DEFIANCE Act vs. TAKE IT DOWN Act: What Is Actually Law Right Now
Drash Eldetron
Writes about digital privacy, reputation, and online presence.
September 3, 2026
Most people assume there’s now a federal law letting deepfake victims sue for damages. There’s a bill for that — it passed the Senate unanimously in January 2026 — but it still hasn’t passed the House.
Here's what's actually enforceable today, what's still just a proposal in Congress, and why the platform that generated an image is in a legally different position than one that just hosts someone else's post.
Quick overview
- The TAKE IT DOWN Act is already law — it forces platforms to remove non-consensual intimate images, including AI-generated ones, within 48 hours of a report.
- The DEFIANCE Act, which would let victims sue for damages, has passed the Senate twice but remains stuck in a House committee.
- Several states have their own civil or criminal deepfake laws already in effect, independent of federal action.
- Section 230 protects platforms that host someone else’s content — it’s a weaker shield for a platform or app that generates the image itself.
The Federal Law Already in Effect: the TAKE IT DOWN Act
The TAKE IT DOWN Act was signed into law on May 19, 2025. It makes it a federal crime to publish non-consensual intimate images, including ones generated or altered by AI, and — separately from the criminal provision — it requires platforms to remove reported images within 48 hours of a valid request, with the FTC responsible for enforcing that takedown obligation.
This is the law already doing practical work: it’s the basis for the 48-hour reporting right we walk through in our deepfake removal guide. The Department of Justice reported what it described as the first conviction secured under the law in April 2026, which is meaningful mainly as confirmation that the criminal side of the statute is actually being enforced, not just sitting on the books.
The DEFIANCE Act Would Add a Right to Sue, But It Is Not Law Yet
The TAKE IT DOWN Act gives victims a removal right and gives prosecutors a criminal charge. It does not give a victim a way to sue the person who created or distributed the image for damages.
That’s what the DEFIANCE Act is designed to add — and it’s worth being precise that it hasn’t happened yet.
The bill passed the Senate in 2024, but died when the House never took it up before that Congress ended. Reintroduced in the next Congress, it passed the Senate again, unanimously, on January 13, 2026.
As of the most recent public reporting, it remains stuck in the House Judiciary Committee, with no vote scheduled. If it eventually passes, it would create a federal civil right of action with a 10-year statute of limitations and enhanced statutory damages — but none of that is available to victims under federal law today.
What Already Exists at the State Level
Independent of what Congress does, a number of states already have their own laws — and they split roughly into two types:
- Some, like California, combine a civil right to sue with a separate criminal misdemeanor charge.
- Others, including Illinois, provide a civil remedy without a matching criminal charge.
- A separate group of states — among them Texas, New York, Minnesota, Louisiana, Georgia, Hawaii, South Dakota, and Virginia — have criminal statutes specifically targeting non-consensual deepfake imagery.
This list isn’t exhaustive, and state laws in this area are changing quickly enough that it’s worth checking your specific state’s current statute rather than assuming coverage either way.
Why Section 230 Does Not Work the Same Way Here
Section 230 protects a platform from liability for content posted by someone else — the same immunity behind why a business generally can’t force a review platform to take down a review, discussed in our piece on the legal reality behind review removal. That protection depends specifically on the platform not being the one that created the content — legally, an “information content provider,” under the same test courts have applied since the Roommates.com case.
That distinction gets much harder for a platform or app to rely on when it’s the one generating the image in the first place, rather than simply hosting something a user uploaded.
No Supreme Court ruling has resolved this specifically for AI image generators yet, so treat it as a genuinely open legal question rather than a settled one. The fight is playing out on more than one legal front already: Minnesota’s ban on “nudify” apps that generate this kind of imagery is currently being challenged in court by xAI — not on Section 230 grounds, but under the First Amendment, which shows the legal battle here is broader than the immunity question alone.
What This Actually Means If You Are Dealing With This Today
Right now, the tools that actually exist are the TAKE IT DOWN Act’s 48-hour platform obligation and whatever your specific state’s civil or criminal law provides — not a federal right to sue, which is still sitting in a House committee. If a platform doesn’t act on a valid 48-hour request, or you’re dealing with a site that simply won’t respond at all, or the situation involves an ongoing threat to publish rather than something already posted — closer to sextortion than a one-time image — the practical path forward differs case by case.
Dealing with this right now? Our private image removal team can walk you through what actually applies in your situation — get a free, confidential assessment.
Frequently asked questions
Has anyone actually been convicted under the TAKE IT DOWN Act?
Yes. The Department of Justice reported what it described as the first conviction secured under the law in April 2026, confirming the criminal provision is being actively enforced, not just sitting on the books.
If the DEFIANCE Act eventually passes, what would it actually let victims do?
It would create a federal civil right of action to sue the person who created or distributed a non-consensual intimate image, with a 10-year statute of limitations and enhanced statutory damages — none of which is available under federal law today.
Do all states treat non-consensual deepfake images the same way?
No. Some states, like California, combine a civil right to sue with a criminal misdemeanor charge. Others, like Illinois, offer only a civil remedy. A separate group of states have criminal statutes without a matching civil right — the specifics genuinely vary by state.
Is there an active legal fight over whether AI image-generator apps can be held responsible for what they create?
Yes. Minnesota's ban on "nudify" apps that generate this kind of imagery is currently being challenged in court by xAI — not on Section 230 grounds but under the First Amendment, showing this legal battle extends beyond the immunity question alone.
Prefer not to do this yourself?
We can take it from here
If the steps above don't get you the result you need, tell us what's going on and we'll take a look.
Get in touch