Site navigation

Irish Watchdog Probes X Over AI ‘Data Grab’

Tom Quinn

,

DPC X
X is under investigation in Ireland once again over concerns about its use of user data to train its AI chatbot.

Ireland’s data protection watchdog has announced a new inquiry into the use of personal data by social media platform X in training its genAI model, Grok.

The Irish Data Protection Commission (DPC) said it will examine how X processes the personal data contained in EU and EEA users’ publicly accessible posts, specifically in regard to compliance with a range of key provisions in GDPR, including the lawfulness and transparency of the processing.

The inquiry will cover a range of issues concerning the use of data controlled by X to determine whether this was lawfully processed to train the Grok LLMs developed by Elon Musk’s xAI company, which last month acquired the X social media platform.

The DPC’s inquiry into the use of personal data by X is the latest episode in an ongoing saga which began in July 2024 when X first enabled its AI chatbot to access user data for training purposes.

However, just two weeks after turning on the tap, X announced it would suspend feeding user data to its AI training models following a complaint to the DPC from Euroconsumer and an urgent High Court application brought by the watchdog under the Data Protection Act, 2018.

That complaint alleged that X had not adequately explained the purposes of its data processing, that more data was being collected than was strictly necessary, and that the platform may have been using sensitive data without sufficient reason, none of which would be permissible under GDPR. 

The DPC said at the time it ‘welcomed’ X’s agreement to suspend the processing of personal data in the public posts of EU and EEA users, along with X’s move to update privacy settings to allow users to opt out of allowing xAI use their posts to train Grok.

X also faced nine complaints of GDPR violations from the privacy advocate group NOYB (None of Your Business), which said the platform had failed to inform its 60 million European users that their data was being used to train the company’s AI, and they did not ask for user consent.


Recommended reading


For its part, X has previously argued that it had been transparent about the use of public data in training its AI models and directly communicated these policies to users, calling the DPC’s actions ‘unwarranted and overbroad’ in a post from the platform’s Global Affairs account in August last year.

“Unlike the rest of the AI industry, we chose to provide a simple control to all X users allowing them to decide if their public posts and engagement activity could be used to improve the models used by Grok,” said X.

“While many companies continue to scrape the web to train AI models with no regard for user privacy, X has done everything it can to give users more control over their data.” 

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data