xAI Can't Pretend Grok Doesn't Make CSAM. So It's Suing Its Own Users Instead.
For months, Elon Musk insisted he hadn't seen any evidence of Grok being used to generate child sexual abuse material. That position has become rather difficult to maintain now that xAI has filed a lawsuit against one of its own users for doing exactly that.
The target is Terry Wayne Harwood, arrested earlier this year in South Carolina on charges of possessing and distributing CSAM. According to xAI's complaint, Harwood used two accounts over roughly ten weeks, from December to February, to generate sexualized images of real victims, including a girl estimated to be around ten years old. xAI says it helped secure his arrest after flagging the activity internally.
The timing of the lawsuit is telling. It comes just over a week after a separate young girl joined a proposed class action against xAI, alleging her stepfather used Grok to generate approximately 7,000 sexualized images of her before distributing them on the dark web. He later killed himself after being discovered. In that case, xAI allegedly refused to assist police in identifying the user. Supporting that claim, lawyers cited a 2026 NCMEC report finding that 90 percent of xAI's CyberTipline reports lacked sufficient user information for law enforcement to act on.
Musk's response to earlier allegations was to post a warning on X that users generating illegal content would face consequences. Harwood, apparently, was not deterred.
The Blame-the-User Strategy
What xAI is really after here isn't just Harwood. The lawsuit is a legal positioning exercise. By establishing that users, not xAI, bear responsibility for Grok's outputs, Musk's firm would significantly strengthen its defence against the broader class action, which lawyers estimate could eventually represent thousands of victims.
The core argument is that Grok is a neutral tool and every output is a direct product of user prompts and decisions. xAI points to its terms of service, which explicitly prohibit nudifying real people, sexualising minors, or generating CSAM. Every user agrees to these terms at sign-up, xAI notes, with all the confidence of a company that has just discovered terms of service.
Harwood allegedly used misleading prompts to get around content filters. Grok did reject some requests, including one particularly explicit prompt that used coded language to obscure its intent. Another was blocked because Harwood literally typed "remove all her clothing," which is the kind of direct instruction even a mediocre content filter should catch. xAI chose not to include examples of the prompts that did work, reportedly to avoid providing a how-to guide for other bad actors.
The complaint argues Harwood should have self-reported and stopped using Grok the moment he realised he could generate illegal content. There is no mention of xAI sending him any warnings, suspending his accounts, or taking any action against him until after his arrest.
The Indemnity Clause Gamble
The real prize xAI is chasing is judicial recognition of an indemnity clause holding that users, not the platform, are liable for AI-generated harmful content. If that sticks, it creates a legal template xAI can deploy every time a victim surfaces.
There is at least one significant problem with this strategy. The US Copyright Office does not treat AI-generated content as human-created work. If courts follow similar logic when it comes to liability, it becomes rather awkward to argue that a user "created" content that the law might not recognise as having a human author at all.
If xAI wins, Harwood could be on the hook for substantial damages covering harm to victims, xAI's legal costs, and what the complaint delightfully refers to as "xAI reputational harm." Yes, the company suing to avoid accountability for child abuse imagery is concerned about its reputation.
xAI did not respond to requests for comment.