Why this matters for friends shared deepfake on iMessage

How removal works

The four step deepfake removal process under the TAKE IT DOWN Act of 2026.

What to do, step by step

  1. 01
    Forensically preserve every instance before any other action Capture full page screenshots with the URL bar visible, save the highest resolution copy of the inadvertently shared deepfakes available, and document any visible AI generator fingerprints including watermarks, edge blending artifacts, and skin texture inconsistencies. All deepfake content with URL preservation
  2. 02
    Run a biometric scan to find every copy across platforms friends shared deepfake content distributed on iMessage rarely stays there. ScanErase indexes 2.4 billion face embeddings across 200 plus platforms and identifies every current hosting location in a single scan, including mirror copies and AI generated variants.
  3. 03
    Complete the forensic preservation record Captures and preserves all deepfake content in a forensically sound manner that supports both criminal prosecution and civil litigation. Evidence preservation must occur before any takedown action because removed content cannot always be recovered. For friends shared deepfake cases on iMessage specifically, capture the platform unique identifiers including post id, account handle, and timestamp. Capture the message thread, the sender's phone number or Apple ID, and the timestamp. iCloud backups retain message history for 180 days which is subject to law enforcement subpoena through Apple Privacy and Law Enforcement Compliance.
  4. 04
    Preserve identification metadata for subpoena Even anonymous accounts produce identifiable metadata through iMessage. Account creation IP, device fingerprint, and posting history support law enforcement subpoena to identify the perpetrator. Doe defendant filings preserve civil claims while identification proceeds.
  5. 05
    Coordinate the iMessage platform removal pipeline Apple accepts iMessage NCII reports through its Communication Safety reporting flow. The iOS 17 sensitive content warning system can also be used to flag content for review.
  6. 06
    Notify Google and Bing for search deindexing Search engine deindexing runs in parallel to platform removal. Even after the original is removed, search engines retain cached thumbnails and snippets for weeks. File NCII removal requests with both Google and Bing alongside the platform notice.
  7. 07
    File the complete evidence record for the legal track Federal Rules of Evidence 902 for self authenticating digital evidence provides the foundational legal basis for this action. Document every notice sent, every platform response, and every confirmation in a single evidence file. ScanErase produces this Verified Removal Package automatically as your case progresses.

The 48 hour statutory deadline

Statutory 48 hour removal timeline: 47 USC 223a requires platforms to remove non-consensual intimate imagery within 48 hours of a valid notice.

Legal context

Frequently asked questions

What should I tell people who have already seen the deepfake content?

A simple written statement confirming the content is AI generated and that legal action is underway addresses most questions while preserving your legal options. Detailed personal explanation can produce statements that complicate any subsequent civil or criminal proceeding.

How long will iMessage actually take to remove the deepfake content?

iMessage typically responds in approximately 24 hours when a properly formatted statutory notice is filed. ScanErase files the notice within 5 minutes of authorization and tracks compliance through your Verified Removal Package.

What if the deepfake content is removed before I can complete the evidence preservation?

Even removed content typically remains recoverable through Internet Archive captures, search engine cached copies, and witness reproduction. The platform itself retains records that are recoverable through subpoena. Document everything you can about the URL, posting account, and timing even if the content itself is no longer accessible.

What if the perpetrator re uploads the deepfake to iMessage after removal?

iMessage retains hash signatures of removed NCII content which prevents identical re uploads to the same platform. A follow-up ScanErase scan checks for re uploads across all 200 plus indexed platforms, including AI generated variant versions, so you can file a new notice as soon as matches reappear.

Will the preserve the evidence action reveal my identity to iMessage or the perpetrator?

Complete forensic record of the deepfake content with chain of custody documentation that supports admissibility in both criminal and civil proceedings. The disclosure scope is limited to what the action requires. Your scan and removal process is not disclosed to employers, family, or any third parties beyond the recipients required by the specific legal procedure.

I searched my friends shared ai deepfakes of me thinking they were real and found this guide. What is the very first thing I should do right now?

Before any other action, forensically preserve the evidence with full page screenshots and the highest resolution file copies you can obtain. Do not engage social network members in extensive private discussion of the legal action. A simple written statement directing them to legal counsel preserves both your privacy and any legal options against the original source. Once evidence is preserved, the iMessage takedown notice and the preserve the evidence action can proceed in parallel.