Scandal with Grok: xAI Published hundreds of thousands of conversations without user consent

August 21, 2025  14:56

Elon Musk’s company xAI has faced heavy criticism after it was revealed that hundreds of thousands of user conversations with the Grok chatbot were made public and became searchable on Google without the users’ knowledge. Forbes reports that users were not warned that the “share” function leads to chat indexing by search engines. Among the published data were instructions for making drugs, bombs, and even a plan to assassinate Musk himself.

How Did This Happen?

When a Grok user clicks the “share” button, a unique link (URL) is created, allowing the conversation to be sent via email, messenger, or other channels. However, it turned out that these links are automatically published on the Grok website and become available for indexing by search engines such as Google, Bing, and DuckDuckGo. Users received no warnings or notifications about this.

According to Forbes, Google indexed more than 370,000 Grok conversations. These included harmless queries, such as drafting tweets or analyzing news, as well as those blatantly violating xAI’s rules. The company prohibits using the bot to “facilitate harm to people” or to develop “biological, chemical, or weapons of mass destruction,” yet the indexed chats contained instructions for producing fentanyl, methamphetamine, bombs, malware, and even a plan to kill Elon Musk.

“I was surprised that the Grok chats I shared with my team were automatically indexed by Google without any warning, especially after the recent ChatGPT scandal,” said Nathan Lambert, a research scientist at the Allen Institute for Artificial Intelligence in Seattle. He used Grok to create summaries of his blog posts, unaware that they would become publicly available.

Reaction from Users and Experts

British journalist Andrew Clifford, who used Grok for news analysis and tweet drafting for his site Sentinel Current, also did not know his queries would appear in search results. “I would have been a little annoyed, but there was nothing in my chats that shouldn’t have been there,” Clifford told Forbes, adding that he has now switched to using Google Gemini.

Some of the indexed chats contained sensitive information: medical questions, personal data, and even passwords. Uploaded user files — images, spreadsheets, and text documents — were also publicly accessible. This raised concerns about data privacy and security.

Similar Issues at Other AI Companies

xAI is not the only company facing this kind of issue. In July 2025, OpenAI’s ChatGPT users discovered that their conversations, marked as “discoverable,” had appeared in Google search results. Following public backlash, OpenAI called it a “short-term experiment” and disabled indexing. OpenAI’s Chief Information Security Officer Dane Stuckey wrote on X: “This opened up too many opportunities for accidental disclosure of information users never intended to make public.”

Afterward, Elon Musk and the Grok account on X claimed that the chatbot had “no such feature” and that it “prioritizes privacy.” Musk even posted: “Grok ftw” (for the win). However, as Forbes revealed, the “share” function does exist, and since January 2025 users on X had been warning that Grok conversations were being indexed by Google.

SEO Manipulation

Opportunists have already begun exploiting Grok’s vulnerability for promotional purposes. On LinkedIn and the BlackHatWorld forum, marketers discussed how to create and publish Grok chats to boost their products’ visibility in search results. Satish Kumar, CEO of SEO agency Pyrite Technologies, demonstrated to Forbes how one company used Grok to promote dissertation-writing services.

“Every published Grok chat is fully indexed and searchable on Google,” Kumar noted. “People are actively using these tactics to push their pages higher in Google’s index.”

Google, in turn, stressed that website owners can control whether their content is indexed. “The publishers of these pages have full control over whether they are indexed,” said Google spokesperson Ned Adriance. Google itself stopped indexing chats from its Bard bot in 2023, while Meta continues to allow search engines to index its chats.

xAI’s Response and Implications

xAI did not respond to Forbes’ request for comment. The lack of response or user warnings has fueled debate about the company’s transparency on privacy issues. Some of the dangerous queries likely came from security researchers testing Grok’s limits, but even professional AI researchers like Nathan Lambert were caught off guard.

This incident raises broader questions about how AI companies handle user data, especially when such data can become public without consent. The Grok situation underscores the need for clear notifications and strict privacy policies to protect users.

In Brief

The publication of more than 370,000 conversations with the Grok chatbot without user warnings has dealt a serious blow to xAI’s reputation. The “share” function made chats indexable by search engines, including confidential data and prohibited queries such as instructions for making drugs, weapons, and even a plan to assassinate Elon Musk. The case echoes the recent ChatGPT scandal, but in Grok’s case the lack of user notifications worsens the issue. Experts urge users to be cautious with the “share” function and demand greater transparency from xAI in handling data.


 
 
 
 
  • Archive