AI Deepfakes and the Law: What the TAKE IT DOWN Act Actually Says
The phrase "TAKE IT DOWN Act" gets repeated constantly in coverage of non-consensual intimate imagery. Most of that coverage is vague about what the law actually does. This post reads the statute directly and explains what it means in plain language.
What the Statute Is
The TAKE IT DOWN Act was signed into law on April 28, 2026, as Public Law 119-12. It is codified at 47 U.S.C. § 223a. The full name is the Taking Action to Knowingly Eliminate Images That Degrade and Oppress Women Act, but the statutory obligations apply regardless of gender.
It creates two things: a federal prohibition on non-consensual intimate imagery, and a platform compliance mandate with an enforceable removal timeline.
Does It Cover AI-Generated Images?
Yes, and this is the most important thing the 2026 Congress did that earlier state laws failed to do.
Section 1309 of the Act defines a "covered intimate visual depiction" to include:
> "a digital forgery (that is, a realistic-appearing computer-generated image, video, or other visual media) that depicts an identifiable individual engaged in sexually explicit conduct or in a state of nudity, without that individual's consent."
The phrase "realistic-appearing computer-generated image" covers images produced by AI nudify apps, video deepfakes, face-swap tools, and synthetic media models. The depicted person does not need to have ever taken an intimate photo. The legal protection attaches to the likeness, not to any underlying real image.
This closed the most significant loophole in prior state revenge porn laws, most of which required a real underlying photograph.
Who Is an "Identifiable Individual"?
The statute uses this phrase to define who is protected. An identifiable individual is any person "who can be identified from the visual depiction itself, or from information displayed in connection with the visual depiction, by the depicted individual or by another person."
In practice this means: if someone who knows you would recognize your face in the image, you are an identifiable individual under the statute. You do not need to be famous. You do not need to have a public profile. A private person recognizable from their face is fully covered.
What Are Platforms Required to Do?
This is where the statute has teeth. A "covered platform" (defined as any interactive computer service accessible to US users with more than 100,000 users) must:
- Maintain a clear and accessible mechanism for submitting Section 223a removal notices.
- Remove the reported content within 48 hours of receiving a valid notice.
- Make reasonable efforts to prevent re-upload of the same content after removal.
- Notify the filer when removal is completed or when the platform disputes the notice.
The 48-hour timeline is a hard statutory deadline, not a best-effort guideline. A platform that takes 72 hours has violated the statute regardless of its internal moderation backlog or staffing constraints.
What Makes a Notice "Valid"?
The statute specifies the elements of a valid Section 223a notice. It must include:
- Identification of the specific content by URL or equivalent locator.
- A statement, under penalty of perjury, that the filer is the identifiable individual depicted or is acting on behalf of such an individual.
- A statement that the depicted individual did not consent to the creation or distribution of the visual depiction.
- The filer's contact information.
A notice that omits any of these elements gives a platform a legal basis to reject it and restart the clock. This is why generic abuse reports, which contain none of these statutory elements, do not start the 48-hour timer.
What Happens If a Platform Refuses?
The statute creates two enforcement paths that run in parallel.
Private civil action. The depicted individual can sue the platform directly in federal court for violation of 47 U.S.C. § 223a. Statutory damages are $150,000 per violation plus attorney's fees. The platform cannot invoke Section 230 immunity as a defense against this claim for the specific content that was the subject of a valid notice.
FTC enforcement. The Federal Trade Commission enforces platform non-compliance as an unfair or deceptive act under Section 5 of the FTC Act. This path is administrative rather than private and does not produce individual monetary recovery, but it does produce consent decrees that impose ongoing compliance obligations, civil penalties of up to $50,120 per violation, and public enforcement actions that create significant reputational pressure on consumer-facing platforms.
What the Statute Does Not Do
It does not require the image to be sexual. The statute covers intimate imagery broadly, including non-sexual nudity and partial nudity in contexts that a reasonable person would consider private.
It does not require intent. A platform's good faith is not a defense against a failure to remove within 48 hours. The obligation is strict once notice is received.
It does not cover the creator of the image directly. The mandate falls on the hosting platform. The person who generated or distributed the deepfake faces separate liability under criminal statutes including 18 U.S.C. § 2261A (interstate stalking) and state NCII criminal laws, but the TAKE IT DOWN Act mechanism is specifically a platform mandate.
It does not cover platforms with fewer than 100,000 users. Smaller hosts, niche forums, and many offshore platforms fall below the coverage threshold. Those hosts require different legal strategies.
Why This Matters for Anyone Targeted by Deepfakes
Before this statute, a person targeted by an AI-generated deepfake had no reliable federal legal recourse. DMCA claims required copyright ownership of the underlying image. State laws varied by jurisdiction and most excluded synthetic images. The best available option was a slow, expensive civil suit.
The TAKE IT DOWN Act created a fast, free, enforceable path: send a compliant Section 223a notice, the platform has 48 hours, and failure to comply triggers statutory liability without any requirement for the victim to prove actual damages.
The mechanism is powerful but requires the notice to be correctly formatted and sent to the right contact. A properly drafted notice to the wrong inbox, or a notice missing the sworn statement, starts no clock and creates no liability.
How ScanErase Helps
ScanErase's biometric scan finds every instance of your likeness across 2.4 billion indexed face embeddings, then your exposure report gives you what a compliant Section 223a notice requires for each platform: the correct legal contact (not the general abuse queue), the URL, the statutory citation, the 48-hour deadline, and a reference to the $150,000 statutory damages provision for non-compliance. You file the notice yourself.
If you have been targeted by a deepfake, you do not need a lawyer to use this mechanism. You need a correctly formatted notice sent to the right person before the image spreads further.
See where your face is being used
Free scan in under 60 seconds. $15 to unlock your full report.
Start your free scan