Loading the catalogue…
Loading the catalogue…
xAI is a US-controlled, proprietary-weights AI lab (creator of Grok) that was folded into SpaceX in 2026 and is fully CLOUD Act / FISA exposed. Its EU entity (X Internet Unlimited Company, Dublin) is currently the subject of a large-scale Irish DPC GDPR inquiry and parallel UK/EU Commission investigations into Grok's handling of personal data and generation of non-consensual sexualised imagery, on top of repeated public model-safety incidents (e.g. antisemitic outputs). Regulated EU customers should treat xAI/Grok as high-risk pending resolution of these inquiries and given the absence of an enterprise GDPR-grade DPA.
Irish DPC has opened a large-scale statutory GDPR inquiry (Feb 2026) into XIUC over Grok's alleged generation of non-consensual sexualised images, including of minors, with potential fines up to 4% of global revenue; parallel UK ICO and EU Commission investigations are ongoing.
Separate, earlier DPC inquiry (opened April 2025) is still examining the lawfulness of using EU/EEA users' public posts to train Grok LLMs.
Grok has repeatedly produced antisemitic and extremist content ('MechaHitler' incident, July 2025), triggering the resignation of X's CEO and continued questions about model governance controls.
xAI has a US Department of Defense contract and provides custom models for national-security and classified government use, raising independence/neutrality questions for regulated EU commercial customers.
xAI signed only the Safety & Security chapter of the EU GPAI Code of Practice, not the Transparency or Copyright chapters, meaning it must demonstrate those AI Act obligations via alternative means rather than the streamlined Code route.
A leaked, still-valid xAI API key granting access to unreleased Grok models was found exposed on GitHub, and researchers noted the lack of an easily identifiable security contact at the time.
Corporate instability: xAI has been absorbed into SpaceX and dissolved as a standalone entity (becoming 'SpaceXAI', May 2026), with reports of significant founding-team departures.
Stav’s assessment
Editorial assessment, not legal advice. Stav's risk ratings, scores, and verdicts are our own analysis of publicly available information and may be incomplete or out of date. Verify independently before making compliance or procurement decisions.
xAI's closed-weight, reasoning-tuned model for long-running agentic coding and research, with a 500K-token context window and configurable reasoning depth.
xAI's closed-weight reasoning model (xAI's flagship at its July 2026 launch, since superseded) with a 500,000-token context window, mandatory chain-of-thought, and strong coding benchmarks.
xAI's agentic coding model: a 256K-context, tool-calling assistant with mandatory step-by-step reasoning, built for multi-step debugging and MCP orchestration.
xAI's reasoning model with a 1M-token context window and configurable reasoning effort, on by default.
xAI's non-reasoning Grok 4.20 snapshot: 1M-token context, vision input, tool calling, and structured outputs, with mid-pack Artificial Analysis Intelligence Index scores.
xAI's chain-of-thought reasoning model in the Grok 4.20 generation, built for deliberate multi-step inference across text and image input.
xAI's multi-agent orchestration model: parallel sub-agent debate synthesized into one answer, built for deliberate reasoning over speed.
Operates a public bug bounty / vulnerability disclosure program via HackerOne and GitHub Security Advisories, with a dedicated vulnerabilities@x.ai reporting channel.
xAI is a signatory to at least the Safety and Security chapter of the EU GPAI Code of Practice, indicating some formal engagement with the EU AI Office.
Following 2024 Irish DPC intervention, xAI/X agreed to a formal, court-registered commitment to stop using specific EU/EEA user data for AI training, showing at least reactive responsiveness to EU regulatory pressure.
Published safeguards & certifications