Published on: 18th August 2026
Authored by: Soumya Samikshya Sahoo
SOA National Institute Of Law
Introduction
A deepfake is audio, video, or image content that has been created or altered in a way that makes it seem like a person is saying or doing something they never actually said or did. What started as an interesting concept in computer science has now become a widespread tool used for tricking people. India—with over nine hundred million internet users, a culture that highly values celebrity images, and a sensitive political environment—has become one of the most vulnerable regions in the world to this threat. In 2023, a fake video of actor Rashmika Mandanna was widely circulated, and more recently, a scam was built using synthetic video clips impersonating spiritual leader Sadhguru Jagadish Vasudev. These examples demonstrate how deepfakes can be weaponized for defamation, financial fraud, non-consensual intimate imagery, and political misinformation during elections.
Until recently, India lacked a specific statutory framework dedicated to deepfakes. Instead, victims and prosecutors relied on various general laws, such as the Information Technology Act, 2000,[1] the Bharatiya Nyaya Sanhita, 2023,[2] the Bharatiya Sakshya Adhiniyam, 2023,[3] the Digital Personal Data Protection Act, 2023,[4] the Copyright Act, 1957,[5] and constitutional guarantees under Articles 19 and 21.[6] This legal landscape evolved significantly in early 2026 when the Central Government introduced major amendments to the intermediary rules. For the first time, these rules clearly define and directly regulate “synthetically generated information.” This article explores whether this combination of general laws and new regulatory amendments is sufficient to tackle deepfakes or if dedicated primary legislation is still required.
Legal Analysis
The Pre-2026 Patchwork
Before 2026, Indian statutory law did not explicitly define or address deepfakes. Instead, legal liability was pieced together through general statutory provisions that were not originally designed for generative AI or synthetic media:
1. Information Technology Act, 2000: Identity theft and digital impersonation were addressed indirectly under Section 66C, while Section 66D governed cheating by personation using a computer resource.[7] Where deepfakes contained sexually explicit or obscene material, Sections 67 and 67A were invoked.[8]
2. Criminal Provisions: Under the Bharatiya Nyaya Sanhita, 2023, general criminal offences such as cheating, forgery, and criminal intimidation have been applied on a case-by-case basis against deepfake creators.[9]
3. Evidentiary & Data Rules: The Bharatiya Sakshya Adhiniyam, 2023 sets the evidentiary standards for admitting altered digital files in court, requiring strict proof of authenticity.[10] Additionally, the Digital Personal Data Protection Act, 2023 offers indirect recourse by treating unauthorized deepfake creation as unlawful processing of personal data.[11]
4. Copyright Act, 1957: Using an individual’s copyrighted work, image, or voice without authorization could constitute copyright infringement under Section 51.[12]
However, because none of these enactments were drafted with generative artificial intelligence in mind, they addressed only fragmented aspects of the broader deepfake challenge.
Constitutional Anchors
The regulatory debate is bounded by two fundamental constitutional rights:
* Article 19(1)(a): Guarantees freedom of speech and expression, protecting legitimate uses of synthetic media for artistic, satirical, or journalistic purposes.[13]
* Article 21: As interpreted in Justice K.S. Puttaswamy v. Union of India,[14] Article 21 protects individual privacy, personal dignity, and reputation, forming the constitutional basis for curbing the non-consensual exploitation of a person’s likeness.
Consequently, any regulatory regime governing deepfakes must maintain proportionality—curbing non-consensual harmful content without chilling legitimate creative expression.
The IT Rules 2026 Amendments: A Turning Point
A pivotal development occurred with the introduction of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (notified on 10 February 2026 and effective from 20 February 2026).[15] These rules formally defined “synthetically generated information” as content created, modified, or generated using artificial intelligence or automated software.
Under these regulations:
* Major social media intermediaries are required to prominently label synthetic content and embed traceable metadata.
* Platforms are mandated to prohibit users from removing or altering these embedded labels.
* Safe harbor protection under Section 79 of the IT Act, 2000 is conditioned upon proactive compliance, requiring intermediaries to remove harmful synthetic content (such as non-consensual intimate imagery) within expedited timelines.
Judicial Response
Indian courts have actively filled gaps in statutory law through judicial precedent:
1. Personality Rights: In Sadhguru Jagadish Vasudev v. Igor Isakov,[16] the Delhi High Court restrained unauthorized AI-generated content impersonating public figures for commercial gain, affirming personality rights as an effective civil remedy.
2. Free Speech Guardrails: The Supreme Court’s milestone ruling in Shreya Singhal v. Union of India[17] established that restrictions on online speech must be clear, precise, and narrowly tailored.
3. Electronic Evidence Standards: The admissibility of synthetic or altered media in judicial proceedings remains governed by strict certification standards set forth in Anvar P.V. v. P.K. Basheer[18] and clarified in Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal.[19]
Conclusion
India’s legal framework for deepfakes has evolved significantly—transitioning from reliance on legacy statutes governing identity theft and obscenity to a specialized regulatory regime that defines synthetic media, mandates metadata labeling, and enforces expedited takedowns. While this represents meaningful progress, the legal foundation remains grounded in a primary statute passed over two decades ago and reliant on subordinate executive rulemaking. A dedicated parliamentary statute explicitly addressing synthetic media—incorporating independent statutory oversight, direct civil remedies for non-public victims, clear exemptions for satire and journalism, and support for forensic detection—would offer a far more robust long-term solution.
Recommendations and Personal View
In my view, while India possesses multiple statutory avenues to address deepfake-related offenses, the current framework remains fragmented. The reliance on piecemeal provisions across the Information Technology Act, 2000, Bharatiya Nyaya Sanhita, 2023, Bharatiya Sakshya Adhiniyam, 2023, Digital Personal Data Protection Act, 2023, and Copyright Act, 1957 creates regulatory overlap and procedural delays for victims seeking immediate relief.
To effectively address the challenges of generative AI, India should introduce a unified, dedicated legislative framework that:
* Clearly defines deepfakes and distinguishes malicious exploitation from benign innovation.
* Imposes statutory duties on AI software developers and host platforms regarding digital provenance, labeling, and detection.
* Creates accessible, low-cost dispute resolution mechanisms for non-celebrity victims.
* Invests in law enforcement training and digital forensic infrastructure.
* Preserves constitutional protections under Article 19(1)(a) by safeguarding legitimate commentary, artistic expression, and political satire.
Ultimately, a balanced legal structure combining technical accountability, targeted statutory enforcement, and constitutional protection is essential to maintain public trust in the digital ecosystem while fostering responsible technological innovation.
References
[1] Information Technology Act, No. 21 of 2000, INDIA CODE (2000).
[2] Bharatiya Nyaya Sanhita, No. 45 of 2023, INDIA CODE (2023).
[3] Bharatiya Sakshya Adhiniyam, No. 47 of 2023, INDIA CODE (2023).
[4] Digital Personal Data Protection Act, No. 22 of 2023, INDIA CODE (2023).
[5] Copyright Act, No. 14 of 1957, INDIA CODE (1957).
[6] INDIA CONST. art. 19, cl. 1(a); art. 21.
[7] Information Technology Act, No. 21 of 2000, §§ 66C, 66D, INDIA CODE (2000).
[8] Information Technology Act, No. 21 of 2000, §§ 67, 67A, INDIA CODE (2000).
[9] Bharatiya Nyaya Sanhita, No. 45 of 2023, §§ 318, 336, INDIA CODE (2023).
[10] Bharatiya Sakshya Adhiniyam, No. 47 of 2023, § 63, INDIA CODE (2023).
[11] Digital Personal Data Protection Act, No. 22 of 2023, § 6, INDIA CODE (2023).
[12] Copyright Act, No. 14 of 1957, § 51, INDIA CODE (1957).
[13] INDIA CONST. art. 19, cl. 1(a).
[14] Justice K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1 (India).
[15] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, Gazette of India, Extraordinary, Part II, Section 3(i) (Feb. 10, 2026).
[16] Sadhguru Jagadish Vasudev v. Igor Isakov, CS(COMM) 124/2024 (Delhi HC) (India).
[17] Shreya Singhal v. Union of India, (2015) 5 SCC 1 (India).
[18] Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473 (India).
[19] Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1 (India).



