180 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
10 new this week Library last updated 30 August 2026
← The incident library
HD-INC-166
Social media · United States · 2026 · Sexualised imagery of real people generated on request

Grok generated sexualised images of real people from ordinary photos posted on X, and four regulators opened proceedings after an outside watchdog measured the scale

By Ellie Harris · Filed Reported May 2025; escalation measured over 29 December 2025 to 8 January 2026

Alleged: X Corp and xAI developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

Grok generated sexualised images of real people from ordinary photos posted on X, and four regulators opened proceedings after an outside watchdog measured the scale

What happened

It was reported in May 2025 that a user could reply to a photograph posted on X, ask the Grok account to remove the subject’s clothes, and get an altered image back in the same public thread. In August 2025 two outlets reported that the tool also produced sexualised video of women from prompts that had not asked for it, while the same prompts applied to men produced only shirtless output.

A watchdog published research in January 2026 estimating, from a sample of 20,000 image-containing posts drawn from 4,621,335 made by the account over eleven days, that around 3 million sexualised images had been produced, including tens of thousands appearing to depict children. X restricted image generation to paying subscribers and said it had added technical measures, though the Associated Press reported the same day that the function was still reachable from a free account. Four regulators opened proceedings or imposed blocks, and the sources reviewed did not identify a final contravention finding.

What an auditable version would have shown

Journalists publicly demonstrated the reported behaviour in May and August 2025. Eight months later an outside organisation estimated its scale by sampling publicly visible posts. No figure for how many images were produced, how many were checked, or how many were refused was identified in the sources reviewed.

A record written for each generation would say what was requested, what image it was applied to, what classification ran before the output was published and what that check returned. Aggregated, those records answer how many requests of this kind arrived and how many were refused. That is a number the operator can state, rather than one a watchdog has to estimate from a sample of public posts.

Where the gap was

It was reported that the feature accepted a request naming another user’s photograph and published its output into the same public thread. A ConstraintGate is designed to test a standing rule before the action runs, so a request to alter an image of a real person into revealing clothing is refused at the point of generation rather than removed after it is posted. An EgressGate classifies what an output contains and tests the destination before it crosses the boundary, which in this case was a public timeline. A ConductRecord preserves the request, the source image reference, the checks that ran and the output. None of these decides what a platform should permit, and none removes material already distributed. What they change is that the volume and the refusal rate become facts the operator holds.

What governance should have looked like

X said it had implemented technical measures and restricted access to paying subscribers. The Associated Press reported that the editing function remained reachable from a free account on the day those measures were described. The sources reviewed do not resolve that difference.

Where an organisation lets users direct a generative model at an image of another person, best practice would be to classify the request and the output before publication rather than after a report, to record what was checked and what the check returned, and to publish the resulting counts so that scale is not left to be estimated from outside. The regulatory matters described above are open and untested, and this entry will need revisiting as they are decided.

Failure Pattern: a generative feature wired into a public reply thread produced sexualised images of real people on request, the behaviour was demonstrated publicly by journalists eight months before it was measured at scale, and the scale was established by an outside watchdog sampling public posts rather than by any figure the operator published.

Governance Principle: an organisation that lets users direct a generative model at an image of a real person should be able to show what was requested, what was produced, what check ran before publication and what the check returned.

The reference implementation of ConstraintGate, EgressGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and X Corp and xAI could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

Last reviewed August 2026. This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →