Artificial Intelligence (AI) has enabled the creation of highly realistic synthetic content, commonly known as deepfakes, including manipulated audio, video, images, and text. While AI offers immense opportunities, deepfakes pose serious challenges such as identity theft, misinformation, financial fraud, privacy violations, electoral manipulation, and cybercrime.
Recognizing these threats, the Government of India has strengthened its legal and regulatory framework to ensure a safe, trusted, accountable, and open cyberspace, particularly through amendments to the Information Technology Rules in 2026.
What are Deepfakes?
Deepfakes are AI-generated or AI-manipulated digital content that imitates the appearance, voice, or actions of real individuals, making fake content appear authentic.
Major Risks
- Identity theft
- Online impersonation
- Financial fraud
- Spread of misinformation and disinformation
- Non-consensual intimate imagery
- Child sexual exploitation
- Damage to reputation
- Threats to national security and public order
Existing Legal Framework Against Deepfakes
1. Information Technology Act, 2000
The IT Act provides several legal provisions applicable to AI-generated unlawful content.
Important Sections
Section 43
- Penalty and compensation for damage to computer systems.
Section 66
- Punishment for computer-related offences.
Section 66C
- Identity theft.
Section 66D
- Cheating by impersonation using computer resources.
Section 66E
- Violation of privacy.
Sections 67 & 67A
- Publishing or transmitting obscene or sexually explicit content.
Section 69A
- Blocking access to unlawful online information.
Section 79
- Removal of unlawful information by intermediaries.
Sections 78 & 80
- Investigation powers for police authorities.
2. Bharatiya Nyaya Sanhita (BNS), 2023
The BNS also provides criminal penalties relevant to deepfake-related offences.
Key Provisions
Section 319
- Punishment for cheating by personation.
Section 336
- Punishment for forgery, including false electronic records.
Section 353
- Penalizes false statements, rumours, and misinformation causing public mischief.
Section 111
- Covers organised cybercrime involving deepfake content.
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
The IT Rules impose due diligence obligations on intermediaries.
Users are prohibited from sharing content that:
- Belongs to another person without authorization
- Is obscene or pornographic
- Invades privacy
- Promotes hate or violence
- Harms children
- Infringes intellectual property rights
- Misleads users regarding the origin of messages
- Spreads misinformation
- Impersonates others through AI
- Threatens national security or public order
- Violates any applicable law
Intermediaries must clearly inform users about penalties such as content removal, account suspension, or account termination for violating these rules.
Additional Obligations for Significant Social Media Intermediaries (SSMIs)
Platforms with 50 lakh or more registered users in India must:
- Assist law enforcement in tracing originators of serious messages.
- Deploy automated tools to detect unlawful content.
- Publish periodic compliance reports.
- Appoint grievance officers and compliance officers in India.
- Offer voluntary user verification.
- Provide appeals and fair hearing mechanisms.
Grievance Redressal Mechanism
Every intermediary must appoint a Grievance Officer.
If users are dissatisfied, they can appeal before the Grievance Appellate Committee (GAC).
Police investigations are conducted by State and Union Territory law enforcement agencies since Police and Public Order are State subjects under the Constitution.
Major 2026 Amendments to IT Rules
On 10 February 2026, the Government significantly strengthened regulations relating to AI-generated content.
1. Mandatory AI Content Labelling
Platforms must ensure:
- Clear labels for AI-generated content.
- Traceable metadata.
- Easy identification of synthetic content.
2. Stronger User Accountability
Platforms must educate users regarding legal consequences of unlawful AI-generated content.
3. Expanded Protection
The amendments specifically address:
- Child sexual abuse material
- Non-consensual intimate imagery
- AI-based impersonation
- Other harmful synthetic content
4. Faster Content Removal
Timeline reduced:
- Removal of unlawful content: from 36 hours to 3 hours
- General grievance resolution: from 72 hours to 36 hours
- Sensitive grievances (nudity/impersonation): from 24 hours to 2 hours
5. Mandatory Technical Measures
Intermediaries must deploy:
- Automated detection tools
- Other suitable technological mechanisms
to prevent unlawful AI-generated content.
6. Proactive Detection
SSMIs must proactively identify content depicting:
- Rape
- Child sexual abuse
- Previously removed unlawful content
Failure to comply results in loss of Section 79 safe harbour protection, making intermediaries liable under applicable laws.
AI Governance Framework
India follows a balanced and risk-based approach toward AI governance.
The India AI Governance Guidelines, released on 5 November 2025, promote:
- Safe AI
- Trusted AI
- Responsible AI
- Proportionate regulation
rather than blanket restrictions.
IndiaAI Mission
The Safe & Trusted AI pillar under the IndiaAI Mission promotes indigenous AI governance, standards, evaluation mechanisms, and responsible deployment.
Approved Deepfake Detection Projects
- Saakshya (IIT Jodhpur & IIT Madras)
- AI Vishleshak
- Real-Time Voice Deepfake Detection System (IIT Kharagpur)
Institutional Mechanisms
Grievance Appellate Committees (GACs)
Provide appellate review against intermediary decisions.
Takedown Notices
Governments may direct intermediaries to remove unlawful content through valid legal processes.
Indian Cyber Crime Coordination Centre (I4C)
Coordinates cybercrime investigations nationwide.
SAHYOG Portal
Provides centralized automated removal notices to intermediaries.
National Cyber Crime Reporting Portal
Citizens can report:
- Deepfakes
- Cyber fraud
- Content misuse
The cybercrime helpline 1930 is also operational.
Police
Investigate offences under applicable laws.
Samanvaya Platform
Supports interstate cybercrime investigations using analytics-based criminal linkages and the Pratibimb module.
Government Advisories
The Government has issued:
- Advisory on responsible handling of religious information (9 February 2026)
- Advisory against abusive and misleading AI-generated information (16 March 2026)
- Standard Operating Procedure (2025) for tackling Non-Consensual Intimate Imagery (NCII)
Public Awareness Measures
Awareness campaigns include:
- National Cyber Security Awareness Month
- Safer Internet Day
- Swachhta Pakhwada
- Cyber Jagrookta Diwas
CERT-In also regularly publishes advisories and awareness material on deepfake threats and cybersecurity.
Conclusion
The Government’s strengthened regulatory framework reflects a shift from merely reacting to unlawful AI-generated content toward proactive governance. By mandating AI content labelling, reducing takedown timelines, enhancing intermediary accountability, promoting indigenous AI governance, and strengthening cybercrime coordination, India seeks to balance technological innovation with user safety and legal accountability in the age of artificial intelligence.
Summary: Quick Revision Notes
Key Highlights
- AI-generated deepfakes regulated through IT Act, BNS, and IT Rules.
- Mandatory AI content labelling introduced.
- Traceable metadata required.
- Unlawful content removal timeline reduced: 36 hrs โ 3 hrs.
- Sensitive grievance disposal: 24 hrs โ 2 hrs.
- Automated AI detection tools made mandatory.
- SSMIs required to proactively detect unlawful AI-generated content.
- Non-compliance leads to loss of safe harbour under Section 79.
- IndiaAI Mission supports indigenous deepfake detection research.
- Key institutions: GAC, I4C, SAHYOG Portal, CERT-In, National Cyber Crime Reporting Portal, Samanvaya Platform.
Reference: PIB