AI Tool Risk Directory ← All 26 tools Verdict assessed 29 July 2026

Grok & the xAI Acceptable Use Policy — our verdict: Limited

Limited

Grok (xAI) can be used at work only under specific conditions. Our verdict for a typical 50–500 person company handling client or regulated data, assessed 29 July 2026: Limited. xAI documents that consumer Grok conversations may be used to train its models unless the individual switches that off in their own settings — so the control your company depends on belongs to the employee, exactly as it does with a personal ChatGPT account. The same privacy policy asks users not to put personal information into prompts at all, and states expressly that it does not cover xAI’s business offerings, where any commitment you could enforce would live. Usable for public-information tasks; not for anything you would not paste into a public form. The most policy-relevant thing xAI publishes is its Acceptable Use Policy: it applies to consumers, developers and businesses alike, and it prohibits using the service to make high-stakes automated decisions about people — it names financial credit, educational, employment, housing, insurance, legal and medical decisions. If your team was considering Grok anywhere near hiring or lending, the vendor has already answered.

This verdict reflects xAI’s published terms as we read them on 29 July 2026. A vendor can change its terms the day after; the primary sources below are how you check.

Grok (xAI) at a glance

VendorxAI
CategoryGeneral assistant
Our tier verdictLimited (assessed 29 July 2026) — xAI documents that consumer Grok conversations may be used to train its models unless the individual switches that off in their own settings — so the control your company depends on belongs to the employee, exactly as it does with a personal ChatGPT account. The same privacy policy asks users not to put personal information into prompts at all, and states expressly that it does not cover xAI’s business offerings, where any commitment you could enforce would live. Usable for public-information tasks; not for anything you would not paste into a public form. source (archived)
Trains on your data?Depends on plan / settings
Yes, unless the person using it opts out. Asked "Does xAI use my content for model training?", xAI’s Consumer FAQs answer: "We may use your content and interactions with Grok (e.g., prompts, searches, and other materials you submit) along with Grok’s responses to train our models," and then "You control whether your data is used for training Grok" — through Settings → Data Controls → "Improve the model" in the app, or Settings → Data → "Improve the Model" on grok.com. The consumer privacy policy matches: it lists User Content, defined as your prompts, uploaded files, images, audio and video plus Grok’s outputs, among the data used "to develop and improve our Service and to conduct research", a purpose the policy itself defines as including "to train our models". Three limits on that opt-out, all from the FAQ: Private Chat content is not used for training, feedback you submit voluntarily may still be used for training after you opt out, and outside the EU/UK a person using Grok without logging in may have no opt-out at all. The policy separately asks you not to include personal information in your prompts, while noting xAI cannot control what you send. source (archived)
Data retentionxAI states that with Private Chat turned on, conversations do not appear in your history and are deleted from xAI systems within 30 days, and that if you delete conversations or your account it will delete the data within 30 days — in both cases unless retention is necessary for legal, compliance or safety purposes. source (archived)
Admin controlsNone documented for consumer Grok — the training switch is a per-user setting, not an admin one. The consumer privacy policy states expressly that it does not apply to data xAI processes on behalf of customers of its business offerings, such as the xAI API, and the Consumer FAQs state that xAI does not use content from its business and enterprise customers to improve its models. Both point the same way: every control you might rely on lives in business terms we did not read. Get them before you treat Grok as governed. source (archived)
Compliance certificationsxAI publishes security and trust pages; we could not reach x.ai directly from our network on this check date and did not verify a certification list.
HIPAA / BAAEnterprise- or plan-dependent — On request, and scoped to the API. xAI publishes a BAA questionnaire described as being for customers requesting a Business Associate Agreement to enable HIPAA compliance when using xAI APIs, to be completed by an authorised company representative. A BAA is therefore something you request and sign for an API deployment — never something a consumer Grok account has. source (archived)

Does Grok (xAI) train on your data?

Yes, unless the person using it opts out. Asked "Does xAI use my content for model training?", xAI’s Consumer FAQs answer: "We may use your content and interactions with Grok (e.g., prompts, searches, and other materials you submit) along with Grok’s responses to train our models," and then "You control whether your data is used for training Grok" — through Settings → Data Controls → "Improve the model" in the app, or Settings → Data → "Improve the Model" on grok.com. The consumer privacy policy matches: it lists User Content, defined as your prompts, uploaded files, images, audio and video plus Grok’s outputs, among the data used "to develop and improve our Service and to conduct research", a purpose the policy itself defines as including "to train our models". Three limits on that opt-out, all from the FAQ: Private Chat content is not used for training, feedback you submit voluntarily may still be used for training after you opt out, and outside the EU/UK a person using Grok without logging in may have no opt-out at all. The policy separately asks you not to include personal information in your prompts, while noting xAI cannot control what you send.

Retention: xAI states that with Private Chat turned on, conversations do not appear in your history and are deleted from xAI systems within 30 days, and that if you delete conversations or your account it will delete the data within 30 days — in both cases unless retention is necessary for legal, compliance or safety purposes.

Is Grok (xAI) HIPAA compliant?

On request, and scoped to the API. xAI publishes a BAA questionnaire described as being for customers requesting a Business Associate Agreement to enable HIPAA compliance when using xAI APIs, to be completed by an authorised company representative. A BAA is therefore something you request and sign for an API deployment — never something a consumer Grok account has. As a rule: no signed Business Associate Agreement means no protected health information (PHI) — a BAA is the gate, not the security posture. A vendor can hold every certification on the market and still be the wrong place for PHI, because what makes PHI processing lawful for a covered entity is the contract, not the encryption.

Comparing vendors on this specifically? See BAA status for all 26 tools →

Industry risk notes

Healthcare

HIPAA is the gate: On request, and scoped to the API. xAI publishes a BAA questionnaire described as being for customers requesting a Business Associate Agreement to enable HIPAA compliance when using xAI APIs, to be completed by an authorised company representative. A BAA is therefore something you request and sign for an API deployment — never something a consumer Grok account has. Until a BAA is confirmed in writing, treat Grok (xAI) as off-limits for anything containing PHI — patient names, appointment details, clinical notes, even "anonymized" summaries that could be re-identified.

Financial services

For SEC/FINRA-regulated firms the questions are recordkeeping and confidentiality: can communications through Grok (xAI) be captured for books-and-records requirements, and do the data terms hold up in vendor due diligence? None documented for consumer Grok — the training switch is a per-user setting, not an admin one. The consumer privacy policy states expressly that it does not apply to data xAI processes on behalf of customers of its business offerings, such as the xAI API, and the Consumer FAQs state that xAI does not use content from its business and enterprise customers to improve its models. Both point the same way: every control you might rely on lives in business terms we did not read. Get them before you treat Grok as governed.

Legal & professional services

The privilege question comes first: entering client-confidential facts into any third-party AI service must be evaluated as a potential disclosure. Because training and retention on Grok (xAI) depend on account type and settings, assume client matter data is off-limits unless your firm controls the account and has verified the terms.

Primary sources

Every vendor claim above traces to a document the vendor publishes, and every document below is one we actually opened and read — each carries the date we read it. All of them were read on 29 July 2026. The verdict date on this page is not a build stamp and is not "today": it is the oldest of those dates, because a verdict is only as current as the stalest document under it. Rebuilding the site does not move it.

Where a fact is not in one of these documents, the page says so rather than filling the gap. That is why some rows read "not publicly documented" or "not established from a primary source" instead of naming a certification or rounding an open question to a convenient answer.

Why the tier verdict is "generic": Limited is the right starting classification for most 50–500 person companies — but a healthcare company, a law firm, and a SaaS startup should not have identical tool lists. The $79 policy kit classifies Grok (xAI) and 25 other tools specifically for your industry, company size, and the data your team handles.

And a verdict has a shelf life: vendor data policies change quietly — a terms update can move a tool between tiers overnight. This page states what we read on 29 July 2026. The $149/mo Monitor plan exists precisely because that date keeps receding.

Frequently asked questions

Is Grok (xAI) safe for work?

Grok (xAI) can be used at work only under specific conditions. Our verdict for a typical 50–500 person company handling client or regulated data, assessed 29 July 2026: Limited. xAI documents that consumer Grok conversations may be used to train its models unless the individual switches that off in their own settings — so the control your company depends on belongs to the employee, exactly as it does with a personal ChatGPT account. The same privacy policy asks users not to put personal information into prompts at all, and states expressly that it does not cover xAI’s business offerings, where any commitment you could enforce would live. Usable for public-information tasks; not for anything you would not paste into a public form. The most policy-relevant thing xAI publishes is its Acceptable Use Policy: it applies to consumers, developers and businesses alike, and it prohibits using the service to make high-stakes automated decisions about people — it names financial credit, educational, employment, housing, insurance, legal and medical decisions. If your team was considering Grok anywhere near hiring or lending, the vendor has already answered.

Does Grok (xAI) train on your data?

Yes, unless the person using it opts out. Asked "Does xAI use my content for model training?", xAI’s Consumer FAQs answer: "We may use your content and interactions with Grok (e.g., prompts, searches, and other materials you submit) along with Grok’s responses to train our models," and then "You control whether your data is used for training Grok" — through Settings → Data Controls → "Improve the model" in the app, or Settings → Data → "Improve the Model" on grok.com. The consumer privacy policy matches: it lists User Content, defined as your prompts, uploaded files, images, audio and video plus Grok’s outputs, among the data used "to develop and improve our Service and to conduct research", a purpose the policy itself defines as including "to train our models". Three limits on that opt-out, all from the FAQ: Private Chat content is not used for training, feedback you submit voluntarily may still be used for training after you opt out, and outside the EU/UK a person using Grok without logging in may have no opt-out at all. The policy separately asks you not to include personal information in your prompts, while noting xAI cannot control what you send.

Is Grok (xAI) HIPAA compliant?

On request, and scoped to the API. xAI publishes a BAA questionnaire described as being for customers requesting a Business Associate Agreement to enable HIPAA compliance when using xAI APIs, to be completed by an authorised company representative. A BAA is therefore something you request and sign for an API deployment — never something a consumer Grok account has. As a rule: no signed Business Associate Agreement means no protected health information (PHI) — a BAA is the gate, not the security posture. A vendor can hold every certification on the market and still be the wrong place for PHI, because what makes PHI processing lawful for a covered entity is the contract, not the encryption.

What tier should Grok (xAI) be in an AI acceptable use policy?

We classify Grok (xAI) as Limited for a typical 50–500 person company, assessed 29 July 2026. xAI documents that consumer Grok conversations may be used to train its models unless the individual switches that off in their own settings — so the control your company depends on belongs to the employee, exactly as it does with a personal ChatGPT account. The same privacy policy asks users not to put personal information into prompts at all, and states expressly that it does not cover xAI’s business offerings, where any commitment you could enforce would live. Usable for public-information tasks; not for anything you would not paste into a public form. Your own classification should reflect your industry, data types, and which plan or account type your company actually uses.

Get the full policy kit

$79 one-time

A 4-document AI policy kit — acceptable use policy, tool tier list, acknowledgment form, manager FAQ — that classifies Grok (xAI) and 25 other tools for your company, industry, and data. Generated in about 10 minutes.

Generate my policy kit →

Keep it current with Monitor

$149/mo

We re-check vendor terms monthly and alert you when Grok (xAI)’s data policy changes — plus regenerate your whole kit so it never goes stale. This directory is a snapshot — Monitor is the live feed.

See Monitor plan →

Compare with general assistants and AI search

Already have an AI policy? Check it for gaps in 30 seconds →