A covered platform that misses a valid takedown request may face a Federal Trade Commission penalty of up to $53,088 per violation.
The person who knowingly publishes a nonconsensual intimate image or an AI-generated sexual deepfake can face federal prison time: up to two years when an adult is depicted and up to three years when a minor is depicted. Certain threats involving digital forgeries carry separate prison terms of up to 18 or 30 months.
Those are two different risks under the same federal law. One lands on the publisher. The other lands on the platform that failed to build and run a working removal system.
You do not need an office in California, New York, or any other state. This is federal. If your public website or app primarily provides a forum for user-generated messages, images, videos, games, or audio, the TAKE IT DOWN Act may reach the product itself.
What the TAKE IT DOWN Act requires
The TAKE IT DOWN Act became Public Law 119-12 on 19 May 2025. Its criminal provisions cover the knowing publication of certain nonconsensual intimate visual depictions, including a "digital forgery" created or altered with software, machine learning, or AI.
The platform deadline arrived one year later, on 19 May 2026. A covered platform must now provide a clear and conspicuous notice explaining its removal process in plain language. The process must let an identifiable person, or an authorised representative, report an intimate image published without consent and request its removal.
A valid written request must include four things: a physical or electronic signature, enough information to locate the image, a short good-faith statement that it was published without consent, and contact information for the person or representative making the request.
Once the platform receives a valid request, it must act as soon as possible and no later than 48 hours. It must remove the reported depiction and make reasonable efforts to identify and remove known identical copies within the same window.
The definition of a covered platform is broad. It includes public websites, online services, online applications, and mobile applications that primarily provide a forum for user-generated content. The FTC says this can include social media, messaging, image-sharing, video-sharing, and gaming services. Email, broadband access, and mainly editorial sites with only incidental comments are excluded in specified circumstances.
Why this lands on the product, not only the legal page
Building in one of these categories? Send me one message about what you're building and I'll name the laws you're inside — which documents they demand, and what covers you. Free, usually within a day or two. Start here.
— Santosh
A paragraph in your Terms of Use cannot receive a report, confirm its contents, find the media, start a clock, remove copies, and preserve an evidence trail.
The law turns content moderation into an operating system. Your product needs a visible reporting path. Your support team needs a rule for deciding when a request is valid. Engineering needs a way to locate identical copies. Someone must own the 48-hour deadline across weekends and time zones.
The FTC recommends a tracking number for each request and status updates for the person who filed it. It also points platforms toward tools such as hashing to prevent removed content from returning. Those steps are guidance rather than new statutory text, but they are practical evidence that the process works.
This will also surface in enterprise diligence. A buyer that lets staff or customers upload media can ask whether your product has a nonconsensual-intimate-image policy, an accessible reporting channel, a duplicate-removal method, and a response log. Your moderation runbook can become part of the compliance pack that gets the deal through procurement.
In June 2026, the Justice Department and Department of Homeland Security seized CFAKE.com and SOCFAKE.com. The government said the sites published thousands of nude digital forgeries of identifiable women without consent. A federal judge found probable cause to believe the domains were being used for criminal violations of the TAKE IT DOWN Act. This was a domain seizure, not a final criminal conviction, but it shows that federal enforcement is already moving against the infrastructure used to publish sexual deepfakes.
The federal rule now sits on top of state AI laws
The TAKE IT DOWN Act creates one federal floor for covered platforms. It does not erase state rules on voice, likeness, biometric data, minors, unfair practices, or synthetic media.
If your product clones a person's voice or face, read the ELVIS Act article. If your product reaches children or uses synthetic media in ways covered by Connecticut's framework, read the Connecticut SB 5 article. Each law asks a different question. One federal takedown form will not answer all of them.
The document stack must match the product. For image and video tools, that usually means a sharing-and-publication policy, an acceptable use policy, a nonconsensual-intimate-image removal process, contributor or likeness consents where needed, and a response log that records every deadline. StartEase maps those items by product category on its AI document services page.
Where you incorporate does not protect you
A Delaware C-Corporation or Wyoming LLC does not receive a federal exemption. The question is what the service does, who can use it, and whether it fits the Act's covered-platform definition.
A founder outside the United States should not assume distance solves the issue either. If the product serves the US market or its conduct crosses interstate or foreign commerce, the federal scope needs to be checked before launch. Entity formation changes the company record. It does not rewrite the product's moderation duties.
Three things to fix before you scale
1. Build the reporting route into the interface. Put a clear link where intimate content may appear and let non-users submit a request. Capture the signature, content location, good-faith statement, and contact details the statute calls for.
2. Give the 48-hour clock an owner. Write an internal runbook that covers intake, validation, escalation, removal, duplicate search, response, and record retention. Add weekend coverage. A shared inbox with no deadline owner is not a process.
3. Connect policy language to technical controls. Your acceptable use policy should prohibit nonconsensual intimate depictions and digital forgeries. Your moderation tools should locate known identical copies. Your logs should show when the request arrived, what was removed, and when the requester was told.
The one-line summary for each founder
AI image and video tools: a deepfake report now starts a federal product deadline, not an open-ended support ticket.
Social, messaging, and community apps: if users can post or share media, the reporting path and duplicate-removal workflow belong in the launch checklist.
Kids products: a depiction involving a minor raises the highest criminal exposure and needs an immediate escalation route.
Model and API companies: if customers can publish outputs through your service, map where generation ends and platform hosting begins before assuming the duty sits elsewhere.
The 48-hour rule is already in force. The FTC has opened a public reporting portal for complaints against platforms, and it says it is monitoring compliance. Waiting for the first report to design the process leaves the product exposed at the exact moment the clock begins.
Building an AI image or video platform? Send me one message about what you're building, and I'll name the rules you're inside.