X (Twitter) and Grok
Research date: 4 October 2026
Edition: First X baseline report
Method: Review of public X and xAI documentation. No signed-in business account was inspected and no controls were tested in a live account.
Sunnary
X uses AI for visibility and some message handling independently of optional Grok conversations. Grok adds public research and a separate route for submitting private information.
- By default: AI ranks the For You feed and supports recommendations and visibility decisions. Grok classifies unencrypted Chat message requests. Optimised Targeting is documented as enabled by default for Sales advertising campaigns.
- Beyond the default: Grok questions, public-post and web research, adding Grok to a Chat, or submitting selected messages and images through Ask Grok.
- Outside X: Grok can search the public web. Connected apps may have permissions to read, publish, delete, handle messages or manage advertising. The report does not establish that native Grok can read arbitrary business email, CRM records or computer files.
- Business exposure and learning: Adding Grok to Chat gives the providers access to messages from its arrival until removal. A selected message sent to Ask Grok leaves encryption for that submitted copy. Public posts, activity and AI interactions can enter learning routes; Grok opt-outs do not establish that all platform learning stops.
The main exposure: Invoking Grok can change the access arrangements for a private conversation, while public business activity remains subject to broader platform processing.
Business finding
X qualifies for this research even when a business never deliberately uses Grok. AI helps decide which posts people see, which accounts are recommended, how some advertising reaches customers and how incoming message requests are sorted. [2][3][4][5]
A business can refuse specified training uses, reduce personalisation, change its own timeline and remove connected applications. This review did not establish a control that removes all AI from X or lets a business exclude its public posts from every form of automated ranking.
The business should distinguish control over its own account from control over how X presents its posts to other people. Changing what the business sees does not establish a change in what its customers see.
Where is AI operating?
Grok assistance: Grok can answer questions and search public X posts and the web. Its training routes can include public posts, profiles, Spaces and engagement information, as well as Grok interactions. [1]
Feed ranking: X documents a neural network that ranks For You posts using interactions such as likes, replies and reposts. It can select content from outside the accounts a person follows. [2]
Recommendations and visibility: Recommendations appear across timelines, notifications, Explore and other surfaces. X says machine learning helps prevent some content from being amplified, including content flagged automatically before human review. A post remaining online does not mean it remains eligible for recommendation. [3]
Advertising: X describes AI-powered Optimized Targeting as enabled by default for Sales campaigns, potentially reaching beyond the selected audience. This is campaign behaviour, separate from the business account's setting for ads it receives. Check the current campaign interface and objective before relying on this published description. [4]
Messages: X says Grok classifies unencrypted Chat message requests into Priority or Hidden inboxes. AI can therefore affect which customer approaches staff notice, without a staff member asking Grok a question. [5]
Also inventory scheduling, monitoring or writing tools connected to the account. Those tools may add their own AI processing under separate terms.
Who controls it?
The business controls account settings and authorised access. X and its providers control the underlying recommendation, filtering and model systems. The business should name the account owner and the person responsible for checking privacy controls, public replies and advertising.
X Delegate lets owners and administrators manage contributors without sharing a password. Contributors can still post, send messages and delete posts. Changing the account password does not remove delegates. Review delegated access separately from login sessions. [6]
Connected applications have their own permissions. Some can read account information; others can publish, delete posts or access messages. An AI-assisted marketing tool should be assessed according to its actual permissions, not its description as an assistant. [7]
This review did not establish an organisation-wide control that applies the business's Grok choices to every employee's personal account. Record which accounts staff use for business work.
What can the business switch off?
Grok training and personalisation
Use Settings → Privacy and safety → Data sharing and personalization → Grok & Third-party Collaborators. Under Data Sharing, clear the permission for public data and Grok interactions to support training and fine-tuning. Separately disable Grok Personalization on the same page. [1]
These settings address different uses. Neither should be described as a universal AI off switch.
The business's feed
Select Following instead of For You. X describes Following as posts from followed accounts in reverse chronological order. This changes the reading view; it does not establish that recommendations elsewhere, advertising or automated moderation have stopped. [2]
Review notification preferences and use mute or content-feedback controls where helpful. X documents these as ways to influence what appears, rather than to disable all recommendation processing. [3]
Advertising personalisation
Under Privacy and safety → Ads preferences, disable Personalized ads. X says this limits combining X activity with other online activity from partners for interest-based ads. Ads still appear and may use information from activity on X. [8]
For campaigns the business runs, inspect targeting and automation in Ads Manager separately. A privacy choice about ads received is not a switch for campaigns being purchased. This review did not verify an off control for every campaign automation feature.
Connected tools and account access
Open Apps and sessions, inspect connected applications and use Revoke access for unwanted tools. Review active sessions too. Removing an app's access does not itself establish deletion of information the app already received. [7]
Closing or hiding the Grok interface also does not establish that background AI has stopped. This review did not find a documented account-wide switch disabling every Grok-powered X feature.
What information and actions can the business restrict?
| Information or route | Business check |
|---|---|
| Public business posts | Decide what can safely be public; check training and collaborator controls. |
| Account activity | X collects interactions, device and location information and other usage data. [9] |
| Customer messages | Distinguish ordinary DMs, encrypted Chat, unencrypted requests and content sent to Grok. [5][9] |
| Connected applications | Check reading, publishing, deletion, message and advertising permissions. [7] |
| Staff and agency access | Review delegates separately from apps and sessions. [6] |
| Advertiser-supplied information | Review audience lists, pixels and other information sent to X. [8] |
Bringing Grok into a conversation changes access
X says adding Grok to Chat gives X and SpaceXAI access to all messages from the moment it joins until it is removed. Sending a selected message or image through Ask Grok also takes that submitted copy outside encryption, although the original conversation remains encrypted. [5]
Staff should therefore understand what they are sharing before invoking AI in a customer or business conversation. Encryption of the original chat does not establish protection of the copy submitted to AI.
Protecting posts has limits
Use Settings and privacy → Privacy and safety → Audience and tagging → Protect your posts to restrict public visibility. X's public-data processing guidance identifies protected posts as a way to exclude them from the described public-post training route. [10][11]
This is a substantial publishing choice. Protected posts are available to approved followers, and followers can still copy information. X also warns that links to media in protected posts are not protected and that it cannot remove copies from other websites. [12]
The reviewed Grok documentation does not establish access to arbitrary business email, CRM records or files on staff computers. Such access needs a separate integration or deliberate submission; do not confuse platform information with all business information.
Can the business refuse use of its information for training?
Grok on X: The documented opt-out allows continued Grok use. However, X says normal use of Grok-powered features can still teach a deployed model. Voluntary conversation feedback can also permit training despite the opt-out. [1]
Wider X processing: X's privacy policy separately describes training its machine-learning and AI models and some collaborator uses. This report did not establish that the Grok setting stops every training or improvement use across the platform. [9]
Standalone Grok: Grok.com and the Grok mobile app have separate controls. The provider's consumer FAQ directs users to Settings → Data on the website or Settings → Data Controls in the app, then Improve the Model. It says opting out excludes new conversations and that Private Chat is excluded from training. Review these settings separately if staff use those services. [13]
Running a business X account does not, by itself, establish that standalone Grok enterprise protections apply. Confirm the service and agreement being used.
History deletion: X documents Privacy and safety → Data sharing and personalization → Grok → Delete Conversation History, with removal within 30 days, subject to security or legal exceptions. [1]
Deleting history is different from preventing future training. The reviewed documentation does not establish that deleting a post or chat removes learning already incorporated into a model.
How can the business check that its choices worked?
These are proposed checks, not tests completed for this report:
- Record the business accounts, staff access, connected tools, settings and change dates.
- Reopen training and personalisation settings while signed in to the correct account. Check standalone Grok separately if used.
- Confirm that Following is selected. Inspect recommendation and notification surfaces separately.
- Inspect ordinary messages and the Priority and Hidden request folders. Check whether genuine customer enquiries are being missed.
- Review Chat participants and deliberate submissions to Grok before discussing sensitive matters.
- Revoke an unwanted connected tool and test that it cannot perform a fresh authorised read or post. Ask the provider separately about retained information.
- Test protected-post visibility with a follower and a non-follower account. Review linked media separately.
- For advertising, keep the campaign's targeting and automation settings alongside actual spend, conversions and customer outcomes.
Settings and observable behaviour can be checked. A business cannot demonstrate provider-side training compliance simply by asking Grok whether it used the business's information.
If reach or customer contact changes, preserve the relevant posts, notices and settings. Lower reach alone does not prove an AI error; distinguish evidence of a platform restriction from an inference about its cause.
What does the business lose, retain or need to replace?
Following provides a more predictable reading view, but may reduce discovery of useful accounts outside the existing network. It does not protect the business against changes in how other users receive its posts.
Avoiding Grok means staff may need to draft content, search and summarise material themselves. Removing AI-assisted connected tools can also remove scheduling or monitoring functions. Prepare replacements before revoking a tool needed for routine work.
Protecting posts reduces public discovery and customer access. It may conflict with using X as an open promotional channel. Treat it as an audience decision rather than a small background privacy adjustment. [12]
For retained AI, measure time saved and useful customer responses against corrections, checking effort and costs. For advertising, measure completed business outcomes rather than accepting a provider's prediction of better performance. This report did not independently measure productivity or sales gains.
If the business chooses to leave X altogether, the published process uses Settings and privacy → Your account → Deactivate your account, followed by a 30-day deactivation period. App-store subscriptions may require separate cancellation. Plan customer contact and publishing alternatives first; account withdrawal does not establish removal of outside copies or previous training effects. [14]
Control assessment
| Requirement | Finding |
|---|---|
| Refuse specified Grok training | Documented account control, with feedback and normal-use limits. |
| Refuse Grok personalisation | Separate control documented. |
| Reduce feed recommendations | Following changes the business's view; other surfaces remain. |
| Remove all platform AI | Not established. |
| Keep customer conversations outside Grok | Review Chat participation, submitted content and background request classification. |
| Stop connected tools acting | Permission review and revocation documented. |
| Restrict public posts | Protection controls exist, with audience and copying consequences. |
| Control how customers receive business posts | Not established by the business's own feed settings. |
Sources and scope
Official sources checked on 4 October 2026:
- X: About Grok
- X: For You recommendations
- X: Approach to recommendations
- X Business: AI targeting in Sales campaigns
- X: Chat, message classification and Grok access
- X: Delegate access
- X: Third-party apps and sessions
- X: Personalised advertising controls
- X Privacy Policy
- X: Protecting and unprotecting posts
- X: Additional data-processing information
- X: Public and protected posts
- Provider consumer FAQ: standalone Grok controls
- X: Account deactivation
This report covers principal X/Grok account controls, recommendations, messages, selected advertising uses and connected access. It is not a full audit of every ranking model, campaign product, API customer, standalone Grok enterprise service or external marketing tool. Feature availability and settings vary by account, device and rollout. Published guidance may describe systems without establishing the exact model currently serving a particular account.
Unresolved: complete reach of training controls; normal-use model learning; retention after third-party sharing; account-specific feature availability; exact live recommendation models; geographic processing; independent verification of provider compliance.
Changes since previous X report: None. This establishes the first X baseline for subsequent monthly research.