DEEPFAKES AND PERSONALITY RIGHTS: BEYOND COMMERICAL EXPLOITATION TO DIGITAL PERSONHOOD AND ARTICLE 21

Published on: 6th October 2026

Authored by: Taranveer Singh
Bhai Gurdas College of Law (affiliated with Punjabi University Patiala)

Abstract

The proliferation of Generative AI has transformed synthetically generated content from a technological novelty into an existential threat to personal identity.[1] This paper argues that conditioning personality rights solely on commercial value creates a dangerous “non-celebrity void,” leaving ordinary citizens vulnerable to severe personhood violations.[2] Through an evaluation of Indian legal provisions, this article exposes structural enforcement gaps in tackling deepfakes.[3] Drawing comparative insights from the European Union AI Act and state laws in the United States, it advocates for a paradigm shift in Indian jurisprudence—reassessing digital identity to protect individual autonomy under Article 21 of the Constitution of India while preserving legitimate expression and dissent.[4]

I. Introduction

Generative Artificial Intelligence has fundamentally altered the evidentiary value of digital media. Images and videos, historically relied upon in judicial proceedings and public discourse as objective proof, can no longer be assumed authentic.[5] India’s 2024 general elections highlighted this shift through the deployment of deepfake audio and synthetically resurrected deceased politicians in campaign broadcasts.[6] Concurrently, the proliferation of AI-generated Child Sexual Abuse Material (CSAM) underscores the severe risks posed by unmanaged synthetic media.[7]

These developments compel lawmakers to formulate regulatory mechanisms beyond traditional legal remedies.[8] Ensuring the authenticity, lawfulness, and cross-border traceability of synthetically generated content requires a calibrated institutional approach—one that safeguards privacy and personality rights without chilling legitimate dissent or free expression.[9] This paper examines the distinct legal challenges surrounding both the authenticity and the lawfulness of synthetically generated information.[10]

II. What Exactly is a Deepfake?

In general terms, a deepfake refers to synthetically altered or generated audio or visual content depicting individuals or events in a manner inconsistent with reality.[11] The Ministry of Electronics and Information Technology (MeitY) addressed this phenomenon by amending the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, designating deepfakes as “Synthetically Generated Information.”[12] The framework defines synthetic media as audio, visual, or audio-visual representations generated, altered, or modified using computer resources that appear authentic and indistinguishable from real events or individuals.[13]

The regulatory definition excludes modifications performed solely to enhance technical quality or routine editing that does not substantively alter content.[14] At a structural level, deepfakes capture essential components of human identity, including micro-expressions, vocal timbre, and biometric likeness.[15]

III. The Inadequacies of Law on Deepfakes

Current regulatory responses primarily focus on establishing technological provenance.[16] However, this approach often conflates two distinct inquiries: content authenticity and content lawfulness.[17] Under current trends in Indian jurisprudence, once content is deemed inauthentic, it is frequently presumed unlawful.[18] This conflation risks penalizing protected forms of expression—such as political satire, parody, and educational commentary—that rely on synthetic representation without deceptive intent.[19]

To address authenticity, mechanisms such as digital watermarking, provenance tracking, and mandatory “AI-generated” content labeling have been introduced.[20] However, determining lawfulness introduces subjective criteria, including audience perception and deceptive intent.[21] Existing statutory frameworks struggle to distinguish between malicious deception and legitimate commentary.[22] Furthermore, cross-border deepfake generation introduces jurisdictional challenges, particularly when content is designed to induce public disorder.[23] Addressing these issues requires targeted legislative action that balances privacy rights against constitutional freedoms.[24]

IV. The Indian Scenario

In the absence of standalone digital identity legislation, India’s regulatory response to deepfakes relies on a fragmented combination of cyber law, data privacy frameworks, and common law tort doctrines.[25] Amendments to the IT Rules require online intermediaries to deploy reasonable measures to prevent the hosting of unlawful synthetic content violating statutes such as the Bharatiya Nyaya Sanhita, 2023, and the Protection of Children from Sexual Offences (POCSO) Act, 2012.[26] Intermediaries are also mandated to label synthetic media and remove non-consensual or illegal content within specified timelines.[27] However, these rules focus primarily on platform compliance rather than establishing substantive enforceable rights over digital likeness for victims.[28]

The Digital Personal Data Protection Act, 2023 provides a statutory structure for processing personal data but explicitly excludes “publicly available data.”[29] Because many Generative AI models are trained on publicly accessible personal data, this exclusion creates a regulatory gap.[30] Additionally, penal provisions under the Bharatiya Nyaya Sanhita, 2023—including Section 318 (Cheating) and Section 356 (Defamation)—as well as privacy provisions under the Information Technology Act, 2000, function primarily post-facto and offer limited ex-ante preventive remedies.[31]

To address this legislative gap, Indian courts have relied on common law passing-off principles and “John Doe” (Ashok Kumar) injunctions.[32] In Anil Kapoor v. Simply Life India & Ors., the Delhi High Court recognized that an individual’s voice, image, name, and likeness constitute core personal attributes.[33] The Court held that commercial exploitation and unauthorized AI-generated depictions of a public figure’s persona infringe upon personality rights anchored in Article 21 of the Constitution.[34] However, because judicial relief in such cases remains tied to commercial value and endorsement interest, ordinary citizens—who lack commercial goodwill—remain largely unprotected against non-consensual synthetic impersonation.[35]

This commercial focus contrasts with the principles established in Justice K.S. Puttaswamy (Retd.) v. Union of India, where the Supreme Court affirmed that informational privacy and personal autonomy are fundamental rights guaranteed to every individual under Article 21, regardless of commercial or public status.[36] Resolving this constitutional gap requires transitioning from a commercial property framework to a dignity-based digital personhood model.[37]

V. Comparative Perspectives

International legal regimes offer alternative models for regulating synthetic media.[38] The European Union Artificial Intelligence Act addresses synthetic media through Article 50, which establishes mandatory transparency standards for providers and deployers of AI systems.[39] Articles 50(2) and 50(4) require AI-generated content to be marked in a machine-readable format to ensure provenance.[40] While Recitals 133 and 134 seek to balance transparency with freedom of expression, the Act relies on implementation by member states and does not directly establish private civil remedies for affected individuals.[41]

In the United States, several state statutes provide direct civil remedies for non-consensual synthetic depictions.[42] The Tennessee ELVIS (Ensuring Likeness Voice and Image Security) Act of 2024 expands traditional right-of-publicity protections to include voice cloning and AI-generated likenesses, establishing civil liability for platforms and software tools that enable unauthorized replication.[43] Similarly, California Civil Code § 1708.85 (enacted via Assembly Bill 602) provides a private right of action for victims of non-consensual synthetic explicit content.[44] These statutes establish enforceable remedies for individuals without requiring proof of commercial value.[45]

VI. Conclusion

The rapid expansion of Generative AI requires a re-evaluation of legal frameworks governing personal identity.[46] Relying solely on platform compliance obligations under the IT Rules or post-facto penal sanctions under the BNS remains insufficient to prevent harm caused by synthetic media.[47] To bridge this gap, India must transition toward a statutory framework that recognizes digital personhood under Article 21, establishing accessible preventive and civil remedies for all citizens regardless of commercial status.[48]

References

[1] Ministry of Electronics and Information Technology, Advisory on Synthetically Generated Information and Deepfakes, Government of India (2023).
[2] INDIA CONST. art. 21.
[3] Information Technology Act, No. 21 of 2000, INDIA CODE (2000).
[4] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act), 2024 O.J. (L 1689).
[5] Indian Evidence Act, No. 1 of 1872, INDIA CODE (1872).
[6] Election Commission of India, Advisory on Misuse of Generative AI and Synthetic Media in Election Campaigns (2024).
[7] Protection of Children from Sexual Offences Act, No. 32 of 2012, INDIA CODE (2012).
[8] Bharatiya Nyaya Sanhita, No. 45 of 2023, INDIA CODE (2023).
[9] INDIA CONST. art. 19, cl. 1(a).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top