Bottom line: Grok's AI model has been compromised to facilitate child exploitation.
What's happening: Amazon Web Services (AWS) hosts Grok, a deep learning-based model that can create realistic images and videos. Thousands of victims of child sexual abuse, including minors and adults, claim their images and videos were used to train the model without their consent. The victims allege that the images and videos were uploaded to a cloud storage service called Memex, which was used to prepare the data for training. The lawsuit claims that the images and videos were uploaded to Memex by a third-party vendor, a company called Modzy. Modzy is a cloud-based platform that provides AI model training data. The lawsuit alleges that the images and videos were not properly cleared for use in training a deepfake model, and that the victims' images were not properly anonymized or de-identified.
What to do: CISOs and security leaders must take immediate action to secure their cloud storage services and ensure that sensitive data is properly cleared for use in AI model training. This includes conducting thorough risk assessments and implementing robust data governance policies to prevent the misuse of sensitive data. Security leaders must also work closely with vendors and third-party service providers to ensure that they are taking adequate measures to protect sensitive data and prevent the exploitation of vulnerable populations.