The TAKE IT DOWN Act (Tools to Address Known Exploitation by Immobilizing Technological Deepfakes On Websites and Networks Act) is a United States federal law, enacted as S. 146 of the 119th Congress and codified as Public Law 119-12, that criminalizes the nonconsensual publication of intimate visual depictions — including AI-generated deepfakes — and imposes a 48-hour notice-and-takedown duty on covered online platforms, enforced by the Federal Trade Commission. It was signed by President Donald Trump on May 19, 2025. The Act combines two distinct regimes: criminal prohibitions enforced by the Department of Justice, and a platform takedown duty treated as an unfair or deceptive practice under Section 5 of the FTC Act.
Status and timeline
The bill was a reintroduction of a prior-Congress version, introduced in January 2025. Lead Senate sponsors were Sen. Ted Cruz (R-TX) and Sen. Amy Klobuchar (D-MN); First Lady Melania Trump was a public advocate for the bill.
- Introduced: January 2025 (reintroduction of prior-Congress version)
- Senate passage: February 2025 (unanimous consent)
- House passage: April 28, 2025 (409–2)
- Signed: May 19, 2025 (President Donald Trump)
- Criminal provisions: effective on enactment
- Platform takedown duty (Section 3): compliant process required by May 19, 2026
The House vote of 409–2 and unanimous Senate passage made it among the broadest bipartisan AI-adjacent votes of the 119th Congress, a margin more typical of child-safety legislation.
Scope and definitions
The Act establishes two distinct regimes:
- Criminal prohibitions apply to any person who knowingly publishes or threatens to publish nonconsensual intimate visual depictions (NCII), whether authentic or AI-generated, of an identifiable adult or minor.
- Platform takedown duty applies to covered platforms — consumer-facing online services primarily providing a forum for user-generated content. Carve-outs exist for ISPs, email providers, and certain small-scale services.
Key provisions
Criminal NCII and "digital forgery" prohibitions
The Act criminalizes knowing publication without consent of intimate visual depictions of an identifiable individual. It explicitly includes AI-generated, computer-generated, and synthetic "digital forgeries" indistinguishable from authentic depictions of a real person, and creates a separate offense for threats to publish such material (revenge-porn coercion). Minor-victim offenses require intent to abuse, humiliate, harass, degrade, or arouse sexual desire. Penalties run up to 2 years of imprisonment for adult-victim offenses and 3 years for minor-victim offenses, plus fines, restitution, and forfeiture.
48-hour notice-and-takedown duty
Covered platforms must remove NCII within 48 hours of a valid notice from the depicted individual or an authorized representative, and must make "reasonable efforts" to remove identical copies. A valid notice requires an electronic signature of the depicted individual, a URL or locator, a description of the content, and a good-faith statement that the depiction is nonconsensual. Good-faith compliance with a valid notice is expressly protected.
Interaction with Section 230
The Act does not amend Section 230 directly. It operates through a statutory duty that platforms must meet independent of Section 230 immunities, a structure that differs from the DMCA (copyright) and FOSTA-SESTA (trafficking). The duty runs parallel to Section 230 immunity, part of a multi-year trend (FOSTA-SESTA, the pending Kids Online Safety Act) narrowing intermediary protection.
Enforcement and penalties
Violations of the takedown duty are treated as unfair or deceptive acts or practices under Section 5 of the FTC Act; there is no private right of action for the takedown duty. The criminal provisions are enforced by the Department of Justice. The Act is the first federal criminal statute directly targeting AI-generated NCII and the first federal FTC-enforced notice-and-takedown duty for user-generated content outside the DMCA copyright regime.
FTC pre-deadline compliance push
FTC Chair Andrew Ferguson sent a letter on May 11, 2026 to 15 named platforms — Amazon, Alphabet, Apple, Automattic, Bumble, Discord, Match Group, Meta, Microsoft, Pinterest, Reddit, SmugMug, Snapchat, TikTok, and X — reminding them of the "rapidly approaching" Section 3 deadline. The Section 3 deadline of May 19, 2026 is when covered platforms must have a compliant notice-and-takedown process operational. Ferguson's letter signaled that the FTC would treat post-deadline failures as live enforcement risk rather than a glide-in period, and was the first FTC-Chair-level public communication on the Act. Full primary text and a seven-bullet compliance walkthrough are summarized at FTC Take It Down Act Stakeholder Letter (Ferguson, May 11, 2026).
The letter disclosed three operational points not previously made public: the operative civil-penalty figure of $53,088 per violation, the first FTC disclosure of a per-violation dollar figure under the Act; a non-account-holder access requirement under which platforms must accept removal requests from individuals without an account; and an expected cross-platform hash-sharing baseline — NCMEC for minor content and StopNCII.org for adult content, formalizing existing voluntary networks. The letter is non-binding interpretive guidance, and compliance with the seven bullets is not a defense to enforcement under broader statutory text. (Sources: stakeholder letter; ftc.gov; insideaipolicy.com)
Onset of enforcement
The civil notice-and-takedown provisions took effect on May 19, 2026, and the FTC began enforcement the same day. IAPP's May 21 compliance walkthrough reports that, ahead of the deadline, the FTC delivered warning letters to at least 15 companies, and that Chairman Andrew Ferguson and Commissioner Mark Meador repeatedly signaled the agency's intent to enforce. The early enforcement activity paired with the Radnor Township High School (PA) case documented on May 21 — five teenage girls targeted with AI-generated CSAM — as an early concrete case of the platform-side accountability framing (Synthetic Media / Deepfakes). (Sources: iapp.org; 404media.co)
On May 21, 2026, one day after announcing that enforcement was underway, the FTC sent warning letters to 12 unidentified websites over possible violations of the Act, its first concrete enforcement step since the May 19 effective date. The FTC did not name the targeted companies; the letters again invoked the Act's coverage of nonconsensual AI-generated deepfakes. (Source: insideaipolicy.com)
The first criminal conviction under the Act occurred in April 2026, per a Cruz-Klobuchar joint release — the earliest empirical signal that the criminal half of the Act is being used.
Empirical status at one year (Cuevas et al., May 2026)
Princeton CITP postdoc Alejandro Cuevas published a one-year-anniversary status check of the Act in Tech Policy Press on May 13, 2026, distilling his team's arXiv preprint 2602.02754 (It's Too Soon To Tell If the TAKE IT DOWN ACT Is Working (Cuevas, Tech Policy Press, May 13 2026)). The study found that supply and demand for AI-generated NCII grew across the three studied forums in 2025 despite federal criminalization, leading Cuevas to conclude that the federal criminal-deterrence theory had not yet bitten.
The studied ecosystem (with forum names anonymized where the researchers chose to avoid traffic-routing):
- MrDeepfakes (founded 2018; ~50,000 registered users): the previously largest dedicated NCII site, described as "the go-to site for nonconsensual deepfake porn" per 404 Media. It shut down two weeks before the Act was signed, in May 2025, after critical-infrastructure operators rescinded services. MrDeepfakes itself originated one week after the /r/deepfakes subreddit was removed from Reddit, illustrating a takedown-then-rebirth pattern.
- Website A and Website B (each with millions of registered users, orders of magnitude larger than MrDeepfakes, with dedicated subforums for AI-NCII of real people).
- 4chan: a subforum where users request nudification services, used as a demand-side proxy.
Cuevas attributes the post-enactment supply and demand growth to three mechanisms: publicity attracting new users; migration from MrDeepfakes; and migration from policy-tightened platforms such as CivitAI, which removed real-person-likeness content models in 2025. On enforcement readiness as of May 2026, the study notes that 4chan added Act-compliant takedown instructions in 2025 but the researchers "did not observe any substantial deletions of content, which suggests not many users have sent removal requests," and that Websites A and B had yet to provide a takedown protocol.
Cuevas argues that the data implies the operative deterrence lever is platform-side accountability under Section 3 rather than federal criminal liability, since post-passage supply and demand grew despite users' apparent awareness of the criminal provisions. He also notes that the EFF's pre-passage warning that take-down requests could be weaponized as speech-suppression tools had not, through May 2026, materialized — which he attributes to the platform-side duty not yet having activated. The post-May-19-2026 enforcement period is, per Cuevas, the test of both questions.
As a comparative benchmark, Cuevas points to the UK Online Safety Act, whose enforcement began in March 2025; Ofcom designated 4chan a covered platform in April 2025, issued fines, and opened an investigation against Website A later that year. The OSA's broader-harms and risk-assessment-duty structure offers an early comparison for whether the US notice-and-takedown approach or the UK risk-assessment-duty approach bites harder on the AI-NCII ecosystem.
Relation to other legislation
| Dimension | TAKE IT DOWN | State Deepfake Statutes (MN, WA, TX, CA) (MN/WA/TX/CA) | California AI Transparency Act (SB 942) | California SB 243 — Companion Chatbots |
|---|---|---|---|---|
| Level | Federal | State | State | State |
| Harm class | Sexual NCII (real + synthetic) | Political / election deepfakes | GenAI output generally | Companion-chatbot harms to minors |
| Core duty | 48-hr takedown + criminal | Disclosure or prohibition during election windows | Watermarking + detection tool | Crisis-response + disclosure |
| Enforcement | FTC + DOJ | State AG / private action | CA AG / city attorney | CA AG |
| Criminal penalties | Yes (federal) | Some (MN, TX) | No | No |
The federal statute addresses the sexual-NCII gap that state-level election-deepfake laws leave open, and converges with state watermarking laws (California AI Transparency Act (SB 942)) on the broader synthetic-media problem without directly addressing it. Within US AI Regulatory Approaches Compared, the Act adds a dimension the prior taxonomy did not include — federal criminal law targeting AI-generated content. It is narrower in subject (NCII only) but, unlike Executive Order 14365 — Ensuring a National Policy Framework for AI or America's AI Action Plan, imposes binding duties on private actors rather than shaping agency or state behavior. It does not expressly preempt state NCII or deepfake laws; overlap with stronger state regimes (e.g., NY, CA) creates compliance complexity for platforms. Commentators have suggested the Act may serve as a template that other NCII or harmful-content legislation, such as revenge-porn and pending kids-online-safety bills, may copy.
Reactions and contested points
- First Amendment. During passage, critics including the EFF and ACLU argued the takedown duty's speed and low notice threshold risk overremoval of satire, parody, and protected speech. Defenders argue the narrow "intimate visual depiction" definition and good-faith standards mitigate this.
- Platform gaming and bad-faith notices. Critics argue the 48-hour deadline incentivizes over-removal, and that the Act's good-faith requirement and penalty for false notices may be under-enforced.
- Encrypted and decentralized services. Application to end-to-end encrypted messaging and federated platforms (e.g., Mastodon, Bluesky relays) is untested, and FTC rulemaking will be decisive.
- Political versus sexual deepfakes. Congress has not legislated on political deepfakes; the Act limits federal scope to sexual NCII, leaving the election-deepfake question to states (State Deepfake Statutes (MN, WA, TX, CA)).
Relationships
- supersedes: (partially) prior state-only NCII patchwork for AI-generated content, though does not preempt stronger state law
- related: State Deepfake Statutes (MN, WA, TX, CA) — state-level deepfake regimes covering political/election content
- related: California AI Transparency Act (SB 942) — California AI transparency (watermarking) for GenAI outputs generally
- related: California SB 243 — Companion Chatbots — California companion-chatbot child-safety statute
- related: US AI Regulatory Approaches Compared — adds federal criminal-law dimension to the taxonomy
- depends-on: Section 5, FTC Act — enforcement mechanism
Sources
- source summary
- Raw:
Raw Sources/TAKE IT DOWN Act (S. 146, P.L. 119-12).md - One-year empirical anniversary: It's Too Soon To Tell If the TAKE IT DOWN ACT Is Working (Cuevas, Tech Policy Press, May 13 2026) (Cuevas et al. arXiv 2602.02754)
- FTC Stakeholder Letter (May 11, 2026): FTC Take It Down Act Stakeholder Letter (Ferguson, May 11, 2026) — primary-text seven-bullet compliance guidance with $53,088-per-violation civil penalty
- Secondary: RAINN federal-legislation brief; Skadden (Jun 2025); Latham & Watkins; CRS Legal Sidebar LSB11314; NACO; Senate Commerce press release; White House May 19, 2025 signing statement; FTC press release May 11, 2026