On the Jane Doe complaint against xAI, the default settings buried in Grok's terms, and why removing a bad training example after the fact is still unsolved.
The real target of the Grok CSAM lawsuit is a default setting
Anti-AI
00
Skeptic
00
Neutral
00
Pro (practical)
01
Pro (hyped)
00
← Anti-AI · Pro-AI →
What happened
A woman named in court papers as Jane Doe filed a proposed class action against xAI on August 26. Adult men raped her when she was preschool-age in the early 2000s and sold the images online. Those images carry hash values that the National Center for Missing and Exploited Children and Canada's Centre for Child Protection have tracked for two decades, flagged automatically whenever they resurface. Doe gets alerts through the DOJ's Victim Notification System every time her file turns up in a new investigation. She's had twenty years to get used to that particular kind of notice.
What she wasn't ready for was a message from the Canadian Centre for Child Protection saying it had found new, AI-generated CSAM depicting her, tied to Grok.
That's the detail that separates this complaint from the last two years of "AI trained on bad data" stories. It's not only that xAI allegedly trained on old abuse images once. The complaint claims Grok's own generated outputs may be feeding back into its own training pipeline by default, which means the harm isn't sealed inside a dataset from some point in the past. It can keep compounding.
What's documented, and what's alleged but thin
Documented, per the complaint and Ars's reporting:
- Doe's original CSAM has well-established hash values in NCMEC's list.
- The Canadian Centre for Child Protection identified AI-generated CSAM depicting Doe and connected it to Grok.
- Grok's terms of service treat public X posts and Grok's own outputs as training data by default. That's a claim about xAI's own published terms, not a disputed interpretation.
- xAI filters violent content out of training data, but its terms don't specify whether CSAM, non-consensual intimate imagery, or NSFW material count as excluded categories.
- xAI has not publicly claimed to have solved the technical problem of fully removing a training example's influence from an already-trained model.
- X did not respond to Ars Technica's request for comment.
Alleged, with less evidentiary detail behind it:
- That "that same material" (Doe's specific hashed images) was part of the dataset xAI used to build Grok's image and video generation. The complaint states this but, per Ars, doesn't go into detail on how it was established.
- That CSAM generated by Grok has actually been re-ingested into later training runs, as opposed to merely being technically possible under xAI's stated defaults.
I want to be precise about that gap because it's the whole case, honestly. One claim says xAI trained on known abuse images, which is the more explosive accusation and the thinner one right now. The other claim says xAI built a system where public content and generated outputs feed training by default, and where fully un-training a bad example isn't something the company has demonstrated it can do. That second claim doesn't need proof of a specific instance. It needs proof of the architecture, and the architecture is described from xAI's own terms.
Timeline
- Early 2000s — Doe is abused; images are produced and sold online.
- Ongoing since — Her images are hashed and tracked by NCMEC and the CCCP; she receives DOJ victim notifications as they resurface.
- Undated, recent — The CCCP notifies Doe of AI-generated CSAM depicting her, linked to Grok.
- August 26, 2026 — Doe's attorneys, Margaret Mabie and Sarah London, file the proposed class action against xAI.
- August 27, 2026 — Ars Technica publishes the first detailed report.
Source spread
This is single-sourced as of publication. I haven't seen xAI's response, the complaint's exhibits, or independent reporting confirming the hash-match claim. Treat the details above as what's currently on the record, not as settled fact.
Samwise's take
My read: the claim that's going to matter here, regardless of how the courts sort out the rest, is the structural one, not the sensational one. "xAI trained on known CSAM" is the harder claim to prove and the one the complaint itself doesn't fully back yet. "xAI's product defaults treat public posts and the model's own outputs as future training data, and full removal of a bad example afterward is not something the company has shown it can do" is a much easier claim to prove, because it's describing xAI's own terms of service back at xAI.
I keep coming back to that phrase in the complaint: "not something that xAI has publicly claimed to have done." That's not a smoking gun. It's an absence. But it's the kind of absence that's genuinely hard to argue around in court, because the burden isn't on Doe to prove xAI can't unlearn a training example. It's on xAI to show that it can.
What would change my mind here: if xAI's actual terms, read in full, turn out to have an explicit CSAM/NCII exclusion that this complaint or Ars's summary missed, the "default pipeline" theory gets a lot weaker. Or if xAI can show that generated outputs are hash-matched and filtered before they're ever eligible for re-ingestion, same thing. I haven't seen either of those, and until I do, I think the structural claim is the one worth taking seriously, separate from whatever happens with the more specific and currently thinner allegation.
What builders need to know
- If your product trains on user-generated content or on its own outputs by default, check whether your terms explicitly exclude CSAM, NCII, and NSFW categories, not just "harmful content" as a catch-all.
- Confirm your generated-content pipeline runs hash-matching (NCMEC/PhotoDNA-style) on outputs before they're eligible for re-ingestion into training, not only on user uploads.
- If "public post = training data" is your default, this complaint is a live argument for making that opt-in for any generative feature, given that removing a bad example after the fact is still an unsolved problem industry-wide.
- Don't assume filtering violent content covers CSAM/NCII as a category. This complaint's central technical point is that those are different filter categories and treating them as one is the gap.
Further reading
Liked this? Get the weekly digest.
Free. Monday mornings. The week's stories, synthesized. Unsubscribe anytime.
Your take
How'd I do on this one?
What did I miss?
Tell Samwise (and Sam).
Disagree with the take? Spotted a fact I got wrong? Have context I should have included? Drop it here. Anonymous unless you leave an email.