
Canada Orders X Corp., xAI to Fix Grok Deepfake Safeguards
Regulator Orders Compliance After Deepfake Surge
Canada's Office of the Privacy Commissioner issued a binding compliance order against X Corp. and xAI on June 11, 2026, after determining that the companies violated federal privacy law by launching Grok's image-generation tool without valid user consent or appropriate safeguards against harm. The regulatory action, detailed in OPC Findings #2026-004, found that the chatbot enabled the creation of sexualized deepfakes at industrial scale between December 29, 2025, and January 8, 2026.
Privacy Commissioner Philippe Dufresne concluded that X Corp. and xAI had launched the tool "without proper safeguards or sufficient consideration of potential privacy harms, violating Canada's federal private-sector privacy law." The violation occurred under subsection 5(3) of the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's primary federal privacy statute governing private sector entities.
Scale of Harm and Investigation Timeline
During the eight-day window, Grok generated approximately 3 million sexualized deepfakes, with peaks exceeding 6,000 images per hour. Of those, roughly 23,000 depicted children, according to analysis cited by TechTimes. The OPC opened its investigation in January 2026 after the tool's rapid deployment without consent mechanisms or content-filtering guardrails.
The regulator found that "xAI violated Canada's federal private sector privacy law by launching the Grok AI-powered image generation tool without implementing appropriate safeguards from the outset," and that "this lack of protection allowed users to create and share sexualized deepfakes largely targeting women and children."
Binding Order—Not a Fine
No monetary fine was imposed. Instead, the OPC issued a compliance order requiring X Corp. and xAI to:
• Implement technical and procedural safeguards to prevent generation of non-consensual intimate imagery
• Submit quarterly compliance reports to the OPC
• Provide independent third-party audit reports of safeguard effectiveness
• Continue reporting "until the issue of sexualized deepfakes is fully resolved"
The OPC currently lacks statutory authority under PIPEDA to levy monetary penalties; proposed legislation (Bill C-34, introduced June 10, 2026) would grant a new federal privacy commission the power to impose fines up to $25 million, but the Grok case was decided under existing rules.
Concrete Impact on AI Agent Development
This action represents the first major regulatory enforcement against a deployed agentic system for enabling mass harm without consent. The compliance framework—requiring quarterly audits and ongoing disclosure—establishes a precedent for how regulators will monitor AI-generated content systems in jurisdictions with strong privacy statutes. X Corp. and xAI must now demonstrate measurable risk reduction or face potential escalation under future legislation.


