United States - California - Deepfake Image Regulation (SB 981)

California SB 981 - Platform Obligations for Deepfake Intimate Images

United States

RAI-US-CA-CS9POXX-2024
Effective: January 1, 2025
In Force(In Force)
ActData Protection and PrivacyTransparency and DisclosureEnforcement and Penalties
Export PDF

California SB 981 mandates social media platforms to provide reporting and removal mechanisms for non-consensual deepfake intimate images, protecting user privacy.

Overview

California Senate Bill 981 (SB 981), officially enacted as Chapter 292 of the Statutes of 2024, represents a significant legislative effort by the State of California to combat the proliferation of non-consensual intimate deepfake images on social media platforms. Introduced by Senator Wahab on January 29, 2024, and subsequently approved by the Governor on September 19, 2024, this Act became effective on January 1, 2025. The core objective of SB 981 is to impose explicit obligations on social media platforms, compelling them to create and maintain accessible reporting mechanisms for California residents who become victims of "sexually explicit digital identity theft." This form of identity theft is specifically defined to encompass the non-consensual creation and dissemination of digitally altered or generated intimate images or videos that falsely depict an identifiable individual. The legislation acknowledges the severe psychological trauma and reputational damage inflicted upon victims by such content, aiming to provide a clear pathway for redress and removal, thereby fostering a safer online environment.

Prior to the enactment of SB 981, existing legal frameworks in California provided limited recourse for individuals targeted by non-consensual deepfake pornography, often leaving victims without effective means to remove such harmful content. The bill addresses this critical gap by mandating proactive measures from social media platforms, shifting some of the burden of content moderation onto these entities. It requires platforms not only to facilitate reporting but also to undertake prompt investigations, temporarily block reported content during the review period, and, crucially, to permanently remove any material confirmed to constitute sexually explicit digital identity theft. This legislative move underscores California's commitment to adapting its legal landscape to the challenges posed by rapidly evolving artificial intelligence technologies and their potential for misuse, particularly in areas affecting personal privacy and dignity. The law's implementation is expected to significantly enhance user protections against digital exploitation, setting a precedent for platform accountability in the realm of AI-generated content.

Definitions

Central to the understanding and implementation of California SB 981 are several key definitions that delineate the scope of the legislation and the responsibilities it imposes. The most critical term is "sexually explicit digital identity theft," which is defined as the posting of "covered material" on a social media platform where the reporting person is the individual depicted, did not provide consent for the use of their likeness in such material, and the material itself is an image or video created or altered through digitization. This digital alteration must be such that it would appear to a reasonable person to be an image or video of an intimate body part of an identifiable person, or an identifiable person engaged in specific sexual acts, including sexual intercourse, sodomy, oral copulation, sexual penetration, or masturbation. This comprehensive definition ensures that the law specifically targets non-consensual deepfake pornography, distinguishing it from other forms of digital manipulation and focusing on the severe privacy violations inherent in its creation and distribution.

The term "covered material" further elaborates on the nature of the content targeted by the bill. It refers to any image or video that has been created or altered through digitization, and which, to a reasonable person, would appear to depict an intimate body part of an identifiable person or an identifiable person engaged in the aforementioned sexual acts. This definition is crucial for platforms to assess reported content objectively and determine whether it falls under the purview of the law. A "social media platform" is broadly understood within the context of existing California law regulating such online services, generally encompassing platforms that enable users to create, share, and interact with digital content. The "reporting user" is defined as a California resident who holds an account with a social media platform and initiates a report regarding sexually explicit digital identity theft. While the bill primarily uses the term "sexually explicit digital identity theft," the broader concept of "deepfake" is implicitly addressed, referring to digitally altered or manipulated images, audio, or videos that falsely depict individuals, especially in sexually explicit contexts, and is a term frequently used in discussions surrounding this legislation.

Governance and Institutional Framework

The governance and institutional framework for California SB 981 primarily places the onus of implementation and enforcement on social media platforms themselves, under the broader regulatory oversight of the State of California. The legislation mandates that social media platforms establish a readily accessible mechanism for reporting sexually explicit digital identity theft. This requirement signifies a shift towards greater corporate responsibility in policing harmful content generated by advanced AI technologies. Platforms are expected to integrate these reporting tools into their existing user interfaces, ensuring that victims who are California residents with accounts can easily identify and utilize them. The state, through its legislative and potentially its prosecutorial bodies, provides the overarching legal framework and the threat of penalties, which incentivizes platforms to comply diligently with the new requirements.

While SB 981 does not establish a new dedicated state agency for enforcement, its provisions are designed to be actionable through existing legal avenues. The bill's requirements for prompt investigation, temporary blocking, and permanent removal of content, coupled with specific timelines for platform responses, create a clear set of compliance standards. Failure to adhere to these obligations could expose platforms to legal challenges or regulatory scrutiny, although the specific enforcement mechanisms for platform non-compliance are generally implied through the broader legal system rather than detailed within the bill itself. The intent is to leverage the platforms' existing content moderation infrastructure and policies, compelling them to adapt and enhance these systems to specifically address the unique challenges posed by deepfake intimate images. This approach reflects a legislative strategy that relies on private sector accountability, backed by the force of state law, to achieve public policy goals related to digital safety and privacy.

Key Focus Areas

California SB 981 primarily focuses on three critical areas: establishing robust reporting mechanisms, defining clear platform obligations for content removal, and safeguarding the privacy and digital identity of individuals. The first key focus is the mandatory creation of a "reasonably accessible" reporting mechanism on social media platforms. This mechanism must allow California resident users with accounts to report instances where their likeness has been used in sexually explicit digital identity theft without their consent. The emphasis on accessibility ensures that victims, who are often in distress, can easily navigate the reporting process. Platforms are also required to collect sufficient information to locate the reported content and to provide the reporting user with confirmation of receipt within 48 hours, thereby initiating a transparent communication channel.

The second major focus area pertains to the stringent obligations placed upon social media platforms once a report is received. SB 981 mandates a multi-step response: first, platforms must temporarily block the reported instance of sexually explicit digital identity theft from public view while they conduct an investigation to determine if there is a reasonable basis to believe the report is genuine. This temporary blocking is crucial to limit the immediate spread and harm of the content. If the platform determines that the report is credible, it is then required to immediately and permanently remove the content from public view. This swift and decisive action is designed to mitigate the severe emotional and reputational damage that can result from such non-consensual imagery. The bill also encourages platforms to make reasonable efforts to identify and remove unreported instances of such content, indicating a broader expectation of proactive content moderation.

Implementation Framework

The implementation framework for California SB 981 primarily revolves around the operational changes and policy adjustments required of social media platforms to comply with the new mandates. Platforms are tasked with developing and deploying a user-friendly reporting interface that is easily discoverable by California resident users. This interface must be capable of receiving detailed reports of sexually explicit digital identity theft, including information necessary to identify and locate the offending content. Furthermore, platforms must establish internal protocols for promptly acknowledging these reports, with a specific requirement to send confirmation to the reporting user within 48 hours of receipt.

Beyond the reporting mechanism, the implementation framework dictates a structured response process for platforms. Upon receiving a report, the social media platform must initiate an investigation to determine the veracity of the claim. During this investigative period, which is generally expected to conclude within 30 days, the platform is obligated to temporarily block the reported content from public visibility. This interim measure is vital for preventing further harm while due diligence is performed. If the platform's investigation concludes that there is a reasonable basis to believe the content constitutes sexually explicit digital identity theft, the platform must then proceed to immediately and permanently remove the content from public view. The bill also encourages platforms to extend these efforts to proactively identify and address unreported instances of such material, suggesting the need for advanced content detection technologies, potentially including AI-powered solutions, to fulfill the spirit of the law. The overall framework emphasizes speed, accessibility, and definitive action in response to this specific type of harmful content.

Monitoring and Evaluation

While California SB 981 does not explicitly detail a state-level monitoring and evaluation framework with specific metrics or reporting requirements for platforms, the very nature of its mandates implies a continuous process of internal monitoring and self-evaluation by social media companies. The requirement for platforms to provide a reporting mechanism and to act upon reports necessitates that they track the volume of reports received, the speed of their responses, the outcomes of their investigations (e.g., temporary blocks, permanent removals), and the efficacy of their removal efforts. This internal data collection would be essential for platforms to demonstrate compliance if ever challenged or audited. Moreover, the bill's intent to protect victims suggests that public advocacy groups and potentially state consumer protection agencies could play an informal role in monitoring the effectiveness of platform responses, by aggregating user experiences and identifying systemic failures or successes in content moderation.

The effectiveness of SB 981 will likely be evaluated over time through various indicators, including a potential decrease in the prevalence of non-consensual intimate deepfakes targeting California residents, improved user satisfaction with reporting processes, and the overall responsiveness of social media platforms to such content. Although the bill does not prescribe specific governmental reporting requirements for platforms, the legislative intent to curb digital identity theft means that future legislative sessions or regulatory bodies may consider adding such mandates if the current framework proves insufficient. The ongoing public discourse around AI ethics and platform accountability will naturally serve as a form of societal monitoring, pushing platforms to continually refine their compliance strategies and demonstrate their commitment to user safety and privacy. This adaptive approach allows for flexibility in how platforms meet the law's objectives while keeping open the possibility of more prescriptive oversight if necessary.

Penalties, Liability, and Appeals

California SB 981 primarily focuses on imposing obligations on social media platforms rather than establishing new criminal penalties for the creation or distribution of deepfakes, which are addressed by related legislation like SB 926. However, the bill implicitly creates a framework for platform liability should they fail to adhere to the mandated reporting and removal requirements. While SB 981 itself does not specify direct fines or criminal charges for platforms, non-compliance could expose social media companies to civil litigation from victims who can demonstrate that a platform failed to meet its statutory obligations, leading to continued harm. Such civil actions could seek damages for emotional distress, reputational harm, and other losses incurred due to the platform's negligence or willful disregard of the law. This potential for civil liability serves as a significant deterrent and an incentive for platforms to invest adequately in their compliance infrastructure.

Furthermore, the broader legal landscape in California provides avenues for enforcement. While SB 981 does not outline an explicit appeals process for platforms, the general principles of administrative law and due process would apply to any regulatory actions or civil judgments against them. For reporting users, the bill establishes a clear right to have their reports addressed and acted upon. If a platform fails to remove content deemed to be sexually explicit digital identity theft after a reasonable basis is determined, victims may have grounds to pursue legal action. The legislative intent is to empower individuals by providing a clear mechanism for redress, thereby holding platforms accountable for their role in the dissemination of harmful deepfake content. The bill's emphasis on immediate removal once a determination is made underscores the seriousness with which California views this issue, reinforcing the potential for legal repercussions for platforms that do not comply.

Relationship to Other Instruments

California SB 981 operates within a broader legislative ecosystem designed to address the challenges of digital content and artificial intelligence, particularly in relation to privacy and harmful content. It complements existing California laws that generally regulate social media platforms, such as those requiring mechanisms for reporting child sexual abuse material. By specifically adding "sexually explicit digital identity theft" to the categories of content platforms must address, SB 981 expands and strengthens these existing obligations, adapting them to the unique threats posed by deepfake technology. This integration ensures that the new requirements are not isolated but build upon established regulatory principles for online services, maintaining a cohesive approach to content moderation and user protection.

Crucially, SB 981 works in tandem with other recent California legislation, most notably Senate Bill 926 (SB 926), also signed into law in 2024. While SB 981 focuses on platform obligations for removal, SB 926 creates a new criminal offense for the creation and distribution of AI-generated sexually explicit deepfake content, particularly when intended to cause serious emotional distress. Together, these two bills form a comprehensive strategy: SB 926 targets the perpetrators by criminalizing the act, while SB 981 empowers victims and obligates platforms to remove the harmful content. This dual approach addresses both the supply (creation/distribution) and the availability (platform hosting) of non-consensual deepfakes. Additionally, other California laws, such as SB 942, which requires provenance disclosures for generative AI systems, contribute to an overarching framework aimed at increasing transparency and accountability in the AI landscape, further contextualizing SB 981's role in protecting individuals from digitally manipulated content.

International Alignment

California SB 981, while a state-level initiative within the United States, reflects a growing global concern regarding the misuse of artificial intelligence for creating and disseminating non-consensual intimate imagery, commonly known as deepfakes. Many jurisdictions worldwide are grappling with similar issues, leading to a patchwork of emerging regulations. The emphasis on platform accountability, accessible reporting mechanisms, and rapid content removal aligns with principles found in various international discussions and nascent regulatory frameworks, such as aspects of the European Union's Digital Services Act (DSA), which also places significant obligations on online platforms for content moderation and user protection. While not directly harmonized with international treaties or supra-national laws, California's proactive stance contributes to the broader global dialogue on responsible AI governance and digital safety.

The legislative approach taken by California, focusing on the specific harm of sexually explicit digital identity theft, resonates with efforts in other countries to protect individuals from image-based sexual abuse, regardless of whether the images are real or synthetically generated. The bill's provisions, particularly those related to user reporting and platform responsiveness, could serve as a model or a point of comparison for other jurisdictions developing their own laws to address deepfakes. As AI technology continues to advance and its misuse becomes more sophisticated, there is an increasing recognition internationally of the need for robust legal frameworks that compel online intermediaries to take responsibility for harmful content hosted on their platforms. California SB 981, therefore, contributes to a global trend of legislative action aimed at mitigating the societal risks associated with advanced digital manipulation technologies.

Implementation Timeline

MilestoneDateNotes
Bill Introduced2024-01-29Introduced by Senator Wahab.
Approved by Governor2024-09-19Approved by Governor Gavin Newsom.
Chaptered by Secretary of State2024-09-19Became Chapter 292, Statutes of 2024.
Effective Date2025-01-01The Act officially came into force.

Compliance Checklist

CheckRequired Action
Reporting MechanismProvide a mechanism that is reasonably accessible to California resident users with accounts to report sexually explicit digital identity theft.
Information CollectionCollect information reasonably sufficient to locate the reported instance of sexually explicit digital identity theft.
Report ConfirmationProvide written confirmation to the reporting user within 48 hours of receiving their report.
Temporary BlockingTemporarily block the reported content from public view pending a determination of its authenticity.
Investigation & DeterminationConduct an investigation to determine if there is a reasonable basis to believe the reported content is sexually explicit digital identity theft (generally within 30 days).
Permanent RemovalImmediately remove the reported content from public view if a reasonable basis for sexually explicit digital identity theft is determined.
Proactive EffortsMake reasonable efforts to remove and block unreported instances of sexually explicit digital identity theft from public view.

Sources and References

SourceType
California Legislative Information - SB 981legal
LegiScan - CA SB981 (Chaptered Version)legal
Governor Newsom signs bills to crack down on sexually explicit deepfakes & require AI watermarkinggovernment
Los Angeles County District Attorney's Office - SB 981 Letter of Supportgovernment
SB 981 (Wahab) - Senate Bill Policy Committee Analysis (Assembly Committee on Privacy and Consumer Protection)government
Plain English

California's new SB 981 law requires social media platforms to create clear ways for California residents to report and remove non-consensual "deepfake" intimate images.

This law applies to all social media platforms that host content for California residents with accounts. Its primary goal is to combat "sexually explicit digital identity theft," which means any image or video that has been digitally altered or generated to falsely depict an identifiable person in an intimate or sexual way, without their consent. The law takes effect on January 1, 2025.

Platforms face several key obligations under SB 981: - They must provide an easily accessible reporting mechanism for California users to flag such content. - Once a report is received, platforms must confirm receipt to the user within 48 hours. - The reported content must be temporarily blocked from public view while the platform investigates its authenticity, typically within 30 days. - If the investigation finds a reasonable basis to believe the content is non-consensual deepfake intimate imagery, the platform must immediately and permanently remove it.

While SB 981 doesn't impose direct government fines or criminal charges on platforms for non-compliance, it opens the door for significant civil lawsuits. Victims can sue platforms for damages if they fail to meet these obligations, leading to continued harm. This potential for civil liability acts as a strong incentive for platforms to comply. A key practical point for platforms is that there isn't a new state agency specifically overseeing this law. Instead, enforcement largely relies on victims pursuing legal action, meaning platforms must proactively ensure their systems are robust to avoid costly litigation.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 7 marked complete

Plain-English obligations under United States - California - Deepfake Image Regulation (SB 981). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalJan 1, 2025

    Applies to: Social media platforms serving California residents

    The legislation mandates that social media platforms establish a readily accessible mechanism for reporting sexually explicit digital identity theft.
  2. #2CriticalJan 1, 2025

    Applies to: Social media platforms serving California residents

    Platforms are also required to collect sufficient information to locate the reported content.
  3. #3Critical48 hours after report receipt

    Applies to: Social media platforms serving California residents

    Platforms are also required... to provide the reporting user with confirmation of receipt within 48 hours.
  4. #4CriticalImmediately upon report receipt

    Applies to: Social media platforms serving California residents

    platforms must temporarily block the reported instance of sexually explicit digital identity theft from public view while they conduct an investigation.
  5. #5CriticalWithin 30 days of report receipt

    Applies to: Social media platforms serving California residents

    During this investigative period, which is generally expected to conclude within 30 days, the platform is obligated...
  6. #6CriticalImmediately after determination

    Applies to: Social media platforms serving California residents

    If the platform determines that the report is credible, it is then required to immediately and permanently remove the content from public view.
  7. #7Important

    Applies to: Social media platforms serving California residents

    The bill also encourages platforms to make reasonable efforts to identify and remove unreported instances of such content.

© Regulations.AI — created on 06-Jan-2026 using Gemini 2.5 Flash