You type your own name into Google, or a message lands from a friend that just says "is this you?" And there you are, in a photo you never posed for. Maybe it's explicit. Maybe it puts you at an event you never attended, holding something you have never touched. The first reaction is usually a cold drop in the stomach, followed by the urge to delete everything and disappear for a week. Hold that thought for ten minutes, because what you do in the first hour decides how quickly this goes away. "Someone made a fake image of me" is a sentence more people type into search every month, and the ones who get results fastest are not the angriest reporters. They're the most organised ones.

The short version
Capture the evidence before anything gets deleted, then prove the image is fake using metadata and Error Level Analysis instead of just asserting it. Report it on the platform under the exact right category (non-consensual intimate imagery, synthetic media, or impersonation), ask Google to remove it from search results, and hash it with StopNCII so future uploads get blocked automatically. Then escalate under whichever law covers you: the TAKE IT DOWN Act in the US, the Online Safety Act and the Data (Use and Access) Act in the UK, the eSafety scheme in Australia, or GDPR and the Digital Services Act across Europe.

Save the Evidence Before You Report Anything

Your first move is not reporting. It's collecting. The moment a platform removes a post, the URL dies, the account may vanish, and the proof you'll need for police, a lawyer, or a regulator disappears with it. Spend fifteen minutes building an evidence folder and every later step gets easier.

Capture five things for every copy you find: a full-page screenshot with the URL and the date visible in the frame, the direct image address (right-click the image and copy its address, which is different from the page address), the account handle and profile link, the post's date and engagement numbers, and the image file itself downloaded to your device. That last one matters more than people expect. A screenshot of a screenshot destroys the forensic traces; the original file often still carries them.

Keep a plain text log alongside the folder: date found, where, what you did, any reference numbers you receive. It feels excessive on day one and it's the reason your case holds together on day thirty. Save copies to a web archive service too, so a snapshot survives even after the original comes down.

Important exception
If the fake image depicts anyone under 18, including you when you were younger, do not download, save, or forward it. That material is illegal to possess in every country listed in this guide. Report it straight to your local police and, in the US, through NCMEC's Take It Down service, which is built for exactly this situation. Note the URL in writing and let the authorities handle the file.

Prove the Image Is Fake Instead of Just Saying So

A moderator working through a queue sees hundreds of reports saying "this isn't real." Assertions are cheap. Evidence moves you to the front. Two checks take about a minute each and give you something concrete to attach.

Start with metadata. A camera photo usually carries EXIF data: make, model, lens, capture time, sometimes GPS. Fabricated and heavily edited images often show a generative tool or editor in the software field, a creation date that contradicts the story being told, or no camera data at all. Some newer files also carry C2PA content credentials that record how the image was produced.

Then run Error Level Analysis. ELA compares compression levels across a JPEG, and regions that were pasted in or regenerated frequently show up at a different brightness from their surroundings. When someone has grafted your face onto another body, that seam is often visible in the ELA output even when it's invisible to your eye.

Error Level Analysis result
Error Level Analysis result

Now the honest caveats, because overclaiming will damage your credibility. Platforms strip metadata on upload, so a clean file downloaded from Instagram tells you very little. ELA is close to useless on screenshots and on images that have been recompressed a dozen times. And a fully synthetic image, generated in one pass rather than composited, may show no seam at all, because there was never a splice to find. Absence of evidence is not evidence of authenticity, and saying so out loud makes the evidence you do have more persuasive.

Report It to the Platform, and Pick the Right Category

Here's the part almost everyone gets wrong. The category you select decides which queue your report lands in, which policy gets applied, and how fast a human sees it. Report a fabricated nude as "I don't like this" and it dies in a general moderation pile. Report the same image as non-consensual intimate imagery and it hits a priority workflow with a legal clock attached.

48 hours the deadline for US platforms to remove non-consensual intimate images, real or AI-generated, after receiving a valid request, under the TAKE IT DOWN Act. FTC enforcement of the platform requirements began on 19 May 2026.

Match your situation to the right label. Fabricated sexual content goes under non-consensual intimate imagery or synthetic sexual content. A fake image used to make you look like someone you're not goes under manipulated or synthetic media. A fake image posted from an account pretending to be you is impersonation, and you should report the account separately from the post. A fake image used in an advert or a scam is often fastest to kill as a trademark or advertising policy violation.

For US-based reports, use the platform's dedicated intimate image removal form rather than the generic report button. A valid request needs your signature (electronic is fine), enough information to locate the image, a statement that you're the person depicted and did not consent, and contact details. Save the reference number the platform issues. If they miss the 48-hour window, the FTC now runs a complaint route for exactly that failure.

Include the direct URL to the image, a screenshot showing where it appears, and a statement such as: "I am the person depicted in this image, and I did not consent to its creation or distribution."

A takedown request that reads like a case file gets treated like one. A takedown request that reads like a rant gets treated like one too.

Before you submit, attach your proof. Upload the image to our free Error Level Analysis and metadata checker, save the result, and include it with the report. It takes seconds, it costs nothing, and it turns "please believe me" into "here is why."

Push It Out of Google Even If the Site Ignores You

Removal from the host and removal from search are two separate jobs, and search is often the one that actually affects your life. Nobody finds the obscure forum thread on its own. They find it because your name pulls it up. Some offshore sites will never answer an email; Google will still deindex them.

Google's search removal flow now lets you specify that an image is fake and AI-generated using your likeness, rather than a real photo shared without consent. That distinction matters, because it routes you to the right policy. Once a removal succeeds, Google's systems look for duplicates of that image and filter similar explicit results tied to your name, and sites that rack up high volumes of these removals get demoted in ranking. Bing has its own reporting path, so file there too.

For non-sexual fakes, the search route is narrower but still real. Google's personal content removal process covers doxxing-adjacent material, and the "Results about you" tool handles exposed contact details, which often travel alongside a harassment campaign. Deindexing does not delete anything from the web, and it's worth being clear-eyed about that. It just stops the image from being the first thing anyone learns about you.

Stop the Re-Uploads With Hash Matching

Removing one copy is a task. Stopping the next twenty is a system. If the image is intimate, the single highest-leverage step available to you is hashing it, and almost nobody outside the field knows it exists.

StopNCII.org, run by the UK's Revenge Porn Helpline, generates a digital fingerprint of the image on your own device. The image never leaves your phone or laptop. Only the hash gets shared, and it goes to participating platforms including Facebook, Instagram, Threads, TikTok, Snap, Reddit, Bumble, OnlyFans, Aylo's sites, Microsoft's services including Bing, and Google. When a matching upload appears, it gets pulled for moderation and blocked. It's open to anyone 18 or over who was 18 or over when the image was made. For anyone under 18, NCMEC's Take It Down service does the same job.

The image never leaves your device. Only its fingerprint does, and that fingerprint is what stops the next upload before anyone sees it.

Two limits worth knowing. Hash matching only covers participating platforms, so it won't reach a standalone website. And while the technology tolerates resizing and recompression, a heavy crop or filter can produce a new image that needs its own hash. Check back and add new versions as you find them.

Do this before you close the tab
When you create a StopNCII case, you receive a case number and a PIN. Neither can be recovered if you lose them, and without both you cannot check your case or add to it later. Write them somewhere you'll still have access to in six months, not in a note that lives on the phone you're about to replace.

Someone Made a Fake Image of Me: What the Law Says Where You Live

The legal position changed dramatically between 2025 and 2026, and most advice online is out of date. I'm not a lawyer and none of this is legal advice, but knowing which regime applies to you tells you which door to knock on, and that alone saves weeks.

United States: The TAKE IT DOWN Act made knowingly publishing non-consensual intimate imagery, including realistic AI-generated depictions of identifiable people, a federal crime in May 2025. Its platform obligations became enforceable on 19 May 2026: covered services must offer a removal process and act within 48 hours, including on known identical copies. State laws add further routes. Separately, if the fake was built from a photo you took yourself, you likely hold the copyright, which opens a copyright takedown path that often moves faster than anything else.

United Kingdom: Sharing or threatening to share intimate images, deepfakes included, has been an offence for some time, and intimate image abuse is a priority offence under the Online Safety Act, meaning platforms are expected to find and remove it. Since 6 February 2026, Section 138 of the Data (Use and Access) Act 2025 also criminalises creating or requesting the creation of a fake intimate image without consent, even if it's never shared. Ofcom regulates platforms at the systems level rather than handling individual complaints, so for practical removal help the Revenge Porn Helpline is the place to start.

Europe: A fabricated image of you is still personal data, so you can send a GDPR erasure request directly to the site operator and to the hosting provider. The Digital Services Act requires platforms to run a proper notice-and-action mechanism and to explain their decisions, which gives you an appeal when a report is wrongly rejected. From 2 August 2026, the AI Act requires anyone deploying AI to create a deepfake to disclose that the content is artificially generated, so an unlabelled fake becomes a compliance problem as well as a personal one.

Australia, New Zealand and Canada: In Australia, eSafety runs an image-based abuse scheme that explicitly covers digitally altered and AI-generated content, plus an adult cyber abuse scheme for serious non-intimate material. You do not need a police report to start a removal. In New Zealand, the Harmful Digital Communications Act is the main lever and Netsafe is the approved agency that can push platforms directly, though how well the law covers wholly synthetic images is contested and reform is moving through Parliament. In Canada, criminal protection for non-consensual intimate images doesn't clearly extend to fabricated ones after a 2025 Ontario ruling, so provincial intimate image legislation matters more. Manitoba and Quebec name fake images directly, and Quebec offers a fast civil route to a removal order.

When to Bring In Police, a Lawyer, or Your Employer

Not every case needs escalation. Some clearly do, and waiting rarely improves them.

Go to the police when there's blackmail or a demand for money, when threats are involved, when it's part of a pattern of stalking, when the images depict a minor, or when you know who's responsible and it's someone with access to you. If you're being extorted, do not pay and do not send anything further. Payment reliably produces a second demand rather than a deletion. Keep every message.

A lawyer earns their fee when the image is being used commercially, when it's defamatory in a way that's damaging your income, or when the host is ignoring properly filed reports and needs a letter with legal weight behind it. Ask them to write to the hosting provider and the CDN as well as the site, because upstream providers often act when the site owner won't.

On your employer or school: tell them yourself, early, in a short factual message with your evidence attached. It's uncomfortable and it's still better than the version where a colleague forwards it to HR first. In every case I've seen handled well, the person got in front of it within a day. In the ones that went badly, they hoped nobody would notice.

Six Mistakes That Slow a Takedown Down

Most of the delays I see are self-inflicted, and all six of these are avoidable.

Replying publicly to whoever posted it. Your reply hands the post fresh engagement and warns them to make backups. Asking twenty friends to mass-report it. Coordinated reporting can look like brigading to automated systems and sometimes hurts more than three careful reports filed under the right category. Deleting your own accounts in a panic. You need those accounts to verify you're the person depicted. Reporting only the original post and ignoring the account, the reposts, and the search results. Sending the image to people to ask whether it looks real to them. That's distribution, and where minors are involved it's a serious criminal risk. And paying a "removal service" that charges per URL without explaining its method. Google treats charging people to take down their own content as an exploitative practice, and plenty of these operations do nothing you couldn't do yourself in an afternoon.

Look After Your Head While This Plays Out

Takedowns take days, sometimes weeks. The waiting is often harder than the discovery, because there's nothing left to do and no way to stop thinking about it.

One practical thing helps more than anything else: set up an alert on your own name and any handles you use, then stop searching manually. Compulsively checking search results a dozen times a day keeps the wound open and tells you nothing an alert wouldn't. Let the alert do the watching.

Tell one person you trust what's happening. Isolation makes this significantly worse, and the shame most people feel is misplaced. You did not do anything. Someone did something to you. If you want specialist support, the Revenge Porn Helpline covers the UK, the Cyber Civil Rights Initiative runs a helpline in the US, eSafety supports people in Australia, and Netsafe does the same in New Zealand. If this is affecting your sleep, your work, or how safe you feel, that's worth taking to your doctor or a crisis line, and it's a normal response rather than an overreaction.

Questions People Ask When This Happens to Them

Can I get a fake image removed if it isn't sexual?
Yes, though the route differs. Non-sexual fakes are usually handled under impersonation, harassment, or privacy policies rather than intimate image rules, which means slower queues and more judgement calls. In Europe, a GDPR erasure request is often the strongest lever because the image is personal data regardless of subject matter. In Australia, the adult cyber abuse scheme covers seriously harmful non-intimate content targeting people over 18.
How long does a takedown actually take?
For non-consensual intimate imagery on a major US-facing platform, the law now says 48 hours from a valid request. Other categories typically run from a few days to a few weeks. Search deindexing is often faster than getting the host to act, and small offshore sites may never respond at all, which is exactly why the search and hashing steps matter as much as the direct report.
Does proving the image is AI-generated help my case?
It helps, but not in the way people assume. Detection output strengthens a report and helps you describe the manipulation accurately, and it's useful when a platform pushes back. It isn't courtroom-grade proof on its own, and it doesn't need to be, because the legal test in most places turns on consent and identifiability rather than on which tool produced the file.
What if they made it from a photo I posted publicly?
Posting a photo of yourself is not consent to have it altered, sexualised, or used to misrepresent you, and no law in the US, UK, EU, Australia, New Zealand, or Canada treats it that way. There's also a practical upside: if you took the original photo, you probably own the copyright to it, which gives you a copyright takedown route that some hosts respond to faster than they respond to anything else.

Wrapping Up: What to Do in the Next Hour

None of this requires technical skill or money. It requires doing things in the right order while you're still upset, which is the genuinely hard part. Evidence first, then proof, then the report with the correct category attached, then search, then hashing so it can't come back.

Start with the file. Download the image, run it through the free Error Level Analysis and metadata checker on this site, and save the result to your evidence folder. It takes under a minute and gives you something to attach to every report, letter, and complaint that follows. Then work down the list. You will probably not get every copy, and you don't need to. You need the ones that show up when someone searches your name, and those are very much within reach.