AI-Generated Deepfakes in India: What Does the Law Say? (2026 Guide)

If you’ve scrolled through Instagram or WhatsApp in the last year, chances are you’ve already seen one — a “celebrity” endorsing a crypto scheme they never touched, a politician “saying” something they never said, or a cloned voice on a phone call demanding money from a panicked relative. AI-generated deepfake laws in india have moved from novelty to nuisance to genuine national security concern in India, and the law has finally started catching up.

This guide walks through exactly what the law says about deepfakes in India in 2026 — from the brand-new IT Rules amendment to the older criminal provisions still doing much of the heavy lifting, the penalties involved, and what to do if you or someone you know becomes a target.

AI-Generated Deepfake laws in India (2026 Guide)
Confused about deepfake laws in India? This 2026 guide breaks down the new IT Rules, deepfake IT Act sections, BNS provisions, penalties, and how to report a deepfake — in plain English.

What Counts as an AI-Generated Deepfake?

A deepfake is any audio, image, or video that has been created or manipulated using AI so convincingly that it appears to show a real person doing or saying something they never did. Common categories include:

  • Face-swapped videos — someone’s face mapped onto another person’s body
  • Voice cloning — AI-generated audio mimicking a specific person’s voice, often used in “digital arrest” or extortion scams
  • Synthetic political content — fabricated speeches or statements designed to mislead voters
  • Non-consensual intimate imagery (NCII) — sexually explicit content generated without consent
  • Forged documents or identity material — AI-altered images used for fraud

Indian law now has an official label for all of this: “synthetically generated information” (SGI), defined for the first time under the 2026 amendment to the IT Rules.

READ MORE Can an FIR Stop Passport You From Travelling Abroad? A Complete Guide to Immigration & Criminal Cases

For years, India had no law that used the word “deepfake laws in india.” Prosecutors had to stitch together a case using tools built for an entirely different era — mostly aimed at document forgery, obscenity, or garden-variety online fraud. This patchwork approach created real problems: defendants could claim their deepfake was made “for entertainment” or “fan content,” which muddied the intent requirement that older forgery laws demand.

The gap became impossible to ignore after a string of high-profile incidents — most famously the November 2023 case involving actress Rashmika Mandanna, whose face was superimposed onto another woman’s body in a viral video. The creator, later traced to Andhra Pradesh, said he had done it purely to gain social media followers. Cases like this exposed how existing law struggled to keep pace with generative AI.

The Big Change: IT Amendment Rules, 2026

On 10 February 2026, the Ministry of Electronics and Information Technology (Meity) notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, which came into force on 20 February 2026. This is India’s first dedicated regulatory framework built specifically around AI-generated and synthetic content, and it’s the single most important thing to know if you’re researching deepfake laws in India today.

Here’s what it actually does:

1. It legally defines “Synthetically Generated Information”

SGI now covers any audio, visual, or audiovisual content that has been algorithmically created or altered to the point that a reasonable viewer could mistake it for authentic, real content. This gives courts and regulators a clear statutory hook that simply didn’t exist before.

2. Mandatory labelling and provenance metadata

Platforms and creators must attach a visible label identifying AI-generated content as synthetic, along with permanent provenance metadata that traces where and how it was made. Several major platforms have already begun rolling out “Made with AI” style tags in response.

3. Dramatically shortened takedown timelines

Instead of the earlier general 36-hour window, the rules introduce a tiered takedown system:

  • The most harmful content — non-consensual sexually explicit deepfakes impersonating a real person — must come down within roughly 2–3 hours of a valid complaint
  • Other intimate-imagery complaints get up to 36 hours
  • General SGI complaints must be addressed within about 7 days

4. Safe harbour is now conditional on real compliance

Intermediaries that fail to implement “reasonable and appropriate technical measures” — not just make an “endeavour,” as the old wording allowed — risk losing the safe harbour protection under Section 79 of the IT Act that has shielded platforms from liability since 2000. That’s a major shift in incentives for every social media company operating in India.

5. New due diligence obligations

Platforms must periodically warn users about the legal consequences of creating or sharing prohibited deepfakes, deploy filtering and detection technology, and cooperate with law enforcement and an emerging independent review mechanism designed to prevent misuse of takedown powers.

The Criminal Law Toolkit: What Still Applies

The 2026 Rules regulate what platforms must do after deepfake content exists — they don’t, by themselves, create a brand-new criminal offence for making one. So the older criminal provisions are still doing a lot of work, especially in fraud and impersonation cases like the “digital arrest” scams that have hit thousands of Indians. These include:

Under the IT Act, 2000:

  • Section 66C — identity theft (up to 3 years imprisonment + fine)
  • Section 66D — cheating by personation using a computer resource
  • Section 66E — capturing or publishing images of a person’s private area without consent
  • Sections 67, 67A, 67B — publishing or transmitting obscene, sexually explicit, or child sexual abuse material in electronic form

Under the Bharatiya Nyaya Sanhita (BNS), 2023 (which replaced the IPC):

  • Section 356 — criminal defamation, often invoked when a deepfake is designed to damage someone’s reputation
  • Section 77 — voyeurism, covering unauthorised capture or circulation of intimate images
  • Provisions on forgery, cheating, and extortion, which prosecutors increasingly stretch to cover voice-cloning fraud

The Digital Personal Data Protection Act, 2023 (DPDP Act): Rather than governing content directly, this operates alongside the IT Rules to regulate how personal data — including biometric data like a person’s face or voice — can be processed, adding another layer of exposure for anyone misusing someone’s likeness.

The catch, as India’s Supreme Court has itself pointed out, is that these provisions were written for a pre-AI world. Forgery law requires proving “intent to cause damage,” and a defendant claiming the content was for “entertainment” can genuinely complicate a prosecution. This is part of why legal experts continue to push for a dedicated, deepfake-specific criminal statute — something India doesn’t yet have, even after the 2026 amendment.

Civil Remedies: Personality Rights and Injunctions

Alongside criminal law, Indian courts have increasingly recognised personality rights — an individual’s right to control the commercial use of their name, image, voice, and likeness — as a basis for civil action against deepfakes. Public figures and private individuals alike have successfully obtained interim and permanent injunctions against websites and individuals circulating unauthorised synthetic content, along with remedies like damages, account of profits, and orders to hand over infringing material.

What This Means If You’re a Creator, Business, or Platform

  • Content creators using generative AI tools should label synthetic content clearly — platforms can now flag or remove unlabelled AI content on their own.
  • Businesses face board-level exposure: brand misuse, deepfaked executive statements, and synthetic customer complaints can all trigger liability under advertising, data protection, and corporate governance rules simultaneously.
  • AI tool providers operating in India should build in default output labelling and be ready to cooperate with law enforcement requests.
  • Individuals targeted by a deepfake — especially intimate imagery or voice-cloning fraud — now have a much faster takedown route than before, alongside the older criminal and civil options.

How to Report a Deepfake in India

  1. Take screenshots/screen recordings of the content, including the URL, before it’s taken down.
  2. File a complaint on the National Cyber Crime Reporting Portal (cybercrime.gov.in) or call the 1930 cybercrime helpline.
  3. Report directly to the platform using its grievance officer mechanism — under the 2026 Rules, platforms must act within hours for the most serious categories.
  4. Approach the local cyber cell or police station to register an FIR, particularly for fraud, extortion, or sexually explicit content.
  5. Consult a lawyer about civil remedies (injunctions, damages) if reputational or financial harm is significant.

Conclusion

India’s approach to AI-generated deepfake laws in india has shifted from a patchwork of borrowed provisions to a more structured, if still incomplete, legal regime. The IT Amendment Rules, 2026 finally give regulators and platforms a clear definition of “synthetically generated information,” faster takedown timelines, and real consequences — including loss of safe harbour — for platforms that don’t comply. At the same time, the criminal provisions under the IT Act and BNS, along with civil personality-rights remedies, remain essential tools for holding individual creators and fraudsters accountable.

What’s still missing is a dedicated, deepfake-specific criminal statute — something legal experts and even the Supreme Court have flagged as the next logical step. Until that arrives, the safest approach for creators, platforms, and everyday users alike is the same: label AI content honestly, know your rights if you’re targeted, and act fast, since speed is now built directly into the law itself. As deepfake technology keeps evolving, expect this legal framework to keep evolving with it — so it’s worth revisiting this space every few months rather than treating any single rule as the final word.

READ MORE AI Deepfake Laws in India 2026: 3 Hour Takedown Rule Explained

Leave a Reply

Your email address will not be published. Required fields are marked *

To Top