Someone Made a Deepfake of Me: A Step-by-Step Removal Guide

A step-by-step guide to removing a deepfake of yourself: documenting it, filing under the TAKE IT DOWN Act, and monitoring for reposts.

NE

Noticeora Enforcement Desk · Takedown & Compliance Team

Files DMCA and TAKE IT DOWN Act notices daily across platforms, hosts, and search engines.

Published September 12, 2026 · 6 min read

This is a solvable problem, even though there's no "original" to point to

Finding out that AI-generated content depicting you exists is disorienting in a specific way that a normal leak isn't: there's no real photo or video underneath it that got stolen. Someone generated it, or manipulated an existing image into something that never happened. That fact makes people assume, incorrectly, that there's no clean legal remedy — because most people's mental model of "getting something taken down" is copyright, and copyright needs a real original work to protect.

There is a clean legal remedy here, and it doesn't require a real original to exist. Here's the process, step by step.

Step 1: Document the exact URL

Before doing anything else, capture:

  • The exact URL of the page or post — not the site's homepage, the specific location.
  • A screenshot of the content and the page around it (including the account or username that posted it, if visible).
  • The date and time you found it.

This matters because a valid removal notice legally requires precise URLs or information sufficient to locate the content — a vague description of "it's somewhere on this site" doesn't meet that bar, and content on these sites can move or get taken down/reposted without warning, so document it before it changes.

Step 2: Confirm there's no real underlying original

This determines which notice you file. If the content is a real photo or video of you that's been copied or leaked without permission, that's a copyright matter — a DMCA notice. If it's synthetic — a face swap, an AI-generated image or video, or something manipulated to depict an event that never happened — there's no copyrighted original to claim, and DMCA is the wrong tool (or at best a weak, indirect one). This is squarely what the federal TAKE IT DOWN Act was built for.

You don't need to prove how it was made

You don't need to identify the specific AI tool used, or prove the technical process behind it. The statute's threshold is simpler: the content is a non-consensual intimate depiction of an identifiable person that a reasonable viewer would find indistinguishable from authentic — it doesn't require the depicted event to have ever really happened.

Step 3: File under the TAKE IT DOWN Act, not DMCA

Public Law 119-12, signed May 19, 2025, requires "covered platforms" — services that primarily host user-generated content, or whose regular business involves publishing this kind of content — to remove qualifying non-consensual intimate imagery, explicitly including AI-generated "digital forgeries," within 48 hours of receiving a complete, valid notice.

A complete notice needs four things in writing:

  1. A signature — yours, or an authorized representative's on your behalf.
  2. The precise URL(s) or information sufficient to locate the content.
  3. A brief good-faith statement that the content is non-consensual.
  4. Contact information sufficient for the platform to follow up.

Send this to the platform's designated contact for this kind of report — not to the person who posted it. Note that the 48-hour clock only starts once the notice is complete; an incomplete submission doesn't trigger the deadline, so double-check all four elements are present before sending. For the full breakdown of what the statute covers and excludes, see our TAKE IT DOWN Act explainer.

What DMCA can still do here

If the deepfake was built by manipulating a specific photo or video you own the rights to (rather than generated from scratch), you may have a secondary DMCA claim over that underlying source material — but the TAKE IT DOWN Act notice is still the more direct tool for the synthetic content itself, since it doesn't depend on proving ownership of anything.

Step 4: Escalate if the platform doesn't respond

A covered platform's failure to reasonably comply is treated as an unfair or deceptive practice under the FTC Act, and the FTC can enforce against it. If a platform ignores a complete, valid notice past the 48-hour window, that's grounds to escalate — keep your original notice and any correspondence, since that record is what any escalation would rely on.

Not every site is a "covered platform" under the statute (the exclusions include things like email services and platforms that only publish pre-selected, non-user-generated content), so a genuinely obscure or foreign-hosted site may not be bound by the same 48-hour requirement even if the content itself qualifies. In that case, a host-level abuse report and, where applicable, a request under a relevant state right-of-publicity or NCII law are the fallback options — these vary by state, so specifics depend on where you and/or the poster are located.

Step 5: Request search de-indexing

Even after the content is removed at the source, it can still appear in search results until the page is re-crawled. Google has a dedicated removal request for personal explicit imagery, including AI-generated content, that de-indexes the URL directly rather than waiting on a re-crawl — see our guide to removing leaked content from Google search results for the mechanics of that process, which apply the same way to synthetic content.

Step 6: Monitor for reposts

Deepfake content that's been removed once has a real chance of resurfacing — re-hosted on the same platform under a different account, or mirrored to a new site entirely, sometimes by whoever generated it in the first place. Because there's no original file to check against, catching a repost requires the same identity-based approach used for the initial detection: matching your actual face across newly scanned content, not searching for a specific file or filename that may not even match the reposted version.

A one-time takedown without follow-up monitoring is a temporary fix. If the same person or account is motivated to keep posting, without monitoring you may not find out a new copy exists until someone tells you.

Quick reference: the whole process

StepWhat to do
1. DocumentScreenshot the content and record the exact URL, date, and time
2. ClassifyConfirm there's no real underlying original — this points you to the TAKE IT DOWN Act, not DMCA
3. FileSend a complete notice (signature, URL, good-faith statement, contact info) to the platform
4. Escalate if neededFTC enforcement applies if a covered platform doesn't reasonably comply
5. De-indexRequest removal from Google search results directly
6. MonitorWatch for reposts using identity-based (not filename-based) detection

If you want this handled rather than done manually

Noticeora verifies whether content is genuine or synthetic, files the correct notice type automatically on the Autopilot tier ($99/month, which also covers de-indexing and reupload monitoring), or gives you the detection and a self-filed notice path on the DIY tier ($39/month). Either way, the first useful step is knowing what's actually out there — a free scan shows you that before you decide how much of the rest of this process to take on yourself.

Protect your creators before the next leak appears

Facial-recognition detection and legal enforcement, under one flat subscription.

Related reading