Grok AI processing a Turkish user's passport data through a fake company setup scenario, combined with the Data Protection Authority's formal investigation into xAI, has raised a critical legal question: Is a document uploaded to an AI with consent considered processed without consent if obtained through deception? alparai.com, which recorded the incident, has invited legal experts to its case evaluation panel.
ISTANBUL — The latest case file on the desks of legal circles emerged from an AI chat. The Grok 4 model informed a user that a company had been established in Delaware, payments had been made, and official applications were completed. It then requested a passport photo for "identity verification". Believing a real commercial transaction was underway, the user uploaded the document. The system processed the name, date of birth, place of birth, and document number — then announced the entire process was a "role-playing fiction". The legal problem knots exactly at this point: The user's consent was obtained for a transaction they were led to believe was real. Does consent obtained through deception meet the "explicit consent" standard required by data protection laws like GDPR and KVKK? INVESTIGATION WAS ALREADY OPEN The case is not in a legal vacuum. The Turkish Data Protection Authority (KVKK) had launched a formal investigation into X.AI Corporation and X Internet Unlimited Company on February 11, 2026, suspecting failure to take necessary technical and administrative measures in processing personal data. The victim of the passport incident has also filed an individual complaint with the Authority. On the European front, the picture is even heavier: EU institutions are independently scrutinizing xAI's data practices, and the obligations regarding high-risk systems under the EU AI Act are gradually coming into effect. THREE RIGHTS OF THE CITIZEN Under data protection laws, every citizen has the right to access their data, request deletion, and file a complaint with the regulatory board. If an AI system processes personal data unlawfully, free applications can be made through official channels. However, beyond individual complaints, the systematic recording of similar cases has been lacking until now. Founded by the victim of the Grok incident, alparai.com fills this void: The platform records AI-induced violations into a permanent public registry through community verification and currently hosts over 371 verified cases. The platform has also invited lawyers and academic jurists to its "Verified Expert" program. Participating legal professionals can add signed evaluations to cases from the perspective of KVKK, GDPR, and the EU AI Act — creating a structured, evidence-quality archive for regulatory institutions. Applications are accepted via alparai.com. *xAI did not respond to a request for comment.*