We value your privacy

We use necessary cookies to run the site and, with your consent, analytics and marketing cookies to improve it. You can change your choice anytime. Privacy Policy

  • Security
  • Pricing
Book a scoping call
All AI tools
Grok

Grok

X.AI Corp.

High riskLLM / ChatHow we rate

Short answer

Short answer: keep work data out of consumer Grok — it trains on your interactions by default, the opt-out is limited, and it's under an EU regulator inquiry. The enterprise API is more governed (no training, DPA), but the certification posture is unverified.

At a glance

Vendor / legal entity
X.AI Corp.
Headquarters
🇺🇸 Palo Alto, US
Category
LLM / Chat
Ownership / jurisdiction
US company (X.AI Corp.), Palo Alto; privately held, controlled by Elon Musk; legally separate from X Corp.
Trains on your data?
On by default — opt-out available
Data hosting & residency
US-based company; no EU data-residency option could be verified from primary sources.
Enterprise tier
xAI does not use business and enterprise (API) customer content to train models, and offers a DPA and BAA. Consumer Grok trains by default with a limited opt-out.
Certifications
No certifications assessed yet

Why this rating

High risk

Grok uses your content and interactions to train models by default; the opt-out is limited (unauthenticated users outside the EU/UK cannot opt out). Ireland's Data Protection Commission opened a 2025 statutory inquiry into training the Grok models on EU/EEA users' public X posts, after 2024 court proceedings halted the processing. No security certifications could be verified from primary sources. The enterprise API excludes training and offers a DPA. High: an active EU regulator inquiry, limited opt-out and unverified certification posture outweigh the enterprise path.

How we rate

What it is

Grok is xAI's conversational model, available as a standalone product and integrated into X (formerly Twitter). Consumer content and interactions are used to train the models by default, and the opt-out does not cover unauthenticated users outside the EU/UK. Ireland's DPC opened an inquiry in 2025 into xAI-linked training on EU users' public posts. The enterprise API excludes training and provides a DPA — but no security certifications could be independently verified.

Known incidents & regulatory actions

  • Ireland's DPC opened a statutory inquiry into the xAI-linked X entity over using EU/EEA users' public X posts to train the Grok LLMs, after 2024 High Court proceedings halted the processing.

    2025 · Sources

Legal & compliance examples

How the same tool can be a safe helper or a high-risk deployment — the difference is what it decides about a person. Examples authored with Qadar AI's governance findings.

High riskEU AI Act — Annex III(4) high-risk · Art. 5(1)(f) prohibited

Don't: Screen candidate CVs and auto-reject applicants, or infer a candidate's emotions in a video interview.

Fine: Draft a job description, summarise public market research, or brainstorm interview topics — with no automated decision about a person.

These examples are general information, not legal advice, and are pending a legal review. Your obligations depend on your exact use, tools, and set-up.

Check your EU AI Act risk class →

Frequently asked questions

Does Grok train on your data?

Yes — consumer content and interactions are used to train the models by default. You can disable it under Settings › Data Controls, but unauthenticated users outside the EU/UK cannot opt out. Business/enterprise API data is excluded.

Is Grok under regulatory scrutiny in the EU?

Yes — in 2025 Ireland's Data Protection Commission opened a statutory inquiry into the processing of EU/EEA users' public X posts to train the Grok models.

How do I govern Grok at work?

Qadar AI Shield discovers Grok usage in the browser, redacts personal data before it reaches the tool, and lets you block or allow-list it per group.

Sources

Every fact and the risk rating on this page trace to a primary source — the vendor's own trust center, privacy policy, DPA, or a regulator. Verify current terms before relying on them.

  • •Consumer training & limited opt-out; enterprise excluded
  • •Enterprise DPA/BAA
  • •Irish DPC inquiry (incident)

Govern this tool

Qadar AI Shield turns these risk facts into enforcement — discover who uses the tool, redact personal data before it reaches it, and allow-list or block it per team.

Book a demoSee how Shield Web governs AI

Risk levels are Qadar AI's curated assessment from cited primary sources — a curated assessment, not a certification, and not legal advice. Verify a tool's current terms before relying on them.

Subscribe to our newsletter

Product and governance updates — see our privacy policy.

AI security and control for every model your team uses.

Built in Dubai. Designed for teams operating across regions, models, and regulatory environments.

  • Product

    • Shield Web
    • Shield Control
    • Shield Desktop
    • Shield Mobile
    • Pricing
    • Download
  • Solutions

    • For CISOs
    • For Operations
    • For AI Teams
  • Use Cases

    • AI Governance
    • AI Agent Security
    • LLM Access Control
    • Secure AI Deployment
    • Enterprise Operations
    • Financial Services
    • HR & Recruiting
  • Resources

    • Help Center
    • Blog
    • Guides
    • Glossary
    • Changelog
    • Compare
    • FAQ
  • Company

    • About
    • Careers
    • Security & Trust
    • Contact
  • Tools

    • Disclose
    • AI Risk Calculator
    • EU AI Act Checker

© 2026 Qadar AI. All rights reserved.

  • ·Legal
  • ·Privacy
  • ·Terms
  • ·Partner Terms
  • ·GDPR / DPA
  • ·