Regulatory Impact
Between December 2025 and February 2026, xAI's Grok chatbot generated non-consensual sexually explicit deepfakes of public figures and private individuals, triggering a coordinated regulatory response across the EU.
The crisis informed new Article 5 provisions concerning AI practices that generate non-consensual sexual or intimate content or child sexual abuse material. Regulation (EU) 2026/1744 is in force, and these provisions apply from 2 December 2026.

Timeline of Events
The crisis unfolded in three phases. In December 2025, users discovered that xAI's Grok chatbot could generate sexually explicit images of real, identifiable individuals without consent. The capabilities were rapidly exploited at scale, targeting both public figures and private citizens. Unlike previous deepfake incidents, the Grok system's ease of use and wide availability through X (formerly Twitter) made mass generation trivially accessible.
In January and February 2026, the regulatory response intensified. French prosecutors raided X's Paris offices on 3 February 2026. Spain ordered investigations into X, Meta, and TikTok for AI-generated CSAM distribution. On 16 February 2026, Ireland's Data Protection Commission opened a formal EU-wide privacy investigation into xAI under GDPR cross-border enforcement mechanisms. On 17 February, the European Parliament disabled all built-in AI features on lawmakers' devices, citing security and integrity risks.
Simultaneously, the political response crystallized. By 7 May 2026, Council and Parliament negotiators had included a prohibition on AI practices generating non-consensual sexual or intimate content or child sexual abuse material in the Digital Omnibus text, which at that point was pending Official Journal publication.
The Enacted Intimate-Image Provisions
Regulation (EU) 2026/1744 has since added Article 5 provisions concerning specified non-consensual sexual or intimate content and child sexual abuse material. They apply from 2 December 2026 and sit alongside the eight original prohibitions covering subliminal manipulation, exploitation of vulnerable groups, social scoring, predictive policing, facial recognition scraping, workplace emotion recognition, biometric categorization, and real-time remote biometric identification.
Regulation (EU) 2026/1744 is in force, and the new provisions apply from 2 December 2026. Applying their exact scope to a system still requires careful legal and technical analysis; this page does not make that determination.
Regulation (EU) 2026/1744 was published on 24 July 2026 and entered into force on 27 July 2026. The new provisions apply from 2 December 2026; use the consolidated AI Act for their exact scope and exceptions.
Existing Legal Framework
The Grok crisis exposed a gap in the original Article 5 prohibited-practices list. While the existing prohibitions cover social scoring, manipulative techniques, and certain biometric uses, they do not explicitly address non-consensual intimate image generation. The deepfake labelling requirement under Article 50(4) addresses disclosure obligations but does not prohibit the generation itself.
GDPR provides a complementary enforcement vector. The DPC's investigation focuses on the processing of personal data (biometric data derived from publicly available images) without lawful basis. This is the route most likely to produce near-term enforcement outcomes, as GDPR mechanisms are well-established and the DPC has cross-border enforcement powers.

Implications for Your Organization
If you operate image generation AI: Audit your system's safeguards against generating non-consensual intimate imagery. Before and after the new provisions apply, deploying such capabilities carries extreme reputational and legal risk under existing GDPR, national criminal law, and the AI Act's manipulation provisions.
If you deploy AI content generation more broadly: The crisis has accelerated Article 50 enforcement urgency. Content marking, watermarking, and provenance tracking are route-specific controls under Article 50, which generally applied from 2 August 2026. See our Article 50 Code of Practice analysis for the specific technical requirements.
If you are monitoring Article 5 compliance: Review our complete breakdown of all eight original prohibitions plus the new 2026 provisions. Use the 12-question Compliance Checker to verify your AI portfolio against these boundaries.
About the author: Abhishek G Sharma is the founder of Move78 International Limited. He holds ISO 42001 Lead Auditor, CISA, CISM, CRISC, and CEH certifications. He brings over 20 years of practitioner experience in cybersecurity, AI governance, and enterprise risk management.
Disclaimer: This analysis was published in March 2026, before Regulation (EU) 2026/1744 entered into force. The new intimate-content provisions apply from 2 December 2026. This page is educational only; consult qualified legal counsel for binding decisions.