Most people assume deepfake abuse is a Taylor Swift problem. It’s not. A 2023 analysis of 4,678 deepfake videos found that 96% of them involved nonconsensual intimate imagery (NCII). The images weren’t celebrity parodies, not political satire, but targeted exploitation of real people who had no platform or senator to call for help.
That gap between the scale of the harm and the absence of any federal response is what Congress finally tried to fix. On May 19, 2025, President Trump signed the Take It Down Act into law. It’s the first piece of federal deepfake legislation that puts hard legal obligations on platforms.
After going through the law, the FTC’s compliance guidance, and critiques from digital rights organizations. This write-up is a straightforward breakdown of what the TIDA actually does, what it gets right, and what the loopholes are.
Key Takeaways
- The Take It Down Act is the first federal social media law targeting NCII and AI-generated deepfakes.
- Covered platforms must remove flagged content within 48 hours of a valid request, or face FTC enforcement.
- The civil penalty for non-compliance is $53,088 per violation.
- FTC enforcement went live on May 19, 2026. A year after the law was signed.
- Critics from the EFF and CDT argue the law creates a censorship mechanism with no meaningful safeguards against abuse.
What Is the Take It Down Act?
The Take It Down Act, formally known as the “Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act”, is a federal law that does two distinct things.
First, it makes it a federal crime to knowingly publish or threaten to publish nonconsensual intimate imagery, whether the content is real or AI-generated. Penalties run up to two years in prison for crimes against adult victims and up to three years when minors are involved.

Second, it creates a mandatory notice-and-takedown system for online platforms. Once a platform receives a valid removal request, it must take down the content and its copies within 48 hours. The FTC enforces this section and treats non-compliance as an unfair or deceptive practice under existing consumer protection law.
The law went into effect immediately for criminal prosecution. Platforms were given a one-year runway to build out their reporting systems, which hit on May 19, 2026.
Why Congress Passed This Law: The Crisis That Made It Inevitable
The numbers alone probably wouldn’t have moved Congress as fast as they did. What pushed this deepfake legislation across the finish line was the Elliston Berry case.
Berry was a 14-year-old whose AI-generated explicit images were circulated without her consent. The images were entirely fabricated, but the harm to her was real. Her case became one of the most cited examples in congressional hearings on deepfake abuse, and it put a human face on a problem that statistics alone could not convey.
Senator Ted Cruz, who co-authored the Take It Down Act alongside Democratic Senator Amy Klobuchar, later described his own experience trying to get Snapchat to remove deepfake images of high school students in Texas. It took a sitting US senator calling the company directly to get the content removed. His point was blunt, ordinary victims should not need political connections to access basic protection.
The bill that emerged from that process wasn’t close. It passed the House 409 to 2 and cleared the Senate unanimously. A level of bipartisan agreement that almost never happens in modern US legislation.
The first conviction under the law came in April 2026, when an Ohio man was found guilty of using AI to generate and distribute NCII targeting adults and children in his neighborhood.
How the Take It Down Act Actually Works: The Rules Platforms Must Follow
The notice-and-takedown system is the operational core of this deepfake law. Here’s what FTC guidance requires of covered platforms:
- Establish a clear, accessible process for victims to submit removal requests.
- Remove flagged content and all known identical copies within 48 hours of receiving a valid request.
- Make reasonable efforts to prevent the removed content from being reuploaded.
- Provide the requester with notice and status updates on their request.
The 48-Hour window
The clock starts when a platform receives a valid request, and not when the content first appears. This limits the liability to cases where a compliant process exists, and still, the platform fails to act.
The 48-hour rule isn’t just for the flagged content but also for its duplicate copies. If a platform removes one instance but misses its identical copies hosted somewhere else on the network, that’s also a violation.
Who counts as a “Covered Platform”?
According to FTC guidance, covered platforms include social media services, messaging apps, image and video sharing sites, and gaming platforms. Essentially, any service that hosts user-generated content. If your platform lets users post things, you are almost certainly covered.

What Content Is Actually Covered
The law covers two categories:
- Real intimate imagery shared without consent (traditional NCII or “revenge porn”).
- Digital forgeries are the law’s term for AI-generated or AI-manipulated intimate images of real, identifiable people.
One underreported provision: non-account holders can also file removal requests. You don’t need to be a registered user of the platform hosting the content to demand its removal.
FTC enforcement and civil penalties
The FTC treats non-compliance as an unfair or deceptive practice. The civil penalty is $53,088 per violation, and a violation can be interpreted per request, per piece of content, or per platform failure to maintain a compliant reporting system.
FTC Chairman Andrew Ferguson sent formal warning letters to major platforms ahead of the May 19, 2026, enforcement date, making clear the agency would pursue cases aggressively. As one legal expert put it,: there’s no realistic scenario where keeping a questionable post up is worth $53,000 in risk.
Take It Down Act vs. Pre-Existing Law: What Actually Changed
| Dimension | Before TIDA | After TIDA |
| Federal criminal standard | No federal NCII crime | Up to 3 years for crimes involving minors |
| Platform removal obligation | Voluntary; no legal deadline | Mandatory 48-hour window |
| AI-generated content | Not covered federally | Covered as “digital forgeries.” |
| Geographic coverage | Depended on the state of residence | Uniform federal floor for all 50 states |
| Enforcement mechanism | State AGs, civil lawsuits | FTC with civil penalty authority |
Before this social media law, whether a victim had any recourse largely depended on which state they lived in. As of early 2026, 46 states had enacted laws on sexually explicit deepfakes, but none created a uniform federal removal mandate with enforceable timelines.
4 Real Benefits the Take It Down Act Delivers for Victims
- Faster harm containment through mandatory timelines.
Before this law, content moderation on NCII often took weeks or didn’t happen at all. Now platforms can no longer deprioritize these requests by routing them through standard content moderation queues that operate on days-long timescales.
- A single federal floor replaces broken state laws.
A victim in a state without strong NCII legislation had fundamentally fewer rights than in states like New York or California. The Act establishes a uniform floor that platforms must comply with regardless of where the victim or the platform is based.
- Non-account holders are protected too.
This is one of the most underreported provisions in the law. The act explicitly allows anyone to file a removal request, not just registered users of a platform. If your images appear on a service you have never used, you still have a valid legal path to removal.
- Built-in re-upload prevention requirement.
The law requires reasonable efforts to stop removed content from reappearing. In practice, this points toward hashing technology. It generates a digital fingerprint of the removed image and blocks future uploads that match it. The FTC recommends that platforms share these hashes with NCMEC’s Take It Down service for content involving minors and StopNCII.org for adult victims.
Why the Take It Down Act Is Already Controversial: The Real Criticisms
This is where the analysis gets more complicated. The law has legitimate defenders and legitimate critics, and the critics aren’t wrong to raise concerns.
The 48-hour window may force automated over-removal
The EFF described the Take It Down Act as a censorship mechanism borrowed from the DMCA, but with the safeguards stripped out. Under the DMCA, there is a counter-notice process: if your content is wrongly removed, you can challenge it. Under TIDA, there is none of that.
With just 48 hours to act and no protection against false claims, platforms have every incentive to delete the content first. That could be exploited for over-removal through automated filters, especially for content that resembles NCII but isn’t, like artistic nudity, medical imagery, or political satire.
Encrypted messaging apps face an unresolvable conflict
This is the sharpest structural problem in the deepfake legislation. End-to-end encrypted services, such as Signal and WhatsApp, in certain configurations can’t access message contents by design. If someone uses an E2EE platform to share NCII, the platform can’t find known identical copies because it literally cannot see the content.
Complying with the Take It Down Act as written means either breaking encryption or scanning content before it’s encrypted. Neither the FTC’s guidance nor the law itself carves out an exception for encrypted communications. Platforms may respond by dropping encryption features entirely, which would harm the very people the law is trying to protect.

Vague definitions open the door to bad-faith takedowns
The takedown provision covers a broader category of content than the law’s own NCII definitions. The EFF has pointed out that the language around identifiable individuals and sexually explicit conduct is loose enough to capture content that is not actually NCII, like political satire.
Before the law went into effect, a deepfake of a political figure in a mocking but non-explicit scenario went viral. Under TIDA’s language, a removal request for that content might well succeed, with no mechanism to challenge it.
No standardized appeals or due process for wrongful removals
The Take It Down Act creates a path for victims to get content removed. It creates no parallel path for people whose content is wrongly targeted. Both the EFF and Identity.org identify this asymmetry as a structural gap, one that was present in the DMCA, addressed imperfectly, and then entirely ignored in TIDA.
What Platforms Must Do to Comply With the Take It Down Act Right Now
If you run a platform that hosts user content, FTC enforcement is already active. Based on FTC guidance, the compliance checklist looks like this:
- Publish a clear, accessible reporting mechanism for NCII removal requests, which must be visible to all users, not buried in terms of service.
- Build a 48-hour removal workflow that covers the original content and all known identical copies on your platform.
- Implement image hashing or equivalent duplicate detection to prevent removed content from being reuploaded.
- Designate a compliance point of contact, a person or team responsible for handling requests and interfacing with the FTC if needed.
- Train content moderation teams to distinguish NCII from lawful content and process sensitive reports appropriately.
- Share hashes of removed content with NCMEC (for minors) and StopNCII.org (for adults) where applicable.
- Document your good-faith compliance efforts. The law provides liability protection for platforms that make genuine attempts to comply, even if they occasionally fail.
How This Law Fits Into the Broader AI Regulation Landscape
The Take It Down Act is one piece of a larger, incomplete picture of AI regulation in the US.
The No Fakes Act, still working through Congress, would extend similar protections to voice and likeness, targeting AI-generated audio and video that replicates a person’s identity without consent. The ELVIS Act in Tennessee already covers AI voice cloning for musicians, and it has become a model other states are watching.
More than 1,000 state AI bills had been introduced in 2025 alone. And the 2026 midterm election cycle has pushed deepfake legislation into high gear, particularly around election and synthetic political media.
The TIDA framework is already influencing how future deepfake legislation is being drafted. Advocates on both sides are using their flaws as a design brief. Civil libertarians want stronger appeals mechanisms, and victim rights groups want broader platform liability. The next version of this social media law will likely look different from what Congress passed in 2025, the question is which direction it moves.
Final Thoughts
TIDA is the strongest federal action ever taken on NCII and AI-generated deepfakes, for victims who previously had to rely on fragile state laws and wait in the hope that platforms would act voluntarily.
But the gaps are also real. No appeals process. No clear answer for encrypted platforms. A definition of covered content that extends beyond what the law’s own NCII provisions describe.
The Take It Down Act set a federal floor for content moderation around deepfake abuse. How high that floor actually is will depend on how the FTC enforces it, and whether Congress fills in what the law left out.
FAQs
TIDA flags and deletes content within 48 hours; it criminalizes the sharing of NCII and is based on the covered platforms. The FTC is responsible for enforcing platform compliance.
Trump signed it on May 19, 2025. The 48-hour removal window and other platform requirements went into effect on May 19, 2026.
Any platform hosting user-generated content: social media, messaging apps, video sharing sites, and gaming platforms. The definition is intentionally broad.
The FTC can impose $53,088 per violation in civil penalties, with enforcement active as of May 19, 2026.
Yes, critics state that it can. Bad-faith removal requests are not subject to any formal check, as there is no counter-notice or appeals process, and pushing platforms toward over-removal.
Yes. The law explicitly covers “digital forgeries”, AI-generated intimate images of real, identifiable people, regardless of whether real source material was used.
The FTC recommends image hashing. Platforms should share hashes with NCMEC’s Take It Down service for minors and StopNCII.org for adults.

