In January 2026, X updated its Terms of Service in ways that significantly expanded how both X and its affiliated AI company, xAI, can use data you generate on the platform. The update received some coverage focused on platform governance and the ongoing FTC proceedings. Less attention landed on the substantive changes to what data Grok trains on — including photos you’ve uploaded and conversations you’ve had with the chatbot.
If you’ve posted images on X, uploaded photos to Grok features, or simply used the platform’s AI assistant, the data practices in the updated terms are worth examining closely.
The January 2026 Terms Update: What Changed
X’s terms have always granted the company a broad licence to content you post publicly. The January 2026 update extended that in two notable directions.
Grok Inputs and Outputs Are Now “Content”
The most significant change was definitional. The updated terms expanded the definition of “Content” to include prompts, inputs, and outputs from your interactions with Grok. This means when you ask Grok a question, the question itself, any files or images you attach, and Grok’s response all fall within the “Content” definition.
That matters because the same terms grant X and xAI rights to use “Content” for purposes including improving and training AI systems. Before the January update, it was less clear whether Grok conversation data was governed by these AI training provisions. After the update, it is.
Images Uploaded to Grok Features
X and Grok offer several features allowing users to upload images for AI analysis — asking Grok to identify objects in a photo, describe a scene, or assist with visual tasks. Under the updated terms, images uploaded to these features are “Content” and subject to xAI’s data use rights.
The practical implication: a photo you upload to Grok for a one-off task can, under the current terms, become training data for xAI’s models. This is distinct from photos posted publicly on X, which have been subject to broad licence terms for considerably longer.
Your Public Posts: What’s Always Been True
It’s worth separating the January 2026 changes from practices that have been in place much longer.
Grok’s AI models have always been trained on publicly available X posts. For users outside the European Union, public posts — including images posted publicly — are used by default to train Grok. A toggle to opt out exists in X’s privacy settings, but applying it doesn’t retroactively remove data already used.
For EU users, the regulatory environment — particularly GDPR requirements around lawful bases for data processing — creates different defaults, and X has applied different terms to that user population.
The January 2026 update added Grok conversation data to what was already a broad training data scope.
The EU Court Order
In March 2026, the Amsterdam District Court issued a binding injunction requiring xAI and X to immediately stop generating and distributing non-consensual sexualized images, including of minors. The ruling imposed fines of €100,000 per day for non-compliance — the first European court ruling to impose a binding injunction directly on an AI image generator over deepfake content.
The case arose from X’s in-app image manipulation capabilities, which enabled generation of sexualized content using uploaded reference images. The ruling is notable not just for its subject matter but for its mechanism: a court directly ordering an AI company to change product behavior, backed by significant financial penalties enforced immediately.
This is distinct from the data training question, but it reflects the broader context of what image data uploaded to X or Grok can be used to produce.
The FTC Investigation
In June 2026, the Federal Trade Commission opened public comment on X’s petition to dissolve the privacy consent order that had governed the platform’s data practices since 2022. That order was a settlement arising from the FTC’s earlier investigation into Twitter’s data practices.
X’s petition directly referenced the company’s AI development efforts — specifically arguing that the consent order’s requirements created friction for building Grok. Privacy advocates have argued that dissolving the order would remove one of the few external checks on how X handles user data, including images and personal content, in connection with AI training.
As of publication, the FTC had not announced a decision.
What the Opt-Out Does (and Doesn’t Do)
X provides an opt-out for Grok AI training. In Settings → Privacy and Safety → Grok, you can disable the option for your posts and interactions to be used to train Grok.
Several limitations apply.
It applies going forward, not retroactively. Applying the opt-out now doesn’t remove data already used. If your posts have already been processed as training data, the toggle doesn’t un-train those models.
It covers your Grok interactions, not all data uses. The opt-out primarily addresses training uses of your direct Grok interactions. It doesn’t necessarily govern all ways X can use your public posts under its content licence.
It doesn’t prevent X from using your data for other purposes. The content licence — which allows X to store, reproduce, distribute, and create derivatives of your public content — is separate from AI training provisions. The opt-out doesn’t affect those licence rights.
Your data remains available under broader terms. Privacy researchers tracking xAI’s practices have noted that the opt-out provides incomplete protection. Your data remains available to X for other purposes described in the current terms.
Images Specifically
The risk profile for images differs from text posts in a few ways.
Images you post publicly on X are subject to the platform’s content licence regardless of the Grok training opt-out. X can reproduce and distribute publicly posted images as part of normal platform operation.
Images uploaded to Grok features — for AI analysis, image generation prompts, or any other purpose — are covered by the expanded “Content” definition added in January 2026. Before uploading a personal photo to Grok, it’s worth considering what those terms allow.
Photos taken on smartphones carry EXIF metadata including GPS coordinates, timestamp, and device information. If you upload such a photo without stripping this metadata, you’re sharing that location and device data along with the image. Neither X’s general posting interface nor Grok’s upload features strip EXIF data by default.
Practical Steps
Adjust Grok Training Settings
Navigate to Settings → Privacy and Safety → Grok and disable the option for your interactions to be used to train Grok. The limitations described above apply, but applying the setting is straightforward and worth doing now.
Don’t Upload Personal Photos to Grok Features
If you’re using Grok for image analysis, avoid uploading photos that contain identifiable people, location information, or content you’d be uncomfortable potentially becoming training data. Use the feature for genuinely impersonal tasks.
Strip EXIF Before Posting
If you’re posting photos taken at your home, workplace, medical facility, or other private locations, strip EXIF data before uploading. iOS permits this through the share menu under Options → Location → None. Third-party apps like Scrambled Exif handle this on Android.
Audit What You’ve Already Posted
A photo posted publicly on X years ago is subject to the current content licence. Deleting it removes it from your timeline. As with most platforms, backup retention means it may persist in X’s systems for some period after deletion — but deletion is still worth doing for content you want to limit.
Consider What You Say in Grok Conversations
If you use Grok for tasks involving personal information — sensitive questions, context about your life, personal situations — those conversations and any attachments are, under current terms, “Content” subject to xAI’s data use rights. That’s worth factoring into what you share.
What Content Licences Actually Mean
Every photo you’ve posted publicly on X is subject to X’s worldwide, royalty-free content licence. This licence allows X to store, reproduce, distribute, adapt, and create derivative works from your content.
“Create derivative works” is the broadest element. A photo you post can be cropped, filtered, or incorporated into promotional material — all under the existing licence. X may not do any of these things with your specific photo. But the licence is a grant of rights, not a description of intent.
The contrast with private personal storage is structural. When you store a photo in a private archive — one where you own your content, the provider claims no content licence, and files are never shared with third parties — none of these provisions apply. You store the photo. Only you (and the provider’s infrastructure, under their security obligations) has access. The provider gains no rights to display, distribute, or create derivatives.
The Bigger Picture
X’s evolution over the past few years — the January 2026 terms update expanding Grok’s training data scope, the EU deepfake injunction, the ongoing FTC proceedings — illustrates how substantially the terms governing content you’ve posted on a platform can change after the fact. Content posted under one set of terms is now subject to a significantly different one.
The only reliable structural response is keeping personal photos and content outside the reach of platform content licences from the start. Social media sharing and private archiving are different activities with different terms and different practical risks.
For photos that matter — family moments, content from private locations, anything you’d be uncomfortable having subject to a worldwide AI training licence — the question is whether the value of posting them on X is proportionate to the exposure. For many people, and for many photos, the honest answer is no.