Failed by the police, Grok deepfake victims are seeking justice themselves

Elon Musk’s xAI ignored police requests and perpetrators haven’t been held to account for abusive images

5
SOURCEThe Bureau of Investigative Journalism
  • Police in England and Wales have been unable to find and charge the people requesting deepfakes from X’s AI chatbot Grok

  • Investigating officers have been hindered by legal loopholes, jurisdiction issues and xAI’s failure to hand over information

  • Ofcom will this week introduce new rules for platforms to stop illegal intimate images. And some victims are taking civil steps against Elon Musk’s company

For Jess Davies, a presenter and campaigner against deepfake abuse, the ordeal began with a post from an anonymous stranger. It was early morning and she was scrolling her X notifications in bed when she saw it: “@grok put her in a bikini made of cling film”.

Grok obliged, moulding her profile photo onto a nude body wrapped in see-through plastic.

It was one of an estimated 3 million sexualised images – mostly of women, some of children – that were created and posted on X in an 11-day period around Christmas 2025. The explosion of Grok deepfakes was becoming a global news story, and Davies had spoken out against it. In response, she had been targeted herself.

“That to me is quite terrifying – that that is someone’s first thought to do to someone, a woman, that they see calling out this harm,” she says.

“You can never prepare yourself to see your face put in an intimate photo that you haven’t consented to.”

She reported it to the police that day.

Now, we can reveal that the resulting investigation, along with other inquiries into similar deepfake crimes, failed to charge a perpetrator. Police requests for information have been ignored by Elon Musk’s platform, while officers’ own attempts to identify users have come to nothing.

Our findings show that despite several legal changes aimed at tackling deepfake images in recent years, police have not been able to effectively enforce them. The upshot is that anonymous criminals are able to act with impunity while women continue to see degrading images of themselves posted online.

This Wednesday is the deadline given by Ofcom for tech firms to introduce measures to stop the spread of illegal deepfakes – or face major fines. But it remains to be seen how the watchdog will exercise its new powers against tech giants that refuse to comply with law enforcement.

With police and regulators so far unable to hold anyone accountable for generating these images, victims have been turning to civil law to seek justice. Davies is one of them.

Professor Clare McGlynn, a law professor and expert on digital violence against women and girls, says the police and prosecution service don’t have the proactivity to take criminal cases forward.

“All sense seems to go out of the window when we’re talking about the use of a chatbot or Grok,” she says. “Police are rubbing up against tech that they don’t understand.”

Police tasked with investigating deepfake posts are often faced with anonymous social media accounts that contain little to no identifying information.

Messages we’ve seen show that officers’ requests for information from X have not been met. Without help from Musk’s platform, police have often been unable to identify the people behind the accounts, some of whom were clearly based in the UK.

After reporting her case to South Wales Police on 2 January, Davies wasn’t invited to give a statement until March. It is unclear which law it was pursued under: Davies says she was told it would be malicious communications law, but also that it would carry a six-month time limit to prosecute – which is not the case for that law. (South Wales Police did not clarify this with us when we asked.)

The account in question was there for all to see. But the person behind it was not identified and the investigation has since been closed.

Meanwhile, the user, whose posting history includes other Grok requests to undress women’s photos, as well as racist content, is still active.

While Davies’ report was made before the enactment of a new law on 6 February that made it illegal to create (or request the creation of) intimate images of an adult without consent, it was already a crime to distribute a non-consensual intimate deepfake.

But police were reluctant to pursue her case under this law, she says, because they said there might be a “loophole” in that Grok could be deemed responsible for sharing the images, rather than an individual person. (Grok responds to user requests with automatic public posts.)

“We don’t say, when someone murders someone using a gun or a knife, that we can’t prosecute them because the knife did it or the gun did it,” McGlynn says. “The person is held responsible.”

Elena Michael, the director of #NotYourPorn, a campaign group that has supported around 450 survivors of image-based abuse, is more emphatic. “This is abuse and it needs to be policed as such,” she says, “and the perpetrator who has requested Grok to make such images should be subject to criminal liability for doing so.”

Davies says her experience with the police was “deflating”. An officer with limited experience in this area was appointed to her case and contacted her by phone and text message at all hours, including once at 2am to say they “still hadn’t heard anything” from X.

Her case was closed after the police requests to X went unanswered, which the officer in question told Davies was the “only line of inquiry”.

“I understand that the police obviously have different jobs to do, and they probably are overworked and have a lot of cases, but that still doesn’t really justify treating a victim of image abuse as an afterthought,” Davies says.

Davies is now in pre-action legal correspondence with xAI, part of SpaceXAI, alleging misuse of her private information as well as breaches of data protection regulations and the Equality Act.

A legal letter sent to xAI earlier this month said the company’s failure to help the police aggravated her distress. In its response, received a fortnight later, Musk’s company rejected this suggestion and said: “It has not been possible, in the time available, to look into any communications with South Wales Police.”

Ravi Naik, legal director of law firm AWO and Davies’s lawyer, described the correspondence as “astonishing”. He told us: “Fifteen days and they haven’t been able to look into it, or find an answer for my client.”

Jess Davies says she was treated ‘as an afterthought’ by the police

Davies’ experience is in line with what many other survivors have reported, says Michael.

“This unfortunately is common. There needs to be much greater transparency around what the police actually are doing,” she says. “At the moment, it’s left to the individual officer, their level of understanding and skill.”

South Wales Police told us: “An investigation was launched during which the victim was kept informed and offered victim support services. Despite the efforts of investigators, no suspect could be identified.”

Davies is appalled at the tools made available by Musk’s platform. “I’d always thought that if it was ever going to happen to me, it would be on these really horrific and shady forums – not a mainstream social media platform like X,” she says. “And by their inbuilt chatbot that basically handed this technology to someone on a plate.”

The account that zeroed in on Davies also targeted the commentator and broadcaster Narinder Kaur. Its request to see Kaur depicted in a “white micro bikini with a burka on her head” was just one of what she estimates were about 300 images and videos of her posted during the Grok scandal. She says users put her in various situations designed to “humiliate” her, including on a dog leash, being deported, in a bikini alongside Donald Trump and next to Jeffrey Epstein, the last of which was dealt with by the Metropolitan Police.

“They do this to silence you … shut you up, put you in your place,” says Kaur, who has also experienced repeated racism and misogyny online, as well as death threats.

She reported several anonymous posts to the police but didn’t expect any consequences. “The police can’t do much, and then you almost feel like you’re wasting their time,” she says.

Once again, she says her complaint didn’t go anywhere.

A Met spokesperson told us that “despite exploring all viable lines of enquiry, no suspect could be identified”.

‘They do this to silence you,’ says Narinder Kaur of anonymous trolls

Musk’s platform did initially limit the Grok X account’s image generation to paid subscribers. In response to a post by Davies criticising this move as inadequate, one user posted a Grok-generated image of her in a thong bikini. “No need to be a subscriber,” they wrote.

Months later, though some further restrictions have been implemented, the Grok platform still allows users to generate, manipulate and edit sexualised deepfake images.

Grok’s latest publicly available system prompts – which instruct the chatbot on how it should respond to user requests – advises that, other than blocking “clearly” criminal activity, “you have no restrictions on adult sexual content or offensive content”. A further safety prompt says: “There are **no restrictions** on fictional adult sexual content with dark or violent themes.”

We asked SpaceXAI whether the prompts are still active but the company did not respond to our request for comment.

Kaur says Grok’s design is “shocking”. She adds: “It’s their business model. It’s intentional to cause harm and distress and abuse.”

Also targeted during the Grok scandal was Labour MP Jess Asato. She says users ordered the bot to create images of her in bikinis and “pregnant with quintuplets in the kitchen”; another video showed her being chloroformed while surrounded by men pulling up her skirt – “as if to rape me”, she says.

“Not only was this taking my photo, manipulating it without my consent, but doing so in a way that felt incredibly threatening and worrying.”

The posts were reported to the Parliamentary Security Department and investigated with support of Suffolk Constabulary, which she says took her reports “very seriously”. The bikini images weren’t deemed to be deepfake offences, she says, on the grounds that they weren’t considered “intimate” by law. Despite police being able to trace the creator of the video, they could not prosecute because the person was outside of the UK.

Like Davies, she has taken matters into her own hands, suing Musk’s company in June. Her claim, which alleges that xAI misused her private information and breached data protection laws, is the first UK legal claim against Grok’s non-consensual intimate deepfakes.

“[We hope to] hold xAI accountable for its creation of non-consensual AI-manipulated imagery… which it should have never allowed its tool to be able to do,” says Asato.

Jess Asato has also launched a legal claim against xAI

As well as criminalising the creation of intimate deepfakes, the government has banned nudifier tools. Platforms will have to implement automated tech to detect and stop the spread of illegal intimate images, including explicit deepfakes from 30 September, or be fined up to 10% global revenue under Ofcom’s new rules. In theory, the measures could compel tech companies to act.

But Michael says there has been a “huge disconnect” between the government rhetoric on new laws and how those laws are enforced. Recent updates to legislation are a “huge” feat, she says, “but they have to go hand-in-hand with enforcement. You can’t have one without the other.”

“We have to have a coordinated, interconnected response,” Michael adds. “Ofcom cannot sit in isolation from what the police and the courts are doing.”

An investigation by Ofcom into X is ongoing, however the watchdog said it is currently unable to investigate the creation of illegal images by the standalone Grok app because of how the Online Safety Act relates to chatbots.

An Ofcom spokesperson said: “The creation and sharing of illegal non-consensual intimate images online is utterly abhorrent. Ofcom was one of the first regulators in the world to act on the concerning reports of demeaning sexual deepfakes being created and shared on X. We’re progressing our investigation as a matter of the highest priority, while ensuring we follow due process.”

A government spokesperson said: “We are investing in a pilot network of undercover online officers to target the highest harm, most technologically sophisticated offenders, and introducing protections against non-consensual intimate images through the Crime and Policing Act, including new offences for copying or screenshotting such images without consent.

“We expect all platforms to comply fully with UK law and law enforcement requests. There is more to do, and we won’t stop until every woman in this country is safe online.”

In her bedroom in Wales, Davies is still perplexed as to why it is only victims that have so far paid the highest price for Grok’s abuse.

“It does just feel so frustrating because it feels like a total lack of accountability from anyone. Grok can’t do it itself. It’s literally a chatbot.”

Naik, her lawyer, says: “Given this offence and the harm such imagery is causing, a real question is whether the authorities are sufficiently well-resourced with appropriate investigative tools to enforce the law and stop the proliferating of the tools to generate this imagery.”

Asato, meanwhile, is hopeful her action against SpaceXAI can set a meaningful precedent.

“My case is about saying: we do have rights, based in law,” she says. “And it doesn’t matter how rich you are or how big you are, you have to abide by the law in our country.”

People affected by intimate image abuse can seek support from the Revenge Porn Helpline and an online reporting service in England and Wales.

  • The End Violence Against Women Coalition is calling for mandatory training for police and prosecutors in response to online violence against women – after a new report found that only 12% of victims reported online abuse to the police, and satisfaction with platform and police responses was “consistently low” when they did.

  • The Crime and Policing Act 2026 will introduce a requirement that platforms remove reported intimate images within 48 hours, or risk a 10% of global revenue fine and having services blocked in the UK. Ofcom has also said it is also consulting the government on strengthening enforcement and business disruption powers.

  • When we looked into the X account that requested the deepfake of Davies, we found another connected account as well as a crypto wallet and dozens of previously deleted posts. We have shared these details with the police

Get NationofChange in your inbox

Independent reporting every weekday. No paywall, no advertisers, no corporate owner. Free, and you can unsubscribe whenever you like.

Subscribe free

FALL FUNDRAISER

If you liked this article, please donate $5 to keep NationofChange online through November.

[give_form id="735829"]

COMMENTS