Ethics and safety·October 9, 2026, 04:36

Grok sued: Accused of scanning users' faces without consent

AI-generated and checked against the sources listed below.

A user in Illinois is suing Grok's owners, SpaceXAI, because the chatbot allegedly scanned faces in uploaded images without permission. The case is based on one of the strictest US laws on biometric data.

AI-generated image

A user from the US state of Illinois has sued the companies behind the AI chatbot Grok. That's according to the legal news services Bloomberg Law and Law360. The case has been filed as a class action, in which one person sues on behalf of a larger group of users in the same situation.

What is the case about?

The plaintiff is Cesar Padilla, who uses Grok. He claims that he uploaded selfies to Grok to get professional portrait photos and stylized edits. According to the complaint, Grok scanned his face geometry in that process without his consent. Face geometry is the measurable features of a face, such as the distance between the eyes, nose and mouth. This kind of data can be used to recognize a person.

The defendants are SpaceXAI Corp. and SpaceXAI LLC, which own and develop Grok. According to Bloomberg Law, the case was filed on October 7, 2026, in the federal court for the Northern District of Illinois.

Illinois' strict law

The lawsuit is based on Illinois' biometric information law, known as BIPA. The law requires companies to:

- obtain written consent before collecting, for example, facial data - have a public policy on how long data is stored - not profit from such data

BIPA has previously led to many lawsuits against large technology companies. Snapchat, Google and Microsoft, among others, have been sued under the law.

What does it mean?

The case has only just been filed, and no ruling has been made. Therefore, only the plaintiff's claims are known. I have not been able to find information about what SpaceXAI is responding or how much in damages is being sought.

For ordinary users, the case is a reminder that a photo of your face can contain more than a picture. When you upload selfies to an AI service, the service can potentially extract biometric data. It is worth checking the terms before sharing photos of yourself, and especially photos of others.

In the EU and Denmark, biometric data is also specially protected under the data protection rules, GDPR. The US case, however, only concerns US law.

Sources

More on this topic

Get the week's AI news in your inbox

Choose your level, topics and length. One email a week, unsubscribe at any time.

Subscribe to Promptly Newsletter
PromptlyNewsletterRSSLog in

The news on aijour is AI-generated and checked against the cited sources.