For years the federal picture was mostly silence with a few narrow statutes. The federal deepfake law that matters most right now is the Take It Down Act, and it's worth understanding what it actually requires, because it reaches platforms, not just the people making the fakes.

The core: platforms must remove nonconsensual intimate imagery, including AI-generated deepfakes, after a valid takedown request, on a deadline. It also criminalizes knowingly publishing nonconsensual intimate deepfakes. Synthetic and authentic imagery get treated the same, which closes the 'but it was AI' loophole people kept trying.

The Federal Deepfake Law: What the Take It Down Act Actually Does
Image via Wikimedia Commons

What it doesn't do matters as much. It's not a general deepfake ban. It doesn't replace state laws, which keep operating alongside it, sometimes with tougher penalties. And like every takedown regime, the compliance details, what counts as a valid request, how fast is fast enough, will get worked out in practice. Platforms are already adjusting their reporting flows. The smart ones are building for the strictest plausible reading. Waiting for case law to clarify the edges is a strategy. Just not a good one.

Trust and safety teams are responding with platform policy template SaaS tools that standardize takedown and reporting workflows, because ad hoc processes break under deadline pressure. Trust and safety SaaS for deepfake law is having a moment for exactly this reason. A deadline you can't meet with your current process is a liability, not a workflow.

My take, and I'll keep it short: this is the floor, not the ceiling. Treat federal compliance as the minimum and state law as the real test. States keep legislating above it. Anyone operating nationally has to satisfy both layers. Federal compliance alone isn't enough, and it was never going to be.

DeepfakeLaw tracks the federal layer alongside all 50 states and 40+ countries, with requirements, penalties, and effective dates. And if you run a platform or build with generated media, I do plain-language compliance audits at deepfakelaw.fyi.