Wooden judge gavel resting on a dark surface next to law books, the kind of regulatory authority the Office of the Privacy Commissioner of Canada used on June 11, 2026 when it found X Corp and xAI violated federal privacy law
Photo via Unsplash

TL;DR: On June 11, 2026, Privacy Commissioner of Canada Philippe Dufresne released a report finding that X Corp. and xAI violated Canada's federal private-sector privacy law (PIPEDA) by launching the Grok AI image-generation tool without proper safeguards or sufficient consideration of potential privacy harms [1][2]. The OPC initiated the investigation in January 2026 after reports that Grok was being used to generate millions of sexualized deepfakes, many targeting women and children; researchers told the OPC that Grok was at one point generating well over 6,000 sexualized images per hour [2]. X and xAI have since added new safeguards and proactive moderation sweeps and have committed to quarterly reports and independent third-party audits until the issue is fully resolved [1]. The OPC will monitor the implementation. The problem: under Canada's current privacy law, the Privacy Commissioner is not empowered to issue orders to ensure organizations respect Canadians' fundamental right to privacy [1][2]. Dufresne's public statement is a public finding of violation, not a binding enforcement action. He used the ruling to call for modernized federal private-sector privacy law with administrative monetary penalties and order-making power, the same week the Canadian government introduced a new bill to regulate AI chatbots [2][3].

What the Privacy Commissioner Found

The OPC's June 11 report runs 24 pages and reads like a textbook case study in what happens when a frontier AI product ships without a privacy review [1]. The headline finding: X Corp. and xAI violated PIPEDA by launching Grok's image-generation tool without implementing appropriate safeguards from the outset, a violation that the Commissioner characterized as clear and ongoing through the early months of the product's life [1][2].

Three specific failures stood out in the report. First, the lack of pre-launch privacy review. The OPC's investigation found that the safeguards shipped with the product were insufficient to prevent the tool from being used to generate non-consensual sexualized imagery, including deepfakes of real people whose photos had been posted to X for unrelated reasons [1]. Second, the inadequate consent posture. Users whose photos were processed by Grok had not been given meaningful notice that the tool existed, much less an opportunity to consent to having their images used as inputs [1][2]. Third, the slow public response. X and xAI added new safeguards only after the issue became public in early 2026, not before the product launched [1].

Commissioner Dufresne's written statement is blunt about the scale. "According to researchers, Grok was at one point generating well over 6,000 sexualized images per hour" [2]. That is a per-hour figure, not a per-day figure, and it does not count the images that were generated and then deleted by the moderation sweeps X and xAI added later. The full count of non-consensual images created during the months between the product launch and the new safeguards is not in the public record [1][2].

What X and xAI Have Committed To

Both companies pushed back on the OPC's findings. X and xAI argued to the Commissioner that they had already removed illegal content and limited how Grok can be used, and that users were responsible for initiating the collection of personal information when they prompted Grok to generate and post the images [2]. The OPC rejected the "user responsibility" argument. The Commissioner found that the companies themselves are responsible for the product they put into market, and that the safeguards shipped at launch were insufficient under PIPEDA [1][2].

Despite the disagreement, X and xAI have committed to a set of follow-up measures, on the record, in the OPC's report [1]:

  • Quarterly compliance reports submitted to the OPC until the sexualized deepfake issue is fully resolved [1].
  • Independent third-party audit reports on improvements to safeguards, with evidence to demonstrate effectiveness, also continuing until the issue is fully resolved [1].
  • Continued proactive sweeps to detect and remove the harmful content from their platforms, the measure the companies say they added during the investigation [1].

The OPC will monitor the implementation. The Commissioner characterized the report as a finding of violation, with the companies' commitments as the next-step compliance path under his existing authority [1]. The OPC does not have the power under the current federal private-sector privacy law to issue binding orders, impose administrative monetary penalties, or compel the production of records beyond what the companies have agreed to provide [1][2].

The Enforcement Gap: Canada Has a Ruling But No Teeth

The headline of this story is the finding. The subhead is the gap.

Canada's federal private-sector privacy law, the Personal Information Protection and Electronic Documents Act (PIPEDA), was passed in 2000 and amended only marginally since. It does not give the Privacy Commissioner the power to issue orders, impose administrative monetary penalties, or compel compliance. The Commissioner's tools are: investigate, find, name, recommend, and publish [1][2].

Dufresne used the June 11 report to make the gap explicit. "The Grok investigation highlights the need for modern privacy laws that are designed for a modern world and include administrative monetary penalties and the power to make orders to bring companies into compliance," he said in the written statement accompanying the report [2]. "Modernized privacy laws can support both innovation and privacy protection by establishing clear guardrails that ensure the responsible and trustworthy management of Canadians' personal information" [2].

Compare that to the EU, where the GDPR lets regulators fine up to 4% of global annual turnover, and to the UK, where the Information Commissioner's Office has issued nine-figure fines under the Data Protection Act 2018. The United States has no federal commercial privacy law at all, leaving the FTC to act under Section 5 of the FTC Act in egregious cases. Canada now has a public finding of a privacy violation against a frontier AI product, the international press coverage that comes with it, and no domestic statutory mechanism to make the finding binding [1][2].

The Government Introduced an AI Chatbot Bill the Day Before

The timing matters. The Jurist report on the OPC finding notes that "the Canadian federal government introduced a new law to regulate AI chatbots on Wednesday" [3]. Wednesday was June 10, 2026, the day before the OPC released the Grok finding.

The bill, if enacted in its current form, would require AI chatbot operators to act responsibly and mitigate the risk of their chatbots communicating harmful content to their users [3]. The text of the bill is not yet public, and the standing reference in the Jurist coverage does not name a bill number. The bill is the second AI-specific legislative product to come out of Ottawa in 2026, after the joint federal-provincial AI strategy that included a commitment to modernize PIPEDA [1][2].

What the bill does or does not cover will be the policy fight for the rest of 2026. If the bill covers non-consensual intimate imagery generation by an AI product, the Grok finding becomes the first test case under the new statute. If the bill does not cover the use case, the OPC's Grok finding is the public record and the public pressure point, but not a binding enforcement action [1][2][3].

The Second Major OPC Finding Against a Frontier AI Company in 2026

The Grok finding is the second major OPC enforcement product against a frontier AI company this year. On May 6, 2026, the OPC and three provincial counterparts (Quebec, British Columbia, Alberta) released a joint investigation finding that OpenAI had violated PIPEDA and three provincial privacy statutes by scraping personal data without consent to train GPT-3.5 and GPT-4, by shipping ChatGPT knowing it fabricated facts about real people, and by running for years without data retention or deletion policies [4].

The two cases share a pattern. Both involve a frontier AI company that shipped a product without a privacy review, generated or processed personal data at a scale the regulator found alarming, and then agreed to corrective measures under regulatory pressure rather than under an enforcement order. The OPC's structural position is the same in both cases: find, name, recommend, publish, and ask Parliament for the order-making power the office does not have [1][2][4].

The pattern is also the policy ask. The OPC's June 11 report is the second time in six weeks that the office has used a high-profile finding to argue for administrative monetary penalties and order-making power in modernized federal privacy law. The argument is that voluntary compliance works for the companies that already care about privacy, and does not work for the companies that ship first and add safeguards later [1][2][4].

What It Means for You

If you are in Canada. The OPC's June 11 finding does not change anything about your relationship with X or Grok today. The companies have not been ordered to stop the product, modify it, or pull it from market. What it does do is give you a public record you can reference if you have been a victim: the Canadian Privacy Commissioner has formally found that the product violated federal privacy law as of June 11, 2026. That finding is the first piece of paper in any future civil action you might bring, and it is a documented input to the parliamentary debate on modernizing PIPEDA.

If you are a victim of Grok-generated sexualized deepfakes. X's reporting flow and the OPC's complaint intake are the two parallel channels. The OPC's finding is evidence, not a remedy. For civil remedies, the Ontario and British Columbia superior courts have been the most active venues for non-consensual intimate imagery cases in 2024 to 2026, and the Criminal Code provisions on non-consensual distribution of intimate images were amended in 2024 to add AI-generated material. Speak to a Canadian privacy or civil-litigation lawyer before relying on any of this.

If you are a US-based AI safety researcher or a journalist. The OPC's report is the most-cited G7 privacy regulator's documented finding on a frontier AI image generator's non-consensual imagery failure to date. It is going to be cited by the UK ICO, the Irish DPC, the CNIL, the Hamburg DPA, and the California Privacy Protection Agency in their own enforcement decisions. The "6,000 images per hour" figure will be the headline number used by all of them. The finding is also the cleanest summary yet of what "shipping without a privacy review" looks like in a regulatory product.

If you are a Canadian AI startup or a multinational with Canadian operations. The OPC has now publicly committed to using voluntary compliance reports and third-party audits as the workaround for the order-making power the office does not have. Expect the OPC to ask for the same quarterly-report + third-party-audit structure in any future AI product investigation. The OPC's June 11 finding is the new template for what "voluntary compliance" looks like in Canadian privacy enforcement.

The Bottom Line

On June 11, 2026, the Privacy Commissioner of Canada found that X Corp. and xAI violated Canada's federal private-sector privacy law by launching Grok's image-generation tool without proper safeguards. Researchers told the OPC that Grok was at one point generating more than 6,000 sexualized images per hour. The companies disagreed with the findings but committed to quarterly reports and third-party audits until the issue is resolved. The OPC will monitor implementation.

The finding is real and on the public record. The enforcement gap is also real: the Privacy Commissioner cannot issue orders or impose penalties under the current federal private-sector privacy law. The Canadian government introduced a new AI chatbot bill the day before the OPC released the finding, and the Privacy Commissioner used the report to make the case for modernized privacy law with administrative monetary penalties and order-making power. Watch for three things over the next 30 days: the text of the AI chatbot bill, the first quarterly report from X and xAI, and any signal that the OPC's finding is being used as a precedent in UK ICO, EU DPA, or US FTC actions against the same companies.

Sources

  1. Office of the Privacy Commissioner of Canada: "Privacy Commissioner of Canada investigation into the Grok chatbot and sexualized deepfakes finds companies violated privacy law" (June 11, 2026, the primary source for the finding of violation, the companies' commitments to quarterly reports and third-party audits, and the OPC's commitment to monitor implementation)
  2. Office of the Privacy Commissioner of Canada: "Statement by the Privacy Commissioner of Canada on investigation into Grok chatbot and sexualized deepfakes" (June 11, 2026, the primary source for Commissioner Dufresne's written statement, the "6,000 sexualized images per hour" figure, and the explicit call for modernized federal private-sector privacy law with administrative monetary penalties and order-making power)
  3. Jurist: "Canada privacy watchdog says Grok generates explicit deepfakes without users' valid consent" (June 13, 2026, secondary coverage with the OPC recommendation that X suspend the Grok function until comprehensive privacy safeguards are in place, the companies' rejection of the user-responsibility framing, and the disclosure that Canada introduced a new AI chatbot law on Wednesday June 10)
  4. State of Surveillance: "Canada Ruled ChatGPT Was Built on Broken Privacy Law" (May 7, 2026, the prior SOS piece on the May 6 joint investigation that found OpenAI violated PIPEDA and three provincial privacy statutes, the comparable enforcement pattern, and the parallel argument for modernized federal privacy law)