FTC enforcement of the TAKE IT DOWN Act already started

Most write-ups still describe this as a deadline approaching. It passed. The FTC has been enforcing since 19 May 2026, and it sent its first warning letters the day after.

Enforcement began19 May 2026FTC
Removal window48 hours from a valid requestFTC guidance
Also requiredKnown identical copies, inside the same 48 hoursFTC guidance
Civil penalty$53,088 per violationFTC guidance
Warning letters12 nudify sites, 20 May 2026 — the day afterFTC
Where complaints landTakeItDown.ftc.gov, run by the FTCFTC

The part of the TAKE IT DOWN Act that binds platforms is Section 3, the notice-and-removal requirement. It carried a 19 May 2026 deadline, and the FTC began enforcing it that day. The week before, Chairman Ferguson sent letters to fifteen major platforms — Alphabet, Amazon, Apple, Automattic, Bumble, Discord, Match Group, Meta, Microsoft, Pinterest, Reddit, SmugMug, Snapchat, TikTok and X — reminding them to comply in full no later than that date.

Then, on 20 May, one day into enforcement, the Commission sent warning letters to twelve sites offering “nudify” tools, saying they appeared to be violating the Act by not offering victims any removal process at all, and urging them to “immediately come into compliance.”

That ordering matters more than it looks. The reminders went to the largest platforms before the deadline; the enforcement letters went out the day after it, to firms the FTC had identified on its own. The agency was not waiting for complaints to arrive before deciding who to look at.

It also opened a front door for them. The same day enforcement started, the FTC launched TakeItDown.ftc.gov, where victims can complain about platforms that ignored a valid removal request — and, separately, about platforms that never built a way to make one. The second kind of complaint needs no incident at all. An empty site is enough.

Are you a covered platform?

The statute’s definition is broader than most operators assume. A covered platform is a website, app or online service that either primarily provides a forum for user-generated content, or that publishes intimate visual depictions in the regular course of business. The FTC specifically names social media, messaging, image and video sharing, and gaming services.

There is no small-platform carve-out. Headcount, revenue and user count do not appear in the test. If users can post images to your service, you are almost certainly in scope. For the obligations that follow from being in scope, obligation by obligation, see how a small platform complies with the Act.

What the 48 hours actually requires

On receiving a valid notice, a covered platform must remove the depiction as soon as possible, and no later than 48 hours. The deadline is a ceiling, not a target — “we used the full window” is not the standard the text sets.

Inside that same window, the platform must also make reasonable efforts to find and remove known identical copies. This is the requirement most intake processes miss, and the FTC closes the obvious escape route explicitly: the person filing the request does not have to report the duplicates. Finding them is your job, not theirs. Handling the reported URL and stopping there leaves everything the notice implies, and the record will show you did not look.

Three things follow from that, and they are process problems rather than legal ones:

  • The clock starts when the notice arrives, not when someone reads it. A report landing in a shared inbox on a Friday has consumed most of its window by Monday.
  • You need to be able to show what you did, not merely that the content is gone. Removal without a record is indistinguishable from the content having been deleted for other reasons.
  • “Reasonable efforts” to find identical copies has to mean something you can describe afterwards.

What a violation costs

A violation of the TAKE IT DOWN Act is treated as a violation of an FTC rule, which is what makes the number large: civil penalties of up to $53,088 per violation. Per violation, not per company and not per incident — and for a platform with no removal process at all, it is worth thinking carefully about what the FTC would count.

That is the arithmetic that makes this unusual among compliance problems for small platforms. The exposure is not proportional to your size.

What a defensible process looks like

The requirement is a clear and conspicuous notice-and-removal process — which means a reporter has to be able to find it without knowing your company’s internal structure. In practice a process holds up when four things are true:

  • Reports arrive in one structured place instead of scattered across email and tickets.
  • Each report is timestamped on arrival, so the 48 hours is measured, not estimated.
  • Every action against a report is recorded and attributable to a person.
  • Open reports approaching the window surface on their own rather than being noticed.

None of that requires a trust-and-safety department. It requires the intake to exist before the first report does — which is the entire difficulty for a small platform, because the first report is usually what prompts anyone to think about it.

Where TrustDesk fits

TrustDesk is the intake and the record: hosted report intake, a timestamped evidence log, operator actions recorded as signed entries, and sweeps that surface reports approaching the 48-hour mark. The Compliance Kit is $249 one-time and the Hosted Desk is $49/month.

If you are working out whether the Act reaches you at all, the overview on the home page covers scope first. If you know it does and want the full build list, the compliance checklist walks the FTC’s eight named obligations. If the open question is who does that work — counsel, your own engineers, or a hosted desk — the three routes are compared here. If you want the intake standing up today, pricing has both options and contact reaches a person.

Every figure on this page was taken from the FTC’s own press releases and business guidance, and re-checked against them on 29 July 2026. Nothing here is legal advice.