NO FAKES Act clears key vote as platform takedown duties sharpen
Federal policy on AI deepfakes took a meaningful step forward in late June 2026. The NO FAKES Act has now moved through the Senate Judiciary Committee process, and the latest text makes clear that Congress is no longer treating unauthorized synthetic voice and likeness only as a niche celebrity problem. The bill is built around a new federal right to control digital replicas of one’s voice and visual likeness, reflecting the U.S. Copyright Office’s repeated conclusion that existing law does not adequately address realistic, unauthorized AI-generated impersonation.
For platforms, the more important signal is structural. The bill does not stop at direct liability for bad actors. It imports a DMCA-like notice-and-takedown framework, adds a counter-notice procedure, and ties online service protections to concrete compliance steps. That means the legal conversation is shifting from abstract AI ethics to operational governance: intake rules, designated agents, response timing, evidence handling, repeat uploads, and restoration workflows. The bill is not law yet, but it is already showing businesses what a future U.S. compliance baseline could look like.
A federal digital replica right is the real pivot point
The most consequential feature of the NO FAKES Act is not the headline language about deepfakes. It is the attempt to establish a distinct federal right around digital replicas of voice and visual likeness. That matters because the current U.S. landscape is fragmented. Victims often have to rely on a patchwork of state publicity, privacy, unfair competition, and other claims that vary widely in scope and procedure. The Copyright Office has argued that this is no longer enough, especially once generative AI makes realistic impersonation cheap, scalable, and easy to distribute.
The bill also follows an important policy choice: protection is not framed as a privilege for celebrities alone. The Office’s digital replicas report recommended coverage for all individuals, and the revised legislative push moves in that same direction. That is a quiet but major shift. A strong federal standard would affect not just entertainment companies, but schools, employers, consumer platforms, political campaigns, app developers, and any service that lets users synthesize or circulate realistic human likenesses at scale.
The compliance story is really about procedure, not rhetoric
From a platform perspective, the text matters because it is procedural in a very specific way. Once a compliant notice is received, a provider may need to remove or disable access quickly, address links and references in some contexts, and in certain service categories take action against matching reuploads that appear after valid notice has been processed. The bill also builds in designated agent registration and public directory mechanics. In practice, that starts to look less like a broad policy aspiration and more like a compliance system that can be audited by litigants and regulators.
Many companies already have reporting channels for impersonation or manipulated media. That will not be enough if federal obligations become more formalized. The harder questions are operational: who reviews a notice, what evidence is enough to verify identity or authority, how should synthetic audio and synthetic video claims be triaged, when should content be escalated to legal review, what gets preserved before takedown, and how do product teams track near-identical reuploads. Those are the details that determine whether a platform is merely reacting to headlines or actually preparing for statute-driven governance.
It resembles DMCA architecture, but the balance is different
It is tempting to describe the bill as “DMCA for deepfakes,” but that is only partly right. The structure borrows heavily from notice-and-takedown logic, yet the subject matter is different and so are the policy tensions. The revised bill adds a counter-notice pathway and includes consequences for materially false notices or counter-notices. It also leaves room for exclusions and defenses tied to lawful expression. That balance is not accidental. Congress is trying to answer a real victim-protection problem without turning every synthetic likeness dispute into automatic suppression of speech.
This is where the legal risk becomes more nuanced for platforms and businesses. Delayed action can create exposure, but overly aggressive removal can also trigger conflict around commentary, parody, documentary use, journalism, education, or other protected contexts. The practical challenge is not understanding that takedowns may be required. The challenge is designing a workflow that can handle claims, counter-claims, legal defenses, restoration timing, and internal escalation without collapsing into inconsistency.
What companies should do before the bill becomes law
The most useful preparation will happen well before any final enactment. Businesses that operate AI tools, user-generated content services, creator marketplaces, music platforms, ad systems, or enterprise communication tools should map where digital replica risk actually lives inside the product stack. That means voice cloning, face swaps, avatar generation, synthetic spokesperson tools, audio cleanup features that cross into imitation, and internal APIs that may be repurposed by third parties. Once those features are identified, companies can build cleaner pathways for notice intake, evidence retention, user communication, account action, and repeat-use monitoring.
Contracting is another weak spot that will not hold up well under a federal digital replica framework. Many existing agreements still speak in older terms: image use, recording consent, publicity rights, content licenses. They often do not say enough about AI training, synthetic reuse, derivative outputs, post-termination retention, or downstream sublicensing. If this bill continues to advance, those gaps will become more expensive. The companies that move first will not necessarily be the ones making the loudest public statements. They will be the ones quietly rebuilding their permissions, moderation, and documentation layers now.



