One federal law squarely targets AI media, and it is narrower than its reputation: the TAKE IT DOWN Act, signed in May 2025 and enforced by the FTC from May 2026. It covers nonconsensual intimate imagery, deepfakes included, and gives the covered platforms just 48 hours to act.
US digital authenticity is a state patchwork, not one federal law.
No federal law says “label your AI content”. What binds you is state law, and it keeps moving.
Our promise
“A label you cannot trace is a claim.”
Every finding is written against what actually binds you — statute, state rule or standard, each named as what it is. The fee is fixed at $5,000, and nothing is charged until you approve it.
Request this readiness scanThe 2026 picture, in three chapters
Most teams assume a federal rule already tells them to label AI content. None does. What exists instead is guidance that is not regulation, a bill that has not passed, a standard nobody mandates, and fifty states going their own separate ways at their own speed, one statute at a time.
Our review is the independent read. We inventory what you publish, run one real asset through your pipeline to see whether its credential survives the trip, map each surface to the rules that reach it, and date the whole record — so a deferral somewhere else cannot quietly void it.
Two of these bind you. Two do not.
The only question that matters is who can enforce it against you, and from when.
- TAKE IT DOWN Act - enacted, FTC-enforced since May 2026
- Intimate imagery and deepfakes; 48 hours to remove
- The state patchwork - in force, and still arriving
- Texas now, California in August, ~30 states on political ads
- NIST AI 100-4 - federal guidance, and not regulation
- Useful on provenance; says itself it can be stripped
- C2PA / NO FAKES - one voluntary, one still pending
- Content Credentials are expected by buyers, not by law
One statute is enforced. The rest is not.
One narrow federal statute
The TAKE IT DOWN Act was signed on 19 May 2025 and the FTC began enforcing it on 19 May 2026. It reaches nonconsensual intimate imagery, explicitly including AI deepfakes, and it obliges covered platforms to run notice-and-removal within 48 hours of a valid report. It is not a disclosure law.
Guidance, drafts and a standard
NIST AI 100-4 surveys provenance, watermarking and content authentication - as guidance, and it says itself the metadata can be stripped or spoofed. C2PA is a voluntary standard nobody mandates. The NO FAKES Act has been reintroduced repeatedly and has still not passed. None of it binds you.
The states are what bind you
Texas TRAIGA has been in force since 1 January 2026, California SB 942 lands in August 2026, Colorado was reset to 2027, and around thirty states require disclaimers on AI-generated political ads. The dates keep moving, and your obligations follow where the content is seen, not where you are.
“There’s a federal law that makes us label AI content.”
There is no such law. The states are what bind you.
It is the most common correction we write into these reports.
- Who it is for
- Media & marketing teams
- Platforms hosting UGC
- Publishers & agencies
- AI product teams
- Legal & compliance
If you host user content, the TAKE IT DOWN Act’s 48-hour notice-and-removal duty is live and FTC-enforced today.
For everyone else it is the patchwork, plus buyers who increasingly expect AI output to arrive provenance-signed.
So the durable advantage is provenance hygiene plus documented diligence — the one asset a moved deadline cannot devalue.
Three questions. Then you’ll know.
No email, no signup. A starting point, not a determination.
Your exposure check
Four dates, and one has already moved.
Two of these are live obligations today, one lands this year, and one was pushed back twelve months - so this cannot be planned as a single deadline.
-
Texas
1 January 2026TRAIGA came into force, and it is the first of the state rules most readers of this page actually meet.
-
The FTC
19 May 2026Enforcement of the TAKE IT DOWN Act began. If you host user content, the 48-hour clock is live today.
-
California
August 2026SB 942 lands, and it is the transparency rule with the widest practical reach over AI-generated media.
-
Colorado
Reset to 2027The AI Act was pushed back a year. It is the clearest evidence on this page that these dates move.
Teams wait for a federal date that is not coming. There is no national commencement for AI disclosure — the obligations arrive state by state, on four different calendars, and one of them has already slipped a year.
What the rule says, what we ship
20 things that can be asked of you, and the artefact that answers each. Every row says whether it is law, and the ledger below marks which.
- Notice-and-removal TAKE IT DOWN Act - enacted, FTC-enforced
- Your takedown path timed end to end against the 48-hour duty, with the gaps written up as findings.
- Who counts as covered TAKE IT DOWN Act - enacted; the threshold question
- A written determination of whether the Act reaches you at all, so the answer is on record either way.
- Reporting route TAKE IT DOWN Act - enacted; a real person must be reachable
- The reporting route tested as a stranger would use it, not as your own team knows to use it.
- Texas obligations TRAIGA - state law, in force since January 2026
- Which of your surfaces Texas reaches, and what each one owes, set out surface by surface.
- California transparency SB 942 - state law, from August 2026
- Your generative tools and published media read against the duty landing in August, ahead of it.
- Colorado, deferred Colorado AI Act - state law, reset to 2027
- What the deferral changed and what it did not, so the year is used rather than simply waited out.
- Political advertising Roughly 30 states - disclaimer rules, all different
- Every state you run political creative in, with the disclaimer each one requires against it.
- Where the rules reach State law - decided by audience, not by headquarters
- Your publishing surfaces mapped to the states that see them, which is what actually scopes the duty.
- Content Credentials C2PA - voluntary standard, broadly adopted
- Whether your generated and edited media carries credentials at all, checked on the real files.
- Durability of provenance C2PA - voluntary; AI 100-4 warns metadata is strippable
- One real asset run through your real pipeline, and the credential read at the far end of it.
- Signing-key management C2PA - voluntary; the part that is a security control
- Who can sign as you, on what, and what happens the day a key has to be rotated or revoked.
- Capture-side provenance C2PA - voluntary; cameras and phones already ship it
- Whether credentials your suppliers already attach survive ingest, or are stripped on the way in.
- Synthetic-content risk NIST AI 100-4 - federal guidance, not regulation
- Your controls read against AI 100-4's own survey, with its caveats carried rather than dropped.
- Watermarking NIST AI 100-4 - guidance; no federal mandate exists
- What watermarking would and would not buy you here, stated plainly enough to decide against it.
- Detection claims No standard - and vendor accuracy claims are unverified
- Any detection tool you rely on tested on your own content rather than on its vendor's benchmark.
- Disclosure wording State law - present is not the same as adequate
- The label a user actually sees, where they see it, checked against what the rule asks for.
- User-generated content Enacted and state law both reach it, differently
- What you owe for content you did not make, which is where most of the real exposure sits.
- Vendor and model terms Contract - not law, and it is where provenance is lost
- What your generation vendors attach, strip or promise, read off the contracts rather than the decks.
- Voice and likeness NO FAKES Act - PENDING. Not law, in any state of it
- What would be owed if it passed, costed now, so the answer is a decision rather than a scramble.
- The dated record Diligence - the one thing no date can move
- Which rules applied, when, and what you had in place - a trail that still reads a year from now.
Readiness you can evidence
No audit issues legal certification. This verifies artefacts.
-
Inventory
What you generate or host, where it is published, and which rules reach it.
-
Trace
One real asset through your real pipeline, and the credential read at the end.
-
Map
Each publishing surface set against the state rules that actually apply to it.
-
Sign off and file
You see the draft first. Then the trace, the map and the record - each dated.
Why teams choose iDharma to read this landscape with them
Genuinely independent
We build, resell and operate no AI systems of our own, and take no fee tied to what we find.
We test, not review
The credential is read off a real asset at the end of your own real pipeline, and never off a policy.
We say what is not law
Guidance, pending bills and voluntary standards are labelled as such in every line we write.
Built for moving dates
The record says which rule applied when - so a deferral does not invalidate the whole file.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Authenticity posture report
The whole assessment in one document: which rules actually reach you and which do not, what your content carries today, where the credential is lost, which labels are missing or inadequate, and every finding marked as enacted law, state rule, federal guidance or voluntary standard rather than run together.
Content provenance review
Whether your AI-generated and edited media carries C2PA Content Credentials, checked on the real files rather than the settings.
Pipeline trace report
One real asset followed through your real pipeline, with the credential read at the far end and every stage that strips it named.
Disclosure-practice audit
Where you publish AI content, set against the state rules that reach it, with each label checked for present and for adequate.
C2PA readiness gap list
What adopting Content Credentials would take across capture, generation and publishing, including signing-key management.
Takedown-path test
Your notice-and-removal route timed as a stranger would use it, read against the 48-hour duty the Act puts on covered platforms.
Patchwork documentation
A dated trail of which state rules applied, from when, and what you had in place - the deliverable that survives the next deferral.
Real numbers, upfront.
- Scope
- Your surfaces and the rules on them
- Input
- What you publish and what exists on it
- Re-read
- When a date moves, or a surface changes scoped and quoted against your last one
Your surface count fixes the scope, so the fee is flat - nothing to meter, and nothing charged until you approve it.
Request a readiness scan- Which rules reach you, in writing
- One asset traced through your pipeline
- Disclosure checked where readers see it
- The dated record, yours to keep
Four things you have to be able to produce
Nobody issues a certificate for this. Each of these is either in your hand on the day somebody asks, or it is not.
The inventory,
current
What you generate, edit or host, and which surface each of it reaches. Nothing downstream is worth more than this list, and it is the one that goes stale fastest.
The credential,
intact
Content Credentials still attached and still readable at the end of your pipeline, not at the moment of generation. AI 100-4 is explicit that the metadata is easy to strip.
The label,
in place
The disclosure where the reader meets the content, in the words the applicable state rule asks for. A label in a policy page is not a label on the thing being published.
The record,
dated
Which rules applied on which date, what you had in place, and when you checked. On a landscape where the dates keep moving, this is the artefact that keeps its value.
Four cards, and the date on each one is part of the card.
Is there a federal law requiring me to label AI-generated content?
No. As of 2026 there is no comprehensive federal AI-disclosure or watermarking statute. The one enacted federal AI-media law, the TAKE IT DOWN Act, is narrow and is about nonconsensual intimate deepfakes.
Is C2PA / Content Credentials required?
No - C2PA is a voluntary industry standard. It is broadly adopted and endorsed in federal security guidance, but no federal law compels it. It is increasingly expected by buyers, and useful for state-law disclosure.
What about the NO FAKES Act?
It is pending legislation about AI replicas of a person's voice and likeness - reintroduced multiple times but not enacted. Plan for it as a possibility, not as a current obligation.
So what actually obliges us to do anything?
The state patchwork, and the TAKE IT DOWN Act if you host user content. Texas TRAIGA has been in force since January 2026, California SB 942 lands August 2026, Colorado was reset to 2027, and around 30 states cover political ads.
How long does it take?
Typically two to four weeks from hand-over, longer where the number of publishing surfaces turns out to be bigger than expected - which it usually does. Scope is agreed before anything is charged.
Turn a moving target into a documented posture
Tell us what you publish and we come back with a scoping call within one business day.
What we need from you
Nothing you do not already have. Most of this is a folder someone can assemble in an afternoon, and we name every document first, in writing, before you commit.
- Where you publish AI content, and roughly who sees it
- Whether anyone outside your team uploads to you
- Which tools generate or edit the media, and their settings
- One real published file we can read the far end of
- Your target readiness date, if you have one
What happens next
- You send the five items we need.
- You get a scoping call within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Which of these can actually be enforced against you, and from when - stated, not assumed.
What it is drawn from
- TAKE IT DOWN Act - enacted
- NO FAKES Act - pending, not law
- NIST AI 100-4 - guidance
- C2PA Content Credentials - voluntary
- Texas TRAIGA - state law, in force
- California SB 942 - state law, Aug 2026
- Signed
- 19 May 2025
- FTC enforcing
- 19 May 2026
What it means
- Informational only, reflecting our understanding of the US landscape as of 2026 — not legal advice, and no professional relationship arises from reading it.
- Where a rule’s reach is arguable, our reports say so rather than the convenient thing.
Scope & limitation
- Do not rest a binding decision on it; engage qualified counsel.
- Federal bills and state effective dates change frequently — confirm current requirements.
- It covers US authenticity rules alone - the EU AI Act reaches the same content.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
ISO/IEC 42001, SOC 2 and NIST AI RMF: Which One Your Buyer Is Actually Asking For
One certifies an organisation, one is an opinion about controls over a window, one is a method with nothing to issue. What each covers — and what none of them answers.
No payment until you approve the scope
Request an AI audit
Request received
Brijesh Patel, our founder, personally replies within one business day. Nothing is charged until you approve the scope.
- 1We reviewOur team confirms your scope, usually within one business day.
- 2You confirm & payLock it in securely to fast-track your slot.
- 3Your audit beginsUpload documents in your portal and we start.
We’ve emailed you a secure, password-free link to your client portal. Sign in to your portal →
For audit firms and practitioners: co-deliver AI audits on our methodology and audit trail.
Application received
Thank you — your auditor partner application is with our team. We review every application and will be in touch by email.