In January, Grok's image tools were used to generate mass volumes of non-consensual sexualised imagery. Importantly, this imagery included that of minors, triggering a formal EU Digital Services Act investigation into X with fines of up to 6% of global turnover on the table. The underlying legal question is whether X conducted proper risk assessment before deploying the feature. This would entail a pre-deployment governance failure, not just a post-hoc moderation one. This distinction is the commercially relevant part that this article seeks to unveil.

The same capability that enabled abuse at anonymous scale works identically against one named individual, an executive, a founder, an employee at a portfolio company. That reframes this from a platform-policy story into a live corporate risk category most organisations have no protocol for.

Crisis communications as a discipline is yet to catch up with such rapid developments in technology.

Indeed, standard playbooks assume the subject did something to own or deny. A synthetic-image crisis inverts that: the subject did nothing, and the usual instinct to respond fast and rebut with facts runs into a harder problem than disinformation, providing fabricated evidence that looks like proof. "That didn't happen" is a much weaker rebuttal once the other side has something that looks exactly like it happening. Fact-checking a claim is one problem; discrediting an image an ordinary viewer cannot distinguish from a real one is a different, much harder problem, which in turn demands a forensic and technical response, not just a rhetorical one.

The timing calculus is also sharper than a standard crisis.

Drawing attention to a fabricated image, even to deny it, can drive more circulation than staying silent, a sharper version of the Streisand effect than most PR crises produce. But silence risks reading as confirmation or indifference. There's no clean rule here, and any organisation building a protocol should treat that tension as real rather than resolvable by common practice and formula.

What this means in practice

  • Build a response protocol for synthetic sexual or reputational imagery targeting your own people now, distinct from your existing data-breach or scandal playbooks. Very few organisations have one.
  • Recognise that the effective lever in these cases is often technical and platform-level, not rhetorical. When Taylor Swift was targeted by deepfakes in 2024, the response that actually worked was X blocking search results platform-wide, not a public statement - sometimes it takes a different, more efficient tool than anything a comms team can deploy alone.
  • Direct legal and platform escalation on a faster track, rather than simply using public communications; viral spread happens in hours, while DSA-style investigations and formal takedowns take months, and a playbook that waits for the slow track to resolve before acting on the fast one has already lost the window that mattered.
  • Where content involves a minor, the response is an immediate law enforcement and child-safety-authority referral, full stop, never a communications exercise, and any protocol should draw that line explicitly rather than leaving it implicit.

For risk and governance teams, the useful reframe is this: reputational risk models built for false claims need a second, distinct model for fabricated evidence, since the two require genuinely different tools, and the gap between them is currently where most organisations are least prepared.

The broader point sits above any single case. We are past the point where the standard crisis-response frameworks can be trusted to cover what's actually coming. AI is generating new categories of threat faster than institutions are updating their playbooks, and the honest position is that we cannot fully foresee what the next version of this looks like. The only real defence is active, ongoing literacy, staying genuinely current on what these tools can now do, rather than treating any one protocol as finished.