REGULATION OF AI-GENERATED DEEPFAKES UNDER INDIAN LAW
Vaidehi Sharma
When Code Becomes the Counterfeiter: Mapping India's Legal Response to Synthetic Media
I. INTRODUCTION
On 10th February, 2026, MeitY did what India was not doing for quite some time; granting a legal definition to a concept known as "synthetically generated information". Before this notification, the only term one could use is "deepfake", which previously found no space in any law book. Now with the amendment coming into force after two weeks, social media platforms were made to label, limit the time taken for removal, and provide proof of creation for the said content.
This is not surprising given that India has witnessed the negative fallout of deepfake content for the past three years. From fabricated videos of celebrities to impersonating voices of older people defrauding vulnerable elders, morphed images of women to shame and harass them, and even fraudulent digital arrests using synthetic video calls to extort money have increased manifold. So, what is it that India has that pertains to the regulation of such content? Well, laws are not exactly new to deepfake content, the question arises if the authorities were prepared or if they are simply improvising on the go, and the answer is both.
II. WHAT ARE WE EVEN TALKING ABOUT
Before getting to the statutory details, let’s recall what these rules are even about. The deepfake as we know it is a product of deep learning algorithms, specifically generative adversarial networks - systems where two neural nets compete in an iterative process, one attempting to generate realistic forgeries, while the other tries to detect them, until the first manages to fool the second.
The amendment to the 2026 IT Rules does not specify any particular technology or approach. Instead, it defines synthetic information as information that has been “created, generated, modified or altered by means of a computer resource so as to appear reasonably authentic.” In other words, the definition encompasses all forms of computer-generated fakery, which can be a useful property in itself, because it will remain relevant despite technological advances. However, the criticism holds merit as well - the definition can be overly broad, threatening to capture benign or even beneficial uses of digital media, such as parodies or certain types of political satire.
III. THE REGULATORY PATCHWORK
A. The Information Technology Act, 2000
The IT Act remains the central legislation even if not a single word was penned down with generative artificial intelligence in mind. Section 66C deals with punishment for stealing and misusing an identifying feature of another person, and 66D addresses cheating by impersonation by means of a computer resource, which likely includes a fraudulent voice print as well as a deepfake video. In that sense, the scam with the fake senior police officer as the caller is a form of cheating by impersonation that has been around for years. Sections 67 and 67A criminalize publishing or transmitting of material depicting sexually explicit acts or indecent acts, which would include non-consensual deepfake pornography, even if not explicitly stated as such (the law refers to recorded material rather than content generated). Section 69A requires the government to issue directions for blocking access to any information on the internet, and Section 79 creates safe harbour for intermediaries who fulfil the due diligence requirements.
B. The IT Rules, 2021, and the 2023 tweak
The Intermediary Guidelines and Digital Media Ethics Code Rules, 2021 mandated for platforms to take down content when impersonation complaints were received. The amended 2023 rules added "morphed images"to the list. Though helpful, a takedown requirement does not constitute a crime, and only applies once someone has seen the post and taken action to report it, by which time the video has already gone viral.
C. The 2026 Amendment Rules — where things shifted
This is where the framework gains its teeth. The Amendment Rules, notified through G.S.R. 120(E) provide for the formalities of synthetically generated information, directing such ‘significant platforms’ to carry a visible ‘label running through the whole’ of the content rather than just the beginning image, and obliging them to retain the ‘metadata indicating the source of the content’ to trace its origin. For content ‘that falsely depicts a readily identifiable individual,’ the notice period for take down by the platforms has been drastically cut, perhaps to two hours, thereby significantly limiting their safe harbour. The onus is on the platforms to integrate detection capabilities, given that they have the ability to do so. Industry groups, however, argue that this creates “advisories that have the effect of law without parliamentary oversight”, and the debate over this is not over.
D. The Bharatiya Nyaya Sanhita, 2023
On the criminal law side, prosecutors can rely on BNS, which replaces the old Indian Penal Code from July 2024. IPC 319 punishes cheating by personation, which includes using identity cards of persons dead or fictitious. IPC 336 covers forgery, including forging electronic data to cheat or scandalize public morality. IPC 353 criminalizes spreading rumours that could lead to public mischief, which includes politically motivated deepfakes, and IPC 111, the organized crime law, has already been used to go after deepfake fraud gangs.
It is noteworthy that none of the above clause’s mention “deepfake” or even “AI”. The laws are being interpreted in a way that would cover deepfake-related crimes, but the Supreme Court is pushing for legislation that will specifically mention deepfakes, as it is projected that deepfake-facilitated fraud, like the digital arrest scam, has already cost Indians billions of rupees in the last several years.
E. The Digital Personal Data Protection Act, 2023
The DPDP Act does not explicitly refer to deepfake either, but it governs the creation of any synthetic image based on an individual’s biometric or personal information without the subject’s consent. In cases where such data is obtained through unauthorized means, the victim can turn to the DPDP provisions regarding consent. This issue has little jurisprudence to date, and the few cases that have arisen are still pending resolution.
F. Courts stepping in where legislation hasn't
Where statute books have been slow to act, the Delhi and Bombay High Courts have swiftly jumped in, taking inspiration from English common law principles of personality rights to protect their jurisdictions’ celebrities from being impersonated by artificial intelligence. In Anil Kapoor v. Simply Life India, the Delhi High Court restrained use of the plaintiff’s name, voice, and catchphrase “Bol na Bol” in connection with AI programs and face morphing apps. The “John Doe” order also applied to unnamed defendants, and was issued shortly after a similar order in Amitabh Bachchan v. Rajat Nagi one year prior. Protections for personality rights in India have since been extended to Jackie Shroff, Aishwarya Rai Bachchan, and Karan Johar, with Bombay High Court granting similar relief to Akshay Kumar and Arijit Singh, also in the context of voice cloning. All of these are currently civil court actions, which deal primarily in injunctive relief.
IV. WHERE THIS STILL FALLS SHORT
Despite the 2026 changes, the lacunae in the law are still evident, as the legislation remains fragmented and overlapping, requiring a victim of deepfake-enabled damage to identify which statute, targeting a completely different harm, would be applicable in their case. The rules only regulate the actions of online platforms when dealing with already existing AI-made content, not establishing a separate offence of generating malicious deepfake media, thus leaving the prosecutors with cheating, forgery, and personation statutes, which were not designed to address synthetic media. Celebrity rights cases, on the other hand, may be complicated by the fact that the personality right litigation only protects individuals with sufficient “reach and public profile,” making the non-celebrity plaintiff’s case more challenging, as there is no recognized right of publicity in India that would be available for all. Additionally, a problem of detection is a crucial issue around the implementation of the new rules; the labelling of the AI-generated content is only useful if courts have the expert knowledge to distinguish synthetic media from real content. Finally, the new rules risk stifling free speech and satire if the government manages to utilize the ambiguity of the rules to pressure the creators of synthetic content into labelling all deepfake media, not just the defamatory ones.
V. WHAT'S STILL MISSING
A dedicated law criminalizing the malicious creation of synthetic media with due penalties for causing damage proportional to the harm entitled would be an improvement over the current recycled IPC laws. Creation of a civil right allowing every individual to claim damages for unauthorized use of their image would also help, as the current laws only somewhat protect the celebrities. The ability of law enforcement to detect violations is just as important, as a right that cannot be enforced is not worth much. Finally, any law needs to account for satire and journalism by providing exceptions, lest it becomes a censorship tool.
VI. CONCLUSION
India has evolved significantly in its efforts to address the challenges posed by synthetic media in just over three years. The country has progressed from near-total inaction to implementing labelling requirements, shortened takedown procedures, adjusted criminal legislation, and an increasing number of court orders protecting personality rights. While this is a considerable achievement, it only partially addresses the issue. To hold the victims of deepfake abuse in India fully protected, legislative measures should be taken to harmonize data protection laws, criminal legislation, and the jurisdiction over liability as well as provide all individuals with accessible remedies. At present, until a law specifically criminalizing the creation of deepfake media is passed in India, the problem will remain only partially addressed.
VII. REFERENCES
1. Information Technology Act 2000, ss 66C, 66D, 66E, 67, 67A, 69A, 79.
2. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, as amended by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2023.
3. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026, GSR 120(E) (10 February 2026).
4. Bharatiya Nyaya Sanhita 2023, ss 111, 319, 336, 353.
5. Digital Personal Data Protection Act 2023.
6. Anil Kapoor v Simply Life India & Ors, 2023 SCC Online Del 6914.
7. Amitabh Bachchan v Rajat Nagi & Ors, 2022 SCC Online Del 4110.
8. Justice K S Puttaswamy (Retd) v Union of India (2017) 10 SCC 1.
AUTHOR(s): Isha Kumari, BBA.LL.B graduate from ITM University, intern at The Legal Lock
More to Read
DATA FIDUCIARY LIABILITY UNDER THE DPDP FRAMEWORK
blogs
High-Performance Hub: Streamlining Law Firm Intake
blogs
AI AND FACIAL RECOGNITION: PRIVACY VS. PUBLIC SECURITY
blogs
The Corporate Secrets That Leave Thousands Broken: Inside the Mass Tort Battles You Never Hear About
blogs
Handcuffing of Arrested Persons in India: A Critical Constitutional and Human Rights Analysis
blogs
DOES INDIA NEED A COMPREHENSIVE AI REGULATION ACT?
blogs