US Digital Authenticity.
There is no single US federal law that says "label your AI content." Instead there's one narrow enacted statute, voluntary federal guidance, a fast-converging provenance standard, and a shifting state patchwork. Here's the honest 2026 picture — and how an audit helps you stay ahead of it.
At a glance
- TAKE IT DOWN Act — enacted May 2025; FTC enforcement from May 19, 2026
- NO FAKES Act — still pending legislation (not law)
- NIST AI 100-4 — guidance, not regulation
- C2PA / Content Credentials — voluntary, broadly adopted
The standard, accurately
One enacted federal statute squarely targets AI media: the TAKE IT DOWN Act (signed May 19, 2025). It is narrow — nonconsensual intimate imagery, explicitly including AI deepfakes. Covered platforms must run a notice-and-removal process and take content down within 48 hours; the FTC began enforcing this on May 19, 2026. It is not a general "disclose your AI" law.
The NO FAKES Act (voice/likeness replicas) has been reintroduced repeatedly but has not passed — treat it as pending, not law.
Federal guidance, not regulation: NIST AI 100-4 ("Reducing Risks Posed by Synthetic Content," 2024) surveys provenance tracking, watermarking, content authentication and references C2PA — while honestly noting these can be stripped or spoofed. CAISI (the renamed AI institute, June 2025) is a standards and evaluation body, not a content regulator. The 2025 executive orders and the July 2025 "America's AI Action Plan" lean deregulatory, favoring voluntary standards and forensic/evidence tooling over new federal disclosure mandates.
C2PA / Content Credentials is the de-facto provenance standard — adopted by Adobe, OpenAI, Google, and camera/phone makers (Sony, Nikon, Canon, Samsung), and endorsed (not mandated) in federal security guidance from NSA/CISA. It is voluntary.
Why this lands on your desk
The real near-term compliance driver is the state patchwork, not federal law: Texas's TRAIGA is in force (Jan 1, 2026), California's SB 942 lands August 2026, and Colorado's AI Act was reset to 2027 — effective dates keep moving. ~30 states require disclaimers on AI-generated political ads.
If you host user-generated content, the TAKE IT DOWN Act's 48-hour notice-and-removal regime is a live FTC-enforced obligation. For everyone else, the practical exposure is the patchwork plus rising buyer expectations that AI output be provenance-signed.
Because dates and scope shift constantly, the durable advantage is provenance hygiene plus documented diligence — being able to show which rules apply, what controls you have, and that your AI output carries credentials that survive your pipeline.
Readiness you can evidence
An audit can't issue legal certification — but it can verify concrete, checkable artifacts that map to the standard.
Content provenance review
Assess whether AI-generated/edited media carries C2PA Content Credentials and whether provenance survives your pipeline (NIST notes metadata is easily stripped — durability is the value-add).
Disclosure-practice audit
Map where you publish AI content against applicable state rules (political ads, CA transparency, TX TRAIGA) and confirm labels are present and adequate.
C2PA readiness
Gap analysis for adopting Content Credentials across capture, generation and publishing, including signing-key management.
Patchwork documentation
Maintain a dated evidence trail of which state laws apply, their effective dates and the controls in place — the most useful deliverable given how volatile the landscape is.
Common questions
Is there a federal law requiring me to label AI-generated content?
No. As of 2026 there is no comprehensive federal AI-disclosure or watermarking statute. The one enacted federal AI-media law, the TAKE IT DOWN Act, is narrow — it targets nonconsensual intimate deepfakes and is enforced by the FTC from May 19, 2026.
Is C2PA / Content Credentials required?
No — C2PA is a voluntary industry standard. It is broadly adopted and endorsed in federal security guidance, but no federal law compels it. It is, however, increasingly expected by buyers and useful for state-law disclosure.
What about the NO FAKES Act?
It is pending legislation about AI replicas of a person's voice and likeness — reintroduced multiple times but not enacted. Plan for it as a possibility, not a current obligation.
So what should we actually do?
Treat content provenance as hygiene (adopt Content Credentials and make sure they survive your pipeline), track the state patchwork that applies to you, and keep documented evidence of diligence so you can show readiness as dates shift. That's what an iDharma audit verifies.
Informational only, reflecting our understanding of the US landscape as of 2026; not legal advice. Federal bills and state effective dates change frequently — confirm current requirements with qualified counsel.
Turn a moving target into a documented posture
An independent audit gives you evidence you were ready — useful as rules shift and as buyers ask.
Request an AI audit