Take It Down Act 48-hour removal for AI video apps and URLs
The FTC enforces a 48-hour removal duty on covered platforms. If your AI video app serves generated MP4s from durable public URLs, here is what to plan for.

Under Section 3 of the Take It Down Act, a covered platform that gets a valid removal request for a nonconsensual intimate image must remove it and known identical copies within 48 hours, and the FTC began enforcing that on 19 May 2026. If your product shows generated video on a public page, plan the takedown on your side: Sume's media.sume.com URLs do not expire and are public to anyone holding them.
This is a developer planning note, not legal advice, and whether your service is a "covered platform" is a question for counsel. FTC facts read 2026-10-01.
What clock does the 48 hours start?
Per the FTC, it starts at a valid removal request, and it covers the reported content plus known identical copies. The penalty figure the FTC gives is $53,088 per violation.
| Step | Where it happens |
|---|---|
| Valid request arrives | Your intake form or inbox |
| Find the file and its copies | Your own records of each media.sume.com URL you stored or shared |
| Stop serving it | Your pages, proxy or CDN route |
| Confirm to the requester | Your status update |
Why do durable media URLs matter here?
The Runs docs say media URLs are durable media.sume.com HTTPS URLs that do not expire and are public to anyone holding the URL, and suggest proxying or copying them if your product needs per-customer access control. The structured output docs add that you can store the URL against your own record and render it later. Both facts mean a URL you have already shared or embedded keeps resolving, so removal from your own pages and records is a step you design.
What can I build on my side?
Keep a map from each generated asset to the pages, records and customers that show it, so one report resolves to every place the video appears. Serve user-facing video through your own route if you need to cut access quickly, and store a request id so a reporter and your team talk about the same file. The FTC also suggests hashing so removed content does not reappear, and identical copies are part of the 48-hour duty, so record where copies were made.
Which Sume inputs touch this?
Face swap is a Beta endpoint that needs a fetchable public HTTPS video_url, so the source clip is also hosted somewhere public.
Sources
Related posts
More in Developers
- Per-task cost in the API response: Runway vs Sume usage.cost
Runway task responses carry a credit cost, estimated while running and final on completion. On Sume, read usage.cost on the job, a USD billable amount.
- Tavus disclosure_type controls vs Sume authored caption cues
Tavus added disclosure_type, verbal_disclosure and visual_disclosure for EU AI Act use. Sume has no such setting; authored caption cues can burn a line of text.
- Tavus recording storage key_template vs Sume media URLs
Tavus can write recordings to S3, GCS or Azure Blob. Sume returns finished files as media.sume.com artifact URLs, delivered by webhook or job result.
- Temporal Activity ID policies are not a Sume Idempotency-Key
Temporal's Conflict and Reuse policies dedupe Activity IDs inside Temporal. They never reach Sume, so a paid submit still needs its own Idempotency-Key.
Written by Sume