Published on: 18th August 2026
Authored by: Prajna Sarkar
Kirit P. Mehta School of Law (NMIMS)
ABSTRACT
In February 2026, India gave AI-generated content a statutory identity of its own.[2] The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 introduce the category of “Synthetically Generated Information” (SGI), tying an intermediary’s safe harbour under Section 79 of the Information Technology Act, 2000 to labelling, pre-publication verification, and takedown timelines as short as two hours.[2][3][10] This article maps that architecture and asks whether it withstands the proportionality standard Indian courts have applied since Shreya Singhal v. Union of India.[12] Reading the amendment alongside X Corp v. Union of India and Justice K.S. Puttaswamy v. Union of India, it argues that although the SGI regime responds to a genuine problem, its safe harbour framework may encourage excessive content removal, weakening the free speech safeguards developed by Indian courts.[12][16][18]
I. INTRODUCTION
For twenty-five years, India’s principal instrument for policing the internet, the Information Technology Act, 2000 (“IT Act”),[1] operated on a fairly simple premise: someone posts something, someone else complains, and the platform decides whether to take it down. This premise assumed that content was, in some basic sense, a photograph of an actual event or a video of a person actually speaking their own words. Generative artificial intelligence has quietly dismantled that assumption. Today, AI can create highly convincing fake videos and audio in minutes, for example, a chief minister appearing to endorse a fraudulent scheme or a father’s voice being used in a fake ransom call.
The government responded on 10 February 2026. The Ministry of Electronics and Information Technology (“MeitY”) notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (“2026 Amendment Rules”), amending the existing IT Rules, 2021.[2] For the first time, Indian law gives AI-generated content a legal name, “Synthetically Generated Information” or SGI, and builds real obligations around it, such as mandatory labelling, verification before content even goes live, and a takedown window as short as two hours for the worst kinds of harm.[3]
This article examines the new framework. It explains the requirements of the rules, evaluates their impact on intermediary liability, and considers whether the strict takedown timeline is compatible with the free speech principles established by Indian courts. My submission is a cautious one: the SGI regime responds to a real and worsening harm, but its safe-harbour-forfeiture design pushes so much adjudicatory power onto private platforms operating under such severe time pressure that it risks recreating the very over-removal problem Indian free speech law has spent a decade trying to prevent.[12]
II. LEGAL ANALYSIS
A. What the 2026 Amendment Actually Does
Rule 2(1)(wa) of India’s Information Technology (Intermediary Guidelines and Digital Media Ethics Code), inserted by the 2026 Amendment Rules, defines SGI as audio, visual, or audio-visual information that is artificially created, generated, modified, or altered using a computer resource, in a manner that makes it appear real, authentic, or true, in a way that is likely to mislead users into believing that it depicts a real person or an event.[4] The definition deliberately excludes routine and non-deceptive edits, camera filters, or accessibility tools which do not fabricate a real-world event.[5]
The rules divide intermediaries into two categories:
1. Synthetic Content Hosts & Generative Tools: Covers platforms that host SGI created by others or actively facilitate its creation, such as voice-cloning tools or AI image generators. These platforms are subject to stricter due diligence obligations, including the use of automated systems to detect four prohibited categories of content: child sexual abuse material and non-consensual intimate imagery, fake official documents, content related to the procurement of arms or explosives, and deceptive synthetic content that falsely portrays a real person as saying something they never did.[6]
2. Significant Social Media Intermediaries (SSMIs): Applies to platforms with more than five million registered users in India.[20] Under Rule 4(1A), such platforms can no longer wait for a complaint. Before uploading content, users must declare whether it is synthetic, and platforms must use reasonable technical measures to verify this declaration instead of relying solely on the user’s statement.[7]
Synthetic content that does not fall into a prohibited category is not banned; it simply has to be labelled and carry embedded metadata identifying its origin. Rule 3(3)(b) strictly prohibits online platforms from letting users modify, suppress, or remove mandatory labels and embedded metadata on AI-generated or synthetic content.[8] Furthermore, platforms are now required to remove content that impersonates a real person in a sexually explicit, defamatory, or violence-inciting manner within as little as two hours, instead of the previous 24 to 36 hours allowed under the 2021 Rules.[9]
B. The Safe-Harbour Bargain
These obligations would have little practical effect without a legal consequence for non-compliance. Section 79 establishes the “safe harbour” protection for online intermediaries such as social media platforms, internet service providers, and e-commerce websites.[10] It protects them from liability for third-party user-generated content, provided they act as neutral hosts and comply with prescribed due diligence requirements.[10] The 2026 Amendment Rules make compliance with the SGI framework a part of these due diligence obligations through the newly inserted Rule 2(1B).[11] As a result, platforms that comply with labelling, verification, and takedown requirements continue to enjoy safe harbour protection, whereas failing to comply puts them at risk of losing this protection and facing legal liability as if they had published the content themselves.[11]
India has used a similar legislative approach before. Section 79 has always been a conditional grant rather than an absolute one, and the 2021 Rules already tied safe harbour to due diligence obligations under Rule 3.[10] The new factor is the drastic reduction of the reaction time within which due diligence must be discharged, along with the fact that intermediaries can now lose safe harbour protection not only for failing to act on complaints about unlawful content but also for failing to properly verify AI-generated content through their own systems.[9][11]
C. Testing the Design Against Existing Jurisprudence (Case Study)
The Supreme Court’s judgment in Shreya Singhal v. Union of India remains the starting point for any inquiry into intermediary regulation in India.[12] The Court struck down Section 66A of the IT Act, 2000 because it was vague and overly broad.[12] More importantly, for intermediary liability, it interpreted Section 79(3)(b) and the 2011 Intermediary Guidelines to clarify that intermediaries are required to act only when they receive “actual knowledge” through a court order or a government notification issued under Section 69A, rather than removing content based on private complaints alone.[13] The Court was concerned that if intermediaries could lose safe harbour protection based on unverified complaints, they would prefer to remove content immediately rather than risk legal liability, leading to over-censorship of lawful content.[14]
The 2026 SGI regime raises the same concern identified in Shreya Singhal, but in a much more immediate form.[12] A platform operating under a two-hour window to determine whether a video is fabricated, created with intent to deceive, or is protected satirical speech must make complex factual and legal decisions under extreme time pressure.[9] This requirement increases the risk of false positives, as automated detection systems frequently misidentify lawful content.[15] Under the 2026 framework, failing to comply with deadlines risks forfeiture of safe harbour protection, creating strong incentives for platforms to aggressively remove content.[11]
The Karnataka High Court’s decision in X Corp v. Union of India (2025) adds another dimension to this debate.[16] In upholding the “Sahyog” portal, Justice M. Nagaprasanna held that the Supreme Court’s decision in Shreya Singhal was tied to the 2011 Intermediary Guidelines and did not automatically apply to the 2021 Rules.[16][17] If other courts adopt this approach, the 2026 SGI Amendment Rules may face fewer constitutional obstacles.[2] However, the central reasoning in Shreya Singhal was rooted in the structural incentives of the safe harbour framework itself.[12] Therefore, the constitutionality and proportionality of the two-hour compliance window under the SGI regime must be evaluated on its own merits.[9]
A second constitutional issue arises regarding the right to privacy under Justice K.S. Puttaswamy v. Union of India.[18] The 2026 Amendment Rules require platforms to verify metadata and maintain origin information for synthetic content.[7] In Puttaswamy, the Supreme Court held that state action affecting informational privacy must satisfy the tests of legality, legitimate aim, and proportionality.[19] While preventing deepfake-enabled fraud is a legitimate aim, imposing identical verification obligations on an individual posting an AI-edited photograph as on an organized group generating malicious deepfakes warrants careful scrutiny regarding proportionality.[7][20]
D. A Brief Comparative Note
Compared with other jurisdictions, India’s approach is considerably stricter:
1. European Union: The EU AI Act requires providers and users to label AI-generated content and comply with transparency requirements under Article 50 (effective August 2026), supported by a voluntary Code of Practice.[21] While non-compliance risks substantial fines, the EU framework does not require platforms to remove content within a fixed statutory time limit.[21]
2. United States: The federal TAKE IT DOWN Act requires covered platforms to remove non-consensual intimate images, including AI “digital forgeries,” within 48 hours of a valid victim request.[22] Outside this specific category, federal regulation of deepfakes remains fragmented across state laws.[23]
India’s SGI regime stands alone in requiring platforms to remove a broad range of harmful AI-generated content within a fixed two-hour statutory limit, while tying compliance directly to the retention of safe harbour protection.[9][11]
III. CONCLUSION
The 2026 Amendment Rules respond to a non-speculative, urgent challenge.[2] Digital arrest scams, non-consensual synthetic imagery, AI impersonations, and fabricated political speech demonstrate the limits of traditional, complaint-driven regulations. India’s initiative to establish a dedicated legal framework for Synthetically Generated Information is both justified and timely.[2]
The core constitutional challenge lies in the mechanism chosen. Linking intermediary safe harbour protection to mandatory verification obligations and a two-hour takedown timeline incentivizes platforms to censor content before adequately assessing its legality.[7][9][11] This risks recreating the over-removal concerns highlighted in Shreya Singhal.[12] Whether the SGI framework survives judicial scrutiny will depend on how Indian courts balance technological accountability against fundamental constitutional guarantees of free speech and privacy.[12][18]
REFERENCES
[1] Information Technology Act, No. 21 of 2000, INDIA CODE (2000).
[2] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, G.S.R. 120(E) (Feb. 10, 2026) (India), amending Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, G.S.R. 139(E) (Feb. 25, 2021) (India).
[3] Id. r. 3(3), r. 4(1A), r. 3(1)(d).
[4] Id. r. 2(1)(wa).
[5] Ministry of Electronics & Information Technology, Frequently Asked Questions on the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (2026) (India).
[6] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, r. 3(3)(a).
[7] Id. r. 4(1A).
[8] Id. r. 3(3)(b).
[9] Id. r. 3(1)(d).
[10] Information Technology Act, No. 21 of 2000, § 79, INDIA CODE (2000).
[11] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, r. 2(1B).
[12] Shreya Singhal v. Union of India, (2015) 5 SCC 1 (India).
[13] Id. ¶ 117 (reading down the “actual knowledge” standard under § 79(3)(b)).
[14] Id. ¶ 117.
[15] Regulating Synthetically Generated Information: India’s IT Rules Amendment of 2026, Lexology (Mar. 6, 2026).
[16] X Corp v. Union of India, 2025 SCC OnLine Kar 19584 (India).
[17] Id. ¶ 16.1 (holding that Shreya Singhal’s effect, insofar as it concerns intermediaries, is confined to the period governed by the IT Rules, 2011, since superseded by the IT Rules, 2021).
[18] Justice K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1 (India).
[19] Id. (Chandrachud, J., laying down the three-fold test of legality, legitimate aim, and proportionality for state measures touching informational privacy).
[20] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, r. 2(1)(v) (defining “Significant Social Media Intermediary” threshold).
[21] Regulation 2024/1689, of the European Parliament and of the Council of 13 June 2024 Laying Down Harmonised Rules on Artificial Intelligence, art. 50, 2024 O.J. (L 1689); European Commission, Code of Practice on Transparency of AI-Generated Content (June 10, 2026) (final version); AI Act Transparency Obligations: Code of Practice and Draft Guidelines, Lexology (June 2026).
[22] TAKE IT DOWN Act, Pub. L. No. 119-12, § 3, 139 Stat. 55, 58–60 (2025) (requiring covered platforms to remove nonconsensual intimate visual depictions, including AI-generated digital forgeries, within 48 hours of a valid request).
[23] See, e.g., Orrick, TAKE IT DOWN Act Becomes Law, Introducing Landmark Federal Protections to Combat Online Exploitation and Deepfakes (May 21, 2025) (noting that nearly forty U.S. states have enacted some form of legislation targeting online image-based abuse, with no uniform federal standard outside the narrow scope of the TAKE IT DOWN Act).



