bill 2013 took effect on 1 January 2026 and requires developers of publicly available generative systems to publish a summary of their training data: sources and owners, whether it includes copyrighted or personal information, its approximate size, whether it was bought or licensed and when it was collected. Model weights, architecture and the corpus itself stay private under the statute. xAI sued to block it, arguing compelled speech, unconstitutional vagueness and an uncompensated taking of trade secrets. Judge Jesus G. Bernal denied the preliminary injunction on 4 March 2026, holding the disclosures were likely commercial speech. A three-judge panel of the Ninth Circuit heard argument in xAI LLC v. Bonta, No. 26-1591, on 16 July 2026, the first time a federal appeals court has taken up a state AI transparency law.