If someone made a deepfake of you, save evidence of every copy before it disappears, report each copy to the service hosting it, ask Google to delist the pages, and block re-uploads by hashing the fake itself. Then use the official route for where you live: eSafety in Australia, the Revenge Porn Helpline and police in the UK, and in the US a platform removal request under the TAKE IT DOWN Act plus a police or FBI report. None of these steps requires you to know who made it.
This plan covers any image, video or audio of you that was generated or edited with AI, sexual or not, and it is about the order you do things in. The mechanics have their own guides: how hashing with StopNCII works, how to file a TAKE IT DOWN Act removal request, and how to get pages delisted from Google. For what the law says, read the Australian deepfake law map or the UK deepfake offence table.
Sort the fake before you report it
Reporting routes split on what the fake shows, so take a moment to classify it. eSafety's image-based abuse page treats an image as intimate when it shows, or appears to show, things such as you nude or partly naked, during a private activity, or without religious or cultural attire you normally wear in public. It adds that the image can be real, digitally altered or faked, or a nude of someone else shared in a way that makes people think it is you. That last point matters for creators: a stranger's body labelled with your stage name is handled the same way as a face-swap.
- An intimate or sexual fake goes through the non-consensual intimate image routes below, which are the most developed.
- A non-sexual fake, such as a cloned voice note, a fake endorsement ad or a doctored screenshot, goes through privacy, impersonation and scam routes, covered further down.
- A fake that arrives with a demand for money, more content or contact is extortion; go straight to the sextortion safety steps.
- Anything that depicts you, or anyone else, as under 18 needs a police report straight away, and you should not save, screenshot or forward it.
First-24-hours checklist
Work through the list in order. If you feel unsafe at any point, jump to the first item and call for help.
- Check your physical safety. If the fake came with a threat, your home address or someone turning up, call 000 in Australia, 999 in the UK or 911 in the US before anything else.
- Do not reply to the uploader, comment under the post or pay anyone offering removal. eSafety's reporting advice says not to reply or negotiate if a site demands payment to take images down.
- Capture each copy: the full URL, the account name and profile link, the date and time, and a screenshot showing the account and the post together.
- Move those screenshots out of your camera roll into a separate folder, as eSafety's evidence guide suggests, so the fake does not keep resurfacing in your photos.
- Keep a log with one line per copy, reposts included, so every later report can quote the same details.
- Set up a new email address only for removal requests, and leave your home address, phone number and identity documents out of every form; eSafety recommends both.
- Report every copy in-app or through the service's form, choosing the non-consensual intimate imagery or synthetic media option where one exists, and save each confirmation.
- Ask Google to delist search results that show the fake or tie your name to sexual material.
- If the fake is intimate, create a StopNCII case from the fake file itself, not from the public photos it was built from, so participating platforms can block re-uploads.
- Make the official report for your country using the table further down.
- If the source images came from a private account or cloud folder rather than your public posts, change those passwords and sign out of other sessions.
- Tell one person you trust and let them help with monitoring. In Australia, Lifeline takes crisis calls on 13 11 14 if the day gets too heavy.
Reporting routes by where the fake is posted
Report on every service where a copy sits, not only the one where you first saw it. The last column describes what the official source says will happen, which is a process, not a guarantee of removal.
| Where it is posted | Route | What to attach | Expected response |
|---|---|---|---|
| Instagram or Facebook | Report it as non-consensual intimate imagery; Meta's adult sexual exploitation standard says this includes digitally created or AI-generated imagery | The post or profile link, and a note that you are the person depicted, which Meta treats as a sign the sharing lacked consent | Meta's standard sets no timeframe, so log the date you reported and recheck the link |
| YouTube | A privacy complaint under the YouTube privacy guidelines, which accept reports of AI-altered or synthetic content that looks or sounds like you | The video URL, timestamps where you appear, and what makes you identifiable, such as your face, voice or name | YouTube may first give the uploader time to trim or blur the video, then reviews the complaint if the content stays up |
| Google Search results | Google's personal sexual content removal request, which covers fake sexual or nude content of you distributed without consent | Each result URL, with screenshots you are allowed to crop so that only your face shows | If Google approves, it emails you and tries to remove duplicates too, but the page itself stays online unless the host deletes it |
| A standalone website, forum or tube site | The site's abuse or copyright contact, then your country's escalation route if it ignores you | The exact URLs and a short statement that the content is fake and was posted without your consent | Responses vary by site, so record the date you asked; regulators will want to see it when you escalate |
| A DM, group chat, email or AirDrop sent to you or your contacts | Report the message in-app and keep the thread; eSafety's scheme covers intimate images sent by direct message, text, email or file transfer | Screenshots of the thread showing the sender's handle and the time each message arrived | In Australia you can go to eSafety without reporting to the platform first, according to its reporting page |
| Anywhere, if you or the poster ordinarily live in Australia | An image-based abuse report to eSafety | Your evidence log plus any platform report numbers you already have | eSafety's regulatory guidance says a removal notice requires removal within 24 hours, or a longer period eSafety sets |
| A social, messaging or video platform used in the US | A removal request under the TAKE IT DOWN Act, with the elements set out in our request template | The link, your signature, your contact details and a brief good-faith statement that the depiction is not consensual | The FTC says covered platforms must remove it and known identical copies within 48 hours, and failures can be reported at TakeItDown.ftc.gov |
| A service regulated under the UK Online Safety Act | An intimate image content report declaring that you are the person shown and are reporting in good faith | Enough detail for the service to find the content, plus your contact details | Since 29 June 2026, section 10(3A) requires systems designed to take reported content and matching copies down within 48 hours |
Blocking re-uploads with a hash of the fake
Hash-matching turns an image into a digital fingerprint that platforms compare against new uploads. StopNCII.org creates that fingerprint on your own device and shares only the hash with participating companies, and its eligibility questions ask whether you are the person in the image, were an adult when it was taken, and still have the file. For a deepfake, the file you fingerprint is the fake, so keep one copy in a private folder for that purpose and nowhere else. Our StopNCII walkthrough covers the case form and which platforms receive the hashes.
In the UK, hashing is turning into a regulatory expectation. Ofcom announced in May 2026 that it would recommend certain services use hash matching against a database such as StopNCII to detect intimate images shared without consent, explicit deepfakes included. A fingerprint only matches the same or similar versions of the image you submitted, so a heavily re-edited fake still needs its own report.
Official routes by country
Make these reports alongside the platform reports, not instead of them. The law column is a pointer; our country guides go through the elements and penalties.
| Where you live | Who to contact | Law that can apply |
|---|---|---|
| Australia | eSafety for removal, and state or territory police for the person responsible, with 000 for immediate danger | Criminal Code section 474.17A, which the 2024 deepfake amendments extended to material created or altered with technology; see the federal and state law map |
| United Kingdom | The Revenge Porn Helpline on 0345 6000 459, open 10:00 to 16:00 on weekdays with Fridays currently email only, plus police on 101 or 999 | In England and Wales, sharing a fake is an offence under section 66B and creating or requesting one under sections 66E and 66F; Scotland and Northern Ireland have their own, narrower rules, set out in the UK offence table |
| United States | The platform's TAKE IT DOWN process, then local police and the FBI through tips.fbi.gov or 1-800-CALL-FBI, as the FTC's guidance advises | The TAKE IT DOWN Act summary on Congress.gov covers both authentic and computer-generated intimate depictions; many states add their own laws |
| Canada | Your local police service, with the links and screenshots from your log | Criminal Code section 162.1 now defines an intimate image to include depictions made with AI software that are likely to be mistaken for a recording of an identifiable person |
| Somewhere else | Police, plus a local support organisation from StopNCII's global partner network | Local law varies widely, so ask police or a local lawyer which offences cover synthetic images where you live |
If the fake is not sexual
Face-swapped ads, cloned voice notes and invented quotes fall outside the intimate image schemes, so the routes are less direct and depend on how the fake is being used.
- YouTube's synthetic likeness complaint is not limited to sexual content; YouTube weighs whether the fake is realistic, labelled as altered, identifiable to others, and whether it is parody or in the public interest.
- Where an account poses as you to sell the fake or message fans, report impersonation with the impersonation report workflow or the Instagram impersonation steps.
- If the fake is being used to scam your audience, report it to Scamwatch in Australia as well as to the platform, and warn fans only through channels you control.
- If it is menacing or harassing and meant to cause you serious harm, eSafety's adult cyber abuse scheme can step in, but it asks you to report to the service first and come back if you hear nothing.
- If it damages your reputation or exposes private information, a lawyer can advise on defamation or on Australia's statutory privacy tort, whose misuse-of-information limb applies whether or not the information is true.
Telling your audience without spreading it
A short public note can stop fans from passing the fake around, but any screenshot of it, even blurred, gives it a second audience. Say that a fake is circulating, that you did not make it or agree to it, and ask people to report it rather than repost or comment. Leave out any suspect's name; that belongs in a police report, not a caption. The creator crisis playbook covers timing and wording if you decide a statement is needed.
When to bring in police or a lawyer
- Someone wants money, more content or contact to make it stop: report the demand to police and do not pay.
- You know or strongly suspect who made it: police can act on the creation and sharing offences where they exist, and a lawyer can advise on injunctions, protection orders and compensation.
- Copies keep returning, or the same person is targeting you in other ways: treat it as a pattern and follow the stalking safety plan.
- Real paid content leaked alongside the fake: the leaked content response plan handles the copyright and removal side.
- Your employer or a client has seen it: get advice before answering questions, starting with the employment-law guide for creators.
- The material shows anyone who is or looks under 18: report it to police immediately and keep no copy at all.
In Australia you can contact local police on 131 444 about threats that are not an emergency, a number eSafety's adult cyber abuse page lists. Ask for an event or reference number every time you report, and add it to your log so each new report can point back to the last one.
Limitations of this plan
This is general information drawn from official pages read on 1 October 2026, not legal advice. Platforms apply their own rules and can refuse reports, regulators prioritise some complaints over others, and laws differ between countries, states and territories, so not every route above will be open to you. Hashing and delisting limit the spread rather than erase it, and copies saved by other people can resurface later. Contact police whenever you feel unsafe, and speak to a lawyer, community legal centre or legal aid service before taking action against a person you can identify.