Beyond Existing Cyber Laws: Rethinking India’s Legal Response to Deepfakes

Published on: 21st August 2026

Authored by: Srishti Keshri
Amity University, Jharkhand

Abstract

Artificial intelligence has enabled the creation of hyper-realistic synthetic audio-visual content capable of convincingly depicting individuals saying or doing things they never did.[1] While such technology carries legitimate applications in entertainment, education, and accessibility, its misuse for non-consensual intimate imagery, financial fraud, political disinformation, and reputational harm has become a pressing concern in India.[1] This article examines whether India’s fragmented cyber law architecture—comprising the Information Technology Act, 2000, the IT Rules, 2021, the Bharatiya Nyaya Sanhita, 2023, the Bharatiya Sakshya Adhiniyam, 2023, and the Digital Personal Data Protection Act, 2023—adequately addresses deepfake-related harm, or whether these statutes merely retrofit older doctrinal categories onto a technologically distinct problem.[1][2][3][4][5][6] Drawing on judicial developments, recent regulatory amendments, and comparative practice in the European Union, the United States, and China, the article argues that India requires a dedicated statutory framework rather than continued reliance on subordinate legislation and interpretive extension.[1][7][8][9]

Keywords: Deepfakes; Artificial Intelligence; Information Technology Act, 2000; Personality Rights; Synthetic Media; Digital Personal Data Protection Act, 2023; Platform Liability.[1]

1. Introduction

Artificial intelligence-driven synthetic media, popularly termed “deepfakes,” use generative adversarial networks and diffusion-based models to fabricate images, audio, and video that are often indistinguishable from authentic recordings.[1] What began as an experimental application of machine learning has quickly become accessible through consumer-grade applications requiring no technical expertise.[1] This democratisation of synthesis capability has transformed deepfakes into a vector for fraud, defamation, sexual exploitation, and electoral manipulation.[1]

The concern is acute in India.[1] With hundreds of millions of internet users, a vernacular-heavy social media ecosystem, and multi-phase elections, India offers fertile ground for synthetic disinformation to spread rapidly.[1] AI-manipulated videos of politicians, voice-cloning financial frauds targeting elderly citizens, and non-consensual sexualised imagery of public figures and private individuals illustrate the scale of the challenge.[1]

India’s response, however, has been reactive and improvised:[1]

• Judicial Extension: Courts have extended common law personality rights through interim injunctions.[1][10]
• Executive Rules: The executive has amended subordinate rules under the Information Technology Act to define “synthetically generated information.”[1][3]
• Analogous Penal Codes: Criminal provisions drafted for a pre-digital era are stretched to cover AI-fabricated content.[1][4]

No primary statute currently defines a deepfake, prescribes a graded liability regime for creation as distinct from dissemination, or allocates enforcement responsibility with precision.[1] This article interrogates whether such piecemeal adaptation is legally sustainable or whether the distinct evidentiary, technological, and constitutional character of deepfakes demands a dedicated law.[1]

2. Understanding Deepfakes and Their Legal Challenges

A deepfake is synthetic audio-visual content generated or manipulated using deep learning techniques—most commonly generative adversarial networks, autoencoders, or diffusion models—to depict a person’s face, voice, or actions in a manner that did not occur.[1] The term encompasses two techniques:[1]

1. Full Synthesis: The depicted individual never made the relevant statement or action.[1]
2. Contextual Manipulation: Genuine footage is altered to change its context or content.[1]

While the technology carries beneficial applications—such as dubbing in cinema, accessibility tools for speech impairments, and historical recreation in education—its misuse creates severe legal challenges:[1]

• Financial & Identity Fraud: Impersonation for unauthorized transactions and voice-cloned calls targeting corporate or family funds.[1]
• Non-Consensual Intimate Imagery (NCII): Algorithmic generation of explicit imagery inflicting severe dignitary harm.[1]
• Electoral Disinformation & Security Threats: Fabricated political statements during election cycles and synthetic audio-visuals compromising national security.[1]
• The “Liar’s Dividend”: Corrosion of evidentiary value where authentic audio-visual recordings are falsely dismissed as synthetic fabrications.[1]

3. Existing Legal Framework in India

India’s response relies on statutory frameworks enacted for traditional cybercrime and e-commerce, adapted through interpretation:[1]

• Constitutional Foundations: Article 19(1)(a) protects free speech and artistic expression, subject to reasonable restrictions under Article 19(2).[1][11] Following Justice K.S. Puttaswamy v. Union of India, Article 21 guarantees informational privacy and control over one’s likeness.[1][12] High Courts have utilized common law personality rights in cases such as Anil Kapoor v. Simply Life India & Ors. to issue ex parte injunctions, though this remedy remains costly and primarily accessible to public figures.[1][10]
• Information Technology Act, 2000 & Intermediary Rules: Section 66D penalises cheating by personation, Section 66E addresses privacy violations, and Sections 67/67A penalise obscene content.[2] Section 79 conditions intermediary safe harbour on prompt content takedowns.[2] The Ministry of Electronics and Information Technology amended the IT Rules, 2021 (in late 2025 and early 2026) to define “synthetically generated information” and compress takedown windows.[1][3] However, subordinate legislation cannot create primary offences, prescribe civil damages, or establish statutory exemptions for satire and journalism.[1]
• Criminal, Evidentiary, & Data Protection Statutes: The Bharatiya Nyaya Sanhita, 2023 applies traditional forgery and impersonation provisions by analogy.[1][4] The Bharatiya Sakshya Adhiniyam, 2023 retains electronic record certification mechanisms that verify custody rather than actual event authenticity.[1][5] The Digital Personal Data Protection Act, 2023 regulates biometric data processing but includes broad public-data exemptions and lacks mechanisms for AI-generated derivative content.[1][6] Furthermore, the Copyright Act, 1957 does not recognize an individual’s facial likeness or voice as copyrightable subject matter.[1][13]

4. Comparative Analysis

International jurisdictions have adopted distinct regulatory models for managing synthetic media:[1]

• European Union (Transparency Model): Article 50 of the EU AI Act mandates machine-readable watermarking for synthetic content and obligates deployers to disclose deepfakes, enforced by substantial financial penalties.[1][7]
• United States (Targeted Federal & State Framework): The federal TAKE IT DOWN Act (2025) criminalises non-consensual intimate AI depictions and mandates a 48-hour platform removal window, complemented by state-level election integrity statutes.[1][8]
• China (State Administration Model): The 2023 Deep Synthesis Provisions impose compulsory visible labeling, mandatory real-name user verification for generative tools, and security assessments for providers.[1][9]

5. Critical Analysis: Are Existing Cyber Laws Enough?

India’s legal approach exhibits structural fragmentation:[1]

• Statutory Fragmentation: Victims must navigate the IT Act, BNS, DPDP Act, and common law injunctions across multiple forums under conflicting standards of proof.[1][2][4][6]
• Absence of Primary Definition: Relying on subordinate rules creates doctrinal instability, confusing legitimate political satire and parody with unlawful synthetic content.[1][3]
• Enforcement Displacement: Cross-border hosting forces reliance on Section 79 takedowns, shifting accountability to intermediaries while leaving original creators unpunished.[1][2]
• Generative AI Accountability Gap: Current law assumes human criminal intent, failing to assign liability clearly across prompt engineers, platform operators, and foundational model developers.[1]
• Constitutional Vulnerability: Regulating synthetic speech through executive rules rather than parliamentary legislation increases vulnerability to Article 19(1)(a) constitutional challenges.[1][11]

6. Recommendations

To establish a coherent regulatory regime, India should implement the following reform measures:[1]

1. Standalone Legislation: Enact a primary parliamentary statute defining deepfakes and establishing clear legal distinctions between fully synthetic and contextual manipulations.[1]
2. Developer-Side Watermarking: Mandate cryptographic provenance markers and metadata embedding at the point of generation for AI developers.[1]
3. Graded Platform Liability: Establish tiered compliance schedules for intermediaries, prioritizing rapid removal of non-consensual intimate imagery.[1]
4. Civil Compensation Mechanism: Create a statutory civil remedy enabling victims to claim statutory damages independently of criminal proceedings.[1]
5. Electoral Safeguards: Coordinate with the Election Commission of India (ECI) for mandatory disclosure of AI-generated political content during election periods.[1]
6. Specialized Forensic Infrastructure: Equip CERT-In and state cyber cells with dedicated synthetic media detection tools and establish cross-border mutual legal assistance protocols.[1]

7. Conclusion

India’s current legal framework for deepfakes remains fragmented, reactive, and reliant on statutory provisions designed for older technological paradigms.[1] While judicial remedies and subordinate IT Rules have provided interim measures, they cannot substitute for a comprehensive parliamentary statute.[1][3] A dedicated legislative framework is necessary to define synthetic harms, distribute technical liability along the generative chain, safeguard constitutional speech, and ensure effective civil and criminal remedies for victims.[1][11]

References

[1] Author, Beyond Existing Cyber Laws: Rethinking India’s Legal Response to Deepfakes (2026 manuscript text).
[2] Information Technology Act, No. 21 of 2000, §§ 43, 66, 66D, 66E, 67, 67A, 79 (India).
[3] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (as amended 2025/2026) (India).
[4] Bharatiya Nyaya Sanhita, No. 45 of 2023 (India).
[5] Bharatiya Sakshya Adhiniyam, No. 47 of 2023 (India).
[6] Digital Personal Data Protection Act, No. 22 of 2023 (India).
[7] Regulation 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), art. 50, 2024 O.J. (L 1689) (EU).
[8] Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act (TAKE IT DOWN Act) of 2025, Pub. L. No. 119-12 (US).
[9] Provisions on the Administration of Deep Synthesis of Internet Information Services (promulgated by Cyberspace Admin. of China, effective Jan. 10, 2023) (China).[cite: 9]
[10] Anil Kapoor v. Simply Life India & Ors., CS(COMM) 652/2023 (Delhi HC Sept. 20, 2023).[cite: 9]
[11] INDIA CONST. art. 19, §§ 1(a), 2.[cite: 9]
[12] Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.[cite: 9]
[13] Copyright Act, No. 14 of 1957, § 38 (India).[cite: 9]

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top