Published On: August 20, 2026
Authored By: Kalpita Krishnakumar
Woxsen University
Abstract
Generative AI and synthetic media — digital content, including images, text, video, and audio, that is wholly or partly generated or modified with the help of Artificial Intelligence rather than traditional human creation, commonly known as deepfakes — are rapidly evolving. They pose a growing challenge to democratic governance, electoral integrity, informational autonomy, and public trust in India. The legal framework governing these technological developments remains largely reactive, responding to harm only after it has occurred.
This article argues that the current legal framework is scattered across different statutes and focuses primarily on criminalisation. By concentrating on punishing individuals after irreversible reputational harm has occurred, the state fails to address the core drivers of the crisis: systemic platform design, algorithmic amplification, and the absence of AI-developer accountability.
By comparing and analysing emerging regulatory frameworks in the European Union, the United Kingdom, the United States, and China, this paper critiques the limitations of the IT Act, 2000, the BNS, 2023, and the DPDP Act, 2023. It concludes by proposing a comprehensive, preventive, and accountability-driven model that shifts the burden of compliance from the vulnerable user to developers and social media intermediaries, thereby safeguarding democratic discourse without compromising constitutional free speech.
Keywords: Deepfakes, Artificial Intelligence, Democracy, Platform Liability, Digital Governance.
I. Introduction
The global information environment is undergoing disruption due to the democratisation of generative Artificial Intelligence. One of the most consequential disruptions arising from this technological development is the creation of “deepfakes” — realistic manipulations of audio, video, and images generated using deep learning architectures. Historically, such manipulation required specialised software and highly trained human expertise. Today, the process has become far easier, with open-source models and commercial mobile applications allowing any individual to generate synthetic media within minutes.
India does not yet have a dedicated framework for addressing deepfakes. Several statutes, including the DPDP Act[1] and the IT Act,[2] touch upon AI use, but India lacks a consolidated law addressing artificial intelligence comparable to the EU AI Act.[3]
One of the central challenges today is how to regulate the authorities, creators, and amplifiers of AI-generated content, rather than relying solely on criminalising the act after the fact.
II. Why Deepfakes Matter
Deepfakes affect democracy in at least four ways. First, they can spread falsehoods at scale by mimicking political leaders, candidates, journalists, or institutions, making it difficult for ordinary users to distinguish real speech from manipulation. Second, they can intensify polarisation by triggering outrage before fact-checking catches up, which is especially dangerous during campaigns and polling periods. Third, they can silence women, activists, and minorities through sexualised or humiliating fabrications that chill participation in public life. Fourth, they can erode the credibility of genuine evidence by encouraging a general “liar’s dividend,” where authentic footage is dismissed as fake.
This makes deepfakes a constitutional problem, not merely a cybercrime problem. They implicate free speech, privacy, dignity, reputation, equality, and the integrity of elections — all of which sit at the heart of Articles 19 and 21.[4]
III. Current Indian Law
India does not yet have a dedicated deepfake statute. Instead, the present framework is pieced together from the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021,[5] general criminal law, election law, and constitutional remedies. In practice, this means the legal system can sometimes respond to the consequences of deepfakes — such as impersonation, defamation, obscenity, fraud, or privacy violations — but it often lacks a clear rule governing the synthetic media itself.
The 2023 MeitY advisory and related compliance expectations focus on intermediary due diligence, misleading content, and impersonation, including the duty to curb deceptive material and inform users of legal consequences. The Election Commission has gone further in election contexts, directing political parties to refrain from circulating deepfake audio or video and to remove such material quickly, with advisories emphasising responsible and ethical use of AI in campaigns. These are important steps, but they remain administrative and reactive rather than a comprehensive framework of statutory accountability.
The existing framework still leaves many issues unaddressed, making it difficult for individuals to prove that a given image or video is fake. This ambiguity also cuts the other way: individuals can dismiss genuine footage as a deepfake, denying real evidence and harming the opposing party. These gaps make it increasingly necessary for India to adopt a single, consolidated law to address these issues.
IV. Constitutional Stakes
Deepfakes place considerable strain on both speech and democracy. On one hand, overbroad regulation could chill parody, satire, commentary, artistic remix, and legitimate political criticism — all protected forms of expression under Article 19(1)(a), subject to reasonable restrictions.[6] On the other hand, leaving synthetic manipulation largely unregulated weakens the conditions that make meaningful speech possible, since democratic debate depends on a baseline of truthful identity, attribution, and authenticity.
Every journalist, content creator, and individual has the right to create content of their choosing, a right protected as a fundamental freedom. But it is increasingly difficult to determine whether such content is an original creation or has been generated with AI.
Even in schools, colleges, and workplaces, the growing use of AI to generate content for projects and assignments raises concerns about the erosion of independent thinking and creativity, undermining the very purpose of such assignments. What is particularly striking is that even institutions themselves are increasingly relying on AI to design assignments — illustrating the depth of the problem deepfakes and generative AI now pose.
Article 21 matters because deepfakes can invade privacy, autonomy, and dignity in highly personal ways. The Supreme Court’s recognition of privacy as part of Article 21 provides a strong constitutional basis for restraining non-consensual synthetic impersonation, particularly where a person’s face, voice, or likeness is used without permission. In that sense, deepfake law in India should be understood as a rights-balancing exercise: protecting expression while preventing algorithmic deception and exploitation.
V. Judicial Responses
Indian courts have consistently treated personality rights as a meaningful remedy against deepfake misuse. Recent Delhi High Court orders in cases involving public figures have restrained the unauthorised use of names, images, voices, and likenesses, including AI-generated and deepfake content, and have ordered takedown actions against online intermediaries. These orders reflect judicial recognition that digital identity carries commercial and reputational value, and that courts cannot ignore synthetic exploitation in the age of AI.
However, litigation-based relief has its limits. Court orders are typically individualised, time-consuming, and dependent on a plaintiff’s resources and vigilance. They can protect a celebrity or public figure but are far less effective for ordinary citizens, political workers, journalists, or women targeted by fabricated sexual content. This is why personality-rights litigation, though important, cannot substitute for a broader regulatory architecture.
VI. Gaps in Enforcement
The Indian framework still suffers from three major gaps. First, the law is fragmented, with the IT Act, IT Rules, criminal provisions, election directives, and court-made doctrines operating in parallel rather than as a coherent system. Second, enforcement is mostly post-harm, meaning material is removed only after it has already been viewed, shared, screenshotted, or re-uploaded. Third, attribution remains weak: many users, creators, and ad buyers operate through anonymous accounts, offshore tools, or encrypted networks, making accountability difficult.
These gaps become especially acute given that individuals can level false allegations against people they dislike, leaving the accused with little time or means to disprove them. This causes real reputational harm amounting to defamation. In an era of pervasive AI-generated content, India needs a framework that protects reputations before damage occurs, or that establishes a reliable means of identifying which content is AI-generated and which is not.
This creates a structural imbalance: harmful content spreads quickly, while the law moves slowly. A deepfake can influence an election within hours, while a takedown notice, police complaint, or civil suit may take days or weeks. Even where the content is eventually removed, the democratic damage may already be done.
VII. Why Criminalisation Is Not Enough
Criminal law is necessary but insufficient. Penal provisions can punish impersonation, cheating, defamation, obscenity, or election misconduct, yet they do not, by themselves, create preventive duties, technical standards, or platform architecture for authenticity. Criminalisation also tends to focus on individual culpability after the offence, while deepfake ecosystems are typically distributed across creators, advertisers, platforms, forwarding networks, and monetisation chains.
A purely punitive model also risks selective enforcement. When the state relies mainly on arrest or prosecution, smaller users may be targeted while larger platform failures remain unaddressed. For democratic integrity, the more important question is often not only “who should be punished?” but “who must design the system to prevent harm in the first place?” That is the logic of regulatory accountability.
The underlying logic is that the actual wrongdoer should be held responsible, rather than blame circulating without resolution. Clear boundaries need to be established around the permissible use of AI. A punishment-only approach also risks generating false accusations, as seen in practice. The focus, therefore, should not be solely on punishing individuals, but on creating boundaries that developers cannot cross — boundaries that will, in turn, reduce the overuse and harmful use of AI.
VIII. Regulatory Accountability
Regulatory accountability means allocating legal duties across the entire AI content pipeline. Creators should be required to disclose synthetic manipulation where it is likely to mislead. Platforms should maintain rapid notice-and-action systems, preserve evidence, and label or demote high-risk manipulated media. Political actors should face heightened obligations during campaigns, including disclosure of AI-generated material and immediate removal rules for deceptive content. Ad-tech and monetisation networks should also be prevented from profiting from deepfake deception.
This model is particularly valuable because it is preventive, layered, and institutionally realistic. Rather than waiting for a prosecutor to prove intent beyond reasonable doubt, regulators can impose standards of care, transparency, and traceability. This approach does not eliminate free speech; it structures it by making synthetic speech identifiable and accountable — while also reducing the burden on courts.
In a country like India, where millions of cases remain pending, the least that can be done is to introduce a framework that, rather than adding to the burden, helps accelerate the disposal of cases.
IX. Election Safeguards
Elections require a special regime because the democratic harm involved is time-sensitive and irreversible. The Election Commission’s advisories already recognise that AI-generated content and deepfakes can distort campaign fairness, and that political parties should avoid using such material, label synthetic content, and remove harmful posts quickly. This is an important normative shift, as it treats misinformation as a campaign compliance issue rather than merely a criminal one.
However, election safeguards need statutory force, not merely advisory weight. India should consider mandatory disclosure of AI-generated campaign material, provenance tags, accelerated takedown mechanisms during the election period, and special penalties for deceptive synthetic media aimed at voters. A democratically defensible framework would also require platforms to publish transparency reports on election-related deepfake complaints and removals. The aim should be to protect voter autonomy without giving the state a tool to suppress legitimate dissent.
These safeguards should not be limited to the election period alone, but should apply across the country at all times. Elections are not the only context in which deepfakes are used — they are deployed continuously, by a wide range of actors, throughout the country.
X. Rights and Remedies
The most effective Indian response would combine constitutional, civil, and regulatory remedies. Civil remedies should include injunctions, damages, and disclosure orders for identity misuse, supported by stronger recognition of personality rights and privacy interests. Regulatory remedies should include takedown obligations, auditability, provenance labelling, and meaningful penalties for repeated non-compliance by intermediaries. Electoral remedies should include mandatory party-level responsibility for AI content and fast-track grievance resolution during campaign periods.
There is also a strong case for victim-centred support. Ordinary users need accessible complaint systems, legal aid, and emergency takedown support, particularly in cases involving intimate deepfakes or targeted harassment. In a country as large and linguistically diverse as India, legal rules must be accompanied by public awareness and digital literacy, since the first line of defence is often a user’s own ability to recognise manipulation.
XI. Comparative Lessons
Other jurisdictions have begun responding through a mix of disclosure, watermarking, and platform liability, and India can adapt these lessons without adopting them wholesale. The practical lesson is that regulation works best when it is layered: technical provenance standards, intermediary duties, election rules, and clear private remedies operating together. Indian scholarship increasingly points in this direction, urging watermarking, AI accountability, platform responsibility, and public literacy frameworks, rather than relying solely on punishment after the harm has occurred.
Among the most notable international frameworks is the EU AI Act, which comprehensively addresses issues specific to artificial intelligence. India should consider a comparable law and incorporate legislative measures that help regulate the use of synthetic media and deepfakes.
India should not remain a passive observer, responding only after harm has already occurred and proven difficult to reverse through punishment or penalties alone. A person’s reputation, once damaged, cannot easily be restored. It can take a considerable amount of time to establish that footage was fabricated, and less digitally literate sections of society may struggle to grasp the implications of such misuse of AI, making public education an essential part of any solution.
A useful Indian model would therefore be rights-based and context-sensitive. It should distinguish between harmful impersonation, political deception, sexual abuse, and harmless parody. It should penalise deliberate deception more severely where the target is a voter, a child, or a vulnerable person, while preserving space for satire, art, journalism, and legitimate criticism.
XII. Conclusion
India’s deepfake problem is ultimately a governance problem. The legal system has begun to respond through intermediary advisories, election directions, privacy doctrine, and personality-rights injunctions, but these responses remain too fragmented to secure democratic trust at scale. A mature framework must go beyond criminalisation and build regulatory accountability into the architecture of digital communication itself.
The impact of deepfakes now extends well beyond what punishment alone can address. Regulation must strike a balance — enabling people to benefit from AI while protecting them from harm caused by synthetic media and deepfakes.
This means treating deepfakes as a matter of public integrity: requiring disclosure, traceability, rapid removal, platform due diligence, and election-specific safeguards, while preserving lawful speech and satire.
If India wants to protect both democracy and digital innovation, it must regulate synthetic media not as an afterthought, but as a foreseeable risk to constitutional governance.
References
[1] The Digital Personal Data Protection Act, No. 22 of 2023, Acts of Parliament, 2023 (India).
[2] The Information Technology Act, No. 21 of 2000 (India).
[3] Regulation 2024/1689 of the European Parliament and of the Council of 13 June 2024 Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act), 2024 O.J. (L 1689) 1.
[4] India Const. arts. 19 & 21.
[5] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, G.S.R. 139(E), Gazette of India, Extraordinary, pt. II, sec. 3(i) (Feb. 25, 2021).
[6] India Const. art. 19, cl. (1)(a).




