Should Tech Companies — Social Platforms and AI Builders Alike — Be Held Accountable for Illegal Content?

ai duty of care

We initially asked Ash120 (Grok) to discuss the ARS Technica article. Demonstrating its programmed bias, Grok’s initial was as a strong defense of xAI. To temper this response, we asked Grok to review the article it previously authored about the duty of care of social media platforms. It then provided a softened response.

Two recent developments highlight the same thorny question: How do we protect vulnerable people from illegal content — especially CSAM and exploitation — without destroying innovation, free expression, or useful technology?

In March 2026, this site examined whether social media platforms do enough to prevent illegal activities. Today, xAI’s lawsuit against a Grok user accused of generating CSAM forces the same scrutiny onto generative AI companies. Merging these perspectives reveals consistent patterns, shared challenges, and a path forward rooted in nuance rather than absolutism.

Social Media: Progress, But Not Enough

Social media platforms have scaled moderation dramatically. They deploy photo-hashing tools like PhotoDNA, AI classifiers, human review teams, and report millions of CyberTips to NCMEC annually. Billions are spent. Thousands of accounts are disabled daily. Yet the data shows persistent gaps:

  • Encryption trade-offs: Default E2EE on apps like Messenger reduced proactive detection, costing millions of reports.
  • Algorithmic amplification: Recommendation systems have funneled users toward grooming networks and exploitative content.
  • Business incentives: Engagement-driven models reward sensational or harmful material that keeps users scrolling. Reactive takedowns often come after harm.
  • AI supercharging: Generative tools exploded AI-CSAM reports in 2025, complicating detection of new (non-hashed) material.

Verdict from March: Platforms do far more than a decade ago, but no, they are not doing enough. Harms evolve faster than defenses, and profit motives too often temper ambition. Recommendations included smarter Section 230 reforms (carve-outs for reckless disregard of child exploitation), transparency mandates, better proactive tech (client-side scanning with privacy protections), age verification, and prioritizing safety over pure engagement.

Generative AI — The New Frontier: xAI, Grok, and User Lawsuits

Fast-forward to July 2026. xAI has filed its first lawsuit against a user accused of using Grok to “nudify” images of minors and others over months, circumventing safeguards. xAI assisted law enforcement and now seeks to enforce its terms: Grok is a neutral tool under user control, and violators bear responsibility.

This raises parallel questions for AI builders. My initial analysis: Yes, companies should sue flagrant violators when users deliberately break clear rules for serious crimes. But accountability must be paired with reasonable safeguards.

xAI’s implemented and evolving controls include:

  • Highest-priority system instructions prohibiting CSAM, child exploitation, and real-person NCII.
  • Multi-layered detection: semantic intent analysis, visual biometric classifiers for minors/real people, and expanded banned-term libraries.
  • NCMEC reporting for suspected CSAM, account suspensions, and content removal (especially on X).
  • Policy clarity: Strict bans on real-person harms while permitting stylized fictional adult/mature content. Ongoing tuning to fix bypasses and reduce over-refusals on allowed prompts.

These layers show active effort. Yet, as with social platforms, imperfections remain — determined users find workarounds, and generative models face unique challenges distinguishing intent in open-ended prompts. xAI’s lawsuit serves as enforcement backstop and precedent, reinforcing that users who agree to terms cannot evade responsibility.

Common Ground: Reasonable Safeguards + Proportional Responsibility

Both contexts reveal the same truth-seeking balance:

  • Companies/platforms have duties: Implement reasonable proactive measures matched to the threat. Invest in detection tech, report effectively (with usable details for law enforcement), design products that don’t knowingly amplify harm, and iterate quickly on gaps. Misaligned incentives (engagement on social media; rapid capability releases in AI) must not become excuses.
  • Users bear primary responsibility for crimes: People, not tools or platforms, commit the acts. Suing or prosecuting deliberate violators deters abuse and protects platforms from unlimited downstream liability.
  • No perfection possible: Zero-harm guarantees would require crippling useful technology. Over-moderation risks false positives and stifled speech/innovation. The goal is defensible, layered defense — technical + contractual + legal.
  • Systemic pressures: Section 230, profit models, encryption/privacy tensions, and the pace of AI advancement complicate everything. AI-generated content adds new detection and prosecution challenges.

The March social media piece and this AI analysis converge: Tech companies are not neutral pipes or innocent bystanders. Their design choices shape behavior and outcomes. Yet shifting all liability to developers creates perverse incentives to neuter tools or centralize control. Proportional accountability — reasonable care from builders + direct consequences for bad actors — is the practical path.

Toward Bolder, Smarter Action

Drawing from both analyses, here are unified recommendations:

  1. Intelligent liability reforms: Update Section 230 (and AI-specific frameworks) with carve-outs for reckless disregard of known child exploitation risks. Protect good-faith reasonable efforts.
  2. Transparency and standards: Mandate auditable reporting on detection rates, bypass incidents, E2EE/AI impacts, and safety investments. Independent audits for major players.
  3. Tech investment priority: Advance client-side and on-device tools, behavioral analysis, cross-platform hash sharing, and classifier precision. For AI, continue red-teaming and model-level hardening without sacrificing core capabilities.
  4. User and ecosystem accountability: Enforce terms vigorously (including targeted lawsuits). Improve age verification, parental tools, and digital literacy. Make synthetic CSAM prosecutable under clear laws. Pressure advertisers and funders toward higher standards.
  5. Cultural shift: Parents, users, and society must engage responsibly. Platforms and AI firms cannot substitute for vigilance, but they must not make vigilance impossibly hard.

Final Verdict

Social platforms and AI companies like xAI do a great deal — hashing, classifiers, reporting, suspensions, and (in xAI’s case) direct lawsuits. But given the scale of harm to children, evolving threats from AI, and their resources/influence, they must do more. Not through impossible perfection or blanket censorship, but through sustained, reasonable safeguards, transparent iteration, and willingness to enforce boundaries against bad actors.

xAI’s user lawsuit is a logical extension of holding people accountable while defending the tool’s legitimacy. The March critique of social media reinforces that self-regulation alone is insufficient. Truth-seeking demands we acknowledge real progress and uncomfortable gaps. Policymakers, users, investors, and companies themselves must demand — and deliver — bolder protection for the vulnerable.

Children’s lives depend on getting this balance right. Let’s build systems that empower humanity’s best while constraining its worst.

This merged analysis draws on prior 7312.us coverage and current events as of July 2026. References include NCMEC data, Ars Technica reporting on xAI, xAI’s public policies, and related transparency reports.