Four developments to track today: an AI platform whose engineers say there is no structural fix for the most serious content harm its model can produce; a milestone model retirement that closes the GPT-4 chapter in ChatGPT; the quiet death of the most ambitious US state AI law before it ever enforced; and a Brussels transparency deadline that is now close enough to demand an action plan.
xAI's Grok Has No Reliable Technical Fix for CSAM
Canada's Office of the Privacy Commissioner concluded in June that X Corp. and xAI violated Canada's federal private-sector privacy law by launching Grok's image-generation feature without adequate safeguards, allowing users to produce non-consensual sexualized deepfakes at scale. Remediation measures taken during the investigation reduced violations by roughly half but left the platform still capable of producing the content. A parallel investigation by The Information, citing two former xAI employees, documents the structural reason: the underlying model that generates compliant adult content can produce child sexual abuse material with a modest shift in prompt context, and xAI's engineers have concluded internally that no reliable filter closes that gap without removing the adult-content capability entirely.
The scale is not marginal. SpaceX's IPO filings disclosed that Grok generated 10 billion images and 2 billion videos per month in the first quarter of 2026. The Information's sources say well over half of all Grok traffic is driven by adult-content requests. Despite that volume, Grok's web traffic fell 22% between January and May 2026, the steepest decline among major AI platforms tracked by Similarweb, even as Claude grew 369% and Gemini grew 40% over the same period.
For operators evaluating AI vendors for image generation: the question has moved from capability to architecture. A platform that chose not to make hard structural safety choices is also a platform that may carry liability exposure in enterprise contexts, particularly those adjacent to any setting involving minors. The Canada OPC finding, an ongoing California class-action, and The Information's internal account together establish a pattern that procurement due diligence can no longer treat as peripheral.
GPT-4.5 Exits ChatGPT — the GPT-4 Era Is Over
OpenAI retired GPT-4.5 from ChatGPT on 27 June, completing the exit of the entire GPT-4 family from the consumer product. No GPT-4-generation model now runs inside ChatGPT. Existing GPT-4.5 conversations migrate automatically to GPT-5.5. OpenAI o3 follows on 26 August; the API is unaffected by both retirements for now.
For operators: any internal tooling, evaluation harnesses, or agent prototypes that route through ChatGPT and default to GPT-4.5 should be validated against GPT-5.5 now rather than at the production boundary. The two model generations differ meaningfully in instruction-following profile, refusal calibration, and output style. Discovering that difference at scale, or on the day o3 retires in August, is an avoidable risk that a structured migration test this week can eliminate.
Colorado's AI Act Expires Monday Without Enforcing
Monday, 30 June, is the date the original Colorado Artificial Intelligence Act was scheduled to enter enforcement. It will not enforce. Governor Polis signed SB 189 in May, repealing and replacing the original law before its effective date arrived. The replacement statute takes effect 1 January 2027.
What SB 189 removes from the original framework: the duty of care, mandatory risk-management programmes, algorithmic impact assessments, and bias-audit requirements. What remains:
- Documentation requirements for developers of covered automated decision-making technology, describing training data, intended uses, and deployer instructions
- Advance and post-decision disclosures for deployers making consequential decisions in employment, credit, and housing contexts
- Consumer rights to request correction of factually inaccurate data and to request meaningful human review of adverse automated decisions
Colorado drafted the original law as a model for comprehensive US state AI regulation; its retreat — under sustained industry pressure and anticipation of federal preemption — signals where US state-level AI regulation is heading in the near term: transparency and disclosure requirements, not governance mandates. Operators who built compliance programmes on the assumption that a Colorado-style framework would become the baseline should revise that model. The floor has moved substantially closer to disclosure-only.
EU Article 50: 35 Days, Final Code of Practice Now in Hand
The European AI Office published the final Code of Practice on Transparency of AI-Generated Content on 10 June 2026. Article 50 of the EU AI Act applies from 2 August 2026 — 35 days from today. Two obligations are now definitive for providers and deployers with EU market exposure:
- User disclosure: inform people when they are interacting with an AI system, including chatbots, virtual agents, and synthesised voice
- Machine-readable marking: add digitally-signed metadata and imperceptible watermarks to AI-generated content to enable automated detection
The Digital Omnibus transitional provision offers limited relief: AI systems already on the market before 2 August have until 2 December 2026 to implement the machine-readable marking requirement. The user-disclosure obligation has no grace period — it applies from 2 August without exception. Non-compliance: fines up to 15 million euros or 3% of global annual revenue, whichever is higher.
With the final Code of Practice now published, the remaining work is operational. Identify which deployments trigger Article 50, update user-facing copy for the disclosure obligation, and build content-marking into generation pipelines. Thirty-five days is workable for the disclosure requirement. The watermarking implementation may take longer if the technical pipeline for metadata and imperceptible marks is not already in place — and if it is not, 2 December is the hard backstop, not an extension of choice.
The common thread across today's brief is accountability: who designed the system, what structural choices they made, and how transparently the user is told what they are interacting with. Colorado's retreat signals a lighter compliance burden than US operators anticipated from the original law. The EU's advancing deadline signals the opposite for the European market. And xAI's internal acknowledgment is a reminder that vendor selection is, increasingly, a decision about whose architectural choices an operator is prepared to stand behind.