On May 19, 2026, the most significant US law targeting AI-generated sexual content entered full enforcement. The TAKE IT DOWN Act — signed by President Trump exactly one year earlier — now requires every major online platform to remove non-consensual intimate imagery, including AI-generated deepfakes, within 48 hours of a victim’s request. Platforms that fail to comply face enforcement action from the Federal Trade Commission.
This isn’t a hypothetical regulation debated in committee. It’s law, it’s active, and the first criminal conviction under it has already happened.
What the TAKE IT DOWN Act Actually Does
The law operates on two levels: criminal prohibition and platform obligations.
Criminal Prohibition
The Act makes it a federal crime to knowingly publish non-consensual intimate visual depictions through any online platform. This covers both authentic imagery (traditional revenge porn) and AI-generated deepfakes that are realistic enough to depict a real, identifiable person in sexual content.
Penalties: up to two years imprisonment for adult victims, up to three years for minors. The Act also criminalizes threatening to publish such content — meaning even the threat of releasing deepfakes for intimidation, coercion, or extortion is a federal offense.
The first conviction came in April 2026, when an Ohio man was found guilty of using AI tools to create and distribute non-consensual intimate imagery targeting adults and children in his community.
Platform Requirements (Effective May 19, 2026)
Every “covered platform” must now implement a clear, accessible process for victims to request removal of non-consensual intimate imagery or deepfakes. Upon receiving a valid request, the platform must remove the content within 48 hours and make reasonable efforts to remove known copies and re-uploads.
“Covered platform” is defined broadly — it includes social media networks, search engines, image-hosting sites, and any interactive computer service with a substantial number of US users. Platforms that fail to comply face FTC enforcement actions, civil penalties, and potential litigation.
Why This Law Exists Now
The scale of the problem demanded federal action. Non-consensual deepfake pornography accounted for 96% of all deepfake videos online according to Sensity research. Nudification apps — tools that strip clothing from photos using AI — proliferated across app stores, requiring nothing more than a photo to generate realistic fake nude imagery of any person.
The problem reached mainstream consciousness when high-profile cases involving students hit national news. Classmates used freely available AI tools to create sexually explicit images of other students and circulate them on social media. Schools, parents, and law enforcement had no federal legal framework to address the harm.
Before the TAKE IT DOWN Act, victims had to rely on a patchwork of state laws — some states had enacted deepfake-specific statutes, many hadn’t. As of spring 2026, 46 states have enacted some form of deepfake legislation, but the scope, penalties, and definitions vary significantly. The federal law provides a nationwide floor.
The State-by-State Landscape
The TAKE IT DOWN Act provides the federal baseline, but states continue to build additional protections:
- Strongest state protections: Florida, Illinois, Washington, Oregon, New Jersey, Michigan, Pennsylvania, and Arizona have enacted comprehensive combinations of revenge porn expansion laws, non-consensual deepfake statutes, and CSAM updates that explicitly address AI-generated material.
- Election-related deepfakes: 30 states have enacted restrictions on AI-generated content in political campaigns ahead of the 2026 midterms. These laws target deceptive political ads, synthetic candidate speeches, and fabricated endorsements.
- AI-generated CSAM: Federally illegal everywhere. Explicitly criminalized in 45 states. All major AI platforms prohibit generation of this content, and multiple prosecutions have occurred under both federal and state law.
- Fully synthetic content (fictional characters): This remains the most legally ambiguous category. In most states, AI-generated explicit content depicting entirely fictional characters with no resemblance to real people is not explicitly illegal, though it may be subject to general obscenity laws.
Looking Forward: What 2026 Legislation Targets Next
Lawmakers are broadening their scope beyond individual creators to the infrastructure that enables deepfake production. Expected legislative targets include generative AI platforms that don’t implement adequate content filters, payment processors that facilitate transactions for deepfake creation services, hosting services and cloud providers that enable production and distribution, and app stores that distribute nudification or deepfake creation tools.
Congress is simultaneously debating a 10-year moratorium on state AI regulation that would prohibit states and localities from enforcing laws that broadly regulate AI. Whether this moratorium would affect deepfake-specific state laws remains contested — the tension between federal AI policy and state-level consumer protection is one of the key regulatory battles of 2026.
The Broader AI Safety Context
The TAKE IT DOWN Act addresses one category of AI harm — non-consensual intimate imagery. But it exists within a much larger conversation about AI safety that has intensified dramatically in 2026.
Anthropic’s Mythos model demonstrated autonomous vulnerability discovery capabilities so powerful that the company refused to release it publicly. Pope Leo XIV’s encyclical Magnifica Humanitas, released today (May 25), frames AI’s capacity to simulate human faces and voices as a threat to human identity and dignity. The AI image and video generation tools that enable legitimate creative work also enable the creation of harmful content.
The fundamental challenge is that the same AI capabilities that produce beautiful art, useful products, and innovative tools also produce convincing forgeries, non-consensual imagery, and disinformation. The fallout is not limited to regulators and victims either — platform trust can shift quickly when users feel safety systems are failing, as seen in the install surge Bluesky saw afterward. Legislation like the TAKE IT DOWN Act targets specific harms without attempting to restrict the underlying technology — a scalpel rather than a sledgehammer approach.
For individuals concerned about broader data privacy and digital security, the deepfake threat is one component of a larger landscape where AI is both a tool for protection and a vector for harm. Our privacy tools guide covers the defensive side.
What To Do If You’re a Victim
If non-consensual intimate imagery or deepfakes of you exist online, you now have a federal legal framework for removal:
Step 1: Identify the platform(s) hosting the content. Take screenshots documenting the content and URLs before requesting removal (for evidence if legal action is needed).
Step 2: Submit a takedown request through the platform’s NCII removal process. Every covered platform was required to have this process in place by May 19, 2026. Look for “Report” options, “Safety” settings, or specific NCII removal tools.
Step 3: The platform must remove the content within 48 hours and make reasonable efforts to prevent re-uploads.
Step 4: If the platform fails to comply, report the violation to the FTC at ftc.gov/complaint.
Step 5: For criminal prosecution of the person who created or distributed the content, file a report with local law enforcement and the FBI’s Internet Crime Complaint Center (ic3.gov). The TAKE IT DOWN Act provides federal criminal penalties in addition to state-level protections.
StopNCII.org (operated by the UK’s Revenge Porn Helpline) provides a hash-matching service that can help prevent re-uploads of intimate imagery across participating platforms without requiring you to share the actual images.
FAQ
1. What is the TAKE IT DOWN Act?
A US federal law signed May 19, 2025 and fully enforceable as of May 19, 2026. It criminalizes the publication of non-consensual intimate visual depictions (including AI deepfakes) and requires online platforms to remove such content within 48 hours of a victim’s request. The FTC is the primary enforcement authority.
2. Does the law cover AI-generated deepfakes?
Yes. The law explicitly covers “digital forgeries” — AI-generated visual depictions that are realistic enough to depict an identifiable person in intimate content, whether or not the depicted acts actually occurred.
3. What platforms must comply?
All “covered platforms” — social media networks, search engines, image-hosting sites, and any interactive computer service with a substantial number of US users. This includes major platforms like Meta, X, Google, Reddit, Discord, and smaller hosting services.
4. Has anyone been convicted under this law?
Yes. The first conviction came in April 2026 — an Ohio man was found guilty of creating and distributing AI-generated non-consensual intimate imagery targeting adults and children in his community.
5. Can I request removal of AI-generated content even if it doesn’t show nudity?
The TAKE IT DOWN Act specifically covers “intimate visual depictions” — content that is sexual or nude in nature. Non-sexual deepfakes (such as someone’s face placed in a non-intimate context) are not covered by this specific law, though they may be addressed by other regulations, platform policies, or state laws.
6. What about deepfakes used in elections?
The TAKE IT DOWN Act doesn’t specifically address political deepfakes. However, 30 states have enacted separate restrictions on AI-generated content in political campaigns. Federal legislation on political deepfakes is being debated separately.
Originally published: March 10, 2026 (as “Governments Tackle Surge of Non-Consensual AI Nudity on X”). Updated: May 25, 2026 with TAKE IT DOWN Act full enforcement, first conviction, state-by-state analysis, and victim guidance.
