Potential systemic risks in external digital services: the EU’s investigations

Views: 46

As a designated very large online platform under the European DSA, the Grok’s AI tool called X has the obligations to self-assessment and mitigation of any risks related to its services provided among the EU member states. The assessment, among other things, include the spread of illegal content and potential threats to fundamental rights and those of minors, posed by its platform and digital features. The role of the EU-wide Digital Services Coordinators is also vital in the investigation. 

Background
Grok is currently being investigated by the European Commission for reportedly allowing users to produce AI-generated child sexual abuse images. By moving its point of contact to Tallinn, x-AI shifted supervisory responsibility across the European agencies. The Commission and the Irish regulator (more about it below) are investigating the deployment of Grok within X. Meanwhile, the Estonian consumer agency is now in charge of it as a standalone chatbot.
The company x-AI, set up by Musk to challenge rivals like OpenAI, operates the controversial Grok chatbot embedded in X. It added an Estonian address to its terms of service in mid-February; the x-AI’s Tallinn office in Estonia appears to be a phantom set up for legal reasons, according to experts and regulators.
More in: https://pcservicecenter.dk/grok-3-alt-du-skal-vide-om-den-nye-ai-fra-x/

As, the Commission Executive Vice-President for Tech Sovereignty, Security and Democracy (H. Virkkunen) notes: “the DSA gives researchers the way to uncover potential threats; it DSA restores trust in the online environment. With the DSA’s first non-compliance decision, the Commission is holding X responsible for undermining users’ rights and evading accountability”.
Citation from: https://ec.europa.eu/commission/presscorner/detail/en/ip_25_2934

Basics on Grok
Grok is an AI tool developed by the provider of X; since 2024, X has deployed Grok in its platform in various ways: e.g. they can enable users to generate text/images and provide contextual information to users. Grok is a generative artificial intelligence chatbot developed by x-AI: it was launched in November 2023 by E. Musk as an initiative based on the large language model (LLM) of the same name. Grok has apps for iOS and Android and is integrated with the X social network and Tesla’s Optimus robotics.
On other accounts, Grok represents a generative AI chatbot developed by x-AI, integrated seamlessly into the X platform (formerly Twitter). Designed to be “witty, truth-seeking and capable of real-time data analysis”, it enhances the social media experience by summarizing trends, analyzing tweets and generating content. Unlike many traditional AI models, Grok has native access to the live X feed, allowing it to provide instant updates on breaking news, public sentiment and ongoing debates.
Additional info on: https://medium.com/@ramavala/overview-of-grok-ai-integration-with-x-5089537a946c

The Commission’s investigation
The present investigation complements and extends the process launched already in December 2023, which focused on the functioning of X’s notice and action mechanism, its mitigation measures against illegal content, such as terrorist material in the EU, and risks associated with its recommender systems.
These proceedings covered also the use of deceptive design, the lack of advertising transparency and insufficient data access for researchers, for which the Commission adopted a non-compliance decision on 5 December 2025, fining X €120 million.
In September 2025, the Commission sent to X a request for information related to Grok, including also questions in relation to the antisemitic content generated by @grok in mid-2025.
These risks are exposing the European citizens to serious harm: in light of this, the Commission started in January 2026 further investigation on whether X complies with its DSA obligations within the following two circumstances:
= Diligently assess and mitigate systemic risks, including of the dissemination of illegal content, negative effects in relation to gender-based violence, and serious negative consequences to physical and mental well-being stemming from deployments of Grok’s functionalities into its platform.
= Conduct and transmit to the Commission an ad hoc risk assessment report for Grok’s functionalities in the X service with a critical impact on X’s risk profile prior to their deployment.
Source and citation from: https://ec.europa.eu/commission/presscorner/detail/en/ip_26_203

Breaching the European DSA rules: main issues
In December 2023 the Commission opened formal proceedings to assess whether X may have breached the DSA in areas linked to the dissemination of illegal content and the effectiveness of the measures taken to combat information manipulation, for which the investigation continues.
Then, in December 2025, the Commission issued a fine of €120 million to X for breaching its transparency obligations under the Digital Services Act, DSA. The breaches include the deceptive design of its ‘blue checkmark’, the lack of transparency of its advertising repository, and the failure to provide access to public data for researchers.
However, Commission said, X failed to meet the DSA’s obligations to provide researchers with access to the platform’s public data. For instance, X’s terms of service prohibit eligible researchers from independently accessing its public data, including through scraping.
Moreover, X’s processes for researchers’ access to public data impose unnecessary barriers, effectively undermining research into several systemic risks in the European Union.
The fine issued in 2025 was calculated taking into account the nature of these infringements, their gravity in terms of affected EU users, and their duration.
Reference to: https://ec.europa.eu/commission/presscorner/detail/en/ip_25_2934

First non-compliance decision
This is the first non-compliance decision under the DSA: the proceedings covered also the use of deceptive design, the lack of advertising transparency and insufficient data access for researchers, for which the Commission adopted preliminary findings on 12 July 2024 and a non-compliance decision.
Help and support is available at national level for individuals who have been negatively affected by AI-generated images, including child sexual abuse material or non-consensual intimate images. Under the DSA, citizens have the right to make a complaint about a breach of the DSA to the Digital Services Coordinator of their member state.
More on the decision in: https://ec.europa.eu/commission/presscorner/detail/en/ip_25_2934

Commission’s additional efforts
In January 2026, the European Commission opened a major investigation into X over concerns that Grok could be used to generate illegal content.
In apparent response to the Commission’s probe, xAI swiftly updated its terms of service: it appointed European Digital Services Representatives (EDSR) – a Brussels-based legal firm for non-EU companies – as its new legal point of contact for matters related to the bloc’s online safety laws, the Digital Services Act (DSA).
Source: https://www.ftm.eu/articles/elon-musk-ai-company-basement-address?share=l1zweNj%2BkkbibcP53%2BvLngVjQXEDJiQfRZ%2BS4zRa2uxvvTQh%2FeuJFo5%2FViEx1Bo%3D

EU’s Digital Services Coordinators
The Digital Services Coordinators help the Commission to monitor and enforce obligations in the Digital Services Act (DSA). The Commission and the national Digital Service Coordinators (DSCs) are responsible for supervising, enforcing and monitoring the DSA.
Each EU state has to designate and empower a Digital Services Coordinator (DSC), who is responsible for all matters relating to the application and enforcement of the DSA in that country.
While the Commission enjoys exclusive competence to supervise, enforce and monitor compliance by Very Large Online Platforms (VLOPs) and Very Large Online Search Engines (VLOSEs) with the enhanced due diligence obligations the DSA imposes upon them to address systemic risks, the Commission and the national authorities share competence for all other obligations imposed on VLOPs and VLOSEs under the DSA.
The European DSCs have the power to request access to data, order inspections and impose fines on providers of intermediary services in their territory in the event of an infringement. They are also responsible for certifying “trusted flaggers”, independent organisations who are experts in detecting, identifying and removing illegal content, and out-of-court dispute settlement bodies.
Source: https://digital-strategy.ec.europa.eu/en/policies/dsa-dscs

Leave a Reply

Your email address will not be published. Required fields are marked *

two × 1 =