Take It Down Act 48-hour removal for AI video apps and URLs

The FTC enforces a 48-hour removal duty on covered platforms. If your AI video app serves generated MP4s from durable public URLs, here is what to plan for.

4 min readSume
All posts

Under Section 3 of the Take It Down Act, a covered platform that gets a valid removal request for a nonconsensual intimate image must remove it and known identical copies within 48 hours, and the FTC began enforcing that on 19 May 2026. If your product shows generated video on a public page, plan the takedown on your side: Sume's media.sume.com URLs do not expire and are public to anyone holding them.

This is a developer planning note, not legal advice, and whether your service is a "covered platform" is a question for counsel. FTC facts read 2026-10-01.

What clock does the 48 hours start?

Per the FTC, it starts at a valid removal request, and it covers the reported content plus known identical copies. The penalty figure the FTC gives is $53,088 per violation.

The 48-hour clock set against where a generated MP4 lives, read 2026-10-01.
StepWhere it happens
Valid request arrivesYour intake form or inbox
Find the file and its copiesYour own records of each media.sume.com URL you stored or shared
Stop serving itYour pages, proxy or CDN route
Confirm to the requesterYour status update

Why do durable media URLs matter here?

The Runs docs say media URLs are durable media.sume.com HTTPS URLs that do not expire and are public to anyone holding the URL, and suggest proxying or copying them if your product needs per-customer access control. The structured output docs add that you can store the URL against your own record and render it later. Both facts mean a URL you have already shared or embedded keeps resolving, so removal from your own pages and records is a step you design.

What can I build on my side?

Keep a map from each generated asset to the pages, records and customers that show it, so one report resolves to every place the video appears. Serve user-facing video through your own route if you need to cut access quickly, and store a request id so a reporter and your team talk about the same file. The FTC also suggests hashing so removed content does not reappear, and identical copies are part of the 48-hour duty, so record where copies were made.

Which Sume inputs touch this?

Face swap is a Beta endpoint that needs a fetchable public HTTPS video_url, so the source clip is also hosted somewhere public.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume