I spent an afternoon going through X’s revised Terms of Service and Privacy Policy, and I’ll admit I wasn’t expecting to walk away this concerned. Most “policy update” emails get skimmed and archived. This one is different, because it changes what X can legally do with everything you type into the platform — including your Grok prompts. If you run a business account, manage client campaigns, or just post regularly, this is the one update in 2026 actually worth reading in full, not skimming.
The new terms go live on January 15, 2026, and simply continuing to use X after that date counts as accepting them. The current version has been in effect since November 2024, so this is the first major rewrite in over a year, and it lands right alongside a broader wave of AI and privacy regulation hitting every major platform in 2026. Here’s what changed, in plain language.
1. Your AI Prompts and Outputs Are Now “Content” — And X Owns a License to All of It
The biggest shift is a redefinition of the word “Content.” Previously, X’s terms covered what you posted publicly. The 2026 version explicitly folds in “inputs, prompts, outputs,” and anything else created through the service — meaning private Grok conversations are now treated the same way as a public tweet.
Practically, that means X can copy, adapt, publish, and use those prompts and outputs to train its own AI models, and it doesn’t owe you compensation for it — “access to the service” is defined as sufficient payment. If your team uses Grok for drafting client copy, internal notes, or campaign ideas, assume none of it is private.
This is a meaningful departure from how most people think about chatbot conversations. A Google search or a private note-taking app doesn’t typically fold your queries into its public terms-of-service content license. X’s approach treats a Grok prompt the same way it treats a tweet: something you technically own, but something X can use, adapt, and monetize without asking again.
2. New Anti-Jailbreak and Prompt-Injection Rules
X has added a specific misuse clause targeting attempts to “circumvent, manipulate, or disable” its AI systems, naming jailbreaking and prompt injection directly. Legitimate prompt engineering isn’t banned — the language is aimed at people trying to defeat safety guardrails — but the rule gives X much broader grounds to suspend accounts it decides crossed that line, and the definition of “crossed the line” sits entirely with X.
3. Broader Enforcement Powers in the EU and UK
Outside AI, X quietly expanded its enforcement language for the European Union and United Kingdom. The updated terms note that in these regions, X may need to remove content that’s considered harmful or unsafe under local law, even where the content itself isn’t illegal. For marketers running region-specific campaigns, that’s a wider content-risk net than before, and it’s worth reviewing regional posting guidelines before you scale a campaign internationally.
4. Age-Verification Data Collection
The updated Privacy Policy adds language allowing X to collect or share information to estimate or verify a user’s age when legally required. This lines up with a wave of age-assurance laws rolling out across US states and the EU, and it means X may ask for (or infer) more identity signals than it has historically. This is part of a much larger 2026 privacy-law wave — we cover the state-by-state side of that shift in our breakdown of data privacy laws reshaping business compliance in 2026, which is worth a read if your business collects any user data of its own.
5. Scraping Penalties Stay at $15,000 per Million Posts
This isn’t new, but it’s easy to miss: unauthorized scraping still carries a liquidated-damages penalty of $15,000 per 1,000,000 posts scraped within 24 hours. If your team or any tool you use pulls data from X for social listening or competitor research, confirm it’s doing so through the official API. As one legal analysis summarizing the changes put it, the combination of steep scraping penalties and new AI clauses is designed to discourage both independent researchers and casual data pulls alike.
6. Disputes Now Go Through Texas Courts, With a $100 Liability Cap
X keeps Tarrant County, Texas as the exclusive forum for disputes, and the terms include a 1–2 year window to bring a claim, a class-action waiver, and a liability cap of just $100. In practice, this makes it far harder and less financially worthwhile for an individual user to sue over a platform decision, which is exactly the kind of fine print that’s easy to scroll past and hard to challenge later.
7. You Still Own Your Content — But the License You Grant Is Enormous
To be fair to X, ownership of your posts and media technically stays with you. But the license you grant on top of that ownership is worldwide, royalty-free, and sublicensable, covering the right to copy, adapt, publish, and distribute your content “for any purpose.” Combined with the new AI-training language, that license now extends to your prompts and Grok outputs as well, not just your public posts.