Published On: August 22, 2026
Authored By: Muskan Pandey
University of Allahabad
Abstract
A court is only likely to decide a deepfake case once the damage has already been done. For the past four years, India has assembled its response to that problem out of spare parts: a doctrine of privacy borrowed from a 2017 constitutional decision, a handful of Bollywood injunctions, and an intermediary-liability rulebook rewritten twice within sixteen months. This article traces both paths — the judicially created right to personality and the regulator’s law of platform takedowns — and identifies what both still miss: everyone who is not famous.
I. Introduction
India has no law that defines a deepfake, no right of publicity, and no general AI statute. What it has instead is a series of High Court injunctions against AI impersonation of film stars, and an intermediary-liability regime that regulators updated twice in the sixteen months since October 2025 to keep pace with generative AI. Common law and delegated rule-making can move fast, and here they have. But two narrow tracks are not the same as full coverage, and neither was built with the other in mind.
This article examines both tracks. Part II deconstructs the personality-rights doctrine that courts have built with little support from legislation. Part III outlines the regulatory side, including Section 79 of the Information Technology Act — the safe-harbour provision — and its amendments in 2021, 2025, and 2026. Part IV asks whether the new takedown rules actually work. Part V turns to what neither track reaches: AI-enabled fraud and its unsung victims. Part VI proposes remedies.
II. Personality Rights: A Doctrine Built by Injunction
There is no statutory definition of personality rights under Indian law. The doctrine has been built entirely by the courts, drawing on the constitutional right to privacy.[1] With each new case, courts have extended it — from protecting a name and likeness against unauthorised merchandising, to protecting voice, mannerisms, and AI-generated replicas.
The Delhi High Court in Amitabh Bachchan v. Rajat Nagi protected the actor’s name against unauthorised commercial use, including through AI tools, and subsequent orders have followed that precedent. Anil Kapoor v. Simply Life India[2] went further, restricting both the use of AI to morph the actor’s likeness and derogatory deepfakes of him, while carving out an exception for satire, since Article 19(1)(a) must still carry some meaning. In Jaikishan Kakubhai Saraf v. Peppy Store,[3] the court banned an AI chatbot that mimicked an actor’s persona by synthesising his voice alone, without requiring any video or audio clip of him to appear. Arijit Singh v. Codible Ventures LLP[4] is the most significant case in this line and is widely regarded as India’s first ruling on voice cloning: the Bombay High Court held that a singer’s voice and vocal style are protected, and that offering the public a tool that could extract a voice from any recording and generate a clip in his name, without consent, infringed his right to commercially exploit his persona — regardless of whether the resulting clip was itself defamatory.[5]
These cases share two conditions, and those conditions mark the doctrine’s outer limits: the plaintiff must be established, and the use must be commercial. A private individual whose face appears in a non-consensual deepfake made not for profit but for harassment fits neither box. Part V returns to this gap.
III. The Regulatory Track: Safe Harbour Under Pressure
A. Section 79
Section 79 of the Information Technology Act, 2000, shields platforms from liability for content uploaded by their users, subject to specified due-diligence obligations and to platforms acting on “actual knowledge” of illegal content or a government directive.[6] That provision has been the foundation of nearly everything built around Indian platform regulation, which is why it is now being updated for the age of AI.
B. Two Amendments, Sixteen Months Apart
Regulators changed the intermediary rules twice in quick succession. The 2021 Intermediary Guidelines first introduced structured obligations — grievance officers, response windows, and traceability for large platforms — layered on top of Section 79.[7] Then, as deepfake-enabled fraud grew through 2024 and 2025, MeitY moved to bring AI-generated content within that framework. In October 2025, the Guidelines were amended to define “synthetically generated information” (SGI) — content artificially generated or modified to appear real — and to require any platform offering generation tools to label content created or modified with them.[8]
A second amendment, notified on 10 February 2026 and effective ten days later, went further still. An earlier proposal for a fixed watermark covering ten percent of the frame was replaced with a more flexible standard requiring labels to be “prominent and noticeable,” tied to permanent, traceable metadata identifying the service that created the content.[9] The amendment also compressed the takedown clock sharply: content identified by a court order or an authorised government notice must now be removed within two to three hours, down from thirty-six hours under the earlier rules. Miss that window, and a platform can lose safe-harbour protection entirely and face civil and criminal liability.
One change matters more than it first appears. If a platform has, or should have, the technical capacity to detect illegal synthetic content and fails to deploy it, it can now be treated as having constructive knowledge of that content — enough to defeat the safe harbour. That is a marked shift from the earlier standard, under which only actual knowledge triggered liability.[10]
IV. Does the New Regime Actually Work?
MeitY’s case is straightforward: a thirty-six-hour review cycle was never built for a voice-cloned scam call or a non-consensual deepfake, both of which do most of their damage within minutes of upload. Compressing that window to hours, while raising the bar to constructive knowledge, is proportionate to how fast the harm moves. The change has been paired with a lighter-touch instrument, the November 2025 India AI Governance Guidelines, which regulate the output of AI systems without touching the systems themselves.[11]
Not everyone agrees. Digital-rights advocates and platforms argue that a two-to-three-hour window, enforced across a user base of hundreds of millions, pushes companies toward automated “pre-emptive filtering” — and that automated filters misclassify satire, journalism, and legitimate artistic uses of synthetic media as impersonation. The constructive-knowledge standard compounds this: if a platform can be held liable simply for failing to deploy detection software regulators believe it should have deployed, the safer strategy becomes removing content first and litigating its legality later.
The contrast with Europe is instructive. The EU’s AI Act targets synthetic media upstream, regulating the AI systems used to create it and imposing transparency obligations on the companies that build generative models.[12] India’s 2026 Rules address only the downstream content and the platform hosting it, leaving the developers of voice-cloning and face-swap tools largely unsupervised — part of why the pending Digital India Act and a private AI-ethics bill aim to intervene, eventually.
No one in this debate disputes that AI impersonation carries real-world consequences. The live question is whether faster takedowns and a tougher knowledge standard help or hinder that goal, and whether they shift compliance responsibility from platforms to tool makers, who are harder to reach.
V. What Neither Track Reaches
A. Fraud
Voice cloning has become a tool for financial crime faster than regulation can track it. In “digital arrest” scams, fraudsters pose as law-enforcement or court officials, threatening to arrest or charge a victim’s family member unless they comply. With cloned voices, scammers now pose as relatives seeking urgent help from people with no way to verify that the caller is who they claim to be. Prosecutors invoke the IT Act’s provisions on cheating by personation and identity theft, alongside the impersonation and cheating provisions of the Bharatiya Nyaya Sanhita.[13] The difficulty is proving intent: content created for “entertainment” or “research” can almost always be redirected to another purpose, and the celebrity-injunction cases sidestep this problem entirely — they involve commercial use against a known plaintiff, not criminal use against an anonymous one.
B. Everyone Who Isn’t Arijit Singh
The Arijit Singh and Anil Kapoor cases succeeded because they cleared a high threshold: an established, clearly identifiable, commercially exploitable persona. Most deepfake victims clear none of that. There is no equivalent doctrine for a private individual whose image is used to create non-consensual synthetic sexual content — only the general provisions on obscenity, defamation, and identity theft, plus the narrower non-consensual-content provisions the 2026 Rules added. On the platform-facing side, India has made real progress. What is still missing is a standalone statute that extends identity protection to everyone, not just the well-known, and the forensic infrastructure to distinguish a real clip from a fabricated one in court.
C. The Law Above Both Tracks
There is a still larger gap above both the case law and the intermediary rules: how these AI systems are developed and trained in the first place. The Digital India Act, intended to eventually replace the IT Act, remains in consultation. A private member’s bill on AI ethics, introduced in December 2025, signals Parliament’s interest in the question.[14] Until one of these passes, India’s response to generative AI will remain a patchwork of privacy doctrine, passing-off law, and platform rules — none of it written with this problem in mind.
VI. What Would Actually Close the Gap
Closing the gap means rethinking the problem from a different angle. Everyone should have a baseline identity right, not just celebrities, so that a non-consensual deepfake is actionable on its own terms, without first proving a commercial persona. Takedown windows should vary by harm — shorter for non-consensual sexual content, more deliberate review for satire and political speech. Obligations should extend to the creators of voice-cloning and face-swap technology, not just the platforms hosting the results, something a system-level approach like the EU’s addresses and India’s content-only rules do not. And courts need independent forensic capacity to confirm AI-generated evidence, rather than relying on AI classifiers of uncertain accuracy.
VII. Conclusion
India has responded to generative AI quickly on two narrow fronts: courts that moved within days to protect a film star, and a ministry that rewrote its platform rules twice within sixteen months. The question was never whether Indian law can move fast when Bollywood and big platforms are involved — it clearly can. The open question is whether that same speed, protection, and accountability will ever extend to the tool makers, and to the people who have no name at all.
References
[1] Amitabh Bachchan v. Rajat Nagi, CS(COMM) 819/2022 (Del. H.C. Nov. 25, 2022) (India).
[2] Anil Kapoor v. Simply Life India, 2023 SCC OnLine Del 6914 (India).
[3] Jaikishan Kakubhai Saraf v. Peppy Store, CS(COMM) 685/2024 (Del. H.C. 2024) (India).
[4] Arijit Singh v. Codible Ventures LLP, 2024 SCC OnLine Bom 2445, ¶ 41 (India).
[5] Id. ¶¶ 36–39.
[6] Information Technology Act, No. 21 of 2000, § 79, India Code (2000).
[7] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, G.S.R. 139(E) (Feb. 25, 2021) (India).
[8] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2025, G.S.R. 782(E) (Oct. 22, 2025) (India).
[9] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, G.S.R. 120(E) (Feb. 10, 2026) (India) [hereinafter 2026 Amendment Rules]; id. r. 3(1A).
[10] See Shardul Amarchand Mangaldas, Client Alert: IT Rules Amendment, 2026 (Feb. 2026) (India), discussed in India Policy Hub, AI Content Moderation Rules in India: The 2026 Definitive Compliance Guide (May 18, 2026).
[11] Ministry of Electronics & Info. Tech., Gov’t of India, India AI Governance Guidelines (Nov. 2025).
[12] Council Regulation 2024/1689, Artificial Intelligence Act, 2024 O.J. (L 1689) (EU).
[13] Bharatiya Nyaya Sanhita, No. 45 of 2023, §§ 318, 319, India Code (2023) (personation and cheating provisions).
[14] AI (Ethics and Accountability) Bill, 2025 (Private Member’s Bill) (India) (pending).




