Discovering an AI-generated image or video of yourself - sexual or not - that you never made, posed for, or agreed to is disorienting in a specific way: the instinct to act immediately is correct, but a few natural first reactions can make things worse. Downloading and forwarding it to “prove it exists,” confronting the poster directly, or spending hours trying to determine exactly how convincing or technically real it is can all cost time you need for the steps that actually help. This article is a first-response sequence for adults - what to do in the first hours, calmly, before deciding what happens next.
This article covers the adult case specifically. If the person targeted is a minor, the legal framework, the harm, and the correct reporting tools are entirely different - go to the child deepfake first-response plan instead, which covers CyberTipline reporting and NCMEC’s Take It Down. Do not use adult-focused tools or this article’s steps for a case involving a child.
This is first-response guidance, not legal advice
Reporting routes, criminal definitions, and available remedies vary by jurisdiction and by the specific facts of your situation. This article describes generally applicable steps and names real, verifiable tools and channels - it does not invent hotlines, portals, or legal guarantees, and you should get advice from a lawyer or your local victim-support service for anything specific to your case.
Step 1: Preserve evidence without amplifying it
Before reporting or reacting publicly, capture what you can safely, in a way that helps rather than spreads the content further:
- Record the URL, platform, account name, and the date and time you found it, even if you also save other evidence.
- Take a screenshot of the surrounding context - the post, comments, account profile - if the content itself is not sexual. This helps establish where and how it appeared.
- If the content is sexual or intimate in nature, do not screenshot, download, or forward the image or video itself unless a reporting path you are about to use specifically requires a local file (see the StopNCII fork in Step 2). Prefer platform reports and URL-based evidence whenever those are enough.
- Do not send it to friends, family, or a lawyer “to show them” unless a professional handling your case specifically asks you to. Every additional copy is a new point where it could resurface, and it does not change what a platform or investigator needs to act.
Do not pay anyone who is threatening to release, has released, or claims to have more material - whether the threat mentions money, further images, or anything else. Paying does not reliably stop the behavior and often invites further demands. Preserve the threatening messages instead and move to Step 4.
Step 2: Report through the tool built for this
For sexual or intimate imagery specifically, StopNCII.org is a real, free tool operated by the Revenge Porn Helpline (part of the UK charity SWGfL) for adults affected by non-consensual intimate imagery, including AI-generated or manipulated images. It creates a digital fingerprint - a hash - of an image already on your device; the image itself never leaves your device, and the hash is shared only with participating platforms so they can detect matching content. StopNCII.org is for people 18 and older who are depicted in the content. If the person in the image is under 18, stop and use the child deepfake response plan instead.
StopNCII needs a local file. Match the path to what you actually have:
- If the file is already on a device you control (for example it was sent to you directly): use StopNCII from that device without copying the file elsewhere. Then also report the URL to the platform’s abuse tool.
- If you only saw it on someone else’s feed, a group chat you do not control, or a public page: do not download it just to hash it. Record the URL, platform, username, date/time, and a text description; report that URL through the platform’s intimate-image or abuse category; involve law enforcement if there is a threat (Step 4). Let the platform and investigators retrieve the material.
For content that is not sexual - a fabricated video putting words in your mouth, a manipulated image used to embarrass or defame you, an impersonation post - report directly to the platform using its specific abuse or safety reporting category, not a general contact form. Some platforms have a distinct path for manipulated or synthetic media impersonating a real person; use that category when it exists, and treat “faster routing” claims as platform-dependent rather than guaranteed.
Step 3: Decide who else needs to know, deliberately
Unlike a public correction, this is not automatically a “tell everyone” situation - who you inform is a choice you get to make on your own terms, not something the person who made or shared the content gets to force. Consider, separately:
- People who may have already seen it - a close friend, partner, or colleague you trust, chosen deliberately rather than a wide announcement.
- Your employer, if relevant to your role or reputation - especially if the content could plausibly reach colleagues, clients, or a professional network.
- A therapist or counselor, if the discovery is affecting you significantly - this is a real trauma trigger for many people, and support for that is separate from and does not replace the reporting steps.
There is no obligation to make this public or to explain yourself to anyone. Managing disclosure on your own timeline is part of retaking control of a situation designed to take it from you.
Step 4: Involve law enforcement when there is a threat or extortion
If anyone is threatening to release material, demanding payment, demanding more images, or using the content to coerce you into anything, this moves from a content-removal problem to a law-enforcement matter. Practical first moves that victim-support and cybercrime responders commonly recommend: do not pay, do not comply with escalating demands, preserve the threatening messages, and report to law enforcement rather than negotiating directly with the person threatening you. Do not treat those steps as a quotation from any single agency page - report through the channel that matches your country and your situation.
- United States: file a complaint with the FBI Internet Crime Complaint Center at ic3.gov, and contact your local law enforcement if you need an immediate protective response. The FBI also publishes separate sextortion guidance focused on children and teens; if a minor is involved, stop and use the child deepfake response plan instead of this adult sequence.
- Estonia: report cybercrime through the Police and Border Guard Board at cyber.politsei.ee. RIA’s internet-safety guidance points victims toward that channel.
- Elsewhere: use your national cybercrime reporting channel, plus local police if there is an immediate threat.
If you feel you or someone else may be in immediate physical danger, contact emergency services directly rather than starting with an online report.
Step 5: Consider legal counsel for anything beyond removal
Content removal and platform reporting address where the material appears. They do not address compensation, a formal complaint against a known perpetrator, or a situation involving a partner, ex-partner, or someone with real leverage over your life (a workplace, a custody matter, a business relationship). If any of those apply, a consultation with a lawyer familiar with online harassment or image-based abuse in your jurisdiction is a reasonable next step, separate from and in addition to the reporting channels above.
Do not spend time trying to prove it is synthetic first
None of the steps above depend on you first determining, with certainty, that the content is AI-generated rather than a real photo taken without your knowledge, or vice versa. Reporting tools and investigators are equipped to make that determination; you are not, and there is no reliable, publicly available detector that would let you settle it yourself with confidence - see AI image limits, not detectors for why. Report first, on the assumption that the harm is real regardless of exactly how the content was produced.
Where this connects
If the deepfake arrived attached to a scam attempt - a demand for money, a fake emergency, an impersonation of someone you know - recognising AI-enabled scams covers the broader verification habits that apply. If your own voice rather than your image was cloned, voice-clone personal safety covers the parallel exposure and household-habit side of that risk. And if you want to understand what a Content Credentials badge would or would not have told you about the content in the first place, Content Credentials and watermark basics explains what that signal can and cannot prove.
Common pitfalls
- Downloading sexual content “to prove it exists” or just to hash it. If the file is not already on a device you control, use URL-based platform reporting and law enforcement instead of creating a new local copy for StopNCII.
- Paying someone who threatens to release material. It does not reliably stop the behavior and confirms you will pay, which invites further demands.
- Trying to determine “how real” the content looks before reporting. This delays action without changing what a platform or investigator needs from you.
- Assuming this must become public knowledge. Who you tell, and when, remains your decision.
- Confusing this with a child-safety case. If a minor is depicted, stop and use the child deepfake response plan instead - the tools, legal framework, and urgency are different.
Try it today, before you need it
Bookmark StopNCII.org now, while calm, rather than searching for it during a stressful moment. If you want a single place to find the steps quickly if this ever happens, the adult deepfake first-response checklist has the sequence above with the reporting links already listed.



