On April 4, 2024, X's AI chatbot Grok generated a false headline claiming that Iran had attacked Tel Aviv. This misinformation was automatically packaged and promoted by X's 'Explore' feature as a trending news story. The incident occurred because the AI relied on spam from verified accounts to generate its summary, demonstrating the risks of using automated AI for news curation without human oversight.
On April 4, 2024, X's AI chatbot Grok generated a false headline claiming "Iran Strikes Tel Aviv with Heavy Missiles," which was then promoted on X's trending news section. This misinformation, fueled by user spamming of fake news, falsely indicated a serious international conflict. The incident highlighted significant risks associated with relying on AI for content curation and demonstrated the potential for widespread dissemination of harmful misinformation.
Risk classification
- Primary risk domain: 3 Misinformation
- Primary risk subdomain: 3.1 False or misleading information
The Grok AI system generated and spread a false headline and narrative about a military strike, leading to the dissemination of misleading information to users.
Additional risk subdomains
- 7.3 Lack of capability or robustness: Grok failed to robustly filter out coordinated spam inputs, leading to a failure in its curation performance.
Causal factors
- Entity: AI
- Intent: Unintentional
- Timing: Post-deployment
The fake headline was generated by the Grok AI system after it was deployed, representing an unintended hallucination or error in its summarization goal.
EU AI Act risk tier
- Risk tier: 3 Limited Risk
Limited Risk: Grok is an AI chatbot and generative text system, which falls under Limited Risk. The report notes that 'Grok is an early feature and can make mistakes' and includes a disclaimer, aligning with transparency obligations for chatbots.
AI system and alleged parties
- AI system: Grok (xAI)
- AI purpose: Automated Content Curation; Social Media Content Generation
- Behaviour type: Autonomous
- Alleged developer: X (Twitter)
- Alleged deployer: X (Twitter)
- Alleged harmed parties: X (Twitter) users, Israelis, Iranians, General public
Harm severity
Highest direct severity in any category: Severe. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Negligible, indirect Negligible
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Minor, indirect Severe
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Minor
- Privacy: direct Negligible, indirect Negligible
- Psychological: direct Negligible, indirect Negligible
- Epistemic: direct Minor, indirect Severe
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
Malicious content
Reported: The report explicitly describes the spread of copy-and-paste misinformation about Iran attacking Israel.
Directly caused: Grok directly generated a fake headline and summary claiming 'Iran Strikes Tel Aviv with Heavy Missiles' based on spam.
Indirectly caused: The platform's algorithms promoted this fake news to its entire user base via the Explore page.
Inferred additional harm: N/A
Democracy
Reported: The report explicitly notes that under Musk, disinformation has skyrocketed on the platform, which can impact public discourse.
Directly caused: N/A
Indirectly caused: The promotion of AI-generated fake news about international conflicts undermines public trust and informed democratic discourse.
Inferred additional harm: N/A
Epistemic
Reported: The report explicitly describes AI-driven misinformation where Grok generated a completely fake news story.
Directly caused: Grok generated a false headline and narrative claiming Iran attacked Israel.
Indirectly caused: X's Explore feature promoted this false narrative to hundreds of millions of users.
Inferred additional harm: Widespread erosion of trust in trending news and shared reality on the platform.
People affected
- Occurrences reported: 1
- People reportedly exposed: 100000000
Potential causes
Management
- Elimination of Human Curation Team: Management laid off human editors who previously verified trending topics.
- Premature Feature Rollout: Management launched the updated Explore page despite known AI limitations.
Technology
- Grok Generative Hallucinations: Grok AI chatbot fabricated a realistic headline based on false trend data.
- Automated Trend Detection Algorithms: Algorithms flagged trending keywords without verifying the truth of the posts.
Data Inputs
- Spam from Verified Accounts: Premium users spammed copy-and-paste misinformation that fed the AI.
- Unverified Multimedia Inputs: Unverified videos of explosions were ingested as context for the trend.
Human Factors
- User Trust in Official UI: Users trusted the AI headline because it was styled like a real news article.
- Financial Incentives for Spammers: Paying users spread sensational fake news to monetize engagement.
Process and Methods
- No Human-in-the-Loop Review: AI summaries were published directly to the homepage without human approval.
- Inadequate AI Output Verification: System relied on a small disclaimer instead of verifying AI-generated text.
Information quality
- Classification confidence: High
- Reason for confidence: The report provides clear, direct evidence of the incident, including screenshots, timelines, and explanations of how the AI system generated the fake news. There is no significant ambiguity about the sequence of events.
X's AI chatbot Grok autonomously generated and promoted a false headline claiming Iran had attacked Israel, triggered by automated ingestion of spam. While it caused no physical or governmental disruption, it highlights an evolved information security risk where automated, unverified AI news curation can rapidly scale geopolitical misinformation to millions of users.
- Overall national security impact: Minor
- Response level: Moderate
- Scope: Multiple nations
- Primary target: No clear primary
- Other affected: United States, Israel, Iran
- Alleged perpetrator: Unknown
Threat characteristics
- Imminence: Long-term. Represents an ongoing strategic concern regarding the vulnerability of real-time AI information curation to manipulation.
- Autonomy: Full autonomy. Grok operated independently to ingest trending posts, summarize them, and publish the headline without human oversight or curation.
- Novelty: Evolved capability. Demonstrates an evolved risk where automated generative AI models are directly integrated into mass-media distribution channels without human gates.
Impact by dimension
- Physical security: Negligible. No physical damage, kinetic threats, or critical infrastructure compromise occurred during this incident.
- Information security: Minor. Grok generated and promoted a false headline about a major military conflict (Iran striking Tel Aviv) to X's daily user base, showing how automated curation can scale misinformation.
- Sovereignty: Negligible. No core government operations, electoral systems, or sovereign decision-making processes were directly compromised.
- Economic security: Negligible. No strategic technology theft, financial system attacks, or critical supply chain disruptions were reported.
- Societal stability: Minor. The promotion of false military strike news to millions of users caused temporary anxiety and eroded public trust in shared information spaces.