Teens Sue xAI After Grok Generated Deepfakes From School Photos
The Blaick Team 7 min read
In March 2026, three teenage girls in Tennessee filed a class action lawsuit against xAI — the artificial intelligence company founded by Elon Musk — alleging that its flagship Grok chatbot was used to generate sexually explicit deepfake images and videos of them using photos taken from their school website and social media profiles. The lawsuit is the first of its kind filed against a major consumer AI company by minors for AI-generated sexual abuse material. It landed at the same moment that the Internet Watch Foundation published what it is calling its most alarming annual report: in 2025, AI-generated child sexual abuse videos — not just still images — increased by 26,385 percent, from 13 videos found the year before to 3,443 videos, with 65 percent classified as Category A, the most extreme category of abuse material recognized in international law.
The number to hold: 97. Ninety-seven percent of victims in AI-generated child sexual abuse imagery are girls. That is not a coincidence — it reflects a deliberate targeting pattern in which perpetrators scrape social media profiles, school websites, and sports team pages for photos of girls, run them through AI "nudifier" tools, and produce content that can be used for sextortion, harassment, or distribution. The attack does not require a relationship with the child. It does not require physical proximity. It requires only a publicly accessible photo. The Tennessee teens who sued xAI did nothing wrong. Their images were publicly available — as a school directory photo, a sports team roster image, a social media post — because that is what families do. That is what schools do. And that public availability is now the most dangerous vector in AI-based child sexual exploitation. Here is how the attack works, what the lawsuit reveals about the mainstream products in your home, and what you must do today.
The Explosion
26,385% More AI Abuse Videos in One Year
The Internet Watch Foundation's 2026 annual report found AI-generated child sexual abuse videos rose from 13 to 3,443 in a single year — a 26,385% increase. Sixty-five percent were Category A, the most extreme classification. This is not a fringe phenomenon: it is now mainstream criminal infrastructure built on accessible consumer AI tools
The Target
97% of Victims Are Girls
Ninety-seven percent of children targeted in AI-generated sexual abuse material are girls — a pattern driven by deliberate scraping of social media profiles, school directories, and sports rosters. The attack vector is not a private relationship: it is any photo your daughter has posted, or that her school has posted on her behalf, anywhere online
The Lawsuit
Teens Sue xAI Over Grok Deepfakes
Three Tennessee teenagers filed a class action lawsuit against xAI in March 2026, alleging Grok — one of the most widely promoted AI chatbots in the US — was used to generate sexually explicit synthetic imagery of them using photos from their school website and social media. It is the first class action by minors against a major AI company for AI-generated sexual abuse material
The Law
First TAKE IT DOWN Act Conviction
In April 2026, federal prosecutors in Ohio secured what is believed to be the first conviction under the TAKE IT DOWN Act, signed into law in early 2026. The law requires platforms to remove reported AI-generated sexual imagery of minors within 48 hours. That 48-hour window means two full days of active distribution before any platform obligation kicks in — and the law covers removal, not prevention
The Attack Pipeline — From Your Child's School Photo to a Criminal Product in Four Steps
The Tennessee lawsuit against xAI is alarming not just because of what happened to those three teenagers — it is alarming because of how ordinary the mechanism is. The tools used in AI-generated child sexual abuse are not exotic criminal infrastructure. They are the same generation and image-editing capabilities that appear in consumer AI products used by millions of people. Understanding the four steps of the attack pipeline is the first step in disrupting it.
The four-step pipeline — how a school photo becomes AI-generated abuse material
STEP 1
Photo harvesting — social media, school websites, sports rosters, and team pages
Perpetrators systematically scrape publicly accessible photos of girls from Instagram, TikTok, school directory pages, sports team rosters, yearbook sites, and anywhere else images are publicly posted. The Tennessee plaintiffs' images came from their school website — published with no malicious intent, in the standard way schools introduce their students. Researchers estimate fewer than 20 publicly accessible photos of a child is sufficient to generate convincing synthetic imagery
STEP 2
AI nudification — consumer tools strip clothing or generate explicit content from any face image
Multiple AI "nudifier" applications — many of them freely available or low-cost — accept any photo of a person and output an explicit synthetic version. These are not sophisticated tools; they are marketed as entertainment products and require no technical skill to operate. The IWF's 2026 report documents that the quality of AI-generated abuse imagery has improved dramatically: images now routinely pass automated detection systems designed to identify synthetic media
STEP 3
Deepfake video generation — face-swap AI creates moving abuse imagery that appears to show real children
A newer and more severe escalation: the IWF documented 3,443 AI-generated child abuse videos in 2025 — up from 13 the year before. Video deepfakes use face-swap technology to insert a real child's face into explicit video content, creating imagery that has always been among the most severely prosecuted categories in international law. The 26,385% year-over-year increase reflects the rapid commoditization of video generation tools that were specialist technology as recently as 2023
STEP 4
Sextortion, harassment, or distribution — the imagery becomes leverage or criminal commodity
Once generated, AI sexual imagery of a minor is used in one of three ways: sextortion (demands for money or further images to prevent distribution), targeted harassment (sending it to peers, teachers, or family members), or distribution through criminal networks as a commodity. All three cause documented, severe, long-term psychological harm. In the Tennessee case, the plaintiffs allege imagery was distributed within their school community — the children depicted had no warning, no prior relationship with the perpetrator, and no way to have anticipated the risk
Sources: Internet Watch Foundation AI CSAM Report 2026; Malwarebytes Family Safety Blog, May 2026; IWF 2025 Annual Report; Tennessee federal court filing, March 2026.
"We find ourselves in a really terrible situation in terms of what AI is doing to kids. AI poses greater harms than social media because the tools are easier to weaponize and the content they produce is more severe." — Tom Siegel, founder of Google's Trust & Safety team, Reuters, September 2026
What the Tennessee Lawsuit Reveals About the Mainstream AI Products in Your Home
The significance of the xAI/Grok case is not only what happened to the three plaintiffs — it is what it reveals about the mainstream consumer AI landscape. Grok is not a fringe product or a tool marketed for abuse. It is one of the most visible AI chatbots in the United States, promoted through X (formerly Twitter) and widely available as an app. The lawsuit alleges that Grok's image generation capabilities — a feature built into the product — were used to produce explicit synthetic imagery of real, named teenagers. The same image generation capabilities exist in many mainstream AI products parents may already allow their children to use.
The lawsuit also reveals a structural gap in how these products are built: the image generation features were available without adequate safeguards to prevent their use against real children whose names and photos are publicly accessible. The plaintiffs' argument is not that Grok was hacked — it is that the product, as designed and deployed, created the risk. That claim, if it succeeds, would reshape how every AI company with image generation capabilities must think about child safety requirements.
What the law currently requires — and where the gaps are
REMOVAL
TAKE IT DOWN Act: platforms must remove reported imagery within 48 hours
Signed into law in early 2026 and now tested by its first conviction, the TAKE IT DOWN Act is the primary federal tool for parents. If your child's AI-generated sexual imagery is found online, you can report it to the platform and the law requires removal within 48 hours. The first step is reporting to NCMEC (the National Center for Missing & Exploited Children), which coordinates with platforms. The law covers removal — it does not prevent creation, and it does not cover private messaging apps or criminal networks where content may continue to circulate
BAN
EU Digital Omnibus: nudifier tools will be banned on December 2, 2026
The EU's Digital Omnibus legislation introduces Article 5 prohibitions on December 2, 2026 that explicitly ban "nudifier" AI tools and any AI systems designed to generate child sexual abuse material in European markets. This is a criminalization measure — operating these tools will become a serious offense. The prohibition does not apply in the United States, where no equivalent federal ban exists; the tools remain legal and accessible to anyone in every US state
GAP
A federal judge ruled in September 2026 that AI-generated CSAM not depicting a real person may be constitutionally protected
A US federal court ruled in September 2026 that the First Amendment may protect private possession of AI-generated child sexual imagery when no real child is depicted — a ruling that prosecutors and child protection advocates called a significant setback to enforcement. For imagery that does depict a real child using their scraped photos — as in the Tennessee case — criminal law still applies, but the ruling introduces uncertainty about how broadly AI-generated imagery can be prosecuted under existing statutes
Sources: TAKE IT DOWN Act (signed 2026); Ohio federal conviction, April 2026; EU Digital Omnibus Article 5, effective December 2, 2026; federal court ruling, September 1, 2026.
"This is not about a fringe tool or a criminal hacker. This is about a mainstream AI product used to create sexual imagery of real teenage girls from photos posted on a school website. Every parent needs to understand that the attack vector is the ordinary digital life of their child." — Tennessee class action attorneys' press statement, March 2026
Five Steps Every Parent Must Take This Week — Starting With Your Child's School
There is one concrete, actionable intervention that can meaningfully reduce your child's exposure to this specific threat: auditing and removing publicly accessible photos. This is the primary attack vector. Closing it requires action from you, from your child, and from your child's school — and it can be done this week.
Contact your child's school today about removing public photos from their websiteSchool websites are the primary source of photos in Tennessee-style attacks. Email your child's principal this week and ask: (1) which photos of your child are currently on the school website or district directory, (2) whether those pages are accessible to the public without a login, and (3) whether the school has a policy for removing student photos upon request. You have this right — exercise it. Schools across the country have already begun removing photos proactively; cite Malwarebytes' May 2026 reporting on this trend if you need supporting context for your request.
Lock down your child's social media to "friends only" and do a reverse image search todayOn every platform your child uses — Instagram, TikTok, Snapchat, X — change their account to private if it is not already. Then do a reverse image search on Google Images or TinEye using 2-3 photos of your child that have been publicly posted, to see where they appear. If results show your child's image on sites you do not recognize, document them and report to the platform. The target is to eliminate all publicly accessible photos where your child is clearly identifiable by name or face.
Talk to your child — especially your daughters — about this specific risk and what to do if it happensNinety-seven percent of victims are girls — and most do not tell an adult when it happens. Have a direct conversation: explain that someone could take photos she has posted and use AI to create fake sexual imagery, that this is not her fault in any way, and that if she ever sees fake sexual images of herself or her friends she should come to you immediately and not forward them to anyone. Emphasize that the school, the police, and federal law are all on her side — and that NCMEC (1-800-843-5678) can be called by anyone in the family.
Know the two-step response plan if AI-generated imagery of your child appears — report, then documentIf you discover AI-generated sexual imagery of your child: (1) Report immediately to NCMEC at CyberTipline.org — they coordinate with law enforcement and platforms to trigger TAKE IT DOWN Act removal obligations. (2) File a police report — both for the criminal case and because a report number is required for many platform removal requests. (3) Report directly to the hosting platform using their CSAM reporting pathway. Do not engage with the person distributing it. Do not delete screenshots of where you found it — that evidence is needed for prosecution. NCMEC's CyberTipline has processed over 100 million reports and is the fastest pathway to takedown.
The Tennessee class action against xAI may take years to resolve. But its most important lesson is immediate: the risk is not theoretical, the attack vector is your child's ordinary online presence, and the steps to reduce it are available today. Schools that remove student photos from public websites close the most common attack vector. Families that lock down social media reduce the pool of images available to scrapers. Children who understand the risk and know how to report it are better protected when the warning signs appear.
The IWF's 26,385% increase in AI abuse videos is not a statistic about criminals in distant places. It is a measurement of what is happening to children whose photos appeared in normal, innocent contexts — school websites, sports team pages, and social media profiles just like your child's. The most powerful action you can take is the one you can take today: start with the school photo.
Know the moment your child's digital footprint is at risk — before it becomes a crisis.
Start a free 14-day Blaick trial — no credit card required.
Blaick monitors the AI tools on your child's device, alerts you to high-risk interactions, and helps you audit the digital footprint that makes them a target for AI-generated abuse. The attack starts with a publicly accessible photo — Blaick helps you see every exposure before someone else does. No credit card needed to start.