Ireland’s DPC probes X’s alleged use of EU user data to train Grok AI, coinciding with new AI Act rules and parallel CNIL investigations over GDPR compliance.
Ireland’s Data Protection Commission (DPC) launched a formal investigation on 14 June 2024 into whether X (formerly Twitter) unlawfully processed EU users’ public posts to train its Grok AI chatbot. The probe follows X’s updated privacy policy and aligns with France’s CNIL parallel inquiry, testing GDPR’s ‘legitimate interest’ provisions under the shadow of the EU’s newly adopted AI Act.
Regulatory Storm Gathers Over AI Training Data
The Data Protection Commission confirmed its investigation focuses on whether X violated GDPR Article 6 by processing publicly accessible posts without explicit consent. ‘Publicly available doesn’t mean free for commercial AI training,’ stated DPC spokesperson Ruaidhrí O’Connor in a 14 June press briefing.
AI Act Adds New Compliance Layer
The 12 June adoption of the EU AI Act forces companies to disclose training data sources, directly impacting Grok’s operations. Legal experts note this creates dual compliance requirements under both GDPR and the new AI framework. Dr. Elena Müller, data law professor at Maastricht University, warns: ‘Companies now face a regulatory pincer movement – transparency obligations under the AI Act combined with GDPR’s strict consent requirements.’
Historical Precedents and Future Implications
This investigation echoes the 2019 €50M GDPR fine against Google for processing location data without proper consent. However, the AI dimension adds complexity – unlike traditional data misuse cases, machine learning systems create derivative works from billions of data points. The outcome could set precedent for how Article 22 GDPR (automated decision-making) applies to LLMs. Meanwhile, X’s updated privacy policy from 9 June 2024 explicitly references using public data for ‘machine learning’, suggesting anticipated regulatory battles.
The Broader Compliance Landscape
France’s CNIL launched a parallel investigation on 10 June into X’s data retention practices, questioning whether users receive adequate notification about AI training uses. This multi-agency approach reflects the EU’s 2021-2027 Digital Strategy commitment to coordinated tech regulation. Historical context shows escalating enforcement – GDPR fines increased 168% year-over-year in 2023 according to DLA Piper’s annual report.