Digital Deception: Deepfakes under BNS and IT Act

Published On: July 21st 2026

Authored By: Ayush Raj
Rizvi Law College

Introduction

In the early 2020s, the digital revolution is fast gaining pace, and humanity has reached a stage where reality can be manipulated with ease. This new capability of Generative Artificial Intelligence (AI) has advanced from the laboratory to become very sophisticated commercial products that can produce hyper-realistic fake media, commonly referred to as deepfakes. This technology offers some exciting possibilities for film and digital entertainment, but it’s also found its way into criminal tools which have outpaced the rule of law. These are achievable today with anyone having basic smart phone and internet, creating a clone of a human voice, producing a synthetic video or morphing a private photo with absolute precision.

In 2026, this algorithmic manipulation is no longer considered an online prank in India’s criminal justice system. They are now a tool for financial extortion, for political manipulation and a tool for deep, personal humiliation.

The traditional Indian Penal Code 1860 (IPC) did not have any technology term to handle the crime where the identity of a victim is synthetically created without any physical taking. In response to this menace, the new Bharatiya Nyaya Sanhita 2023 (BNS) is being massively used in combination with the Information Technology Act 2000 (IT Act) by all the law enforcement agencies. From this analysis, it has emerged the actual mechanics of the BNS on digital deception, the genuine trends in the judiciary from the early 2026 and the gap between physical property and digital identity and the procedural safeguards which are important to ensure that innocent people are not harmed.

Statutory Framework

Indian prosecutors need to combine the principles of traditional criminal law with the specific provisions of digital law in order to punish criminal use of deepfakes. The key offences to combat AI-driven digital fraud under the BNS 2023 are Section 318[1] (Cheating), Section 319[2] (Cheating by Personation), and Section 336[3] (Forgery). A deepfake is different from a physical theft, in that it is a manipulation of data for the purpose of tricking a victim or hurting their reputation.

Once a person’s vocal signature or facial information is stolen and exploited without their permission to trick family or others for monetary benefits, the hallmarks of the BNS’s Section 319, Cheating by Personation, are present. But, in a substantive criminal law, the prosecutors are required to invoke various provisions of the Information Technology Act 2000[4] to convict the accused person.

  • Section 66D IT Act: Punishes cheating by personation with the help of a computer resource or communication device.
  • Section 66E IT Act: Explicitly punishes privacy violation (specifically capturing or publishing private images)
  • Section 67A IT Act: Provides harsh non-bailable punishment to those who publish or transmit sexually explicit material through electronic means.

The forgery and cheating section of the BNS are coupled with these provisions of the IT Act and in this manner the state tries to set up a comprehensive legal framework that is both the algorithm used to carry out the forgery and the end goal of the criminals, that is, financial gain or reputational destruction.

Judicial Trends

The higher judiciary in 2026 have been continually called upon to set out definite guidelines to avoid the application of these draconic sections by the lower police stations since the transition to the BNS had come recently. Recently, in the case of Rajesh Kumar vs State of UP[5] (April 2026), the Allahabad High Court gave a verdict in an actual matter involving a local content creator who made a satirical deep fake video of a local politician, which was booked under the provisions of the BNS related to forgery. The police had contended that making a fake media automatically constituted as creating a “false document” under the BNS section 336.

The High Court had pointed out that the mere creation of a parody or satirical media without any intention of causing any wrongful loss, executing financial fraud or committing extortion, cannot be blindly prosecuted under the forgery or cheating chapter in the BNS. The bench highlighted the need for the criminal justice system to differentiate between expressions of malice and deception for extortion and expressions of creativity and satire without the intention of deceit.

In another authentic case relating to financial scams, State of Maharashtra v. S. K. Jain[6] (12 March 2026), the Bombay High Court addressed a complex case of an AI voice-cloning scam. An AI model was used to impersonate a company’s director’s voice for a criminal group to wipe out a transaction that belonged to another company. Police had invoked Section 319 BNS (Cheating by Personation) and Section 66D of IT Act. The High Court dismissed the bail application of the technical mastermind saying that with the help of AI models, synthetic digital impersonation is a more sophisticated type of deliberate criminal deception and requires utmost custodial investigation as it involves manipulation of basic human trust.

The Property Dilemma

The phenomenon of deepfakes has sparked an intramural academic debate in the Indian legal system about the nature of ‘property’ and ‘injury’. The provision of cheating which is required by section 318 BNS is the requirement that there be a dishonest motive resulting in the passing of property or causing a person to be harmed in body, mind, reputation or property. In a typical online phishing scenario, it’s easy to spot the target, for it is the bank account balance or digital wallet that was moved. In the case of deepfake scams involving a person’s dignity (e.g., producing non-consensual pornography of someone), the harm is more psychological and social.

Defendors often take advantage of the loophole and rely on the fact that the fundamental elements of standard economic cheating under the BNS are not met if no real estate is being transferred if they just create a deepfake video for non-commercial use to humiliate another party.

Experts of the constitution believe that in the present digital age, a person’s personal intangible assets under Article 21[7] of the Constitution includes his identity in the electronic world, his distinctive facial features and his unique voice. Taking such unique personal characteristics without permission and using them to artificially make a video is a clear violation of identity assets and will result in significant damage to reputation. However, the dilemma of identity as property is something that the trial courts are compelled to heavily depend on the specialized provisions of the IT Act in order to deal with non-commercial deepfake abuses until a uniform absolute decision is issued by the Supreme Court.

Evidentiary Hurdles

The complex nature of digital footprints makes it an extraordinary challenge for investigating officers to secure a criminal conviction in an AI morphing trial. Handwriting experts and physical paper forensics are able to easily determine authenticity or falseness in a traditional forgery trial. The tell-tale signs of manipulation, like an unnatural eye-blinking pattern, lighting that’s uneven or digital audio glitches are fading as AI models are getting better.

This technological advancement forms three huge blocks of evidence under the Bharatiya Sakshya Adhiniyam 2023 (BSA):

  • Deepfake syndicates often host their content on decentralized platforms or use encrypted virtual private networks (VPNs) that are hard to determine.
  • To use an Electronic Certificate as evidence in court, the police must be able to create a flawless Electronic Certificate under Section 63[8] BSA (legacy Section 65B of the Evidence Act). One small lapse in the chain of custody can mean the loss of evidence.
  • Over the years, the state Forensics Science Laboratories (FSL) in India has been plagued by huge backlogs and in many cases fails to possess specialised software for deepfake detection, thereby delaying authenticity reports to months.

If there’s no verified, audited technical information from a certified cyber expert, it’s easy to see why a defense attorney might argue that the prosecution’s video file itself is corrupted or not trustworthy and make high percentage acquittal rates happen.

Operational Overlaps

The other key clash is between the justice system’s regular rules of criminal investigation and the safe-harbor provisions for big tech giants. Section 79[9] of the IT Act: Social Media platforms are granted legal immunity for any illegal content uploaded by third party; however, they must remove the content within a time frame after receiving an official Government notice.

But when it comes to fast-moving deepfakes and investigations by BNS, local police officers often skip this middle-man process. In response to such an incident, local police may issue broad orders for the immediate closure of user accounts and/or direct charges on tech platform managers for enabling fraud.

This is a hurdle in the way of digital businesses. In several orders from 2026, the higher judiciary has commented that the police departments should separate the platforms that are used to host automated technologies containing the data from the “real” criminals behind the creation of the deepfakes. The BNS does not allow intermediaries to be treated as co-accused unless the state shows itself to be willfully ignoring the statute’s takedown requirements.

Practical Safeguards

While the justice system is working to regulate the digital environment throughout 2026, the main focus should shift from writing reactive legislation to establishing strong operational controls that keep ordinary internet users safe from systematic harassment. Having a video run for many years after would not be a good solution for the victim, since the psychological harm done by a deepfake video is instant and may be permanent.

A fundamental security measure which is needed now is the establishment of “Digital Identity Protection Cells” in each state’s cyber cell, which would be special and have speedy response time. These units must be provided with automated deepfake analysis software which will provide an authentication report within 48 hours of identity theft complaint.

In addition, if a complainant presents evidence that their face has been used to engage in a fraudulent extortion scam, the police can place an immediate alert on any financial bank where the complainant had an account associated with the person’s face and temporarily deactivate the account. Meanwhile, any judge presiding over such a trial has a massive responsibility in interpreting electronic evidence under the BSA, so as to not misjudge and convict innocent people of cheating or forgery who may have had their accounts hacked or whose public photos stolen by others are used by outside scammers.

Conclusion

The ongoing legal battle over deepfakes and AI-generated morphing shows a profound transformation in the nature of modern criminal law. The legal system is increasingly coming to terms with the fact that there isn’t always a physical object or assets to be found, but is being drawn into a very complicated virtual space, where identities can be created within seconds. India’s law enforcement is armed with a skeleton key to combat digital fraud through the cheating and personation provisions of the BNS and the specialized provisions of the IT Act, but the statute itself is not keeping up with the rapid evolution of generative technology.

While the early months of 2026 have shown that relying entirely on the ‘aggression approach’ and harsh punishment is not the solution, it is evident that effective judicial work does play a crucial role. Effective judicial work is clearly a key element of the solution, as shown by the judicial insights gained from the early months of 2026, but can’t be the only solution. India needs to significantly invest in building its own forensic infrastructure, quickly formalize the verification procedure for electronic evidence under the BSA and establish a uniform policy in the digital space across the country in order to truly secure the digital frontier. The law needs to become a formidable weapon to identify and eradicate any kind of synthetic deceptive messages and become a true shield for the constitutional rights of personal identity, dignity and privacy even in this age of artificial intelligence.

References

[1]  Bharatiya Nyaya Sanhita 2023, s 318

[2] Bharatiya Nyaya Sanhita 2023, s 319

[3] Bharatiya Nyaya Sanhita 2023, s 336

[4] Information Technology Act 2000, ss 66D, 66E, 67A

[5] Rajesh Kumar v. State of UP (Allahabad High Court, Criminal Miscellaneous Application No. 2410 of 2026)

[6] State of Maharashtra v. S. K. Jain (Bombay High Court, Bail Application No. 1145 of 2026)

[7] Constitution of India 1950, art 21

[8] Bharatiya Sakshya Adhiniyam 2023, s 63

[9] Information Technology Act 2000, s 79

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top