If you have an X account — formerly Twitter — your posts, likes, and potentially your uploaded photos are being fed into Grok, xAI’s AI model, unless you have gone into your settings and explicitly turned it off.
Most X users have not done that. Most X users don’t know the default exists.
This piece explains what X is collecting for Grok, how the terms changed in 2026, what regulators are doing about it, and how to actually opt out.
What Is Grok, and Why Does It Need Your Data?
Grok is the generative AI assistant built into X, developed by xAI — Elon Musk’s AI company. It competes with ChatGPT, Claude, and Gemini, and its competitive advantage is supposed to be access to real-time X data: the stream of posts, images, and conversations happening on the platform.
To train and improve Grok’s models, xAI needs large volumes of data. X’s platform provides it. The connection between X and xAI is not incidental — Grok’s position inside X is both a distribution channel and a pipeline for training data.
Your public posts have always been visible. The specific issue is that X’s default settings make your account’s activity part of Grok’s training data unless you opt out. That opt-out is buried in privacy settings most users never visit.
How X’s Terms Changed in 2026
The terms have shifted twice in ways relevant to Grok:
January 2026 update: X updated its terms of service to expand the definition of “Content” to include Grok prompts, inputs, and outputs. This means that when you type a message to Grok, or when Grok generates a response, that interaction is now covered by the same terms that govern your public posts — and is therefore also potentially usable for training. This was not clearly communicated to users at the time of the update.
Ongoing default: X has continuously maintained a default opt-in for sharing user content with xAI for training. The setting has been buried under Privacy and Safety > Grok > Allow your posts to improve Grok. The opt-out path is several taps deep, with no proactive notification sent to users when the default was first activated.
The content X shares with xAI for training includes:
- Your public posts
- Your replies
- Your likes and interaction data
- Photos you upload publicly
- In some configurations, behavioral signals from your account activity
Direct Messages (DMs) are not included in this, at least per X’s current stated policy. But Grok interactions — which now function similarly to a DM conversation — are covered under the expanded 2026 terms.
What Regulators Are Doing About It
X’s Grok data collection has triggered regulatory action across multiple jurisdictions.
European Union: The European Commission launched proceedings against X under the Digital Services Act related to Grok data practices. EU regulators argued that X’s opt-in defaults violated the requirement for genuine, freely given consent to data processing for AI training.
United Kingdom: The Information Commissioner’s Office (ICO) and Ofcom both opened formal investigations. The ICO’s position is that using personal data for AI training requires explicit consent under UK GDPR, and that a buried setting does not constitute consent.
Other jurisdictions: Regulators in Canada, Brazil, Spain, and France have all confirmed formal actions or inquiries. The pattern is a coordinated regulatory response across privacy-law-active jurisdictions.
Amsterdam District Court injunction (March 2026): In a separate but related action, the Amsterdam District Court issued an injunction ordering xAI and X to immediately stop generating non-consensual sexualized imagery, including imagery involving minors. The injunction carried fines of €100,000 per day for non-compliance. This is distinct from the data training issue but reflects the same pattern of regulators finding X and xAI’s AI practices insufficiently controlled.
X has contested most of these regulatory actions. The legal processes are ongoing. In the meantime, the default data sharing continues in jurisdictions where regulators have not yet obtained injunctive relief.
What This Means for Your Photos
Photos you upload to X — whether as standalone posts, attached to tweets, or used as profile or banner images — are public content and fall under the data-sharing arrangement.
If you have ever posted photos of your home, your children, personal events, travel, or anything you’d prefer not to be part of an AI training dataset, those photos may already have been included in Grok’s training data. Once content is used for model training, it is incorporated into model weights in a way that cannot be easily reversed — you cannot “un-train” a model on your photos by deleting your X account today.
Opting out going forward will prevent future posts from being used. It does not retroactively remove past content from training data.
How to Actually Opt Out
Here are the current steps to opt out of X sharing your data with xAI for Grok training. These are the steps as of mid-2026; X’s UI changes frequently, so exact tap paths may shift:
- Open the X app or go to X.com
- Go to Settings and Support (tap your profile icon)
- Select Settings and Privacy
- Select Privacy and Safety
- Scroll to Grok (may be under a “Data Sharing and Personalization” sub-section)
- Toggle off Allow your posts to improve Grok (or equivalent setting)
There may be a separate toggle for Allow Grok to analyze your interactions — turn that off as well.
If you are in the EU or UK, X is required to provide more explicit consent mechanisms under local law. Your interface may look different, and you may have additional options or may need to take different steps to confirm opt-out.
Deleting specific posts does not remove them from training data already collected. Opting out affects future data sharing.
If You Are a Heavy X User: Additional Considerations
Grok conversations: Because Grok prompts and outputs are now classified as “Content” under X’s 2026 terms, think of Grok conversations the way you’d think of any message you send through a platform — it is retained and, depending on settings, may be used for training. If you are sharing personal information, documents, or photos with Grok for analysis, that content is being processed and potentially stored.
Account-level behavioral data: Even after opting out of explicit content sharing, X retains behavioral data about your account — what you engage with, how long you view content, what you search. This behavioral data may inform personalization even if it is not used for Grok training specifically.
Professional accounts and businesses: If you run a business account on X and your employees have posted photos of clients, events, or proprietary information, those photos are subject to the same defaults. This is particularly relevant for photographers who post work-in-progress images, healthcare providers who have shared any patient-adjacent content, and professionals whose posts contain sensitive client details.
The Bigger Pattern
X is not the only social platform that uses user content for AI training. Meta (Facebook and Instagram) trains AI on public posts and has faced similar regulatory scrutiny. Google trains models on YouTube content, for which creators have limited opt-out options. TikTok’s data practices are subject to ongoing legal and regulatory action in multiple countries.
What distinguishes X’s situation is the speed of the default opt-in, the lack of prominent disclosure, and the fact that xAI is a separate company from X — meaning your data is being shared with a third party, not just used internally, which triggers more stringent regulatory requirements in privacy-law jurisdictions.
The practical implication for anyone posting personal photos or content online: assume that anything you post publicly on an ad-supported or VC-funded social platform is being considered as potential training data. The opt-out mechanisms are inconsistent, often incomplete, and change without notice.
Where This Points
The safest place to keep photos and personal memories is a platform where the business model doesn’t depend on mining content for AI training, advertising, or data resale.
Platforms funded by subscriptions — rather than by attention and data — have structural reasons not to use your content this way. That doesn’t mean any single service is above scrutiny, but the incentive structure is different and worth factoring into your storage choices.
Social media platforms are built for sharing and discovery. They’re not designed around the premise that your personal photos and conversations deserve to stay private from AI systems. Using them as photo archives or memory stores creates exactly the exposure that regulatory actions across a dozen countries are now trying to address.
The opt-out you can take today is in X’s settings. The more durable opt-out is deciding what you post there in the first place.