UK regulators have widened scrutiny of Elon Musk’s X and its Grok chatbot, with Ofcom saying it is continuing an investigation and the Information Commissioner’s Office opening a separate probe, BBC News reported on February 3.
The two regulators are responding to complaints over sexual deepfakes and the possible misuse of personal data. BBC said the images, often made from real photos of women without consent, triggered criticism from victims, online safety campaigners and politicians before the platform moved to stop the practice.
Ofcom said it was treating the matter as urgent, but also said it lacked sufficient powers to investigate the creation of illegal images by a chatbot in this specific case. That limitation is important: it shows that regulatory concern is not the same as regulatory reach, and that existing frameworks may not yet fit the speed and shape of generative AI abuse.
The ICO’s move fills part of that gap. William Malcolm, the regulator’s executive director for regulatory risk and innovation, said the reports raised troubling questions about how personal data was used to generate intimate or sexualized images without consent and whether proper safeguards were in place. In practical terms, that means the ICO is now looking at data processing, not just platform behavior.
The BBC report also places the UK action beside a French investigation into X. French prosecutors raided the company’s offices in Paris as part of a separate cybercrime probe, and the report said the case could involve unlawful data extraction and complicity in possessing child sexual abuse material. Those allegations are separate, but together they show how aggressively European authorities are moving on Musk’s platforms.
The deeper issue is not one website or one chatbot. It is whether existing digital regulation can keep pace with AI tools that can generate sexualized images from ordinary personal data or public photos. The UK response suggests regulators now see that as a live enforcement problem, not a hypothetical future one.
For users, the outcome will likely hinge on how quickly platforms can detect misuse, how much user data is available to model operators and whether the law can assign responsibility before harm spreads. The latest UK probes suggest the answer is still being written.
The case is also a test of how much pressure regulators can apply to a company whose products span social media, data, advertising and AI. The BBC report shows that the UK is no longer treating the issue as a simple content moderation problem.



