xAI filed suit on July 16, 2026 against Terry Wayne Harwood, a user it accuses of prompting Grok to generate child sexual abuse material, marking the first time Elon Musk's company has taken a Grok user to court over illegal outputs. The complaint alleges Harwood used two accounts between December 8 and February 18 to undress or 'nudify' non-sexual images of multiple victims, including a girl who appeared to be as young as 10. xAI is asking a US district court to rule that users, not the model provider, bear legal responsibility for what Grok produces.
The lawsuit lands a little more than a week after a separate victim joined a proposed class action against xAI. That plaintiff alleges her stepfather used Grok, possibly alongside other AI tools, to generate 7,000 sexualized images of her and distribute them on the dark web. Her lawyers say xAI reported just one of those 7,000 harmful outputs to the National Center for Missing & Exploited Children, and cite a 2026 NCMEC report finding that 90% of xAI's CyberTipline reports were not actionable by law enforcement because xAI declined to include user information.
Musk had previously said he had not seen examples of Grok-generated CSAM, and rather than restrict outputs, he warned users on X on January 3 to police themselves.
“anyone using Grok to make illegal content will suffer the same consequences as if they upload illegal content.”— Elon Musk, xAI founder
Key facts
- 01xAI sued Terry Wayne Harwood on July 16, 2026, alleging he used two Grok accounts from December 8 to February 18 to generate illegal images.
- 02A 2026 NCMEC report found 90% of xAI's CyberTipline reports were not actionable because xAI declined to include user information.
- 03A separate proposed class action alleges Grok was used to generate 7,000 sexualized images of one 10-year-old victim.
- 04xAI reported only one prompt to NCMEC out of the 7,000 harmful outputs cited in that victim's case.
- 05xAI's complaint argues Grok is 'a neutral tool, subject to user control,' seeking to make users solely liable for outputs.
Harwood was arrested earlier in 2026 by South Carolina authorities on charges of distributing, transporting, exhibiting, receiving, selling, purchasing, exchanging, or soliciting CSAM 'through the use of an artificial intelligence platform.' A spokesperson for the South Carolina attorney general's office told Ars Technica the case is still pending and would not confirm which platform was used. xAI's complaint, however, states 'upon information and belief' that at least some of the images in the criminal case were generated through Grok.
xAI's complaint describes Harwood using convoluted account names — 'ceae2cb4-a9f6-4885-8ae9-6e2096d084f4' and 'befccb94-4029-454d-9f1f-0d4945e8fa7c' — and modifying prompts to route around safeguards. The filing includes one rejected prompt using phrases like 'white slime' to mask intent, alongside an explicit request to 'remove all her clothing,' which directly violates xAI's terms against undressing real people. xAI did not publish examples of prompts that succeeded, likely to avoid handing a playbook to other bad actors.
The legal theory at the center of the suit is that Grok should be treated as 'a neutral tool, subject to user control.' xAI argues that its terms of service draw 'a bright line' between permitted and prohibited uses, that every user agrees to those terms at sign-up, and that Harwood 'flagrantly violated' the rules by using misleading prompts. The terms prohibit undressing real people, sexualizing or exploiting children, and depicting real likenesses in intimate or sexual contexts.
“Like any generative AI tool, every response, every image, every generation is the result of the user's prompts and directions.”— xAI, from the company's complaint
xAI wants the court to enforce an indemnity clause making users liable for both inputs and outputs. If it wins, xAI says Harwood could owe damages for harm to third parties, exposure to future third-party claims, and reputational harm to xAI itself. The company also frames the suit as pre-emptive protection against 'substantial legal fees' and 'considerable liability for damages' should Harwood's alleged victims sue xAI directly.
The strategy has an obvious downstream target: the proposed class action, which lawyers estimate could involve thousands of victims. A court finding that users alone are responsible for Grok outputs would give xAI a template defense for every future CSAM or non-consensual intimate imagery complaint, and a hammer to bring down on individual users whenever a victim files.
There is a legal wrinkle. The US Copyright Office does not treat AI outputs as human-created work, a position that has shaped copyright rulings across generative AI cases in the past two years. If a court adopts xAI's framing that users author Grok outputs for liability purposes, it creates tension with the copyright regime's opposite conclusion that no human authored them at all. xAI's complaint does not indicate that Harwood received any warnings from the platform before continuing to use Grok, even as the company now argues he should have known his account was banned after his first violation.
The case will test whether the 'neutral tool' framing survives contact with a product marketed for its permissive image generation. xAI has positioned Grok as less restricted than competitors, a selling point that becomes harder to defend in court when the company simultaneously argues the tool is inert and users are the sole authors of what comes out. Section 230 protections, which shield platforms from user-generated content, were written before generative models existed and have not been settled for AI outputs.
For the broader AI industry, xAI's filing is the opening move in a fight every model provider will eventually have. Anthropic, OpenAI, and Google have taken the opposite approach — investing heavily in output-side filtering and refusing high-risk prompts by default — precisely to keep this liability question theoretical. xAI's bet is that terms of service and an indemnity clause can substitute for guardrails, and that courts will accept the substitution. If that bet loses, the cost is not just damages in one suit; it is a legal precedent that every consumer AI product ships with the vendor holding the bag for whatever users can coax out of it.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




