Intel Briefings Legal

The Legal Landscape for Deepfake Victims in 2026

On 19 May 2026 the Federal Trade Commission began enforcing Section 3 of the TAKE IT DOWN Act. Covered platforms now owe a 48-hour removal deadline on valid requests for non-consensual intimate imagery, including AI-generated forgeries. That is the single largest practical change for synthetic-media victims since 2023, and most of the advisory content on this topic has not caught up to it.

This page walks through what is actually enacted at the federal level, what is enforceable at the state level, and what each major platform’s official reporting channel really is — separating the three from the much larger pile of bills, proposed rules, and enjoined statutes that get cited as though they were law.

A note on how we treat sources. Every statute here is cited by its public law or code number and was checked against the primary source, not a summary. Where a claim could not be verified, we say so rather than rounding it up. We are applying that standard to ourselves first: an earlier version of this page asserted that Section 230 had been amended for synthetic media and cited FTC enforcement figures that do not exist in any FTC publication. Both were wrong. They are corrected below, and the correction is flagged in place rather than quietly deleted, because a firm that will not show you its own errors is not a good source on anyone else’s.

Federal law: one statute, one rule, and a long list of bills that are not law

The single most useful thing to know is how little federal law there actually is. As of August 2026 there is exactly one enacted federal statute aimed squarely at synthetic media, plus one final FTC rule that covers less than most summaries claim. Everything else you will read about is a bill.

The TAKE IT DOWN Act — in force, and now actually being enforced

Signed 19 May 2025 as Pub. L. 119-12. It runs on two clocks:

  • The criminal prohibition on non-consensual intimate imagery, expressly including AI-generated “digital forgeries,” took effect on signing.
  • The platform duty in Section 3 is the part that matters operationally. Covered platforms must run a notice-and-removal process and, on a valid request, take down the content and known identical copies within 48 hours. Platforms were given a one-year implementation runway, so FTC enforcement of Section 3 began 19 May 2026.

Enforcement mechanism: the FTC treats a violation as an unfair or deceptive practice, with civil penalties up to $53,088 per violation. There is a public complaint portal at TakeItDown.ftc.gov.

If you take one thing from this page: for NCII-category synthetic media, you now have a 48-hour statutory clock you can invoke by name. Most takedown requests still do not cite it. Ones that do move differently.

What the Act does not do: it does not amend Section 230. See below.

The FTC impersonation rule covers your company, probably not you

The final rule is 16 CFR Part 461, published at 89 FR 15017 on 1 March 2024 and effective 1 April 2024. Read the title carefully: Impersonation of Government and Businesses. That is its actual scope.

The individual-impersonation half was issued the same day as a supplemental notice of proposed rulemaking (89 FR 15072) and, as of August 2026, is still not final — it remains at proposed-rule stage under RIN 3084-AB71.

The practical consequence is the thing most articles get wrong: if a deepfake impersonates your company, this rule reaches it. If a deepfake impersonates you personally and is not tied to a business or government impersonation, it very likely does not.

Enforcement volume is also far lower than the category’s marketing implies. The FTC’s own April 2025 accounting for the rule’s first year: five cases brought, thirteen websites shut down. Civil penalties run to $53,088 per violation.

The Lanham Act route is weaker than it is sold as

The closest thing to a roadmap decision is Lehrman v. Lovo, Inc. (S.D.N.Y. 2025), an AI voice-cloning case. The court dismissed the Lanham Act false-association and false-advertising claims: the marketing disclosed the voices were AI clones, so there was no actionable consumer confusion, and misrepresenting the scope of a license is not “false advertising.”

What survived dismissal was New York Civil Rights Law §§ 50–51 (right of publicity) and direct copyright infringement.

That is the strategic lesson of the whole federal picture. Federal unfair-competition theory is the weakest lane. State right-of-publicity and digital-replica statutes are where the actual leverage is, which is why the state section below is longer than this one.

What is not law, no matter how often it is cited

  • NO FAKES Act (S.1367), a federal digital-replica right: introduced April 2025, still pending.
  • DEFIANCE Act (S.1837), expanded civil remedies for NCII: passed the Senate by unanimous consent on 13 January 2026, has not passed the House, and is not law.
  • The FTC’s individual-impersonation rule: still proposed, not final.

Treat any firm or counsel citing these as enacted authority as a signal about their diligence.

State law: where the actual leverage is

Because the federal picture is thin, state statutes carry the weight. They are also where published summaries are least reliable, so each entry below gives the real citation, the real effective date, and the real remedy.

California

AB 730 — election deepfakes. Still law, but not the law it is usually described as. Enacted 2019 (Ch. 493, Stats. 2019), codified at Elections Code § 20010, not 2024. Its original 1 January 2023 sunset was extended by AB 972 to 1 January 2027, so it never lapsed. The 60-day pre-election window is correct. The commonly cited “$50,000 statutory damages” figure does not appear anywhere in the text. The real remedy is uncapped general and special damages for a depicted candidate plus attorney’s fees, and injunctive relief that any registered voter may seek. There is a private right of action.

AB 2839 — permanently enjoined. The 2024 election-deepfake disclosure and takedown scheme was struck down on First Amendment grounds.

AB 2655 — permanently enjoined, and this is the correction that matters most. The Defending Democracy from Deepfake Deception Act is the statute most often cited to platforms as creating a notice-and-removal duty. It does not currently create one. In Kohls v. Bonta, No. 2:24-cv-02527 (E.D. Cal.), with X Corp. and Rumble as co-plaintiffs, Judge Mendez entered final judgment on 20 August 2025 holding AB 2655 preempted by 47 U.S.C. § 230 and permanently enjoining enforcement. A stipulated order the following week extended that bar to any interactive computer service provider. California appealed to the Ninth Circuit (No. 25-6138) on 30 September 2025; we could not verify any ruling since, so treat the appeal as pending.

Note the irony, since it is also the practical lesson: the statute that supposedly proved Section 230 had been weakened was itself killed by Section 230.

SB 942, the AI Transparency Act — check the date, it moved. Effective 2 August 2026, delayed from the original 1 January 2026 by AB 853 (Ch. 674, Stats. 2025). It applies only to “covered providers” with over one million monthly California users, and requires latent and manifest watermarking plus a free public detection tool. The claim that watermark removal gives you a cause of action is wrong: there is no private right of action. The penalty is $5,000 per violation, enforceable only by the Attorney General, a city attorney, or county counsel. You cannot sue under it. You can complain to someone who can.

AB 1836 and AB 2602, both effective 1 January 2025, are the two that most often actually apply to a commercial client. AB 1836 (Civil Code § 3344.1) creates a civil action for unauthorised AI digital replicas of a deceased personality, with statutory damages of the greater of $10,000 or actual damages. AB 2602 voids contract terms that let a producer substitute a living performer’s AI replica for in-person work unless the clause was specific and the performer was represented.

New York

There is no GBL § 397-a deepfake provision. That section exists and concerns delivery signage. It has nothing to do with AI, impersonation, or damages of any multiple. Anyone citing it has not read it.

There is no “NYS AG Synthetic Media Task Force.” No such body exists. Attorney General James has issued consumer alerts on AI election misinformation, but no task force was formed. Two real bodies are easy to confuse with the invented one: the New York City Bar Association’s AI and Digital Technologies Task Force, which is a private bar group, and the federal DOJ AI Litigation Task Force established in January 2026, which has nothing to do with New York.

What New York actually gives you:

  • Penal Law § 245.15, unlawful dissemination of intimate images, amended by S1042A (Ch. 513, signed 29 September 2023) to cover deepfakes through a defined term, “digitization.”
  • Civil Rights Law § 50-f, the right-of-publicity and digital-replica statute, and the one that matters. Enacted 2020, digital-replica definition added 2022, and substantially strengthened by S8391, signed 11 December 2025 as Ch. 616, effective immediately: use of a deceased performer’s digital replica now requires prior consent rather than a disclaimer. Damages are the greater of $2,000 or compensatory damages plus profits, with punitive damages available.

Recall that § 50-f’s siblings, §§ 50–51, are exactly what survived dismissal in Lehrman. New York publicity law is the most tested route in this entire article.

Texas

SB 1077 has nothing to do with deepfakes. The 2025 bill of that number concerns the duration of protective orders in family-violence cases. The claimed “Texas Public Information Act amendment (2025)” creating enhanced penalties for government-impersonation deepfakes does not exist; none of the 2025 PIA amendments touch deepfakes or impersonation at all.

What Texas actually has:

  • SB 1361 (88th Leg., 2023), codified at Penal Code § 21.165, effective 1 September 2023: criminalises producing or distributing non-consensual sexually explicit deepfake media. It is a Class A misdemeanor, enhanced on a repeat offence or a minor victim. It is not felony-graded and is not framed around intent to defraud. (Do not confuse it with the 2025-session bill numbered SB 1361, an unrelated disaster-recovery loan bill that died.)
  • SB 751 (2019), the election-deepfake statute, which is real: publishing an AI-fabricated video within 30 days of an election with intent to injure a candidate or influence the outcome.
  • HB 149 (TRAIGA), the broader 2025 Texas AI statute, carries civil penalties of $10,000–$200,000 for certain prohibited AI practices. Whether it reaches impersonation specifically is unverified, so we are not going to tell you it does.

Tennessee

The ELVIS Act is real. The remedy everyone quotes for it is not. Effective 1 July 2024 (Public Chapter 588), it extends the right of publicity to AI-generated voice and likeness. That much is true and it was genuinely first-in-the-nation.

The “treble damages and attorney’s fees for prevailing plaintiffs” line, repeated across most summaries, is wrong. The general remedy at TCA § 47-25-1106(d)(1) is actual damages plus attributable profits. The 3x-damages and fee-shifting language sits in subsection (d)(2) and is a pre-existing 2009 carve-out that applies only where the victim is a member of the U.S. armed forces or National Guard. The ELVIS Act did not touch it. The claim generalises a narrow military provision to every plaintiff.

If your counsel has quoted you treble damages on a Tennessee ELVIS claim and you are not a service member, ask them to show you the subsection.

Illinois and Washington — usually missing, often the best fit

  • Illinois Digital Voice and Likeness Protection Act, 815 ILCS 550, effective 9 August 2024 and amended effective 1 January 2026. Same contract-voidability mechanism as California’s AB 2602.
  • Washington HB 1999 (RCW 9A.86.030), effective 6 June 2024: knowingly disclosing an AI-fabricated intimate image without consent is a gross misdemeanor, rising to a felony on repeat or aggravated facts. This covers the deepfake-pornography lane that the California/New York/Texas/Tennessee statutes above mostly do not.
  • Washington SB 5886, effective 11 June 2026, extends Washington’s personality-rights statute (RCW 63.60) to AI-forged likeness of living or deceased individuals. It is broader than the California, Tennessee and New York equivalents, and it is new enough that most advisers have not read it yet. If you have any Washington nexus, this is worth checking first rather than last.

Section 230 has not been amended, and you should distrust anyone who says it has

This is the most common false claim in the synthetic-media advisory market, and we are calling it out because an earlier version of this very page carried it.

No enacted federal statute has amended 47 U.S.C. § 230 for synthetic media. There is no “synthetic media safe harbor reform.” Section 230(c)(1) stands unchanged as of August 2026.

The TAKE IT DOWN Act is frequently described as a Section 230 carve-out. It is not one. It works by a completely different mechanism: it imposes an affirmative statutory duty on platforms — the 48-hour notice-and-removal process — and hands enforcement to the FTC under its unfair-and-deceptive-practices authority. It does not create a private cause of action against a platform, and it does not strip immunity.

Why the distinction is worth your time: if you believe Section 230 has been carved out, you will think you can sue the platform. You cannot. What you can do is trigger a regulator-enforced 48-hour clock, and escalate to the FTC when the platform misses it. Those are different letters, sent to different people, with different leverage.

Platform takedown channels: the actual policies, and the response times nobody promises

Independent of legal action, every major platform now operates a formal channel for synthetic-media reports. This section is where most published guidance goes wrong, so one warning before the detail:

Almost no platform publishes a response-time commitment, and the ones circulating in comparison tables are invented. An earlier version of this page carried a table of “average response” figures — 4-12 hours, 6-28 hours, and so on. Those numbers had no source. They are gone. Below, where a platform states a timeframe we quote it; where it states nothing we say NONE STATED, because a fabricated SLA is worse than no SLA: it sets a client expectation nobody is contractually on the hook for.

X (formerly Twitter)

The governing policy is Authenticity, specifically its Synthetic and Manipulated Media section, last dated April 2025. This is the policy people mean when they search for X’s deepfake rules, and it is separate from the Non-Consensual Nudity policy, which carries a faster path for certain content types.

X is one of the few platforms that states timeframes at all, and the stated language is worth reading exactly, because it is far less reassuring than the tables suggest: reports are acknowledged within 24 hours, and are “typically resolved within a few days” though resolution “may take thirty days.”

Thirty days is the number to plan against, not the few days. If the content is NCII-category, this is precisely why you file under the TAKE IT DOWN Act’s Section 3 as well — the statutory clock is 48 hours and it does not care what the platform’s own policy page says about thirty.

The definition it enforces: “You may not share inauthentic media, including manipulated or out-of-context media that may result in widespread confusion on public issues, impact public safety, or cause serious harm.”

There is no standalone synthetic-media report category with a fixed URL. You report in-app from the post’s overflow menu, and X notes it “may ask you to select additional posts from the account you’re reporting so we have better context” — so gather the account’s other posts before you start, not after.

For NCII the separate policy is Non-Consensual Nudity (help.x.com/en/rules-and-policies/intimate-media), which explicitly covers AI and digitally manipulated superimposed images. Some categories are reportable by anyone; others only by the depicted person or an authorised representative. Violating posters face immediate permanent suspension. X also has a TAKE IT DOWN Act page at help.x.com/en/rules-and-policies/us-tida.

AI-labelling: only for armed-conflict content, under the Creator Monetization Standards, with suspensions up to 90 days for non-disclosure. There is no general synthetic-media labelling mandate on uploaders. StopNCII: X is not listed on its own help pages, but StopNCII.org’s own partner list names X.

YouTube — the one platform that publishes a hard removal deadline

This is the most useful single fact in this section. YouTube’s NCII webform at youtube.com/contact/NCII carries an explicit commitment: “YouTube will review and remove confirmed NCII content within 48 hours of a submission of the linked webform and will make reasonable efforts to identify and remove identical copies.”

That is a stated 48-hour removal, not an acknowledgment, and it is the only one of its kind among the platforms surveyed here. If your incident touches YouTube and is NCII-category, that form is the first thing you file.

For everything else — likeness, impersonation, non-sexual deepfakes — the route is the “Protecting your identity” policy and its Privacy Complaint Process, which is a multi-step troubleshooter rather than a single stable form URL. The gating requirement is that you must be uniquely identifiable in the content, and the complaint must come from you or a legal representative. Stated response time for standard privacy removal: NONE STATED. (Don’t misread the “up to 5 days” figure on Likeness Detection enrolment — that is identity verification, not a removal deadline.)

Uploader obligation: YouTube requires disclosure of realistic AI-generated or meaningfully altered content depicting a real person, place or event, via the AI-use toggle in Studio. Non-disclosure risks a YouTube-applied non-removable label, removal, or Partner Program suspension — which is a useful lever, because a creator who did not tick the box has a second violation on top of yours. Google also runs a US TAKE IT DOWN Act page in its legal help centre.

Meta (Facebook, Instagram, Threads)

Know this before you cite the wrong rule: the standalone “Manipulated Media” policy no longer exists. It was folded into the Misinformation Community Standard in July 2024, after the Oversight Board’s “Altered Video of President Biden” decision. Meta also stopped removing content solely for being manipulated media, and shifted to labelling it “AI Info” while enforcing other standards regardless of AI origin.

The practical consequence: “it’s a deepfake” is, by itself, a weaker argument to Meta than it is anywhere else. Report it under the standard it actually violates — impersonation, fraud, bullying, NCII — and mention the synthesis as an aggravating fact rather than the violation.

Routes: Facebook impersonation form at facebook.com/help/contact/634636770043106; Instagram at help.instagram.com/contact/636276399721841, which only the impersonated person or their representative may file. Meta directs NCII cases to StopNCII.org, and is a confirmed partner across Facebook, Instagram and Threads.

Uploader obligation (exact wording): “We require people to disclose, using our AI-disclosure tool, whenever they post organic content with photorealistic video or realistic-sounding audio that was digitally created or altered.” Stated response time: NONE STATED — only “as quickly as possible.”

Reddit

Policy: Manipulated Content and Misleading Behavior. Generative AI content is “generally allowed”; what is prohibited is AI content that “deliberately misleads others about real-life events or the actions of real-life individuals, or that presents itself as human-generated.” Permitted AI content must carry a disclosure tag.

NCII is Rule 3, “Non-consensual intimate media” — note the current name, since a report citing the retired “Involuntary Pornography” wording signals you are working from stale guidance. The rule explicitly covers deepfake and lookalike pornography. Reddit is a confirmed StopNCII participant and says so in its own words: “Reddit leverages StopNCII.org, a free, online tool provided by U.K. not-for-profit charity SWGfL.” It also maintains a US Take It Down Act help article.

Stated response time: NONE STATED.

LinkedIn

Often skipped, and it should not be, because LinkedIn is where executive impersonation actually converts into wire fraud. The rule sits in the Professional Community Policies under Be Trustworthy: “Do not share synthetic or manipulated media that depicts a person saying something they did not say or doing something they did not do without clearly disclosing the fake or altered nature of the material.”

That clause is both the prohibition and the disclosure requirement; there is no separate AI-label toggle. Fake profiles are reported via More → Report/Block → “This person is impersonating someone” or “This account is not a real person.”

Stated response time: NONE STATED. Any “48-72 hours” figure you see quoted for LinkedIn is third-party invention. No LinkedIn NCII channel or StopNCII participation could be confirmed.

Snapchat

The applicable policy sits under Harmful False or Deceptive Practices rather than any “deepfake” heading, which is why it is commonly missed. There is no dedicated AI-deepfake report category; you press-and-hold the Snap and pick the nearest one.

Stated response time: NONE STATED, except DSA and UK Online Safety Act acknowledgment language, which obliges a response, not a removal. Snap is on StopNCII.org’s published partner list and has a Take It Down Act page.

Labelling: Snap labels its own AI surfaces (My AI, Dreams, AI Lenses) but states plainly that third-party AI output may not be labelled. Do not treat the absence of a Snap AI label as evidence that content is authentic.

Spotify

Two separate policies, and picking the right one changes who is allowed to file. Podcast impersonation covers a host’s likeness: “Spotify will remove podcast shows and content that impersonate another creator or host’s likeness without permission, whether that’s using AI voice cloning or any other method.” Music impersonation covers an artist’s voice in near-identical terms.

Both route to support.spotify.com/report-content/ — select “Impersonation” plus “Podcast,” or “Publicity / Likeness” for a voice-clone music case. Standing is restricted: the claim must come from the artist or someone acting on their behalf. Bring the content URI and links to the impersonated party’s profile; incomplete reports get queued behind complete ones.

No NCII channel, as expected for an audio platform. Stated response time: NONE STATED.

Google Search — de-indexing is not removal

Worth separating from the platforms above, because it solves a different problem. Google runs a removal path for fake sexual or nude content depicting you, and a separate one for private personal information and doxxing. Both route to the same content removal form. Evidence: the URLs, screenshots cropped to the relevant material, confirmation you are identifiable, and for fake content an assertion that it is fabricated and distributed without consent. No government ID is required.

Google states the limit of the remedy in its own words, and clients should hear it in these terms before they think the problem is solved: “The reported URL will no longer appear in Google search results. That being said, the content may still exist on the web, and people may be able to find it through a shared link, social media post, or a different search engine.”

De-index Google and pursue the host. Doing only the first is the most common half-measure in this category. Stated response time: NONE STATED.

StopNCII.org — one filing, many platforms

For adult NCII, StopNCII lets you generate a hash of the image locally and submit the hash rather than the image, so participating platforms can match and block it without you distributing the material further. It is operational as of 2026.

Confirmed participants relevant here: Facebook, Instagram, Threads, TikTok, Reddit, Snapchat, X, Microsoft, Bluesky, plus a number of adult platforms. Not participating, so they need separate direct filings: YouTube/Google, LinkedIn, Spotify.

For anyone who was a minor at the time the content was made, the correct route is NCMEC’s Take It Down (takeitdown.ncmec.org) instead.

Where platforms have published TAKE IT DOWN Act compliance pages

Confirmed to exist: YouTube/Google, X, Reddit, Snapchat. No dedicated compliance page could be located for TikTok, Meta, LinkedIn or Spotify — their obligations appear folded into existing NCII flows. That absence is not an exemption, and it is a reasonable thing to note in a filing to those four.

What works in practice

In 2026, the actually-effective response to a deepfake incident looks like this:

Hour 0-1: Evidence chain

Screenshot, archive, save the URL via archive.org and the Wayback Machine, save the source file with cryptographic hash. The evidence chain is what turns a takedown request from “we don’t like this” into “this violates X policy and here’s the verification.”

Hour 1-6: Platform takedowns

File the platform-specific channel. Include: target identity verification, evidence of synthesis (waveform analysis, face-swap artifact detection), evidence of harm (commercial, reputational, or election-impact).

If the content is NCII-category, name the statute in the request. A request that says “this is a valid removal request under Section 3 of the TAKE IT DOWN Act, Pub. L. 119-12, and the 48-hour removal window began on receipt” is a compliance event with a documented deadline. A request that says “please remove this, it is fake” is a queue ticket. Same content, same platform, different handling — because since 19 May 2026 the first one carries FTC exposure and the second one does not.

Ask explicitly for removal of known identical copies, not just the URL you reported. That is in the statutory text, and it is the part platforms most often skip.

Counsel files preservation letters to the platform and any identified amplifiers. This is not litigation — it’s preservation. It protects evidence for potential later litigation.

Day 1-7: Counter-narrative + media

Public-facing counter-narrative on owned channel + 2-3 sourced placements. Counter-narrative shapes the next news cycle’s framing more than the takedown does.

Day 7-30: Civil action if warranted

Lanham Act, state right-of-publicity, FTC referral, AG complaint. The civil action is the last step, not the first — because it’s slow, public, and locks the engagement into a multi-month posture.

What doesn’t work

  • Cease-and-desist letters sent directly to anonymous accounts. Almost never effective; sometimes harden the position.
  • Filing John Doe lawsuits as a first move. Becomes news. Often counterproductive.
  • DMCA when the content is not copyrightable. DMCA covers copyright, not personality rights or impersonation. Wrong tool. The one real exception is worth knowing: in Lehrman v. Lovo, direct copyright infringement survived dismissal because actual source recordings had been copied. If your own copyrighted audio, video, or images were ingested to build the fake, copyright is back on the table — but that is a claim about the training input, not about the output.
  • Citing the Lanham Act as your lead theory. Lehrman dismissed exactly that. Lead with state right of publicity.
  • Citing bills as law. NO FAKES and DEFIANCE are not enacted. A demand letter that cites them tells opposing counsel you did not check.
  • Going public with the takedown attempt. Streisand effect is real for synthetic media at scale.

When to call counsel vs. when to call us

If the incident involves:

  • Wire fraud, financial loss → counsel + law enforcement first
  • Non-consensual intimate imagery → law enforcement first. This is now a federal crime under the TAKE IT DOWN Act, in force since the day it was signed. In parallel, file the platform request citing Section 3 to start the 48-hour clock, and file at TakeItDown.ftc.gov if the platform misses it. Those three tracks run at once, not in sequence.
  • Election content → state AG + law enforcement first
  • Your own copyrighted recordings were used to train or build the fake → counsel, because copyright is a live claim there and it is the one federal theory that survived dismissal in Lehrman

If the incident involves:

  • Brand or executive reputation damage without an active crime → us first (we coordinate counsel as needed)
  • Voice or face impersonation without fraud → us (we engage counsel for civil preservation)
  • Preventive defense / monitoring → us alone, no counsel needed

The economics

Our own published range starts at $2,500/mo for personal-brand monitoring and runs to $25,000+/mo for multi-entity executive defense with a crisis-PR retainer, with a $4,800 forensic baseline paid up front and refunded if you decline the engagement after seeing it.

We publish that because the alternative is what the rest of this category does, and you should hold the comparison in mind while shopping. The honest framing of the trade is not “us versus lawyers.” Counsel is not a competing purchase; for several of the scenarios below it is the first call and we are the second. The trade is between a standing watch that catches an incident inside the 48-hour statutory window and a cold start that finds out from a journalist on day nine.

The point

Synthetic-media law in 2026 is thinner than the commentary makes it sound and sharper than it was in 2023. Precisely one federal statute is enacted. One federal rule is final, and it covers your company rather than you. One high-profile state statute is enjoined. Several of the laws most frequently cited at you are bills.

But the part that is real is genuinely useful: a 48-hour statutory removal clock, enforced by a federal regulator, that you can invoke by name — and a set of state right-of-publicity and digital-replica statutes that carry treble damages and fee-shifting where the federal theories do not.

The advantage does not come from knowing that deepfakes are bad. It comes from knowing, on the day it happens, which of these applies to your facts, which of them is currently enforceable, and which letter goes to whom in the first six hours. Most of the field cannot do that, which is why so much of what is published about it is wrong.

For a calibrated read on your synthetic-media exposure specifically, run the audit. The model isolates deepfake risk as its own segment with its own posterior probability. Most executives we audit show it as their highest gap.

VIII · Closing Folio

The standing engagement opens with a private call.

A single conversation, signed under non-disclosure, with the principal who would own your matter. You leave with a printed posture assessment and the engagement letter, whether or not you retain us.