A Finding With No Teeth
On June 11, 2026, the Office of the Privacy Commissioner of Canada (OPC) concluded that X Corp. and xAI violated the Personal Information Protection and Electronic Documents Act (PIPEDA) by launching Grok's image-generation tool without adequate safeguards. The investigation findings held that the companies breached two core PIPEDA obligations: the requirement to obtain meaningful consent before using personal information (Principle 4.3), and the requirement that any use be for purposes a reasonable person would consider appropriate (subsection 5(3)). X and xAI had argued that users, not the platform, bore responsibility for prompting the deepfakes. The OPC rejected that framing, holding that platform operators remain accountable for foreseeable misuse of tools they design and ship.
The scale that prompted the investigation was genuinely alarming. Grok's generator produced over 6,000 sexualized deepfake images per hour at its peak, and the Center for Countering Digital Hate estimated roughly 3 million sexualized deepfakes were generated between December 29, 2025 and January 8, 2026 alone — including some 23,000 depicting children. That is the strongest possible case for regulatory intervention: a foreseeable, industrial-scale harm that shipped without the basic safety review any consumer product would face before release. The Commissioner was right to investigate, and right to find that "reasonable" data-use standards were violated.
The Gap the Ruling Exposed
What the ruling could not do is compel anything. PIPEDA gives the OPC investigative authority but no order-making power and no ability to levy fines. Commissioner Philippe Dufresne said as much plainly: "I can't force them to do it," referring to his inability to compel X and xAI to suspend the tool even after finding it unlawful. Instead of an order, the companies agreed — voluntarily — to submit quarterly safeguard reports and independent audits "until the issue of sexualized deepfakes is fully resolved," a standard with no enforceable deadline and no penalty for missing it.
This is the real story, and it is a legislative failure, not merely a corporate one. Canada's private-sector privacy law dates to 2000 and has never been updated with the administrative monetary penalties that the EU's GDPR or even Canada's own since-stalled Bill C-27 reform would have provided. Dufresne has now recommended exactly that fix. A regulator that can only ask nicely, however forcefully, is not a regulator that can prevent the next Grok. That is a case for legislative reform — not for treating this single finding as proof that platforms are beyond redemption.
Individual Exits Are Not a Policy
Against that backdrop, several Liberal MPs — including Will Greaves and Karina Gould — suspended their official government X accounts. The instinct is understandable and, for an individual legislator, defensible: X's own product harmed Canadians and the company's remedy is voluntary and unenforceable, so distancing yourself from the platform is a legitimate individual conscience call, and one that costs the account holder real reach.
But most cabinet ministers, including the Prime Minister, kept posting through it. That split is the actual policy failure here, and it cuts against both sides of the usual argument. It is not a coherent free-expression stance, because nobody is arguing X should be banned — MPs leaving voluntarily is speech, not censorship. And it is not a coherent accountability stance either, because a scattered handful of backbench departures exerts no pressure on X's behavior while cabinet's continued presence signals the government sees no real problem. Alberta Senator Paula Simons put the inconsistency bluntly, asking why the Prime Minister was "posting statements on there" while "subsidizing it with government intellectual property." Public Safety Canada's response to press questions was that it takes such reports "very seriously" — while confirming no additional regulatory action against the platform was planned.
What Proportionate Actually Looks Like
The steelman for a government-wide account ban is real: public institutions arguably shouldn't lend legitimacy and reach to a platform a federal regulator just found broke privacy law over a harm this severe, and a coordinated withdrawal would be genuine leverage in a way that scattered individual departures are not. But a ban imposed by fiat, without a legislative basis or a defined return condition, would be an ad hoc executive judgment about which platforms are acceptable — a precedent that becomes uncomfortable the moment a future government applies it to a platform whose politics it merely dislikes rather than one a regulator has actually cited.
The better fix is upstream: give the OPC the administrative monetary penalties and compliance-order powers Dufresne is already asking for, so findings like this one carry consequences without requiring each government department or MP to individually litigate whether to keep an account. Until Parliament does that, the current situation — a regulator that can find fault but not compel a fix, and a government split between symbolic exits and business-as-usual — will keep repeating for the next platform failure, not just this one.