UNITED STATES · ONE STATUTE · THE REST IS VOLUNTARY

US digital authenticity is a state patchwork, not one federal law.

No federal law says “label your AI content”. What binds you is state law, and it keeps moving.


A reviewer with silver hair, in a navy blazer, a closed notebook at the edge of the desk, seated at a dark stone desk by a window in a warm, low-lit office, signing a printed page with further papers and a stoneware cup beside them.
One statute is enforced. The rest is voluntary
TAKE IT DOWN Act 48 hours C2PA NIST AI 100-4 State patchwork

Our promise

“A label you cannot trace is a claim.”

Every finding is written against what actually binds you — statute, state rule or standard, each named as what it is. The fee is fixed at $5,000, and nothing is charged until you approve it.

Request this readiness scan
The case file

The 2026 picture, in three chapters

The Statute

One federal law squarely targets AI media, and it is narrower than its reputation: the TAKE IT DOWN Act, signed in May 2025 and enforced by the FTC from May 2026. It covers nonconsensual intimate imagery, deepfakes included, and gives the covered platforms just 48 hours to act.

The Gap

Most teams assume a federal rule already tells them to label AI content. None does. What exists instead is guidance that is not regulation, a bill that has not passed, a standard nobody mandates, and fifty states going their own separate ways at their own speed, one statute at a time.

The Office

Our review is the independent read. We inventory what you publish, run one real asset through your pipeline to see whether its credential survives the trip, map each surface to the rules that reach it, and date the whole record — so a deferral somewhere else cannot quietly void it.

Law, guidance, standard

Two of these bind you. Two do not.

The only question that matters is who can enforce it against you, and from when.

The two that bind № 01
  • TAKE IT DOWN Act - enacted, FTC-enforced since May 2026
  • Intimate imagery and deepfakes; 48 hours to remove
  • The state patchwork - in force, and still arriving
  • Texas now, California in August, ~30 states on political ads
United States · iDharma · Presented for assay
The two that do not № 02
  • NIST AI 100-4 - federal guidance, and not regulation
  • Useful on provenance; says itself it can be stripped
  • C2PA / NO FAKES - one voluntary, one still pending
  • Content Credentials are expected by buyers, not by law
United States · iDharma · Presented for assay
The standard, accurately

One statute is enforced. The rest is not.

Enacted

One narrow federal statute

The TAKE IT DOWN Act was signed on 19 May 2025 and the FTC began enforcing it on 19 May 2026. It reaches nonconsensual intimate imagery, explicitly including AI deepfakes, and it obliges covered platforms to run notice-and-removal within 48 hours of a valid report. It is not a disclosure law.

Not law

Guidance, drafts and a standard

NIST AI 100-4 surveys provenance, watermarking and content authentication - as guidance, and it says itself the metadata can be stripped or spoofed. C2PA is a voluntary standard nobody mandates. The NO FAKES Act has been reintroduced repeatedly and has still not passed. None of it binds you.

The catch

The states are what bind you

Texas TRAIGA has been in force since 1 January 2026, California SB 942 lands in August 2026, Colorado was reset to 2027, and around thirty states require disclaimers on AI-generated political ads. The dates keep moving, and your obligations follow where the content is seen, not where you are.

What most teams assume

“There’s a federal law that makes us label AI content.”

What is actually true

There is no such law. The states are what bind you.

It is the most common correction we write into these reports.

  • Who it is for
  • Media & marketing teams
  • Platforms hosting UGC
  • Publishers & agencies
  • AI product teams
  • Legal & compliance
Why this lands on your desk
A bound statute volume lying open on a dark desk under a low lamp, with reading glasses and a fountain pen resting across its pages.
01 The real near-term driver is the state patchwork, not federal law — and its effective dates have already moved once in public.
02

If you host user content, the TAKE IT DOWN Act’s 48-hour notice-and-removal duty is live and FTC-enforced today.

03

For everyone else it is the patchwork, plus buyers who increasingly expect AI output to arrive provenance-signed.

04

So the durable advantage is provenance hygiene plus documented diligence — the one asset a moved deadline cannot devalue.

The 60-second check

Three questions. Then you’ll know.

No email, no signup. A starting point, not a determination.

0 of 3

Platform -

This is the question that settles the federal duty. The TAKE IT DOWN Act’s 48-hour notice-and-removal regime is aimed at covered platforms, not at everyone who publishes.

States -

Audience, not headquarters. The state rules generally follow where the content is seen, which is why “we are not a California company” is rarely the end of the analysis.

Provenance -

Attaching it is the easy half. NIST AI 100-4 says plainly that provenance metadata is easy to strip — and most of it is lost to an ordinary resize or re-encode, not to an attacker.

The calendar

Four dates, and one has already moved.

Two of these are live obligations today, one lands this year, and one was pushed back twelve months - so this cannot be planned as a single deadline.

  1. Texas

    1 January 2026

    TRAIGA came into force, and it is the first of the state rules most readers of this page actually meet.

  2. The FTC

    19 May 2026

    Enforcement of the TAKE IT DOWN Act began. If you host user content, the 48-hour clock is live today.

  3. California

    August 2026

    SB 942 lands, and it is the transparency rule with the widest practical reach over AI-generated media.

  4. Colorado

    Reset to 2027

    The AI Act was pushed back a year. It is the clearest evidence on this page that these dates move.

The trap

Teams wait for a federal date that is not coming. There is no national commencement for AI disclosure — the obligations arrive state by state, on four different calendars, and one of them has already slipped a year.

Requirement & coverage

What the rule says, what we ship

20 things that can be asked of you, and the artefact that answers each. Every row says whether it is law, and the ledger below marks which.

Notice-and-removal TAKE IT DOWN Act - enacted, FTC-enforced
Your takedown path timed end to end against the 48-hour duty, with the gaps written up as findings.
Who counts as covered TAKE IT DOWN Act - enacted; the threshold question
A written determination of whether the Act reaches you at all, so the answer is on record either way.
Reporting route TAKE IT DOWN Act - enacted; a real person must be reachable
The reporting route tested as a stranger would use it, not as your own team knows to use it.
Texas obligations TRAIGA - state law, in force since January 2026
Which of your surfaces Texas reaches, and what each one owes, set out surface by surface.
California transparency SB 942 - state law, from August 2026
Your generative tools and published media read against the duty landing in August, ahead of it.
Colorado, deferred Colorado AI Act - state law, reset to 2027
What the deferral changed and what it did not, so the year is used rather than simply waited out.
Political advertising Roughly 30 states - disclaimer rules, all different
Every state you run political creative in, with the disclaimer each one requires against it.
Where the rules reach State law - decided by audience, not by headquarters
Your publishing surfaces mapped to the states that see them, which is what actually scopes the duty.
Content Credentials C2PA - voluntary standard, broadly adopted
Whether your generated and edited media carries credentials at all, checked on the real files.
Durability of provenance C2PA - voluntary; AI 100-4 warns metadata is strippable
One real asset run through your real pipeline, and the credential read at the far end of it.
Signing-key management C2PA - voluntary; the part that is a security control
Who can sign as you, on what, and what happens the day a key has to be rotated or revoked.
Capture-side provenance C2PA - voluntary; cameras and phones already ship it
Whether credentials your suppliers already attach survive ingest, or are stripped on the way in.
Synthetic-content risk NIST AI 100-4 - federal guidance, not regulation
Your controls read against AI 100-4's own survey, with its caveats carried rather than dropped.
Watermarking NIST AI 100-4 - guidance; no federal mandate exists
What watermarking would and would not buy you here, stated plainly enough to decide against it.
Detection claims No standard - and vendor accuracy claims are unverified
Any detection tool you rely on tested on your own content rather than on its vendor's benchmark.
Disclosure wording State law - present is not the same as adequate
The label a user actually sees, where they see it, checked against what the rule asks for.
User-generated content Enacted and state law both reach it, differently
What you owe for content you did not make, which is where most of the real exposure sits.
Vendor and model terms Contract - not law, and it is where provenance is lost
What your generation vendors attach, strip or promise, read off the contracts rather than the decks.
Voice and likeness NO FAKES Act - PENDING. Not law, in any state of it
What would be owed if it passed, costed now, so the answer is a decision rather than a scramble.
The dated record Diligence - the one thing no date can move
Which rules applied, when, and what you had in place - a trail that still reads a year from now.
The engagement

Readiness you can evidence

No audit issues legal certification. This verifies artefacts.

  1. Inventory

    What you generate or host, where it is published, and which rules reach it.

  2. Trace

    One real asset through your real pipeline, and the credential read at the end.

  3. Map

    Each publishing surface set against the state rules that actually apply to it.

  4. Sign off and file

    You see the draft first. Then the trace, the map and the record - each dated.

Request a readiness scan
An auditor in a plum trouser suit and cream blouse, with short natural hair, standing against a warm pale wall and pointing into the open space alongside.
The trace is what you are buying.
Struck in your favour

Why teams choose iDharma to read this landscape with them

Genuinely independent

We build, resell and operate no AI systems of our own, and take no fee tied to what we find.

We test, not review

The credential is read off a real asset at the end of your own real pipeline, and never off a policy.

We say what is not law

Guidance, pending bills and voluntary standards are labelled as such in every line we write.

Built for moving dates

The record says which rule applied when - so a deferral does not invalidate the whole file.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

Authenticity posture report

The whole assessment in one document: which rules actually reach you and which do not, what your content carries today, where the credential is lost, which labels are missing or inadequate, and every finding marked as enacted law, state rule, federal guidance or voluntary standard rather than run together.

Findings

Content provenance review

Whether your AI-generated and edited media carries C2PA Content Credentials, checked on the real files rather than the settings.

Trace

Pipeline trace report

One real asset followed through your real pipeline, with the credential read at the far end and every stage that strips it named.

Matrix

Disclosure-practice audit

Where you publish AI content, set against the state rules that reach it, with each label checked for present and for adequate.

Ranked

C2PA readiness gap list

What adopting Content Credentials would take across capture, generation and publishing, including signing-key management.

Memo

Takedown-path test

Your notice-and-removal route timed as a stranger would use it, read against the 48-hour duty the Act puts on covered platforms.

Dated log

Patchwork documentation

A dated trail of which state rules applied, from when, and what you had in place - the deliverable that survives the next deferral.

Format & fee

Real numbers, upfront.

Scope
Your surfaces and the rules on them
Input
What you publish and what exists on it
Re-read
When a date moves, or a surface changes scoped and quoted against your last one

Your surface count fixes the scope, so the fee is flat - nothing to meter, and nothing charged until you approve it.

Request a readiness scan
US authenticity · Readiness scan $5,000 flat
  • Which rules reach you, in writing
  • One asset traced through your pipeline
  • Disclosure checked where readers see it
  • The dated record, yours to keep
Show your hand

Four things you have to be able to produce

Nobody issues a certificate for this. Each of these is either in your hand on the day somebody asks, or it is not.

The inventory,
current

What you generate, edit or host, and which surface each of it reaches. Nothing downstream is worth more than this list, and it is the one that goes stale fastest.

The credential,
intact

Content Credentials still attached and still readable at the end of your pipeline, not at the moment of generation. AI 100-4 is explicit that the metadata is easy to strip.

The label,
in place

The disclosure where the reader meets the content, in the words the applicable state rule asks for. A label in a policy page is not a label on the thing being published.

The record,
dated

Which rules applied on which date, what you had in place, and when you checked. On a landscape where the dates keep moving, this is the artefact that keeps its value.

Four cards, and the date on each one is part of the card.

FAQ

Common questions

What is law, what is not, and what to do about it.

Request a readiness scan
Is there a federal law requiring me to label AI-generated content?

No. As of 2026 there is no comprehensive federal AI-disclosure or watermarking statute. The one enacted federal AI-media law, the TAKE IT DOWN Act, is narrow and is about nonconsensual intimate deepfakes.

Is C2PA / Content Credentials required?

No - C2PA is a voluntary industry standard. It is broadly adopted and endorsed in federal security guidance, but no federal law compels it. It is increasingly expected by buyers, and useful for state-law disclosure.

What about the NO FAKES Act?

It is pending legislation about AI replicas of a person's voice and likeness - reintroduced multiple times but not enacted. Plan for it as a possibility, not as a current obligation.

So what actually obliges us to do anything?

The state patchwork, and the TAKE IT DOWN Act if you host user content. Texas TRAIGA has been in force since January 2026, California SB 942 lands August 2026, Colorado was reset to 2027, and around 30 states cover political ads.

How long does it take?

Typically two to four weeks from hand-over, longer where the number of publishing surfaces turns out to be bigger than expected - which it usually does. Scope is agreed before anything is charged.

Get started

Turn a moving target into a documented posture

Tell us what you publish and we come back with a scoping call within one business day.

What we need from you

Nothing you do not already have. Most of this is a folder someone can assemble in an afternoon, and we name every document first, in writing, before you commit.

  1. Where you publish AI content, and roughly who sees it
  2. Whether anyone outside your team uploads to you
  3. Which tools generate or edit the media, and their settings
  4. One real published file we can read the far end of
  5. Your target readiness date, if you have one

What happens next

  1. You send the five items we need.
  2. You get a scoping call within one business day.
  3. Nothing is charged until you approve the scope.
Request a readiness scan
Sources & standing

Where this page gets its facts

Which of these can actually be enforced against you, and from when - stated, not assumed.

What it is drawn from

  • TAKE IT DOWN Act - enacted
  • NO FAKES Act - pending, not law
  • NIST AI 100-4 - guidance
  • C2PA Content Credentials - voluntary
  • Texas TRAIGA - state law, in force
  • California SB 942 - state law, Aug 2026
Signed
19 May 2025
FTC enforcing
19 May 2026

What it means

  • Informational only, reflecting our understanding of the US landscape as of 2026 — not legal advice, and no professional relationship arises from reading it.
  • Where a rule’s reach is arguable, our reports say so rather than the convenient thing.

Scope & limitation

  • Do not rest a binding decision on it; engage qualified counsel.
  • Federal bills and state effective dates change frequently — confirm current requirements.
  • It covers US authenticity rules alone - the EU AI Act reaches the same content.

Something on this page out of date?

Tell us