Product2 publishers3 min readPublished
Grok CSAM suit gains a fourth plaintiff and a 7,000-image count
One alleged user is accused of generating more than 7,000 explicit images of a single child with Grok. That figure is a discovery target, not a talking point.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- A fourth party is pursuing legal action against xAI, alleging that Grok was used to create child sexual abuse material based on her childhood photos.
- The woman is named as Jane Doe 4 in the lawsuit and is described as a Wyoming woman.
- The development was first reported by The Washington Post.
- According to the lawsuit, her stepfather created more than 7,000 fake explicit images of her using Grok, including converting a photo taken of her when she was 11 into a sexually explicit image.
- The original lawsuit was filed by three Tennessee teenagers who alleged Grok was used to create sexually explicit deepfake images of them.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
A woman identified as Jane Doe 4 has joined the lawsuit against xAI over Grok's alleged role in producing child sexual abuse material, a development first reported by The Washington Post [1][2][3]. Her allegation puts a number on the docket that no policy page absorbs: more than 7,000 explicit images of one child, allegedly generated by her stepfather from a photo taken when she was 11 [4].
The case began with three teenagers in Tennessee who alleged Grok was used to make sexually explicit deepfakes of them, and who accused xAI of failing to take basic precautions against the tool being pointed at real people, including minors [5][6]. With Jane Doe 4, the named plaintiffs go from three to four [7]. More consequentially, the pleaded facts move from a handful of individual images to sustained output by one alleged offender, which the suit says was traded online [8]. The plaintiffs are seeking class action status, and the complaint argues the class could reach at least thousands of minors [9][10].
That is the change operators should register. Three named victims can be characterised as misuse at the edges. A pleaded volume of 7,000 images attributed to one person, inside a certified class, is an assertion about how a system behaved over time, and it is the kind of assertion that gets tested against server-side records rather than against a published acceptable-use policy. Anything a company wrote about guardrails becomes a document to be compared with what the pipeline actually did: how uploads of real faces were handled, whether per-account volume triggered review, what classifiers ran on image-to-image edits as opposed to text prompts, and what was logged and retained. The plaintiffs' claim is precisely that the precautions were absent [6]; a discovery record is where that stops being rhetoric in either direction.
The regulatory backdrop is already building the same kind of paper trail. California's attorney general, Rob Bonta, opened an investigation into xAI in January, accusing it of generating nonconsensual deepfake nudes of women and children [11]. Later that month, the European Union opened a probe of X over whether it had adequate measures against the spread of AI-generated CSAM [12]. TechCrunch notes that X was flooded with millions of Grok-generated sexualised images earlier this year [13], and that xAI is now part of SpaceX [14].
The Wyoming woman's account also includes what happened next: state and local law enforcement raided her stepfather's devices for CSAM, and two days later he was found dead by suicide in his car [15]. TechCrunch published the 988 Suicide and Crisis Lifeline alongside its report [16]. "Limitless access to these tools is spreading so quickly," she said, according to the Post's reporting relayed by TechCrunch. "It is taking everyday life and turning it into child sexual abuse." [17]
Both Engadget and TechCrunch said they had contacted xAI for comment; neither published a response [18][19].
Watch class certification first, because it determines whether discovery runs against a class-wide record or four individual ones [9]. Then watch whether the 7,000 figure survives contact with xAI's own logs, and whether the California and EU inquiries produce internal documents about what controls existed and when [11][12].