Published On: July 22nd 2026
Authored By: Subhiksha M
Sathyabama Institute of Science and Technology, Chennai
Abstract
The development of artificial intelligence has enabled the creation of highly realistic synthetic media known as deepfakes. Although deepfake technology has legitimate applications in entertainment, education and communication, its misuse has raised serious concerns relating to privacy, consent, reputation and intellectual property rights. Deepfakes can facilitate identity theft, misinformation, financial fraud and non-consensual intimate imagery, thereby exposing gaps in existing legal frameworks. In India, remedies are scattered across the Information Technology Act, 2000, the Copyright Act, 1957, the Digital Personal Data Protection Act, 2023 and the Bharatiya Nyaya Sanhita, 2023; however, these laws were not specifically designed to regulate AI-generated content. This article examines the impact of deepfakes on privacy, consent and intellectual property rights, analyses the adequacy of existing Indian laws and compares regulatory approaches adopted by the European Union, the United States and China. It argues that India requires a specialised legal framework that recognises personality rights, strengthens platform accountability and provides effective remedies to victims.
Keywords: Deepfake Technology, Artificial Intelligence, Privacy, Consent, Personality Rights, Intellectual Property Rights.
I. Introduction
Artificial intelligence has transformed digital content creation and given rise to deepfake technology, which enables the generation of highly realistic audio, video and image content. While the technology has beneficial applications in entertainment, education and accessibility, its misuse has created significant legal and ethical challenges. Deepfakes can manipulate facial expressions, voices and mannerisms with remarkable accuracy, making them capable of spreading misinformation, facilitating fraud and damaging reputations.
Deepfakes derive their name from the combination of “deep learning” and “fake” and are primarily created through Generative Adversarial Networks (GANs). These systems analyse extensive data to replicate human characteristics with high precision. As access to such technology becomes easier, concerns relating to privacy and misuse have increased.
The unauthorised use of an individual’s image or voice directly affects the right to privacy protected under Article 21 of the Constitution. In Justice K.S. Puttaswamy (Retd.) v. Union of India,[1] the Supreme Court recognised privacy as a fundamental right encompassing dignity and informational autonomy. Deepfakes therefore threaten constitutional protections by creating fabricated representations without consent.
Deepfakes also raise concerns regarding personality rights and intellectual property. Celebrities and ordinary individuals may suffer unauthorised commercial exploitation of their identity. Although Indian courts have recognised personality rights through judicial decisions, statutory protection remains absent. Existing laws such as the Information Technology Act, 2000, the Copyright Act, 1957 and the Digital Personal Data Protection Act, 2023 provide only fragmented remedies and do not comprehensively address AI-generated content.
II. Understanding Deepfake Technology
Deepfake technology refers to AI-generated synthetic media capable of producing manipulated images, videos and audio that closely resemble reality. These systems rely upon deep neural networks and GANs, where one network generates content and another evaluates its authenticity. Through repeated iterations, the generated content becomes increasingly convincing.
Despite these concerns, deepfakes have several legitimate uses. In the entertainment industry, they are employed for visual effects, film restoration and dubbing. AI-generated voice technologies also assist individuals with speech impairments and facilitate language translation, while educational institutions use such technologies for historical recreations and digital learning.
However, misuse has become widespread. Non-consensual intimate imagery, political misinformation and financial fraud represent some of the most dangerous applications. Fabricated videos can influence elections, while voice-cloning technologies have enabled impersonation and cybercrime. Deepfakes also create reputational damage by falsely depicting individuals engaging in unlawful or immoral activities.
The challenge before lawmakers is therefore to regulate harmful uses without preventing technological innovation.
III. Deepfakes and the Right to Privacy
Privacy forms an integral part of Article 21 of the Constitution of India. It includes informational privacy, dignity and personal autonomy. Deepfakes interfere with these protections because they enable the manipulation and dissemination of an individual’s identity without consent.
In Justice K.S. Puttaswamy (Retd.) v. Union of India,[1] the Supreme Court recognised privacy as a fundamental right and emphasised the importance of informational self-determination. Deepfake technology undermines these principles by replicating facial expressions and voice patterns without authorisation.
Similarly, in R. Rajagopal v. State of Tamil Nadu,[2] the Supreme Court held that individuals possess the right to prevent unauthorised publication of their private affairs. Although the judgment predated AI, its principles remain relevant in cases involving fabricated content.
Deepfakes also raise concerns relating to data protection because their creation often involves collecting photographs and videos from social media platforms without consent. Victims, particularly women and public figures, frequently experience psychological trauma and reputational harm due to non-consensual intimate deepfakes.
While freedom of speech under Article 19(1)(a) remains important, Article 19(2) permits restrictions in the interests of defamation, morality and public order. Therefore, future regulation must balance privacy rights with freedom of expression.
IV. Consent and Personality Rights
Deepfakes raise serious issues concerning consent and the unauthorised exploitation of identity. They allow third parties to replicate a person’s voice, face and mannerisms without permission, thereby violating dignity and autonomy.
Personality rights refer to an individual’s right to control the commercial use of their identity. Although Indian legislation does not expressly recognise such rights, courts have gradually developed protection through judicial interpretation.
In ICC Development (International) Ltd. v. Arvee Enterprises,[3] the Delhi High Court recognised the right of publicity and held that celebrities possess proprietary interests in their identity. This principle was further strengthened in Amitabh Bachchan v. Rajat Nagi & Ors.,[4] where the court restrained unauthorised use of the actor’s image and personality attributes through an ex-parte, ad-interim injunction covering both named and unknown (“John Doe”) defendants.
Similarly, in Anil Kapoor v. Simply Life India & Ors.,[5] the Delhi High Court protected the actor’s voice, image and signature expressions, including AI-morphed and deepfake misuse of his persona, against unauthorised commercial exploitation. The court acknowledged that technological developments necessitate stronger protection of personality rights.
However, these protections largely benefit celebrities. Ordinary individuals remain vulnerable because personality rights have not yet received statutory recognition. Therefore, legislation is required to provide comprehensive protection to all persons against AI-based identity misappropriation.
V. Impact on Intellectual Property Rights
Deepfake technology raises several challenges relating to copyright and ownership. AI systems rely upon existing photographs, videos and audio recordings, many of which are protected under the Copyright Act, 1957. Unauthorised use of such materials may constitute copyright infringement.
Another important issue concerns training datasets used by AI systems. Deep learning models require large amounts of data, often collected from publicly accessible sources. Since Indian copyright law does not specifically address machine learning, uncertainty exists regarding whether such use amounts to infringement.
Questions also arise regarding ownership of AI-generated works. Section 2(d) of the Copyright Act provides that the author of a computer-generated work is the person who causes the work to be created. However, increasing AI autonomy complicates the application of traditional concepts of authorship.
Performers’ rights under Sections 38 and 38A also become relevant because deepfake technologies can replicate voices and performances without consent. Furthermore, unauthorised use of celebrity identities in advertisements may amount to passing off and unfair competition.
Thus, existing intellectual property laws require adaptation to address the challenges posed by AI-generated content.
VI. Existing Indian Legal Framework
India currently lacks dedicated legislation regulating deepfakes. Instead, remedies are scattered across different statutes.
Information Technology Act, 2000
Section 66C criminalises identity theft. Section 66D penalises cheating by personation. Sections 67 and 67A prohibit obscene and sexually explicit electronic content. These provisions can address certain deepfake-related harms but do not specifically regulate AI-generated media.
Digital Personal Data Protection Act, 2023
The Act establishes a consent-based framework for personal data processing. Since deepfakes often rely on personal data, unauthorised use may violate its provisions; however, the Act does not expressly address synthetic media.
Bharatiya Nyaya Sanhita, 2023
Deepfakes may attract offences relating to forgery, defamation, cheating and criminal intimidation. Nevertheless, these provisions are general in nature and do not specifically deal with AI technologies.
Copyright Act, 1957
The Act protects copyrighted works and performers’ rights, but it provides no clarity regarding AI-generated content and machine-learning datasets.
Overall, India’s legal framework remains fragmented and reactive.
VII. Comparative Approaches
European Union
The European Union Artificial Intelligence Act, 2024 adopts a risk-based approach and imposes transparency obligations on AI-generated content. The General Data Protection Regulation (GDPR) further strengthens privacy protection by regulating personal data processing.
United States
The United States follows a decentralised approach. States such as California and Virginia have enacted laws addressing deepfake pornography and electoral manipulation. Publicity rights also provide protection against unauthorised commercial exploitation.
China
China has adopted one of the strictest approaches. Its 2023 Deep Synthesis Regulations require mandatory labelling of AI-generated content and impose obligations upon digital platforms to detect and remove harmful material.
These international developments demonstrate the growing importance of specialised regulation.
VIII. Need for Legal Reforms
Several deficiencies exist within the Indian legal framework:
1. Absence of dedicated legislation governing deepfakes.
2. Lack of statutory recognition of personality rights.
3. Uncertainty regarding the liability of creators, platforms and developers.
4. Inadequate platform accountability mechanisms.
5. Limited remedies available to victims.
6. Cross-border enforcement difficulties.
These shortcomings highlight the need for comprehensive reforms.
IX. Recommendations
India should adopt a specialised legal framework that includes:
• A statutory definition of deepfakes.
• Recognition of personality rights for all individuals.
• Mandatory labelling and watermarking of AI-generated content.
• Greater accountability for digital platforms.
• Fast-track remedies and compensation mechanisms for victims.
• International cooperation in regulating synthetic media.
• Public awareness and digital literacy programmes.
Regulation should focus on preventing misuse while encouraging beneficial applications of artificial intelligence.
X. Conclusion
Deepfake technology represents one of the most significant legal challenges of the digital age. Although AI offers immense opportunities, its misuse threatens privacy, consent, reputation and intellectual property rights. Existing Indian laws provide only fragmented remedies and fail to address the unique characteristics of synthetic media.
Judicial decisions such as Justice K.S. Puttaswamy v. Union of India, ICC Development v. Arvee Enterprises, Amitabh Bachchan v. Rajat Nagi and Anil Kapoor v. Simply Life India demonstrate judicial willingness to adapt existing principles to new technologies. Nevertheless, judicial intervention alone is insufficient.
India must therefore adopt a comprehensive legal framework recognising personality rights, strengthening platform accountability and ensuring effective remedies for victims. A balanced approach based on transparency, accountability and constitutional values would enable India to harness the benefits of artificial intelligence while safeguarding privacy, dignity and intellectual property rights in the digital era.
References
[1] Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 (India).
[2] R. Rajagopal v. State of Tamil Nadu, (1994) 6 SCC 632 (India).
[3] ICC Development (International) Ltd. v. Arvee Enterprises, 2003 (26) PTC 245 (Del) (India).
[4] Amitabh Bachchan v. Rajat Nagi & Ors., CS(COMM) 819/2022 (Del. H.C. Nov. 25, 2022) (India).
[5] Anil Kapoor v. Simply Life India & Ors., CS(COMM) 652/2023, 2023 SCC OnLine Del 6914 (Del. H.C. Sept. 20, 2023) (India).
- Information Technology Act, No. 21 of 2000, INDIA CODE (2000).
- Copyright Act, No. 14 of 1957, INDIA CODE (1957).
- Digital Personal Data Protection Act, No. 22 of 2023, INDIA CODE (2023).
- Bharatiya Nyaya Sanhita, No. 45 of 2023, INDIA CODE (2023).
- Regulation (EU) 2024/1689 of the European Parliament and of the Council (Artificial Intelligence Act), 2024 O.J. (L 1689).
- Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation), 2016 O.J. (L 119) 1.
- Cyberspace Administration of China, Provisions on the Administration of Deep Synthesis Internet Information Services (2023).




