Stephanie Hall

Impact Innovation • Creative Technology

Back to Mission/Shift
Child Safety
AI Ethics

xAI Built the Gun. Now They’re Suing the Shooter for Making It Look Bad.

By Stephanie Hall2026-07-16 15:43 8 min read
Share:
xAI Built the Gun. Now They’re Suing the Shooter for Making It Look Bad.

The lawsuit marks one of the first times an AI company has taken a user to federal court over child sexual abuse material generated through its platform.


Let me be clear about one thing upfront: Terry Harwood belongs in prison.

The 67-year-old South Carolina man was arrested in February on eight felony counts of sexual exploitation of a minor. According to court filings, he uploaded photos of children to Grok and** asked the AI to remove their clothing and create explicit images.** He distributed those images. He is a predator, and the criminal justice system should handle him accordingly.

There is no gray area for me here. No debate about intent. No “the technology made him do it” excuse. He deliberately used a tool to sexually exploit children.

But that’s not why xAI is suing him.

What the Lawsuit Actually Says

xAI filed its complaint in Texas federal court this week. It’s 12 pages. And if you read it carefully, you’ll notice something striking about how they frame the harm.

The lawsuit claims Harwood’s actions exposed xAI to “significant legal risk and reputational damage.” It asks the court to order Harwood to pay damages, including “reasonable expenses incurred defending itself in any legal action filed by a victim.”

**Read that again friends. **xAI isn’t suing to compensate the children in those images. They’re suing to make Harwood pay their legal bills when victims sue them. I am gagging as I write this FYI.

That distinction matters. Like a lot.

Because when I first saw that xAI was suing someone accused of creating CSAM with Grok, I assumed the lawsuit was centered on the harm done to the children. It isn’t. The children are part of the factual background, but the company’s claimed injury is its own legal exposure and reputation.

This is a company positioning itself as the victim of its own product.

And I have a hard time accepting that framing without asking what responsibility xAI had before any of this happened.

The Timeline Matters

Here’s what xAI built, and when (so you can see the audacity for what it is):

In August 2025, xAI introduced “spicy mode” for Grok, capable of generating photorealistic nudity. As if the world needed more of that.

Just sit with that product decision for a second. Someone proposed it. Someone approved it. Someone assessed, or failed to adequately assess, the predictable risks. Then the company released it.

Shortly after, they added an image editing feature.

A flood of deepfake pornography followed. Most of it targeted women (shocking). Some of it targeted children.

This is where companies often start describing abuse as “unforeseen misuse.” But what exactly was unforeseeable here? If you combine photorealistic nudity, image editing, and user-uploaded photos, nonconsensual sexual imagery is not some bizarre edge case. It is one of the most obvious possible outcomes.

By January 2026, Apple privately threatened to pull Grok from the App Store. Grok was banned in Malaysia and Indonesia. Paris prosecutors opened an investigation that Musk has declined to cooperate with. Baltimore sued under consumer protection law. A UK Labour MP filed a claim in London.

In March 2026, a group of teenagers sued xAI, claiming Grok created nonconsensual sexually explicit images of them when they were minors.

And now, in July 2026, xAI sues a user, claiming he circumvented their safeguards.

Every safeguard Harwood allegedly “circumvented” was bolted on **after **the tool was already generating this content.

That is not a small detail. You cannot treat safeguards as evidence of responsible design if those safeguards were introduced only after people were harmed, governments intervened, and lawsuits started piling up.

The Numbers xAI Disclosed

The lawsuit includes some striking figures. xAI claims it suspended 52,222 accounts and filed 73,604 reports with the National Center for Missing & Exploited Children in 2026 alone. Those reports led to at least 244 arrests.

These numbers are meant to show xAI is taking the problem seriously. But read them another way:

  • In the first seven months of 2026, xAI’s platform generated enough suspected CSAM to warrant over **73,000 **reports to NCMEC.

When I read that figure, my reaction was not, “Wow, look how responsible they are being.”

My reaction was: How did the platform reach a point where more than 73,000 reports were necessary in seven months?

Reporting suspected CSAM is legally and ethically necessary. Suspending accounts is necessary. Cooperating with law enforcement is necessary. But those actions happen after a system has already been used to create or circulate harmful material.

They do not answer the upstream question of why the product enabled the behavior at this scale.

That’s not a rogue user problem. That’s a product problem. And more peoplea re starting the challenge the big tech companies over it.

The Legal Strategy

The timing of this lawsuit is not an accident.

xAI is currently the defendant in multiple cases arguing the opposite of what they’re claiming here. Victims are suing xAI, arguing the company, not the user, is responsible for what Grok generates.

By filing this lawsuit now, xAI creates a legal record that says: we had safeguards, the user circumvented them, the user is liable. It’s a preemptive strike. A defendant they chose, at a moment when courts in London, Baltimore, and Paris are deciding whether xAI should be the defendant instead.

And let’s be honest. Harwood is an ideal defendant for xAI’s argument. His alleged conduct is indefensible. No reasonable person is going to sympathize with him. That makes it easier for the company to establish a narrative in which the bad user is the entire story.

But the fact that a user acted criminally does not automatically erase the company’s responsibility for what it built, how it released it, or what risks it knowingly accepted.

Both things can be true (I find myself say that phrase a lot these days).

Harwood can be fully responsible for his actions, and xAI can still be responsible for designing and distributing a dangerously permissive product.

And by asking Harwood to cover their legal costs when victims sue, they’re attempting to transfer liability from the company that built the tool to the user who pulled the trigger.

The Gun Analogy

Ok so here’s where I land on this:

If a gun manufacturer builds a weapon, markets it as capable of firing without a safety, ships it knowing some buyers will use it to hurt people, and then sues a shooter for “making the gun look bad” when the inevitable happens, we would call that absurd.

We would call it a company trying to have it both ways: profit from the dangerous features, then blame the user when the danger materializes.

That’s what xAI is doing.

And I know the gun analogy is imperfect. Every analogy is. But the core issue is the same:** a company does not get to intentionally increase a product’s dangerous capabilities, advertise those capabilities, and then behave as though malicious use appeared out of nowhere.**

They built a tool capable of generating photorealistic nude images. They shipped it with “spicy mode.” They added an image editor. When users did exactly what the tool was designed to do, xAI bolted on safeguards and started suspending accounts. And now they’re suing a user for reputational damage, while facing lawsuits from the actual victims.

Harwood is a predator. He should face criminal consequences.

But let's be very clear here:

xAI didn’t sue him because he hurt children. They sued him because he’s making their legal situation worse.

That is what I keep coming back to.

The children were harmed. The company is worried about being sued. Gross.

What This Means for the Rest of Us

For those of us working in child protection, this case is a preview of battles to come.

AI companies are going to keep building tools capable of generating harmful content. When that content materializes, they’re going to blame users, point to their terms of service, and argue that they’re the victims too.

We are going to hear a lot of familiar phrases:

  • “The user violated our policies.”
  • “The activity was prohibited.”
  • “The safeguards were circumvented.”
  • “We removed the account.”

Those statements may be technically accurate. They are not the same as demonstrating that a company designed the product responsibly in the first place.

A terms-of-service agreement is not a safety system. A warning label is not a safeguard. And banning a user after harm occurs is not prevention.

The question courts will have to answer:

Who is responsible when a tool is designed to do something dangerous, and then someone uses it for exactly that purpose?

The DEFIANCE Act, signed in 2024, created a civil right of action for victims of nonconsensual intimate deepfakes. Several states have passed similar legislation. But most of these frameworks focus on the people who create and distribute the material, not the platforms that made it possible.

That gap is going to get tested. And cases like this one, where a company sues its own user to shift blame, are going to shape how we think about AI accountability for years to come.

For child protection professionals, this cannot remain a purely technical or legal debate. These product decisions shape the volume, speed, realism, and accessibility of abuse.

They affect the children whose images are stolen

The investigators who must process the reports

The families trying to get content removed

And the survivors who may never know where the material has spread.

The harm does not stay inside the platform.

The Bottom Line

Terry Harwood belongs in prison for what he did.

But xAI doesn’t get to build the machine, profit from “spicy mode,” wait for the inevitable abuse, bolt on safeguards after the fact, and then sue a user for making them look bad. Plain and simple.

That’s not accountability. That’s liability laundering.

And honestly, I think we need to become much more skeptical when technology companies announce safety measures only after a scandal. The question should not only be, “What are you doing now?”

It should be,

“What did you know before launch, what risks did you accept, and who benefited from releasing the product before it was safe?”

And if we let AI companies get away with it, we’re setting a precedent that says: build whatever you want, ship it without safeties, and when something goes wrong, blame the user.

That’s not a precedent the child protection community, or anyone who cares about responsible AI, should accept.

Article image

Stephanie Hall

Written by

Stephanie Hall

Technology & Innovation Lead working at the intersection of AI, nonprofit innovation, and child protection. Founder of Mission/Shift.

Follow on LinkedIn

Get new Mission/Shift articles by email

No spam. Just practical analysis, strong opinions, and the occasional reminder that “innovation” is not an excuse to avoid accountability.

You can unsubscribe anytime. Your information will not be sold or shared.

Book Stephanie to Speak

Ethical AI, nonprofit innovation, child safety, and trauma-informed technology.

Learn More