Privacy Groups to FTC: Don't Let Musk Wriggle Out of Twitter's Data Order
A coalition of fifteen privacy and consumer advocacy organisations has filed a joint letter urging the Federal Trade Commission to reject X's attempt to terminate the agency's oversight of its data practices. The deadline for public comments is July 2, and the groups want the FTC to know they're watching.
The backstory is straightforward enough. Back when it was still called Twitter, the platform got caught using phone numbers people had submitted for two-factor authentication to target them with ads. The FTC penalised the company with a consent order requiring independent audits and giving the agency authority to demand compliance documents without launching fresh legal action. Costly and annoying for the platform, but that was rather the point.
Now X wants out. The company's argument, stripped of the legal dressing, is basically: we changed our name, Musk moved things around structurally, and besides, we have GDPR obligations in Europe that cover the same ground. Order no longer needed. Thanks, goodbye.
The advocacy groups, which include the Electronic Frontier Foundation, the Electronic Privacy Information Center, and Demand Progress, are not buying any of it.
Their letter states bluntly that X's petition fails to meet the legal threshold required for such a request, and that the platform's current direction actually warrants more scrutiny, not less. Former US Attorney General William Barr has filed his own comments on the other side, arguing the FTC has been excessive in its information demands and shouldn't treat terminating consent orders as requiring extraordinary circumstances. X did not comment when asked.
The AI angle is where it gets interesting
The advocates' sharpest criticisms are aimed at what X has been doing with user data to feed Grok, its AI chatbot. X harvested hundreds of millions of posts for AI training without anything resembling explicit user consent. Instead of asking, the company just quietly updated its terms of service and apparently hoped most users wouldn't notice. Research suggests 73 percent of X users had no idea their posts were being used to train Grok.
There is also a particularly unsettling detail buried in here: deleting your posts from X does not delete the behavioural signal those posts already contributed to the model. The algorithm may keep targeting content at you based on information you thought you had removed. That is not how most users would expect things to work.
Cambridge Analytica, of all organisations, weighed in on this. Their assessment was that Musk did not create a new business model when he enabled AI training on user content. He just industrialised the surveillance capitalism approach they themselves pioneered, building personality and prediction models from behavioural data at scale. The key difference from the Facebook era, they argued, is that X is unusually transparent about it. Musk announced Grok's capabilities without much pretence about user benefit. Cambridge Analytica's somewhat ironic conclusion is that this brazenness might actually make effective regulation harder, because regulators and observers tend to fixate on hidden extraction rather than the obvious kind.
Grok has also attracted a lawsuit from three girls accusing X of allowing the chatbot to generate child sexual abuse material and non-consensual intimate images. And in 2024, 2.8 billion records leaked from the platform. The advocates note the FTC had already found that Musk directed employees to take actions that would have violated the existing order, specifically when he gave journalists access to internal data during the Twitter Files episode.
The GDPR argument from X is particularly weak given that regulators are currently investigating X for collecting European users' data to train Grok without valid GDPR consent. Hard to use a framework as your compliance alibi when you're under investigation for breaching it.
The legal arguments don't hold up either
The coalition also picked apart X's case law citations, finding them misleading. One of the cases X referenced involved an order terminated after 20 years under a sunset policy. The other saw an order modified after 16 years of compliance, not terminated because the company restructured. X's current order is four years old. Neither precedent actually supports what X is trying to do.
Musk also agreed to take on the order's obligations and costs when he bought Twitter. The advocates argue he cannot now complain that those obligations are inconvenient.
Perhaps most damaging to X's transformation argument is the obvious reality that the platform operates in essentially the same way as Twitter did. It is still a social media platform. It still uses personal data for targeted advertising. And it now has additional commercial incentives to collect and exploit user data through its AI business. The company is not transformed. It just has a different logo and more reasons to want oversight removed.