Green matrix-style digital code streaming down a dark screen

TL;DR: X Corp (the company formerly known as Twitter) is asking the FTC to throw out a 2022 privacy consent order that requires biennial security audits and restricts how user data gets used. X's argument: the company that violated users' trust "no longer exists," compliance costs $17 million, and the order blocks AI development. The FTC opened public comment through July 2, 2026. If X wins, it hands every acquired company a playbook: rebrand, fire everyone, then claim old privacy obligations died with the old name.

The Petition Nobody Should Be Surprised By

On June 2, 2026, the FTC announced it's seeking public comment on X Corp's petition to "set aside or modify" a consent order that's been hanging over the platform since the Twitter days. X wants the order gone entirely, or at minimum gutted to the point of irrelevance.[1]

The petition makes four arguments, and each one is more audacious than the last:

  • "The company no longer exists." X argues the order was imposed on Twitter, and Twitter is dead. Every person responsible for the original violations is gone. X Corp is a different entity.
  • "It costs too much." X claims compliance has cost $17 million, including biennial third-party security assessments and responding to FTC requests.
  • "Other laws already cover this." X says domestic and international privacy frameworks make the order redundant.
  • "AI needs this." X argues the order is "critical to advancing American leadership in artificial intelligence" and that compliance diverts engineering resources from building AI tools.[2][3]

That last one is the kicker. X is literally arguing that privacy oversight prevents AI innovation. Every hour engineers spend preparing for security audits, X claims, "is an hour not spent building AI tools that serve users and advance American competitiveness."[3]

How We Got Here: A 15-Year Privacy Disaster

This consent order didn't appear out of nowhere. It's the result of Twitter repeatedly failing to protect user data.

2011: The FTC slapped Twitter with its first consent order after two hacking incidents exposed user data. Twitter agreed to 20 years of privacy and security oversight, including regular third-party audits.[2]

2022: The DOJ and FTC came back. Twitter had violated the 2011 order by using phone numbers and email addresses (data people provided specifically for two-factor authentication) to run targeted advertising. Twitter took your security data and sold ads with it. The settlement: $150 million in penalties, a reopened consent order, and stricter requirements including biennial independent security assessments.[1][2]

October 2022: Elon Musk buys Twitter for $44 billion. What followed was a demolition job on the company's privacy and security infrastructure.

Former Chief Privacy Officer Damien Kieran told regulators that mass firings left "no one responsible for about 37% of X Corp's privacy program controls." Former CISO Lea Kissner said Musk's decisions "impaired" the company's ability to protect user contact data, the exact thing the FTC order was designed to prevent.[4]

Former Director of Security Engineering Andrew Sayler described an incident where Musk ordered employees to transfer servers to a new data center without adequate time to follow security protocols. Sensitive user data was on those servers.[4]

So the timeline reads: violate user trust, get a consent order, violate it again, get a stricter order, gut your privacy team, then petition to eliminate the order entirely.

The AI Excuse: Privacy as an Obstacle to Innovation

X's AI argument deserves special attention because it's going to become a template.

The petition explicitly invokes President Trump's executive order on AI, framing privacy compliance as a barrier to American competitiveness. X wants to use its massive trove of user data (posts, DMs, behavioral patterns, relationships) to train AI models. The consent order requires X to consider privacy and security risks before launching new products. That's the obstacle X wants removed.[2][3]

Read that again: X is asking the government to let it skip privacy reviews when building AI with your data. The company that already got caught using your security data for advertising now wants fewer guardrails on how it feeds your data to machine learning systems.

The $17 million compliance cost X complains about is pocket change for a company Musk purchased for $44 billion. That's 0.04% of the acquisition price. Biennial security audits (the specific thing X wants eliminated) exist because the company proved it couldn't be trusted to police itself. Twice.

The Rebrand Playbook: Why This Sets a Dangerous Precedent

If the FTC grants this petition, it writes a how-to guide for every company sitting under a consent order:

  1. Acquire the company (or restructure it)
  2. Fire the people responsible for the violations
  3. Change the name
  4. Tell the FTC the entity that violated the law "no longer exists"
  5. Claim your new business model requires the data freedom the order restricts

The FTC has consent orders with hundreds of companies. Meta's 2012 consent order. Google's data collection agreements. Health apps, fintech platforms, data brokers, all operating under privacy obligations they agreed to after getting caught mishandling data.

Every single one of those companies is watching this petition. If "we rebranded" is enough to kill a consent order, the FTC's enforcement authority means nothing. A consent order only works if it sticks to the data, the systems, and the users, not just the corporate name on the letterhead.

The Political Context: A Friendlier FTC

The timing isn't accidental. FTC Chairman Andrew Ferguson, a Trump appointee, may prove more receptive to X's arguments than a Biden-era commission would have been.[3]

The petition's language mirrors administration talking points: American AI leadership, regulatory burden, innovation blocked by government oversight. X isn't just making a legal argument; it's making a political one, betting that the current FTC would rather be seen as pro-innovation than pro-enforcement.

The public comment period (open until July 2, 2026) is the check on this. The FTC asked for input, and the volume and substance of that input will matter.[1]

What X Actually Wants to Do With Your Data

Strip away the legal language and X's petition is straightforward: they want fewer restrictions on how they use the data of hundreds of millions of users to build and train AI systems.

X already updated its privacy policy in 2023 to allow using public posts to train AI models. Grok, X's AI chatbot, was trained on user data. But the consent order requires privacy impact assessments and security reviews before new data uses. X wants that gone.[2]

The California court dismissal X cites in its defense (a May 2024 ruling that dismissed a class action over the 2FA data abuse) doesn't mean what X implies. That case was dismissed on standing grounds, not because the court said the behavior was acceptable. X is spinning a procedural win as vindication.[3]

Meanwhile, the consent order's biennial audits exist precisely because of the kind of data misuse X is building toward. Independent security assessments are the only mechanism confirming that X actually protects user data the way it claims to. Remove them, and you're trusting X on its word. The same X that inherited Twitter's track record of two separate FTC enforcement actions.

What You Can Do

Submit an FTC Comment

The public comment period is open until July 2, 2026. Comments that cite specific concerns (AI training without consent, the rebrand precedent, the gutted privacy team) carry the most weight. Submit at the FTC's announcement page.

Lock Down Your X Data

Go to Settings → Privacy and Safety → Grok and disable "Allow your posts to be used for Grok training." Also check Data Sharing settings and revoke third-party app permissions you don't recognize.

Download Your Archive

Request your Twitter/X data archive (Settings → Your Account → Download an archive). See exactly what they have. Then decide if you want it there when the consent order disappears.

Consider Leaving

If the consent order goes, X will have fewer privacy obligations than almost any major platform. Bluesky, Mastodon, and Threads all exist. Your data is the product, and you can take it somewhere with better guardrails.

What Happens Next

The FTC's comment period closes July 2. After that, the commission will review submissions and decide whether to grant, modify, or deny X's petition. There's no set timeline for the decision.

Privacy organizations (EFF, EPIC, the ACLU) are expected to file comments opposing the petition. Their arguments will likely focus on the precedent: if a rebrand can kill a consent order, enforcement is meaningless.

Watch for X's next move on Grok and AI training. If the petition succeeds, expect rapid expansion of AI data use across the platform, without the privacy impact assessments the consent order currently requires. Your posts, your DMs metadata, your behavioral patterns: all of it becomes AI training data with even fewer checks than exist today.

The core question: should a company be able to buy its way out of privacy obligations by changing its name and claiming AI needs require it? The FTC's answer will shape corporate privacy enforcement for years.

References

  1. FTC: Press Release: FTC Seeks Comment on X Corp Petition to Set Aside or Modify FTC Order Concerning Twitter
  2. National Law Review: FTC Seeks Comment on X Corp. Petition to Set Aside or Modify FTC Order
  3. Bank Info Security: Musk's X Asks US FTC to Nullify Data Security Order
  4. CyberScoop: Former Twitter executives: Privacy and security practices deteriorated under Musk
  5. Bloomberg Law: X Corp. Petitions FTC to Void Privacy Settlement Requirements