Adult Deepfake First-Response Checklist
For the method in If There Is an AI Deepfake of You: An Adult First-Response Plan. First-response guidance, not legal advice. For a child depicted, use the child deepfake response plan instead.
Not for
A minor depicted in the content. Stop and use the child deepfake first-response checklist, which covers NCMEC’s Take It Down and CyberTipline reporting.
Step 1: Preserve evidence without amplifying it
- URL, platform, account name, date/time recorded
- Non-sexual context screenshotted (post, comments, profile) if relevant
- Sexual/intimate content: NOT downloaded, screenshotted, or forwarded unless a tool you are about to use already requires a local file you control
- Not sent to friends/family/lawyer “to show them” unless a professional handling the case asked for it
Step 2: Report through the right tool
Sexual/intimate imagery of an adult (18+):
- File already on a device you control: checked StopNCII.org’s current eligibility first. It is for an adult depicted who was 18 or older in the image/video and still has the file; the file stays on the device while a hash is shared. Do not make a new copy merely to use it.
- Only saw it on someone else’s feed / chat / public page: did NOT download it just to hash it; recorded URL + description; reported via the platform’s intimate-image / abuse tool
- Platform abuse report filed either way
- US: first used the platform’s Take It Down Act removal process; if that process was missing/broken or the platform did not remove the image and known identical copies within 48 hours of a valid request, reported the platform at TakeItDown.ftc.gov
- Understood that StopNCII’s hash is used by participating platforms, not the whole internet, so platform reports and jurisdiction-specific routes may still be needed
Non-sexual manipulated/impersonation content:
- Reported via the platform’s specific abuse/safety category (not a general contact form)
Step 3: Decide who else needs to know (your choice, not automatic)
- Specific trusted people informed, if any (deliberate, not a wide announcement)
- Employer informed, if relevant to role/reputation
- Therapist/counselor contacted, if this is affecting you significantly
Step 4: Law enforcement, if there is a threat or extortion
- Not paid, not complying with escalating demands
- Threatening messages preserved
- Followed current platform, lawyer, advocate, or law-enforcement instructions for preserving sensitive evidence securely; did not create or circulate extra copies
- Reported to law enforcement / official channels:
- US adults: TakeItDown.ftc.gov for a missing/broken platform removal process or failure to remove within 48 hours; ic3.gov + local law enforcement for threats/extortion/fraud
- Estonia: cyber.politsei.ee (see also RIA internet-safety guidance)
- Elsewhere: your national cybercrime reporting channel
- If a minor is involved: stopped and switched to the child deepfake response plan
- If immediate physical danger: contacted emergency services directly
Step 5: Legal counsel (if beyond removal)
- Considered for: compensation, formal complaint, situations involving a partner/ex-partner/employer/custody matter
Do not delay reporting to “prove” it’s synthetic
- Reported first, regardless of certainty about how the content was produced
Bookmark before you need it
- StopNCII.org (check current eligibility; adult intimate imagery; on-device hash shared with participating platforms)
- TakeItDown.ftc.gov (US FTC portal for a missing/broken platform removal process or failure to act within 48 hours of a valid request)
- ic3.gov (US internet crime complaints)
- Your national cybercrime reporting page