opinion
Open this photo in gallery:

A billboard organized by corporate accountability group Eko passes through Westminster in London in January, urging British Prime Minister Keir Starmer to stand up to Elon Musk and ban X and Grok.Maja Smiejkowska/Reuters

J.B. Branch is the director of Federal AI Governance and Technology Policy at Public Citizen.

The Office of the Privacy Commissioner of Canada delivered a remarkable rebuke to Elon Musk’s companies last month.

After investigating xAI and X, Privacy Commissioner Philippe Dufresne concluded in a report that Grok’s image-generation tools violated Canadian privacy law by enabling the creation and dissemination of non-consensual sexualized deepfakes. Despite months of promised improvements and new safeguards, the commissioner reached a conclusion that should concern every Canadian: He is still not satisfied the problem has been solved.

Canadians should not be, either.

xAI’s response has been familiar. It has promised better safeguards, committed to audits and reports, and says it is taking the issue seriously. Yet when the privacy commissioner recommended suspending Grok’s image-generation functions until the company could demonstrate the problem was truly under control, xAI refused. Canadians, therefore, are being asked to trust the company will fix things.

But trusting in a company with repeated failure of safety protocols is a poor regulatory strategy.

Meta to alert parents if teens discuss self-harm with AI chatbots

According to the report, Grok generated millions of sexualized deepfakes, some allegedly depicting children. The report found xAI and X failed to implement adequate safeguards from the outset, failed to identify key risks and did not obtain valid consent from people whose images were transformed into degrading sexual content.

These events were foreseeable. In fact, I’ve spent the better part of the year documenting all of the safety flaws in Grok including antisemitic outputs and propensity to generate conspiratorial-laden responses. And let’s not forget the surge of non-consensual deepfake imagery when the tool was first released in December, 2025. What’s more, Mr. Musk encouraged this type of behaviour himself, writing on X in February, 2025: “Post your best unhinged NSFW Grok posts to this thread!”

This is not a safety protocol lapse. It is a feature of Grok and it embodies the “spiciness” the company fosters. The pattern is familiar by now. When controversies erupt, apologies are issued. New safeguards are announced. Executives promise that lessons have been learned. Users are even blamed! Then another crisis emerges. Rinse. Repeat.

The issue confronting Canada, then, is much larger than Grok. It is whether Canadians are prepared to entrust the protection of their privacy and dignity to voluntary promises made by some of the world’s most powerful technology companies. But rights should not depend on Big Tech’s goodwill. Rights should be grounded in the rule of law.

The Editorial Board: Ottawa must move urgently to ban nude deepfakes

If anything, Canada should view this moment as a cautionary lesson from south of the border. The United States has struggled to enact comprehensive protections against deepfakes and has failed to enforce child protection laws against xAI. Canada now has an opportunity to chart a different course and demonstrate that technological innovation need not come at the expense of privacy, dignity and accountability.

That is why Parliament passed Bill C-16. The law criminalizes the sharing of non-consensual sexual deepfakes and strengthens protections against AI-generated child sexual-abuse material. This is an important and necessary step. Likewise, the newly introduced Safe Social Media Act, which would require platforms to remove sexually explicit content within 24 hours, reflects a growing recognition that platforms must bear responsibility for the harm they enable.

But this legislation alone will not resolve the problem. The Grok investigation has exposed the uncomfortable truth that Canada’s privacy watchdog lacks the powers needed to effectively enforce human rights. Mr. Dufresne has warned that pursuing companies through litigation is slow and expensive. He has repeatedly called for powers and penalties that would bring Canada in line with other Western democracies.

He is right.

Across Canada, the fight against artificial intelligence goes offline

In the era of artificial intelligence, a regulator that can only make recommendations is basically asking technology companies to voluntarily comply. That is unacceptable when AI systems can create millions of harmful images before regulators can send an e-mail telling companies to stop.

Equally important, Canada should not fall for the corporate blame shift onto users. xAI has argued that users bear primary responsibility. This makes no sense. If an automaker sells vehicles with defective brakes, it cannot avoid accountability by blaming drivers for stepping on the pedal. Why then should technology companies evade responsibility for foreseeable harms arising from products they designed and deployed with the capability to create non-consensual deepfake imagery?

Perhaps the most revealing finding in the privacy commissioner’s report was that after months of apologies and promises, the issue is unresolved. That should tell Canadians something. Big Tech appears to treat Canadian laws as voluntary guidelines. If that dynamic persists, Silicon Valley – not Canadians – sets the terms of accountability. Canadians should not have to rely on xAI’s assurances that everything is under control.

They deserve something stronger than a promise. They deserve laws with teeth.

Follow related authors and topics

Authors and topics you follow will be added to your personal news feed in Following.

Interact with The Globe