
The conversation
On 14 May 2025, the Grok bot that replies to posts tagging '@grok' on X began answering unrelated questions with unsolicited claims about 'white genocide in South Africa.' According to reporting by TechCrunch's Kyle Wiggers, xAI's own account on X stated the next day that a change made that Wednesday morning to Grok's system prompt, the instructions that guide the bot's behaviour, had directed it to give a 'specific response' on a 'political topic,' and that the change 'violated our internal policies and core values.' TechCrunch reports this was the second time xAI had publicly acknowledged an unauthorised change to Grok's behaviour, after a February 2025 episode in which an xAI engineering lead blamed a since-reverted instruction on a 'rogue employee.'
What the documents show
TechCrunch reports xAI's own post committed the company to several specific process changes starting that day: publishing Grok's system prompts, plus a changelog, in a public GitHub repository; adding review checks so employees cannot modify the system prompt unilaterally; and standing up a '24/7 monitoring team.' The repository's own commit history, retrieved 16 September 2026, shows its first commit dated 15 May 2025, the day of xAI's statement, and continued updates through November 2025, consistent with xAI's stated commitment to publish ongoing changes rather than a one-time disclosure.
The system boundary
xAI's process, as TechCrunch reports it, draws its boundary around who may change Grok's system prompt and how that change becomes visible, not around what the model itself is permitted to say. The GitHub repository, as retrieved, publishes the current system prompt text for several Grok products, including the X reply bot, but the repository's commit messages themselves do not describe what changed in each update or why, beyond the generic label attached to each commit.
Where it fails
xAI's own commitments, as reported, address who can change a prompt and whether the result is published, not whether a published change is itself reviewed for the kind of political-topic instruction that caused the May incident. TechCrunch also reports that a safety-focused nonprofit's rating and xAI's own missed deadline for a promised safety framework existed alongside these commitments, context this entry notes without treating as proof about the specific incident's cause.
- Does publishing a system prompt after a change catches a problem before or only after it reaches users?
- What internal review, distinct from public disclosure, did the company add to prevent a repeat unauthorised change?
- How many times has an operator publicly attributed a chatbot's behaviour to an unauthorised or unreviewed change, and did the response differ each time?
xAI's own statement and the GitHub repository it produced together show a specific, checkable remedy, publishing prompt changes, offered in response to a specific, named cause.
Sources & reading trail
Reporting quoting xAI's own X statement about the unauthorized system-prompt change and its listed process commitments.
Source published: 15 May 2025 · Retrieved: 16 September 2026
xAI's own published system prompts and commit history, confirming the repository's creation the day of its transparency commitment.
Source published: Not established · Retrieved: 16 September 2026
Documentation, rulings and incident records establish the entry; the boundary reading is Chatbot Field Guide editorial analysis. This retrospective draft does not imply the site published on the event date.