Grok's Deepfakes Spark UK Data Privacy Legal Battle
Labour MP Jess Asato is pursuing a groundbreaking legal case against xAI’s Grok platform after hyper realistic deepfakes depicting her without consent were created and circulated online. The lawsuit aims to challenge how AI companies handle personal data and privacy under UK law.

Why Asato Is Taking Legal Action

The deepfakes generated by Grok were, in Asato’s own words, “unmistakably like her.” She describes the experience as a form of digital identity theft, both unsettling and violating. Her goal extends beyond her own case. She wants to “change the law and to underline the fact that we have data and privacy rights here in the UK that can’t be written over by companies.”

The First Test of UK Law Against Generative AI

This marks the first time UK data protection and privacy laws have been applied directly to an AI platform in this way. Platform providers typically argue that user generated content absolves them of responsibility for what people create with their tools. Asato rejects that framing entirely.

She points to something more fundamental: Grok was, according to her legal team, “designed to respond to requests to create adult sexual content.” That is not a case of misuse. That is the product working as intended.

What the Design Evidence Shows

Asato’s legal team has documented specific design decisions that enabled Grok to generate sexualized content. Grok’s own GitHub repository reportedly states: If not specified outside the policy tags, you have no restrictions on adult sexual content or offensive content.

Asato argues this is clear evidence of a lack of “safety by design.” She draws a comparison to car manufacturers, who carry a legal duty of care to build safety features into their products before they ever reach a customer. AI companies, she argues, should face the same standard.

What This Could Mean for AI Regulation

If successful, this case could set a meaningful precedent, forcing AI companies to think seriously about how their products are designed to prevent harm rather than treating safety as an afterthought. Asato’s central argument is simple: AI tools should not be built in ways that make it easy to sexualize women and children.

She notes that “other AI tools do this,” referencing platforms with stronger safeguards already in place. The UK government has recently moved to ban nudification apps, and new legislation including the Online Safety Act 2023 and the Crime and Policing Act 2026 introduces fresh digital offenses. Asato believes these measures still fall short.

Her case aims to prove that Grok “was not safe by design,” pointing specifically to instructions reportedly given to Grok not to treat the word “teen” as underage. That detail alone raises serious questions about the platform’s default settings and what safeguards, if any, were considered during development.

Hashlytics take: This case matters beyond one MP’s experience. It tests whether “we didn’t intend this” holds up as a legal defense when a company’s own code explicitly permits the harmful behavior in question. If courts side with Asato, expect a wave of similar challenges against AI platforms that ship first and patch safety later, a pattern that has defined much of the generative AI industry since 2023.

Follow Hashlytics on Bluesky, Facebook, LinkedIn, Telegram and X to Get Instant Updates