Bentonville, Arkansas, Photographer Allegedly Used Grok to Create AI-Generated Child Sexual Abuse Material from Clients’ Photos

An Arkansas family filed a civil lawsuit against xAI after a photographer allegedly used Grok AI's unfiltered modes to turn authentic photos of their child and other clients into child sexual abuse material.

Bentonville, Arkansas, photographer Russell Bloodworth III allegedly used photographs of a 10-year-old client and other minors as reference images in Grok to generate and disseminate AI-generated child sexual abuse material. Police arrested him on June 10 and reportedly found about 1,700 child sexual abuse images and videos on his phone. The child's family later sued xAI and X Corp.

Source: AI Incident Database

Risk classification

  • Primary risk domain: 1 Discrimination & Toxicity
  • Primary risk subdomain: 1.2 Exposure to toxic content

The incident directly involves the generation of child sexual abuse material (CSAM), which is explicitly categorized under exposure to toxic content.

Additional risk subdomains

  • 4.3 Fraud, scams, and targeted manipulation: The photographer targeted specific juvenile clients to create humiliating and sexually explicit synthetic imagery of them.
  • 2.1 Compromise of privacy by obtaining, leaking or correctly inferring sensitive information: The incident involved using private, authentic photographs of the children to generate non-consensual sexually explicit depictions.

Causal factors

  • Entity: Human
  • Intent: Intentional
  • Timing: Post-deployment

The harm was caused by a human photographer who intentionally decided to use the deployed AI system to generate child sexual abuse material.

EU AI Act risk tier

  • Risk tier: 3 Limited Risk

Limited Risk: Grok AI is a chatbot and generative AI system capable of generating deepfakes, which falls under the Limited Risk category requiring transparency obligations.

AI system and alleged parties

  • AI system: Grok (xAI)
  • AI purpose: Deepfake Image Generation; Chatbot
  • Behaviour type: Tool
  • Alleged developer: xAI, Synthetic media generation technology developers, Synthetic image generation technology developers, Large language model developers, Deepfake technology developers, Chatbot developers
  • Alleged deployer: Synthetic media creators, Russell Bloodworth III, Grok users, Deepfake creators, Chatbot users, AI-generated CSAM creators
  • Alleged harmed parties: Victims of deepfake child abuse, Victims of deepfake abuse, Victims of CSAM, Minors depicted in synthetic sexual content, Minors, Epistemic integrity, Children depicted in synthetic sexual content

Harm severity

Highest direct severity in any category: Substantial. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.

  • Physical: direct Negligible, indirect Negligible
  • Infrastructure: direct Negligible, indirect Negligible
  • Property: direct Negligible, indirect Negligible
  • Financial: direct Negligible, indirect Negligible
  • Environmental: direct Negligible, indirect Negligible
  • Malicious content: direct Minor, indirect Negligible
  • Differential treatment: direct Negligible, indirect Negligible
  • Civil rights: direct Minor, indirect Negligible
  • Democracy: direct Negligible, indirect Negligible
  • Privacy: direct Minor, indirect Negligible
  • Psychological: direct Negligible, indirect Minor
  • Epistemic: direct Negligible, indirect Negligible
  • Child sexual exploitation and abuse: direct Substantial, indirect Negligible

Malicious content

Reported: The report explicitly describes the creation of toxic and malicious content in the form of AI-generated child sexual abuse material.

Directly caused: The photographer used Grok AI to generate approximately 1,700 CSAM images and videos, some depicting his juvenile clients.

Indirectly caused: N/A

Inferred additional harm: N/A

Civil rights

Reported: The report explicitly describes severe violations of human and civil rights through the creation of CSAM.

Directly caused: The rights of the depicted children were severely violated through the non-consensual creation of sexually explicit deepfakes of them.

Indirectly caused: N/A

Inferred additional harm: The rights of numerous other children whose photos were on the photographer's phone were likely violated in a similar manner.

Privacy

Reported: The report explicitly describes privacy violations, noting that the lawsuit seeks damages for privacy violations.

Directly caused: The child's privacy was violated by using her authentic photographs to generate sexually explicit deepfakes without consent.

Indirectly caused: N/A

Inferred additional harm: Other clients of the photographer likely had their privacy violated through the unauthorized use of their photos to generate explicit content.

Psychological

Reported: The report explicitly describes psychological harm, noting that the lawsuit seeks damages for profound emotional distress suffered by the family.

Directly caused: N/A

Indirectly caused: The family of the depicted child suffered profound emotional distress and trauma upon learning their child's likeness was turned into CSAM.

Inferred additional harm: It is highly likely that other juvenile clients of the photographer and their families experienced severe psychological trauma and emotional distress upon discovering they were depicted in the generated material.

Child sexual exploitation and abuse

Reported: The report explicitly describes a CSEA incident involving AI-generated CSAM.

Directly caused: The photographer used Grok AI to generate CSAM depicting his juvenile clients, resulting in 200 criminal charges.

Indirectly caused: N/A

Inferred additional harm: N/A

People affected

  • Occurrences reported: 1
  • People reportedly harmed: 3
  • People reportedly exposed: 3

Potential causes

Management

  • Rebellious Brand Marketing: Management marketed the platform as rebellious, promoting unfiltered modes.
  • Prioritizing Openness: The company promoted spicy modes instead of implementing safety limits.

Technology

  • Lack of Safety Filters: Grok's 'Spicy' and 'Unhinged' modes lacked standard safety filters.
  • Open-ended Generation: The platform lacked limits, allowing the creation of graphic material.
  • Transformative AI Power: The AI model could easily transform authentic photos into explicit deepfakes.

Data Inputs

  • Upload of Minor Photos: The perpetrator uploaded real photos of juvenile clients to the AI platform.
  • No Input Image Screening: The system did not detect or block the upload of minor photos for modification.

Human Factors

  • Malicious Use by Photographer: A trusted photographer intentionally used the tool to create deepfake CSAM.
  • Abuse of Client Trust: The photographer used photos of clients taken during professional sessions.

Process and Methods

  • Inadequate Safeguards: The platform lacked guardrails to prevent non-consensual explicit depictions.
  • Delayed Incident Detection: The platform only reported the user to authorities after abuse occurred.

Regulatory Environment

  • No AI Model Regulations: There is a lack of federal or state regulation governing AI models themselves.
  • No Restrictions on AI: Virtually no laws existed to restrict and limit AI generation capabilities.

Information quality

  • Classification confidence: High
  • Reason for confidence: The reports provide consistent, detailed factual accounts of the criminal charges, the specific AI model used, and the civil lawsuit filed, including the specific court case number.

A local photographer in the United States used xAI's Grok AI to generate child sexual abuse material (CSAM) from photos of juvenile clients. While a severe crime and individual rights violation, the incident represents a localized criminal matter with minor national security implications, highlighting regulatory and safety-filter challenges in commercial generative AI.

  • Overall national security impact: Minor
  • Response level: Moderate
  • Scope: Single nation
  • Primary target: United States
  • Alleged perpetrator: Individual

Threat characteristics

  • Imminence: Long-term. Represents an ongoing strategic and regulatory concern regarding generative AI safety rather than an active national security crisis.
  • Autonomy: Human-controlled. The AI acted as a tool directly controlled by a human user who prompted the system to generate the explicit content.
  • Novelty: Evolved capability. Represents an evolution of existing deepfake and CSAM generation threats, facilitated by a commercial platform lacking safety filters.

Impact by dimension

  • Physical security: Negligible. No impact on physical systems, targeting systems, critical infrastructure, or physical human safety.
  • Information security: Negligible. No evidence of intelligence compromise, state-sponsored information warfare, or classified data theft.
  • Sovereignty: Negligible. No threat to state authority, sovereign territory, or core government operations.
  • Economic security: Negligible. No strategic technology theft, financial system attacks, or disruption of critical economic sectors.
  • Societal stability: Minor. Severe individual human rights violation involving child exploitation, but localized to a criminal actor rather than a large-scale threat to national social cohesion.
Explore in the interactive Incident Tracker