A federal law designed to protect students and employees from nonconsensual intimate images just reached full effect. It is worth understanding what it does, and being clear-eyed about what it does not do for the people who report these incidents to your school, district, or institution.
What Just Changed?
The TAKE IT DOWN Act, signed into law on May 19, 2025, creates federal criminal liability for sharing or threatening to share nonconsensual intimate images of adults and minors, including AI-generated deepfakes. Its second major provision requires covered online platforms to build processes for victims to request removal of those images. That requirement had a one-year implementation window, and as of May 19, 2026, the Federal Trade Commission began enforcing it. Social media platforms, messaging apps, and image and video sharing services are now required to remove reported content within 48 hours of receiving a valid request.
For victims, that is a real and meaningful tool. For the first time, there is a federal mechanism to pursue removal of nonconsensual intimate images from the platforms where they spread.
What the Law Does Not Do
The TAKE IT DOWN Act governs platforms and creates criminal exposure for perpetrators. It does not investigate complaints. It does not create a hostile environment framework. It does not tell your Title IX coordinator how to respond when a student walks in and reports that someone created a deepfake of them. That work belongs entirely to your district or institution, and the obligations that govern it have not changed.
Under Title IX, when conduct creates a hostile environment on the basis of sex, your district or institution has to respond. Whether the underlying content is a real photograph or a completely fabricated AI-generated image is beside the point. The harm to the person targeted is real: the psychological damage, the reputational exposure, the experience of knowing that intimate images of you are circulating among your peers. Title IX’s hostile environment standard asks about the impact of the conduct, not the authenticity of the content.
K-12 Districts Have the Most Catching Up to Do
The TAKE IT DOWN Act’s protections for minors are more expansive than those for adults, and that reflects a real difference in harm and vulnerability. But those protections exist in courts and on platforms. They do not reach inside a school building.
When a student in a K-12 district reports a deepfake, the district has its own immediate obligations under Title IX, state law, and its own policies. It cannot wait for a criminal process to run before it responds. And in most districts, the policy language and the staff preparation are simply not there yet. Most sexual misconduct policies were written before AI-generated content was a practical concern, and the language addressing sexual exploitation almost never contemplates a fabricated image that was never a real photograph. That gap creates real uncertainty at the moment a report comes in, and uncertainty at intake tends to produce underresponse.
Higher education institutions face the same questions, though the investigative stakes and the population differ. College students experience technology-facilitated sexual violence at elevated rates, and AI-generated content introduces complications at every stage of a complaint that most existing investigative frameworks were not built to handle.
Takeaways
The compliance work the TAKE IT DOWN Act does not do is exactly the work districts and institutions need to be doing right now. That means two things in practice.
- Review your policy language. If your sexual exploitation or sexual misconduct definitions do not explicitly address synthetic or AI-generated content, your framework has a gap. A student reporting a deepfake should never encounter uncertainty about whether your conduct policy even covers what happened to them.
- Prepare the people who answer the door when these reports come in. The instinct to treat a “fake” image as less serious than a real one is understandable and wrong. Compliance teams that have not worked through this explicitly are not ready for the moment it arrives.
ICS works with K-12 districts and higher education institutions on both of these questions. This fall, we are offering a live virtual training built around exactly this issue: AI, Deepfakes, and Title IX: Responding to Emerging Forms of Sexual Misconduct on August 12 from 12 to 2 PM ET. Registration is $399, and the training is free for ICS Community Partners. If your district or institution would benefit from a tailored version brought directly to your team, we can make that happen. Reach out to our team to get started.
Discover more from ICS Lawyer
Subscribe to get the latest posts sent to your email.
