TAKE IT DOWN Act
Federal law criminalising publication of non-consensual intimate imagery, including AI-generated deepfakes. Covered platforms must operate a notice-and-removal process and take down reported content and known copies within 48 hours; civil provisions enforced by the FTC from 19 May 2026.
| Jurisdiction | United States |
|---|---|
| Category | Privacy & Data Protection |
| Status | Active |
| Effective date | |
| Latest development |
Recent developments
- — A June report said the Take It Down Act was now in full effect and asked what comes next for tech firms. It noted that companies face financial and criminal penalties if they do not remove nonconsensual intimate images within 48 hours after notice. (source)
- — County officials summarized the law’s requirements and noted that digital platforms had one year to establish appeal and removal processes after enactment. The piece reflects the broader public-sector view that the law imposes new compliance duties on online services. (source)
- — The FTC announced it began enforcing the TAKE IT DOWN Act and launched a complaint portal for victims to report platforms that fail to remove nonconsensual intimate images or fail to provide a removal process. The agency said covered platforms must remove the material and known identical copies within 48 hours of a valid request. (source)
- — The FTC’s business guidance says enforcement of Section 3 began and explains the obligations for covered platforms under the law. It emphasizes notice-and-removal requirements and the need for a clear process for people to request takedown. (source)
- — FTC Chairman Andrew N. Ferguson sent compliance reminder letters to more than a dozen technology companies ahead of the deadline. The letters warned that platforms must provide conspicuous notice and remove qualifying content within 48 hours of a valid request. (source)
- — Senators Amy Klobuchar and Ted Cruz marked one year since enactment and highlighted the start of FTC enforcement. Their statement framed the law as a tool against nonconsensual intimate imagery, including AI-generated NCII. (source)
- — The Verge reported that the law’s takedown requirements took effect on May 19, 2026, making the compliance deadline active for social platforms. The article also noted potential civil fines exceeding $53,000 per violation. (source)
- — An industry compliance analysis said the one-year grace period had expired and platforms without a documented NCII takedown process were exposed to FTC enforcement. It also argued that the law creates immediate operational pressure for platforms hosting user-generated content. (source)
- — A later-updated overview article states that the first conviction under the law occurred in April 2026 in Ohio involving AI-generated NCII. This is not as authoritative as official or mainstream reporting, but it suggests early enforcement activity beyond platform compliance. (source)
Related regulations
- COPPA (Children's Online Privacy Protection Act) — United States, Active
- Cybersecurity Maturity Model Certification — United States, Phased, effective 2025-11-10
- NIST AI Risk Management Framework (AI RMF 1.0) — United States, Active, effective 2023-01-26
- SEC Cybersecurity Disclosure Rules — United States, Active, effective 2023-12-18
- Executive Order 14365 - Ensuring a National Policy Framework for Artificial Intelligence — United States, Active, effective 2025-12-11
- SEC Regulation S-P Amendments (Customer Data Incident Response) — United States, Active, effective 2026-06-03
- CIRCIA Cyber Incident Reporting Rule (CISA) — United States, Proposed
- HIPAA Security Rule Modernisation (Proposed Rule) — United States, Proposed
Put it into practice
- Generate the policy: COPPA policy generator (generatepolicy.com)
- Buy the policy pack: Privacy Program Bundle (cyberpolicy.shop)
- Build it yourself: 2026 US Privacy Program Workbook (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates