posted in Technology

Elon Musk’s xAI used child porn to train Grok models, lawsuit says

For her safety, Doe has opted to receive alerts from the US Department of Justice Victim Notification System any time she may be a victim in a new criminal investigation. Although she has received countless alerts, she was shocked when the CCCP notified her that it had identified AI-generated CSAM on xAI that depicted her. This re-traumatized Doe, whose complaint alleged that messages were found on online forums “between offenders chatting about creating AI generated CSAM of Plaintiff and other similarly situated known, legacy, victims of CSAM.”

Now, Doe fears that xAI has not only made it easier to make more violative images of the most distressing time in her life, but also that xAI allegedly has stored the images that Grok generates and uses those outputs to further train Grok. Because of this, she believes that Grok has been trained on both the initial set of images that have haunted her for more than 20 years and the more recent AI-generated ones.

This is the first case to accuse xAI of training on CSAM, and the complaint does not go into great detail on that claim. Previously, Ars reported on a controversial dataset that was later scrubbed after researchers found CSAM in the training data, but there’s no indication xAI trained on that data. In a press release from lawyers representing Doe, it explained that Doe’s images were included in a CSAM Hash List maintained by NCMEC, and “that same material” allegedly “was part of the dataset xAI used to build Grok’s image and video generating capabilities.” The complaint similarly only alleged that “CSAM depicting Plaintiff with its longstanding well-known hash values has been used as a part of the dataset used by xAI.”

arstechnica.com/tech-policy/2026/08/elon-musks-xai-used-child-porn-to-train-grok-models-lawsuit-says/

Replying to @⁨Waterpumpee@lemmus.org⁩

In all seriousness, there are some very interesting legal questions that will be raised if this case makes it that far.

The problem is that there’s no existing law that would effect this on its own. To my knowledge, no country in the world has a law on the books specifically dealing with AI models trained on CSAM. So the question, under existing laws, would turn on whether the data stored within the model itself would constitute CSAM.

The problem, in no small part, is that we have serious gaps in our public consensus knowledge about how LLMs actually work.

There’s a case that, AFAIK, is still being argued in Germany pushing the theory that LLMs actually do, in effect, store a copy of all their training data, just in a compressed form. This certainly seems to hold some water given both the tests they relied on, and the situation with this Jane Doe where the model produced images so alike to real images of her that they tripped hash detections.

The German case argues that this is analogous to the difference between an MP3 and a WAV, or a JPEG and a PNG. That sharing a lossy copy of a work is no less infringing just because it’s imperfect.

If the underlying claim - that LLMs function as a form of lossy compression - can be substantiated then there would be a real argument that the model itself would constitute CSAM. Since there would be no realistic method that I’m aware of for removing the offending material from the model - and presumably SpaceX would have to somehow prove that they’ve done so - that would make the entire model contraband. They’d have to retrain on a clean dataset.

Of course I said “if the case makes it that far” at the top because I don’t think it will. SpaceX will do anything and everything to avoid handing over meaningful discovery in this case, including, I suspect, outright destruction of evidence. If there is anything that actually proves that they used CSAM in the training data then they are so far beyond fucked that there’s simply no downside to further illegality in pursuit of concealing their crimes. They have the world’s wealthiest asshole in a position to throw literal billions at making this go away. I genuinely wouldn’t be surprised if people turn up dead off the back of this if that’s what it takes.

Replying to @⁨scrubbles@poptalk.scrubbles.tech⁩

Was going to say basically say the same exact same thing. There is no law saying how AI is handled when using stollen materials or other “illegal” content.

But somehow we have all been brought to believe that somehow “new” technology isn’t subject to existing laws.

If x or any other company downloaded CSAM everyone in the company should be arrested.

Replying to @⁨Voroxpete@sh.itjust.works⁩

I won’t say everyone. I’ve actually been at a company who was investigated (not for CSAM, but other things that happened). I had no idea it even happened, and luckily was not involved with any of it. So for me no, I wouldn’t have wanted that. That being said 2 things, say I had been in the position. If our scraper was downloading it and it was my scraper, damn right I would have flagged it to legal, HR, and everyone I could have, along with writing some way to prevent it, and written everything down in a complete log (off company computer). If it wasn’t stopped immediately I would either quit, whistleblowed, or happily talked with anyone raiding and making sure any of the decision makers were hauled off. I don’t blame someone for being lowest level at a shit company, been there. (Although I will say, xAI, come on, no one is “stuck” there, but that doesn’t mean that Dave the brand new intern out of college should be hauled off). Who I blame are the suits who were probably told it was happening and chose to ignore it, and any engineer I do blame if they knew about it and chose not to do one of the above.

As an engineer I’ve had my fair share of let’s say… challenges that I’ve had to morally grapple with. Things I’ve been asked to do that may not be moral. However, there’s a pretty wide chasm between “Implement this dark pattern so people won’t unsubscribe” and “host this and don’t tell anyone”

en