A class-action lawsuit against xAI has been expanded with two additional anonymous plaintiffs, including a minor, who allege the company’s Grok tool was used to generate nonconsensual deepfake child sexual abuse material from their real images. The amended complaint says perpetrators chose Grok because it was less restrictive, and in one case allegedly used it to create more than 7,000 illicit images of an 11-year-old girl that were later distributed online. Plaintiffs say the spread of the generated material caused severe emotional distress, humiliation, and ongoing anxiety.
The lawsuit also adds Stability AI as a defendant, alleging its Stable Diffusion models were trained on explicit web-scraped data, including CSAM, and released without adequate safeguards to prevent downstream abuse. The complaint further alleges that protections could be bypassed through jailbroken or modified versions of the models and that xAI failed to provide law enforcement with generated-image evidence and IP address information after reporting only the original image to NCMEC. xAI and Stability AI did not respond to requests for comment, according to the reports.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The expanded lawsuit also names Stability AI as a defendant, alleging its Stable Diffusion models were trained on explicit web-scraped data including CSAM and released without adequate safeguards. Plaintiffs allege downstream developers could bypass or weaken protections, enabling abusive modified applications.
A class-action lawsuit against xAI over its Grok tool was amended to add two new anonymous plaintiffs, including a minor, who allege Grok was used to create nonconsensual deepfake child sexual abuse material from their real images. The amended complaint alleges one perpetrator created more than 7,000 CSAM-related images of an 11-year-old girl using Grok.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.