The core purpose of the Take It Down Act is straightforward: Publishing or threatening to publish nonconsensual intimate imagery—including AI-generated deepfakes—is now a federal offense, and online platforms face a mandatory 48-hour deadline to remove such content.
Still, the bill’s passage — signed into law by President Donald Trump in 2025 and enacted this May — was something of a miracle. It was one of very few recent bills to have broad bipartisan support, led by Minnesota Democrat Amy Koch and Texas Republican Ted Cruz, with support from first lady Melania Trump.
The legislation represents an urgently needed response to a rapidly evolving technology that authorities are still learning to manage. Yiota Souras, chief legal officer at the National Center for Missing and Exploited Children, described the measure as an «incredibly quick response to a really new technology that we’re still figuring out.» Just months after signing into law, federal prosecutors had already secured one conviction under the new framework.
This rapid yet necessary response comes amid the explosive growth of generative AI. A 2023 global study by Security Hero found that deepfake pornography makes up 98% of all digital forgery videos online, with 99% of these featuring women as the primary subject. The total number of deepfake videos online has surged by 550% from 2019 to 2023.
I believe the Take It Down Act (hereafter referred to as TIDA) stands as the United States government’s most significant countermeasure against the wave of AI-enabled sexual harassment online. It establishes a strong legal foundation for prosecuting offenders while offering some support to survivors. However, TIDA remains only a partial solution toward fully protecting children, women, and vulnerable communities from image-based abuse.
Enforcing TIDA: Progress Since Enactment
Implementation efforts under TIDA have produced two main outcomes: new reporting channels for victims and expanded legal avenues to hold offenders accountable.
As required by the law, Meta and Google each launched dedicated portals allowing social media users to report instances of nonconsensual intimate content shared online. The Federal Trade Commission, which monitors tech companies’ compliance, also created a new process to flag when social networks fail to remove prohibited material. (See our complete guide for what to do if you’ve been deepfaked for more information.)
Having intimate images circulated online without your consent violates personal boundaries and can strip victims of their sense of control. These reporting mechanisms help people reclaim agency, according to Nicol Turner Lee, a Brookings senior fellow and director of the Center for Technology.
«Most people accepted the social contract of the online economy when sharing details were less intimate,» Turner Lee explained. «I don’t think many people were surprised that technology can … create these extreme harms. The reason Take It Down was established is that you could actually see the harm.»
Specific data on the volume of posts removed under TIDA remains unavailable, and such metrics may not be forthcoming depending on whether Meta and Google release statistics on content removals under the federal law or their standard community guidelines.
In terms of prosecutorial results, the first conviction involved an Ohio man who pleaded guilty to cyberstalking, publishing or sharing digital forgeries of adult sex abuse material, and producing child sexual abuse material. The swift resolution demonstrated that the law «has teeth,» according to advocates at the time. The Department of Justice continues to pursue additional cases under the statute.
However, TIDA does not directly prevent harm; it only creates pathways to address it after the fact. Advocates contend that a law like this derives its strength from deterrence—the ability to impose meaningful punishments on offenders to discourage future behavior. To unlock its full potential, consistent and public criminal enforcement is essential, Souras noted.
«Until people witness that individuals are being charged, people are going to jail, offenders may think, ‘I still have an open ticket to commit this,'» Souras stated.
The final component involves the FTC, which ensures tech companies comply with the law. The agency sent notice letters to 12 companies operating «nudify» services designed to create sexually explicit material, during the same week TIDA took effect.

Yet the FTC’s authority is more limited than it might appear. According to CNET, the agency cannot resolve individual reports or remove images directly, and by law it cannot disclose details about ongoing investigations.
Lawmakers and regulators are striving to incentivize hosting platforms to proactively eliminate such content. Whether enforcement will meaningfully safeguard consumers remains uncertain at this stage—as we must adopt a long-term perspective, and harm will persist in the interim.
«Laws take time, and a law is only part of the solution,» Souras observed. «It represents a tremendous foundational element, but you still require education, training, and resources for investigation and continued prosecution.»
Removing Content Is Not Without Flaws
Multiple services exist to assist individuals whose intimate images have been shared online without their consent. The two largest are the Take It Down program from NCMEC for teens under 18, and StopNCII.org for adults.
Both services employ a method called «hashing.» To report sexually explicit images circulating online, users upload the image, which receives a unique digital identifier known as a hash. Rather than sharing the actual image, this hash is shared with social media platforms. These platforms can then scan their posts for matching IDs and remove any corresponding content.
This approach is far from flawless. Each image or video requires its own separate case submission. Whenever content undergoes even slight alterations, a new hash must be generated. This becomes a logistical nightmare in the era of AI, which enables exponential image editing capabilities.
A woman in Wyoming recently discovered that her stepfather had created more than 7,000 sexually explicit images of her using Elon Musk’s Grok AI, some derived from her genuine childhood photographs. (She also filed a lawsuit against Musk’s xAI, alleging devastating harm from AI-generated child sexual abuse material.)
Compounding complications arise because tech companies are not obligated to participate in these programs—they operate voluntarily. Both NCMEC and StopNCII.org maintain partnerships with major tech firms, including Meta, YouTube, Pornhub, and OnlyFans. Yet the opt-in nature of these systems grants companies leeway to allow abusive content to persist unchecked.
The fundamental difficulty lies in placing the burden of reporting on survivors. Those affected are encouraged to document instances of their images being shared online in preparation for potential legal action. The necessity of uploading, reviewing, and tracking abusive content can be traumatic, extending harm in many cases.
This imperfect, ongoing process—which ultimately falls entirely on survivors—often leads to post-traumatic stress disorder, according to Susanna Gibson, founder of My Own Image, a nonprofit supporting survivors of technology-facilitated sexual violence.
«Survivors shouldn’t have to construct their own digital rape kits,» Gibson explained. «They’re still expected to perform incredible labor … such as locating and identifying sexually abusive material of themselves.»
A Global Problem Needs Global Solutions
While TIDA may represent a victory within the United States, it operates under jurisdictional constraints. Intimate image abuse is inherently transnational, noted Raphaelle Rafin, a policy specialist on ending violence against women and girls at the United Nations.
«An offender might reside in one country, utilize a platform headquartered elsewhere, and upload content to servers located in a third nation while targeting a victim in a fourth jurisdiction,» Rafin explained via email. «This creates substantial obstacles for investigation, evidence collection, content removal, and prosecution.»
For example, MrDeepfakes—a major hub for nonconsensual deepfake porn—was reportedly operated by a Toronto-based individual, according to an investigation by Germany’s Der Spiegel. The site announced closure last summer, citing termination by a «critical service provider.» Around the same period, Canada enacted legislation criminalizing sexual deepfakes.
Services facilitating deepfake creation, sometimes termed «nudify» applications, operate globally as well. A recent study by the Institute for Strategic Dialogue identified 181 publicly accessible nudify websites (PDF). Collectively, they attracted over 40 million unique monthly visitors, and cryptocurrency payments enable users to circumvent international financial regulations. A specific series of apps used to generate deepfake porn was discovered to be managed by networks spanning Eastern Europe and Russia, Der Spiegel further reported.
«The most aggressive and problematic sites are not U.S.-based. It’s not Facebook and Instagram. It’s these pirate sites,» Gibson stated.
Another obstacle involves the fact that such images and videos frequently circulate on private channels—such as Discord servers and encrypted messaging applications—that evade detection. Telegram, for instance, was uncovered in 2024 to host «nudify bots» capable of undressing images of women and children. «Two bots logged more than 400,000 monthly users each, while another 14 boasted over 100,000 members,» Wired reported at the time.
So how does one address an issue of this magnitude and scope? Regional legislation serves as one approach; the United Kingdom, Panama, and Brazil have each passed laws comparable to TIDA. The European Union has also adopted measures banning nudify applications by 2027. International frameworks, including those from organizations like the UN, provide additional layers. The UN Convention against Cybercrime, a 2024 global treaty, contains provisions addressing nonconsensual intimate content (though the U.S. is not a signatory).

«From a policy standpoint, the central challenge is less the location of any single website and more the capacity of offenders and platforms to exploit legal and regulatory gaps between nations,» Rafin observed. Offenders can easily relocate, switch domains, and operate across borders, making international cooperation and harmonized legal standards essential.
Writing New Rules for the AI Era
As Gibson put it: «As technology evolves, so do the methods we choose to harm each other.» Historically, legislation typically follows technological innovation. Only after technology becomes widespread do societies begin imposing limits or safeguards.
We have witnessed how poorly this dynamic unfolds when left solely to tech companies. More than 20 years after Facebook’s launch, American society is only now beginning to genuinely confront social media’s profound impact on mental health and wellbeing.
Although the issues addressed by TIDA are not new, Turner Lee argued that the U.S.’s absence of fundamental privacy legislation laid the unstable groundwork for these problems to escalate. Effective legislation should prioritize empowering users to dictate how their data is utilized, where it appears, which tools they prefer, and how they can provide feedback when issues arise, he said.
In the void of privacy legislation, education on these matters offers one avenue for prevention. According to Rafin, teaching teens and adults about accountability, consent, and bystander intervention in digital spaces is crucial for disrupting online cultures like the manosphere that normalize misogyny, sexual entitlement, and hostility toward women.
Beyond tech policy and legal theory, deeper cultural and societal understandings regarding online sexual harassment require transformation. AI-generated image-based abuse is «not merely a technology issue. It is fundamentally a form of gender-based violence,» Rafin emphasized.

