Deepfake Regulation in India: Is Existing Criminal and Data Protection Law Sufficient?

Published On: 17th August 2026

Authored By: Anjali Agrawal
KLE Law College, Bengaluru

Abstract

The emergence of deepfake technology has transformed the challenges posed by artificial intelligence in the digital age. What initially appeared to be a tool for entertainment and creative content has increasingly become a means of violating privacy, damaging reputations, spreading misinformation, committing financial fraud, and influencing democratic processes. As generative AI systems continue to evolve, creating realistic synthetic audio, images, and videos has become easier, faster, and significantly more convincing. Consequently, legal systems across the world are struggling to respond to harms that affect not only individuals but also public trust in digital information.

In India, there is no dedicated legislation governing deepfakes. Instead, the legal response is spread across multiple statutes, including the Bharatiya Nyaya Sanhita, 2023, the Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Digital Personal Data Protection Act, 2023, and certain principles developed through judicial decisions on privacy and personality rights. While these laws address particular consequences of deepfake misuse, they do not directly regulate the creation, distribution, or governance of synthetic media.

This paper examines whether the existing Indian legal framework is sufficient to deal with the growing risks associated with deepfakes. Using a doctrinal research methodology, it analyses statutory provisions, judicial precedents, government advisories, and comparative approaches adopted in jurisdictions such as the European Union, the United States, the United Kingdom, and China. The study concludes that although current laws provide remedies after harm has occurred, they are largely reactive and fail to establish an effective preventive framework for regulating synthetic media. It argues that India should move beyond relying solely on scattered criminal and data protection provisions and adopt a comprehensive regulatory framework that balances technological innovation with the protection of privacy, dignity, freedom of expression, and democratic integrity.

Keywords: Deepfakes; Generative Artificial Intelligence; Data Protection; Intermediary Liability; Personality Rights; Privacy; Synthetic Media; India.

1. Introduction

Artificial Intelligence has transformed the way digital content is created and shared. Among its many developments, deepfake technology has emerged as one of the most controversial because it enables the creation of highly realistic yet fabricated audio, video, and image content. Unlike traditional photo editing or video manipulation, deepfakes rely on advanced machine learning techniques to imitate a person’s face, voice, expressions, and mannerisms with remarkable accuracy. As a result, distinguishing genuine content from manipulated media has become increasingly difficult, creating serious legal and ethical concerns.[1]

The misuse of deepfakes extends far beyond harmless entertainment. In recent years, synthetic media has been used to spread political misinformation, facilitate financial fraud through voice cloning, circulate non-consensual intimate images, and falsely attribute statements or actions to individuals. Such misuse not only harms individual privacy and reputation but also undermines public confidence in digital information. When fabricated content becomes almost indistinguishable from authentic material, it affects democratic discourse, journalistic credibility, criminal investigations, and even judicial proceedings.

Although Indian law has long dealt with offences such as cheating, forgery, defamation, obscenity, and impersonation, deepfakes present a challenge that these traditional legal categories were never designed to address. The technology does not merely alter an existing image or recording; it recreates a person’s identity in a manner that can convincingly simulate real events. This ability to fabricate identity at scale distinguishes deepfakes from conventional forms of digital manipulation and raises questions about whether existing legal protections remain adequate.[2]

At present, India does not have a standalone law specifically regulating deepfakes. Instead, different aspects of deepfake-related harm are addressed through a combination of the Bharatiya Nyaya Sanhita, 2023, the Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Digital Personal Data Protection Act, 2023, intellectual property laws, and constitutional principles relating to privacy and dignity. While these laws provide remedies in particular situations, they operate independently of one another and were enacted for purposes broader than regulating AI-generated synthetic media. Consequently, victims often have to rely on multiple legal provisions to seek relief, leading to uncertainty and delayed enforcement.

The debate surrounding deepfake regulation in India generally revolves around two competing viewpoints. One perspective argues that the existing legal framework is sufficiently broad to deal with emerging harms and that creating a separate law would only result in unnecessary legislative overlap. The opposing view contends that deepfakes represent an entirely new form of technological harm that cannot be effectively addressed through conventional criminal offences or general data protection principles alone. Both arguments have merit, but neither fully considers the unique nature of synthetic media, which spreads rapidly through digital platforms and frequently causes irreversible harm before legal remedies become available.

This paper argues that India’s existing legal framework provides only partial protection against deepfake-related harms. Although current laws may punish offenders after the damage has occurred, they do little to prevent the creation and rapid dissemination of deceptive synthetic content. Issues such as consent for AI-generated identity replication, mandatory disclosure of manipulated content, platform accountability, digital provenance, and rapid removal mechanisms remain inadequately addressed under the present legal framework.

To examine these issues, the paper adopts a doctrinal research methodology based on statutory analysis, judicial decisions, government advisories, and comparative legal developments in jurisdictions including the European Union, the United States, the United Kingdom, and China. Rather than advocating the wholesale adoption of foreign models, the study seeks to identify principles that can be adapted to India’s constitutional values and digital governance framework. The objective is to evaluate whether existing Indian laws are capable of responding to the challenges created by deepfakes and, where necessary, to suggest reforms that strike an appropriate balance between technological innovation, freedom of expression, privacy, and the protection of individual dignity.

2. Understanding Deepfake Technology

Deepfake technology is a product of recent developments in artificial intelligence, particularly in the field of deep learning. The term “deepfake” combines “deep learning” and “fake” and refers to synthetic media that uses AI algorithms to generate or manipulate audio, video, images, or even text so that they appear authentic. Unlike conventional editing software, which requires visible manual alterations, deepfake systems can realistically imitate a person’s face, voice, expressions, and mannerisms, making it increasingly difficult to distinguish genuine content from fabricated material.[3]

From a legal perspective, the defining feature of a deepfake is not simply that the content has been altered. Digital editing has existed for decades and has long been recognised by the law in the context of forgery, defamation, and fraud. Deepfakes are different because they allow artificial intelligence to recreate or simulate an individual’s identity with remarkable accuracy. As a result, the technology can produce content that appears entirely genuine even though the events shown never actually occurred. This ability to convincingly imitate identity creates legal concerns that traditional forms of digital manipulation rarely presented.

The scope of deepfake technology has also expanded considerably in recent years. Earlier discussions mainly focused on face-swapped videos, but modern generative AI systems are capable of producing realistic voice clones, fabricated photographs, synthetic news reports, and AI-generated conversations. Recognising these developments, several jurisdictions have adopted broader definitions of synthetic media. For example, China’s Deep Synthesis Provisions and the European Union’s Artificial Intelligence Act regulate AI-generated content generally rather than limiting their focus to manipulated videos alone.

The risks associated with deepfakes are equally diverse. One of the most common forms of misuse involves the creation of non-consensual intimate images, where an individual’s likeness is digitally inserted into explicit content without permission. Such material often causes severe psychological distress and irreparable reputational harm. Another growing concern is voice cloning, which has been used to impersonate family members, corporate executives, and public officials for financial fraud and extortion. During election periods, deepfakes may also be employed to spread misinformation by falsely portraying political leaders making statements or engaging in conduct that never occurred. In the commercial sphere, manipulated videos or images can falsely suggest that celebrities or public figures endorse products or services, misleading consumers and damaging both personal reputation and commercial goodwill.

These different forms of misuse demonstrate that deepfakes cannot be addressed through a single legal principle. Privacy law protects an individual’s control over personal information and identity. Criminal law becomes relevant where synthetic media is used for fraud, intimidation, extortion, or other offences. Data protection legislation governs the collection and processing of personal data used in creating AI-generated content, while intellectual property law may apply where copyrighted works or protected performances are reproduced without authorisation. Constitutional principles further shape the legal response by requiring an appropriate balance between protecting individual dignity and safeguarding freedom of expression.

Deepfakes also create a broader societal challenge that extends beyond harm to individual victims. Legal scholars describe this as the “liar’s dividend.” Once fabricated media becomes widespread, people may begin to doubt the authenticity of genuine photographs, videos, or audio recordings. At the same time, those responsible for genuine misconduct can simply dismiss authentic evidence by claiming that it is AI-generated. This erosion of trust affects journalism, elections, criminal investigations, and judicial proceedings, all of which increasingly depend on digital evidence. Consequently, the challenge posed by deepfakes is not limited to protecting individual rights; it also concerns preserving public confidence in the authenticity of digital information.

For this reason, regulating deepfakes requires a balanced approach. The law must effectively address malicious uses of synthetic media while avoiding unnecessary restrictions on legitimate applications of artificial intelligence. AI-generated content is increasingly used in filmmaking, education, accessibility tools, language translation, satire, and artistic expression. A legal framework that criminalises every form of manipulated media would risk discouraging innovation and limiting constitutionally protected speech. The real challenge, therefore, lies in distinguishing deceptive and harmful deepfakes from legitimate and socially beneficial uses of AI technology.

3. Existing Indian Legal Framework

A. Bharatiya Nyaya Sanhita, 2023

The Bharatiya Nyaya Sanhita, 2023 (BNS)[4] does not contain any provision that specifically regulates deepfakes or AI-generated synthetic media. Nevertheless, several of its provisions may apply where deepfakes are used to commit offences such as cheating, personation, criminal intimidation, defamation, extortion, or the circulation of sexually explicit material. In other words, the BNS addresses the consequences arising from the misuse of deepfakes rather than the technology itself.

This approach has certain advantages. Since the law focuses on the harmful conduct instead of the underlying technology, it avoids criminalising legitimate uses of artificial intelligence, including filmmaking, satire, education, and other creative applications. However, the same approach also exposes an important limitation. Legal action generally becomes possible only after a victim has suffered harm. By the time criminal liability is invoked, manipulated content may already have spread across multiple online platforms, making the resulting damage to reputation or privacy almost impossible to reverse.

The limitations of the BNS become more evident when deepfakes are used on a large scale. For example, a manipulated political video released shortly before an election can influence public opinion within a matter of hours. Even if criminal proceedings are initiated later, they cannot undo the immediate impact of such misinformation. Similarly, deepfakes intended to damage an individual’s reputation may continue to circulate online long after legal remedies become available. These situations demonstrate that conventional criminal law often struggles to respond to digital harms that spread rapidly through the internet.

Another practical challenge is proving who is responsible for creating or distributing a deepfake. Successful prosecution depends on establishing authorship, intention, and knowledge. In many cases, however, AI-generated content is created anonymously, modified several times, and shared through multiple online platforms, sometimes across different jurisdictions. Identifying the original creator therefore becomes extremely difficult. Without effective mechanisms for preserving metadata, tracing digital content, or requiring platforms to maintain relevant records, criminal investigations may not always produce meaningful results.

For these reasons, although the Bharatiya Nyaya Sanhita provides an important legal basis for prosecuting offences arising from deepfake misuse, it remains largely reactive in nature. It can punish offenders after the damage has occurred, but it does little to prevent the creation, circulation, or rapid amplification of deceptive synthetic media. Consequently, criminal law alone cannot provide a comprehensive regulatory response to the growing challenges posed by deepfake technology.

B. Information Technology Act, 2000 and Intermediary Rules

In the absence of a dedicated law regulating deepfakes, India’s primary response has largely been through the Information Technology Act, 2000[5] and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Rather than directly governing artificial intelligence, these laws focus on regulating digital platforms and the responsibilities of intermediaries that host or facilitate online content. Since deepfakes are primarily circulated through social media platforms, messaging applications, and other online services, intermediary regulation has become one of the most important legal tools for addressing their spread.

Recognising the growing threat posed by AI-generated misinformation, the Ministry of Electronics and Information Technology (MeitY) issued a series of advisories in 2023 and 2024[6] directing intermediaries to strengthen their compliance with the due diligence obligations prescribed under Rule 3(1)(b) of the IT Rules. These advisories reminded platforms to inform users about prohibited content, respond promptly to complaints involving impersonation or misinformation, and take appropriate steps to curb the circulation of harmful deepfakes. The March 2024 Advisory further encouraged platforms to label AI-generated content or incorporate metadata and other technical identifiers that could help users recognise artificially created or manipulated media.[7]

These measures represent an important policy response because they acknowledge that online platforms play a central role in the rapid spread of deepfakes. Once manipulated content is uploaded, it can be viewed, downloaded, and reshared thousands of times within a very short period. Requiring intermediaries to establish efficient complaint mechanisms and remove unlawful content is therefore far more practical than relying exclusively on criminal prosecution against individual creators, who often remain anonymous or operate from different jurisdictions.

Despite these developments, the existing framework has significant shortcomings. MeitY advisories, although influential, do not have the same legal force as parliamentary legislation. Their implementation depends largely on the existing provisions of the Information Technology Act and the IT Rules, both of which were framed before generative AI became a widespread concern. As a result, important issues such as mandatory watermarking, technical standards for provenance, AI-specific risk assessments, and election-related safeguards remain largely outside the statutory framework.

Another concern is that the present due diligence regime follows a broad, uniform approach towards intermediaries. In reality, different online services pose different levels of risk. A public social media platform, an encrypted messaging service, and a generative AI application perform distinct functions and contribute differently to the creation and circulation of synthetic media. Treating all these platforms under the same general obligations does not adequately reflect the unique challenges associated with each category of intermediary. A more nuanced regulatory framework would impose responsibilities that correspond to the specific risks created by different digital services.

Judicial decisions interpreting intermediary liability have traditionally focused on concepts such as actual knowledge, due diligence, and notice-and-takedown procedures. While these principles remain relevant, they are often inadequate in the context of deepfakes. Harmful synthetic content can become viral within minutes, whereas legal notice procedures and content moderation processes may take several hours or even days. For victims of deepfake abuse, especially in cases involving intimate images, election misinformation, or financial fraud, such delays can render legal remedies largely ineffective.

Therefore, although the Information Technology Act and the Intermediary Rules provide an essential foundation for regulating online platforms, they do not offer a comprehensive solution to the challenges created by deepfakes. The existing framework recognises the importance of platform accountability but does not establish clear statutory obligations relating to AI-generated content, digital provenance, rapid response timelines, or differentiated responsibilities for various categories of intermediaries. As deepfake technology continues to evolve, these gaps are likely to become increasingly difficult to address through advisories alone.

C. Digital Personal Data Protection Act, 2023

The enactment of the Digital Personal Data Protection Act, 2023 (DPDP Act)[8] marked an important step in India’s evolving data governance framework. The legislation seeks to regulate the processing of digital personal data by recognising the rights of individuals while imposing corresponding obligations on data fiduciaries. It establishes a legal framework for obtaining consent, ensuring data security, providing grievance redressal mechanisms, and allowing individuals to exercise rights such as correction and erasure of their personal data. Given that many deepfakes are created using facial images, voice recordings, or other identifiable information, the DPDP Act initially appears to offer a useful legal basis for addressing such misuse.

However, its ability to regulate deepfakes is limited. The primary objective of the Act is to govern the collection, storage, and processing of personal data rather than the creation or circulation of AI-generated synthetic media. Consequently, while the Act may address certain instances where personal data is obtained or processed without consent, it does not specifically regulate the use of artificial intelligence to create realistic digital replicas of an individual’s identity.

This distinction is particularly important in the context of deepfakes. In many cases, AI models generate synthetic content by relying on publicly available photographs, videos, or voice recordings collected from various online sources. The final output may not simply reproduce the original material but instead generate a completely new image or video that merely resembles the individual concerned. Such situations raise difficult legal questions regarding whether the resulting content should be treated as personal data, a digitally manipulated representation, or an entirely new AI-generated creation. The present framework does not provide clear answers to these issues.

Another limitation is that the DPDP Act does not establish a specific consent regime for AI-based identity replication. Although the Act emphasises consent as the foundation for lawful data processing, it does not expressly require separate permission before a person’s face, voice, or likeness is used to generate synthetic content. In practice, this creates a significant gap because an individual may never have consented to the use of their identity for AI-generated videos or voice cloning, even if the underlying photographs or recordings were lawfully accessible online.

The scope of the Act is further restricted because it functions as a general data protection statute rather than legislation specifically designed to regulate artificial intelligence. Deepfake-related harms often extend well beyond privacy concerns. They may involve electoral misinformation, identity fraud, reputational damage, financial scams, non-consensual intimate imagery, or the manipulation of public opinion. These harms affect several legal interests simultaneously, many of which cannot be effectively addressed through data protection principles alone.

The constitutional principles recognised in Justice K.S. Puttaswamy (Retd.) v. Union of India reinforce the importance of informational privacy and individual autonomy in the digital age. The Supreme Court recognised privacy as an essential component of dignity and personal liberty, emphasising that individuals should have meaningful control over their personal information. These principles undoubtedly strengthen the legal foundation for protecting individuals against the unauthorised use of their identity. Nevertheless, constitutional recognition of privacy cannot substitute for detailed statutory provisions that specifically regulate AI-generated synthetic media.

Therefore, while the DPDP Act represents a significant development in India’s digital regulatory landscape, it should not be viewed as a complete solution to the challenges posed by deepfakes. It can provide remedies where personal data has been collected or processed unlawfully, but it does not comprehensively address issues such as identity replication, synthetic impersonation, mandatory disclosure of AI-generated content, or platform accountability. As deepfake technology continues to evolve, it is increasingly evident that data protection law, by itself, cannot adequately regulate every dimension of synthetic media.

D. Copyright Act, 1957 and Trade Marks Act, 1999

The Copyright Act, 1957[9] and the Trade Marks Act, 1999[10] may provide limited protection against certain forms of deepfake misuse, but neither statute was enacted with AI-generated synthetic media in mind. As a result, their application to deepfakes is often indirect and depends on the facts of each case.

Under the Copyright Act, protection is available for original literary, artistic, musical, dramatic, and cinematographic works. If a deepfake reproduces substantial portions of a copyrighted video, photograph, sound recording, or performance without authorisation, the copyright owner may have a valid claim for infringement. However, many deepfakes do not simply copy existing works. Instead, they generate entirely new content by using artificial intelligence to imitate a person’s appearance, voice, or expressions. In such situations, there may be no direct reproduction of a copyrighted work, making copyright law an uncertain remedy.

This limitation becomes more apparent when the primary harm is not the unauthorised copying of creative expression but the misuse of an individual’s identity. A manipulated video may convincingly portray a person saying or doing something that never actually occurred, even though no copyrighted material has technically been reproduced. In such cases, the injury arises from false representation and identity manipulation rather than copyright infringement. Consequently, the Copyright Act offers only partial protection against deepfake-related harms.

The Trade Marks Act, 1999 has an even narrower role. Trademark law primarily protects brand identity and prevents consumer confusion regarding the source or origin of goods and services. Nevertheless, it may become relevant where deepfakes falsely depict celebrities, influencers, or well-known personalities endorsing commercial products or services. Such deceptive advertisements can mislead consumers while simultaneously damaging the goodwill and commercial reputation associated with the individual’s identity.

Even in these situations, trademark law is not a complete answer. A person’s face, voice, or manner of speaking is not merely a commercial identifier; it is closely connected to their personality, dignity, and individual identity. Deepfake misuse often causes emotional, reputational, and psychological harm that extends far beyond commercial loss. These interests cannot be adequately protected through trademark principles alone.

For this reason, Indian courts have increasingly relied on the broader doctrine of personality rights, supported by constitutional principles of privacy and dignity, rather than attempting to fit every dispute within the traditional framework of intellectual property law. While copyright and trademark statutes continue to play an important supporting role in specific circumstances, they cannot independently provide a comprehensive legal response to the challenges created by deepfake technology.

E. Constitutional Protections, Privacy, and Personality Rights

Among all the legal principles relevant to deepfake regulation, constitutional protections relating to privacy, dignity, and personal autonomy provide the strongest foundation for developing an effective legal framework in India. Although the Constitution does not expressly refer to artificial intelligence or deepfakes, the rights guaranteed under Articles 14, 19, and 21[11] have evolved through judicial interpretation to address emerging technological challenges.

The Supreme Court’s landmark decision in Justice K.S. Puttaswamy (Retd.) v. Union of India[12] fundamentally changed the understanding of privacy in Indian constitutional law. Recognising privacy as a fundamental right under Article 21, the Court held that privacy extends beyond physical space and includes informational privacy, decisional autonomy, and an individual’s ability to control personal information. These principles have become increasingly significant in the digital era, where personal data and identity can be copied, manipulated, and distributed on a massive scale.

Deepfakes directly threaten these constitutional values because they interfere with an individual’s control over their own identity. A person’s face, voice, or likeness can be digitally replicated without consent and used in fabricated videos that falsely portray them engaging in acts or making statements they never made. Such misuse affects more than reputation alone; it undermines personal autonomy, dignity, and the freedom to determine how one’s identity is represented in the public sphere. In this respect, the harm caused by deepfakes goes beyond ordinary defamation and enters the realm of constitutional protection.

At the same time, any legal framework regulating deepfakes must respect the guarantee of freedom of speech and expression under Article 19(1)(a). Artificial intelligence is widely used for legitimate purposes, including filmmaking, satire, education, journalism, accessibility technologies, and creative expression. An overly broad prohibition on AI-generated content could discourage innovation and interfere with constitutionally protected speech. Therefore, any restrictions imposed by law must satisfy the test of reasonableness under Article 19(2) and remain proportionate to the objective sought to be achieved.

This balancing exercise is particularly important because not every manipulated image or AI-generated video causes legal harm. Satirical content, fictional storytelling, artistic performances, and clearly disclosed synthetic media often serve legitimate public purposes. The challenge for lawmakers is to distinguish malicious impersonation and deceptive manipulation from lawful and socially beneficial uses of artificial intelligence. A regulatory framework that fails to make this distinction risks either overregulating innovation or leaving victims without adequate protection.

Another important development has been the gradual recognition of personality rights by Indian courts. Although these rights are not codified in a single statute, judicial decisions have increasingly acknowledged that an individual’s name, image, voice, likeness, and other distinctive personal attributes deserve legal protection against unauthorised commercial exploitation and digital misuse. These rights have acquired greater significance with the rise of generative AI, which makes it possible to imitate an individual’s identity with unprecedented realism.

Despite these constitutional developments, the existing legal framework remains fragmented. Fundamental rights establish important legal principles, but they do not prescribe detailed procedures for issues such as AI-generated identity replication, mandatory disclosure of synthetic content, platform responsibilities, or emergency takedown mechanisms. Consequently, constitutional jurisprudence provides the values upon which deepfake regulation should be built, but it cannot replace comprehensive legislation specifically designed to address the unique challenges created by synthetic media.

4. Judicial Developments

Although India does not yet have judicial decisions dealing exclusively with deepfakes, constitutional and commercial disputes concerning privacy, identity, and personality rights have laid an important legal foundation for addressing AI-generated synthetic media. These decisions demonstrate that Indian courts are increasingly willing to protect an individual’s identity from unauthorised digital exploitation, even though the technology itself has evolved faster than the law.

The Supreme Court’s decision in Justice K.S. Puttaswamy (Retd.) v. Union of India[13] remains the cornerstone of privacy jurisprudence in India. By recognising privacy as a fundamental right under Article 21 of the Constitution, the Court significantly expanded the scope of constitutional protection available to individuals in the digital age. It observed that privacy is closely connected with dignity, autonomy, and an individual’s ability to exercise control over personal information. Although the case was decided before the widespread emergence of deepfake technology, the principles laid down by the Court have become highly relevant today. The unauthorised creation of AI-generated videos or voice clones directly interferes with a person’s autonomy and their ability to control how their identity is represented in the public domain.

The recognition of privacy in Puttaswamy also provides an important constitutional standard for evaluating future deepfake regulation. While the State has a legitimate interest in preventing online fraud, misinformation, and identity theft, any restrictions on digital content must satisfy the requirements of legality, necessity, and proportionality. Consequently, the judgment protects both individual rights and freedom of expression by ensuring that any future regulatory framework remains constitutionally balanced.

Another significant development can be seen in Amitabh Bachchan v. Rajat Nagi,[14] where the Delhi High Court granted an interim injunction restraining the unauthorised use of Amitabh Bachchan’s name, image, voice, and other distinctive attributes. The Court recognised that the misuse of a celebrity’s identity through online platforms and fraudulent activities could result in serious reputational and commercial harm. Although the dispute did not directly concern deepfake technology, its importance lies in acknowledging that a person’s identity deserves legal protection even in the rapidly evolving digital environment.

A similar approach was adopted in Anil Kapoor v. Simply Life India & Ors.,[15] where the Delhi High Court extended interim protection to the actor’s name, likeness, voice, signature style, and other aspects of his personality. The Court specifically took note of the misuse of generative artificial intelligence and AI-generated images that falsely represented the actor. This judgment is particularly significant because it is one of the first Indian decisions to expressly acknowledge the legal risks associated with generative AI. Rather than treating such misuse as a conventional intellectual property dispute, the Court recognised that AI-enabled identity replication can seriously affect both commercial interests and personal dignity.

These judicial developments undoubtedly strengthen the protection available against digital identity misuse. However, they also reveal the limitations of relying exclusively on judicial intervention. Most personality rights cases involve well-known public figures who possess the financial resources and legal support necessary to approach constitutional courts for urgent relief. Ordinary individuals who become victims of deepfake pornography, financial scams, or political impersonation often lack similar access to immediate legal remedies. As a result, litigation remains an expensive and time-consuming option for many victims.

Another limitation is that these judgments primarily provide relief after the harm has already occurred. Courts can grant injunctions, award damages, or restrain further publication of unlawful content, but they cannot always prevent manipulated media from spreading rapidly across digital platforms. Once a deepfake becomes viral, removing every copy from the internet becomes extremely difficult, regardless of the legal remedy granted. This highlights the need for preventive mechanisms alongside judicial protection.

Taken together, these decisions demonstrate that Indian courts have recognised the importance of protecting identity, dignity, and privacy in the digital age. However, judicial precedents alone cannot provide a complete regulatory framework for deepfakes. They establish valuable legal principles, but comprehensive legislation remains necessary to ensure consistent standards relating to consent, platform accountability, rapid content removal, and the responsible use of artificial intelligence.

5. Comparative Legal Analysis

A comparison with international regulatory approaches demonstrates that countries have responded to deepfakes in different ways, depending on their legal systems and policy priorities. While no single model offers a perfect solution, the experiences of the European Union, the United States, the United Kingdom, and China provide useful guidance for India in developing a balanced legal framework. Rather than adopting any one model in its entirety, India can draw lessons from each jurisdiction while ensuring that future legislation remains consistent with its own constitutional principles.

Among the jurisdictions considered, the European Union has adopted one of the most comprehensive regulatory approaches through the Artificial Intelligence Act, 2024. Instead of treating deepfakes solely as a criminal issue, the Act introduces transparency obligations for providers and users of AI-generated content.[16] Article 50 requires certain AI-generated audio, images, videos, and text to be clearly disclosed as artificially generated or manipulated, subject to limited exceptions such as artistic expression, satire, or law enforcement activities. This approach focuses on preventing deception before significant harm occurs rather than relying entirely on legal remedies after the damage has been done.

One of the strengths of the European model is that it places responsibility not only on individuals who misuse AI but also on developers and deployers of AI systems. By requiring disclosure and promoting traceability, the law attempts to improve transparency without imposing a blanket prohibition on synthetic media. Such an approach recognises that artificial intelligence has many legitimate uses and that regulation should target deception rather than innovation itself.

The United States has adopted a markedly different approach. Instead of a comprehensive federal law, deepfake regulation has largely developed through a combination of state legislation, election laws, civil remedies, platform policies, and existing criminal offences. Several states have enacted laws dealing with non-consensual intimate deepfakes and election-related misinformation, while civil claims relating to defamation, privacy, and publicity rights continue to play an important role. Although this decentralised framework allows individual states to experiment with different regulatory solutions, it also creates inconsistencies in the level of protection available across jurisdictions. In addition, concerns regarding freedom of speech under the First Amendment have often limited the scope of legislative intervention.

The experience of the United States illustrates both the advantages and disadvantages of a fragmented regulatory structure. While innovation remains largely unrestricted, victims frequently encounter procedural complexities and varying legal standards depending on where the dispute arises. For a country such as India, which already relies on multiple statutes to address deepfake-related harms, adopting a similarly fragmented model may increase legal uncertainty rather than improve regulatory effectiveness.

The United Kingdom has generally addressed deepfake-related harms through its broader framework of online safety, privacy, communications offences, and image-based abuse laws. Instead of creating legislation exclusively for synthetic media, the United Kingdom has expanded the scope of existing legal mechanisms to respond to emerging technological risks. This provides flexibility because established legal principles can evolve alongside technological developments. However, it also means that courts and regulators must continually adapt older laws to situations that were never specifically anticipated by Parliament.

By contrast, China has adopted one of the most direct regulatory approaches. The Provisions on the Administration of Deep Synthesis Internet Information Services require service providers to clearly label AI-generated content, obtain consent before manipulating identifiable facial or voice data, verify user identities, and implement technical safeguards to reduce misuse. These rules impose proactive obligations on technology providers rather than relying solely on criminal punishment after harmful content has already circulated. Although China’s regulatory model reflects its own governance philosophy and cannot be transplanted wholesale into democratic legal systems, it demonstrates that enforceable obligations relating to labelling, consent, and platform responsibility can be implemented in practice.

A comparison of these jurisdictions reveals several common themes. Modern deepfake regulation increasingly emphasises transparency, consent, platform accountability, and technical safeguards rather than relying exclusively on traditional criminal offences. The objective is not to prohibit artificial intelligence altogether but to reduce the risks associated with deceptive and harmful uses of synthetic media. These preventive measures recognise that once manipulated content becomes widely accessible online, legal remedies alone may be insufficient to reverse the resulting harm.

For India, the comparative experience offers an important lesson. Existing laws already provide remedies for offences such as fraud, defamation, obscenity, and unauthorised data processing, but they do not establish a unified framework governing AI-generated content. A future Indian law should therefore combine the transparency requirements reflected in the European Union’s AI Act, the consent-based protections adopted in China’s Deep Synthesis Rules, and India’s own constitutional commitment to privacy, dignity, and freedom of expression. Such an approach would be more effective than relying exclusively on scattered statutory provisions or executive advisories.

6. Critical Evaluation

The discussion in the preceding chapters shows that India already possesses several legal mechanisms capable of addressing certain forms of deepfake misuse. The Bharatiya Nyaya Sanhita, 2023, the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, and constitutional principles relating to privacy and dignity each contribute to the existing legal framework. However, these laws were enacted for broader purposes and not with AI-generated synthetic media in mind. Consequently, while they may offer remedies in individual cases, they do not together form a coherent system for regulating deepfakes.[17]

A major limitation of the present framework is its reactive nature. Most legal provisions become relevant only after harm has already occurred. Criminal law is invoked after a fraud has been committed, a defamatory video has been circulated, or an individual’s privacy has been violated. Similarly, civil remedies and constitutional litigation usually begin only after the victim has suffered measurable injury. In the context of deepfakes, this approach is often inadequate because manipulated content can spread across multiple digital platforms within minutes. Even if courts later order the removal of such material, the reputational, emotional, or financial damage may already be irreversible.

Another concern is the fragmented nature of the legal framework. Victims frequently have to rely on multiple statutes depending on the type of harm they have experienced. A single deepfake may simultaneously involve unauthorised use of personal data, impersonation, defamation, copyright concerns, and financial fraud. Since these issues are governed by different laws, enforcement becomes more complicated and often results in overlapping proceedings. The absence of a dedicated statutory framework creates uncertainty for victims, investigators, digital platforms, and even courts attempting to determine the most appropriate legal remedy.

The rapid development of artificial intelligence has also created challenges that existing legislation never anticipated. Today’s generative AI systems can produce highly realistic videos, clone voices with minimal audio samples, and generate entirely new digital identities within a matter of seconds. Most Indian statutes currently in force were drafted before these technological capabilities became widely available. As a result, important regulatory questions, such as mandatory disclosure of AI-generated content, verification standards, digital provenance, and responsibility for AI developers, remain largely unanswered.

Platform accountability presents another area where reform is necessary. Social media companies and digital intermediaries play a significant role in the circulation of deepfakes because their algorithms can rapidly amplify manipulated content. While the Information Technology Rules require intermediaries to exercise due diligence, the present obligations remain relatively general and are not specifically designed to address the risks associated with generative AI. In practice, there is little uniformity regarding how different platforms identify, label, or remove deepfake content, leading to inconsistent protection for users.

At the same time, any proposal for stronger regulation must recognise the legitimate benefits of artificial intelligence. Deepfake technology is not inherently unlawful. Similar AI tools are increasingly used in education, cinema, accessibility technologies, healthcare, language translation, scientific research, and creative industries. A legal framework that criminalises every form of synthetic media would not only discourage innovation but could also interfere with constitutionally protected speech and artistic expression. Therefore, the objective should be to regulate harmful and deceptive uses of AI rather than the technology itself.

The comparative analysis undertaken in this study further demonstrates that several jurisdictions have shifted towards preventive regulation by imposing obligations relating to transparency, consent, and platform responsibility. India, however, continues to rely primarily on post-harm legal remedies. While existing statutes undoubtedly provide an important foundation, they cannot adequately respond to the speed, scale, and complexity of modern deepfake technology without targeted legislative reform.

In light of these considerations, it is difficult to conclude that the present Indian legal framework is fully sufficient to regulate deepfakes. Existing laws address particular consequences of misuse, but they do not comprehensively regulate the creation, dissemination, authentication, and governance of AI-generated synthetic media. A more integrated and forward-looking approach is therefore necessary to ensure that technological innovation develops alongside effective legal safeguards for privacy, dignity, and public trust.

7. Recommendations

The growing misuse of deepfake technology demonstrates that relying solely on existing criminal offences and data protection laws is no longer sufficient. While India’s current legal framework addresses certain consequences of deepfake misuse, it does not provide a coordinated mechanism to prevent the creation, circulation, and misuse of AI-generated synthetic media. Based on the analysis undertaken in this paper, the following measures may strengthen India’s legal and regulatory response.[18]

1. Enact a Dedicated Legal Framework for Deepfakes
India should consider introducing either a standalone law on deepfakes or a dedicated chapter within future AI legislation. Instead of merely penalising offenders after harm has occurred, such legislation should clearly define what constitutes a deepfake, distinguish between legitimate and malicious uses of AI-generated content, and prescribe appropriate civil as well as criminal remedies. A specialised framework would reduce uncertainty and provide greater consistency than the present reliance on multiple overlapping statutes.

2. Introduce Mandatory Labelling of AI-Generated Content
One of the most effective preventive measures would be to require AI-generated or substantially manipulated content to carry a clear and visible disclosure wherever reasonably possible. This would not prevent the use of artificial intelligence for creative or educational purposes but would help users identify synthetic media before relying on it. Such transparency obligations, similar to those adopted in the European Union, could significantly reduce the spread of deceptive content while preserving freedom of expression.

3. Strengthen Platform Accountability
Digital platforms should be assigned clearer statutory responsibilities for identifying and responding to harmful deepfakes. In addition to existing due diligence obligations, intermediaries should establish dedicated reporting mechanisms, adopt faster review procedures for verified complaints, and cooperate more effectively with law enforcement agencies. Where deepfakes involve identity theft, financial fraud, or non-consensual intimate content, expedited takedown procedures should be made mandatory to minimise further harm.

4. Develop Technical Standards for Digital Provenance
Legal regulation alone cannot effectively address the challenges posed by synthetic media. India should encourage the development and adoption of technological safeguards such as digital watermarking, metadata preservation, content authentication systems, and provenance standards that allow users to verify the origin of digital content. Combining legal obligations with technical solutions would make it easier to distinguish authentic material from AI-generated manipulations.

5. Recognise AI-Based Identity Misuse More Explicitly
The law should provide stronger protection against the unauthorised use of an individual’s face, voice, likeness, or other identifiable characteristics for AI-generated content. While constitutional principles and judicial recognition of personality rights offer some protection, statutory recognition would provide greater clarity for courts, investigators, and victims. Explicit legal recognition of AI-enabled identity misuse would also reduce uncertainty regarding available remedies.

6. Promote Public Awareness and Digital Literacy
Legislation alone cannot eliminate the risks associated with deepfakes. Public awareness campaigns should educate individuals about recognising manipulated media, verifying online information, and reporting suspicious digital content. Schools, universities, public institutions, and media organisations can all contribute to improving digital literacy. A more informed public is less likely to become a victim of misinformation or online fraud involving AI-generated content.

7. Encourage Responsible AI Innovation
Regulation should not discourage technological development. Artificial intelligence continues to provide substantial benefits in sectors such as healthcare, education, scientific research, accessibility, filmmaking, and public administration. Any future legal framework should therefore focus on preventing harmful and deceptive uses of AI rather than restricting legitimate innovation. A balanced approach would protect individual rights while allowing responsible technological progress to continue.

8. Enhance Institutional Coordination
The regulation of deepfakes involves several authorities, including law enforcement agencies, data protection regulators, digital platforms, and government departments responsible for information technology. Greater coordination among these stakeholders would improve enforcement and reduce delays in responding to harmful content. Standard operating procedures and specialised training for investigators could further strengthen India’s institutional capacity to deal with AI-enabled offences.

Taken together, these recommendations seek to shift India’s approach from a largely reactive system towards one that is preventive, transparent, and technologically informed. Such reforms would not only improve protection against deepfake-related harms but would also ensure that innovation in artificial intelligence develops within a framework that respects constitutional values, individual dignity, and public trust.

8. Conclusion

Deepfake technology represents one of the most significant legal challenges created by the rapid advancement of artificial intelligence. By enabling the creation of highly realistic yet fabricated digital content, it has blurred the distinction between reality and manipulation in ways that existing legal frameworks were never designed to address. The resulting harms extend beyond individual victims and affect public confidence in digital communication, democratic institutions, commercial transactions, and the administration of justice.

This study examined whether India’s existing criminal and data protection laws are sufficient to regulate deepfakes. The analysis demonstrates that while statutes such as the Bharatiya Nyaya Sanhita, 2023, the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023, and constitutional principles relating to privacy and dignity provide important legal remedies, they do not together constitute a comprehensive regulatory framework for synthetic media. Most existing provisions operate only after harm has already occurred and therefore struggle to address the speed with which deepfakes are created and disseminated in today’s digital environment.

Judicial developments have undoubtedly strengthened the protection of privacy, personality rights, and digital identity. Likewise, comparative experiences from jurisdictions such as the European Union, China, the United States, and the United Kingdom demonstrate that transparency obligations, platform accountability, and preventive safeguards are becoming central features of modern AI regulation. These developments offer valuable guidance for India while also highlighting the need to develop solutions that remain consistent with its constitutional values and democratic framework.[19]

In my view, the question is no longer whether deepfakes require legal regulation, but whether the existing framework can continue to respond effectively as artificial intelligence becomes more sophisticated. Although current laws provide a useful starting point, they are not sufficient to address every dimension of AI-generated identity manipulation and synthetic media. A more integrated legal framework, supported by technological safeguards, institutional cooperation, and clear statutory standards, would provide greater certainty for individuals, digital platforms, and enforcement agencies alike.

Ultimately, the objective of regulation should not be to restrict artificial intelligence as a technology. Instead, the law must ensure that innovation develops responsibly while protecting privacy, dignity, freedom of expression, and public trust. Achieving this balance will be essential if India is to harness the benefits of artificial intelligence without compromising the fundamental rights that lie at the heart of its constitutional order.

References

[1] Robert Chesney & Danielle Keats Citron, Deep Fakes: A Looming Challenge for Privacy, Democracy, and National Security, 107 Calif. L. Rev. 1753 (2019).
[2] Danielle Keats Citron, The Fight for Privacy: Protecting Dignity, Identity, and Love in the Digital Age 45–52 (W.W. Norton & Co. 2022).
[3] Stuart Russell & Peter Norvig, Artificial Intelligence: A Modern Approach (4th ed. 2021).
[4] Bharatiya Nyaya Sanhita, No. 45 of 2023 (India).
[5] Information Technology Act, No. 21 of 2000 (India).
[6] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, r. 3.
[7] Ministry of Electronics & Information Technology, Advisory on AI-Generated Content and Deepfakes (Mar. 15, 2024).
[8] Digital Personal Data Protection Act, No. 22 of 2023 (India).
[9] Copyright Act, No. 14 of 1957 (India).
[10] Trade Marks Act, No. 47 of 1999 (India).
[11] India Const. arts. 14, 19 & 21.
[12] Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
[13] Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
[14] Amitabh Bachchan v. Rajat Nagi & Ors., CS(COMM) 819/2022 (Del. H.C. Nov. 25, 2022).
[15] Anil Kapoor v. Simply Life India & Ors., CS(COMM) 652/2023 (Del. H.C. Sept. 20, 2023).
[16] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act).
[17] Robert Chesney & Danielle Keats Citron, supra note 1.
[18] OECD, Recommendation of the Council on Artificial Intelligence (2019).
[19] Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.

Bibliography

  • Shreya Singhal v. Union of India, (2015) 5 SCC 1 (India).
  • Robert Chesney & Danielle Keats Citron, Deep Fakes and the New Disinformation War, Foreign Affairs (Jan./Feb. 2019).
  • Ministry of Electronics & Information Technology, Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
  • NITI Aayog, National Strategy for Artificial Intelligence (2018).
  • UNESCO, Recommendation on the Ethics of Artificial Intelligence (2021).
  • World Economic Forum, Global Risks Report 2025.
  • DEEPFAKES Accountability Act, H.R. 5586, 116th Cong. (2019) (U.S.).
  • Online Safety Act 2023 (U.K.).
  • Provisions on the Administration of Deep Synthesis Internet Information Services (China) (2023).
  • European Commission, Questions and Answers on the Artificial Intelligence Act (2024).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top