Legal

What The TAKE IT DOWN Act Is — For Creator Agencies

Scope, eligibility, timelines, and evidence requirements under Public Law 119-12 — written for managers who file removals on behalf of a roster, not for a general audience.

NE

Noticeora Enforcement Desk · Takedown & Compliance Team

Files DMCA and TAKE IT DOWN Act notices daily across platforms, hosts, and search engines.

Published 4 August 2026 · 8 min read

If you manage creators, you'll hear this law cited constantly. Most of what circulates about it online is directionally right but imprecise on the details that actually matter when you're the one filing a notice. This is a plain breakdown of what Public Law 119-12, signed May 19, 2025, actually says.

The two things this law does

The TAKE IT DOWN Act does two distinct things, and it's worth keeping them separate. Section 2 creates a new federal crime for knowingly publishing a nonconsensual intimate depiction of an identifiable person, including AI-generated “digital forgeries” — this is enforced by prosecutors, not something an agency files directly. Section 3 creates a notice-and-removal system that platforms must build, giving individuals — or someone authorized to act for them — a way to demand takedown, with a hard compliance clock. This article focuses on Section 3, since that's the mechanism agencies actually use.

Who has to comply: “covered platform”

The removal obligation applies to a covered platform: a website, online service, or app that serves the public and either primarily hosts user-generated content (posts, videos, images, games, audio), or whose regular business involves publishing, curating, or hosting nonconsensual intimate content specifically. That second branch matters — it's written broadly enough to catch sites whose whole model is hosting this kind of content, not just mainstream social platforms.

Excluded from the definition: broadband internet providers, email, and platforms that consist mainly of content the provider itself selects, where any comment or chat feature is incidental to that content. In plain terms — this targets social platforms, forums, video and image hosts, and messaging-adjacent services with public content, not an ISP or a curated media site with a comments section bolted on.

Who can file — the part that matters for agencies

The statute allows a request from “an identifiable individual (or an authorized person acting on behalf of such individual).” That parenthetical is what makes agency-filed takedowns valid under this law. A manager or agency filing on a creator's behalf, with authorization, fits squarely within the statute's own language — this isn't a gray area or a workaround.

What counts as protected content

Two categories are covered. Authentic intimate visual depictions are real footage or images published without consent. Digital forgeries are the statute's term for deepfakes — any intimate depiction of an identifiable person created through software, machine learning, AI, or similar means, including by altering real footage, that a reasonable person viewing it as a whole would find indistinguishable from authentic. This is the language that closes the gap copyright law leaves open: a deepfake with no underlying original footage still qualifies, because the definition doesn't require one.

“Identifiable individual” means someone who appears in the depiction and whose face, likeness, or another distinguishing characteristic is shown in connection with it, so heavily obscured or non-identifying content likely falls outside scope.

What a valid notice must include

The statute is specific here — four required elements, in writing:

  • A physical or electronic signature of the individual, or the authorized person filing on their behalf.
  • Enough information for the platform to actually locate the content (URL, identifying details).
  • A brief statement of good-faith belief that the content is nonconsensual, with any relevant supporting information.
  • Contact information sufficient for the platform to reach the individual or their authorized representative.

Practically: a notice missing any of these four elements isn't a “valid removal request” under the statute — which matters if a platform is slow and you need to point to exactly what obligates them to act.

The timeline

Covered platforms had until May 19, 2026 — one year from enactment — to actually establish their notice-and-removal process and post clear, plain-language instructions for using it. Once a platform receives a valid removal request, it must, as soon as possible but no later than 48 hours, remove the depiction and make reasonable efforts to identify and remove known identical copies. That 48-hour obligation only attaches to a valid request under the platform's established process, which is exactly why getting the four notice elements right matters more than speed.

Enforcement and penalties

A platform's failure to reasonably comply with the notice-and-removal obligations is treated as an unfair or deceptive act or practice under the FTC Act. The FTC enforces it using its standard FTC Act powers, including against nonprofit organizations that would normally fall outside its jurisdiction — this law specifically extends FTC authority to reach them too. The per-violation civil penalty isn't stated as a dollar figure in this statute itself; it's the standard maximum civil penalty available under FTC Act enforcement, periodically adjusted for inflation and currently just over $53,000 per violation. Worth re-verifying the current figure directly on ftc.gov before quoting it, since it adjusts.

Section 3 also includes a good-faith safe harbor: a platform that removes content based on a good-faith belief it's a nonconsensual depiction cannot be held liable for that removal, regardless of whether the content is later determined to be lawful or not. This is a big part of why platforms tend to act quickly once a notice looks facially valid — they have no legal downside to erring toward removal.

What's explicitly excluded

The removal obligation, and the underlying criminal offense, don't apply to law enforcement or intelligence activity conducted under legal authority; good-faith disclosures to law enforcement, in legal proceedings, or for legitimate medical, scientific, or educational purposes; disclosures reasonably intended to help the individual depicted; content someone publishes of themselves; or content that separately qualifies as CSAM, which is handled under existing federal child-exploitation statutes rather than this one.

A practical checklist for filing

When preparing a notice on behalf of a creator, confirm you have:

  • Written authorization from the creator naming you as their representative
  • The specific URL(s) or enough locating detail for the platform to find the content
  • A short, clear statement of good-faith belief the content is nonconsensual
  • Valid contact information for follow-up
  • A signature — yours, as the authorized filer, is sufficient under the statute's language

The bottom line for agencies

The reason this law matters more than DMCA for a growing share of what agencies deal with is structural: DMCA protects a specific copyrighted work, and a deepfake has no original work to point to. This statute doesn't ask whether the content is copyrighted — only whether it's a nonconsensual intimate depiction of an identifiable person, real or synthetic. That's the gap it was built to close, and it's why it's become the primary legal tool for deepfake removal rather than a supplement to copyright-based takedowns.

This piece summarizes Public Law 119-12 as enacted; it isn't legal advice, and if a specific case turns on an interpretive question, that's worth a conversation with counsel rather than relying on a summary.

Protect your creators before the next leak appears

Facial-recognition detection and legal enforcement, under one flat subscription.

Related reading