xAI filed suit against Terry Wayne Harwood, a South Carolina man who allegedly weaponized Grok—the company's AI chatbot—to generate child sexual abuse material.
The lawsuit treats this as straightforward. A bad actor breached the terms of service, committed a crime, and should be held liable. But this framing assumes something nobody in the room has actually defended.
It assumes xAI can be sued for what users do with its system but not held liable for what its system itself produces. That assumption is about to collapse.
When a payment processor like Stripe or PayPal gets sued for facilitating fraud, they hide behind Section 230 immunity. When a hosting company like Cloudflare discovers CSAM on its servers, it reports it and operates as a conduit. But Grok didn't host Harwood's material—Grok generated it. The output is not user-created content that the platform merely transmitted.
xAI cannot argue both that it took safety seriously and that its safety failed because one man was clever enough to break it.
”Section 230 explicitly excludes liability for content that platforms develop themselves. Neutral conduits are protected. Co-creators are not. This distinction has been dormant because until now, nobody built an AI system and then sued when someone used it to make CSAM. The category didn't exist. Harwood's alleged method matters here—he didn't find the images somewhere and distribute them through Grok, he circumvented safeguards that xAI supposedly installed.