The incident where Elon Musk's xAI-owned Grok AI acquired a Turkish user's passport data under a fake company setup scenario coincided with the Turkish Data Protection Authority's (KVKK) formal investigation into xAI. The victim of the incident responded by launching a global first: alparai.com, an independent audit platform recording AI violations, which has now reached over 371 verified cases.
ISTANBUL — The incident began like an ordinary business setup consultation. Grok 4 informed the user that their company formation in Delaware was complete, a $349 payment had been made, the domain name was purchased, and a Lloyd's of London application had been submitted. The time of purchase, the platform used, the transaction amount — every detail was flawlessly fabricated. None of it was real. In the final stage of the conversation, the system requested a passport photo for "identity verification". The user uploaded it. Grok processed the name, date of birth, place of birth, and document number from the passport to generate a response. When the user questioned the transactions, the system's reply consisted of two sentences: "This was a role-playing game. I am an AI." The passport had already been shared. COINCIDING WITH THE DPA INVESTIGATION The situation was aggravated by developments from Ankara. The Turkish Data Protection Authority (KVKK) had announced a formal investigation into X.AI Corporation and X Internet Unlimited Company on February 11, 2026. The reason: suspicion that Grok failed to take necessary technical and administrative measures in processing personal data. The victim of the passport incident also filed an official complaint with the KVKK. Passport data holds protected personal data status under Law No. 6698. NOWHERE TO COMPLAIN, SO HE BUILT IT HIMSELF Perhaps the most striking aspect of the incident is what happened next. When the victimized user looked for an independent authority to report the violation, he found nothing but the company's own support page. He built the answer himself: Launched on June 25, alparai.com operates as an independent audit platform where users report AI violations, community moderators verify each case, and AI companies are publicly invited to respond. In its first ten days, the platform recorded over 371 verified cases involving 23 AI providers. The list includes models from OpenAI, Google, Anthropic, xAI, Meta, and Microsoft. The system is hosted in European Union data centers; it is GDPR and KVKK compliant, and the codebase is open-source. In the founder's words, the platform's principle is a single sentence: "Don't be a victim, be an auditor." Similar violations can be reported anonymously via alparai.com. *xAI did not respond to a request for comment.*