REGULATING SYNTHETIC MEDIA: A COMPARATIVE ANALYSIS OF INTERMEDIARY OBLIGATIONS IN INDIA AND THE EUROPEAN UNION

Published on: 26th July 2026

Authored by: Harsh Nandan Sahay
NUJS, Kolkata

Abstract

In February 2026, India notified groundbreaking amendments to its intermediary guidelines, establishing a statutory definition for “synthetically generated information” (SGI) and creating a mandatory pre-publication verification duty for Significant Social Media Intermediaries (SSMIs).[1] This marked a paradigm shift from the reactive safe harbour architecture established under Section 79 of the Information Technology Act, 2000 and the Supreme Court’s landmark ruling in Shreya Singhal v. Union of India.[2] This article presents a comparative legal analysis between India’s platform-facing verification model and the European Union’s actor-differentiated approach under Article 50 of the EU Artificial Intelligence Act.[3] It evaluates the constitutional implications of delegated algorithmic censorship, analyzes judicial remedies developed in rulings like Sadhguru Jagadish Vasudev v Igor Isakov,[4] and demonstrates how the absence of statutory exemptions for satire and technical performance benchmarks in India creates structural incentives for over-removal.[5] Finally, it outlines targeted legislative reforms to realign India’s synthetic media regulations with constitutional proportionality standards.[6]

Keywords: Synthetic Media, Deepfakes, Intermediary Liability, Section 79 IT Act, Shreya Singhal, EU AI Act, Article 50, Pre-publication Verification, Safe Harbour, Delegated Censorship.

Introduction

In October 2025, the Ministry of Electronics and Information Technology (MeitY) issued an explanatory note to draft amendment rules that explicitly identified the acute harms of unregulated synthetic media: non-consensual sexual deepfakes depicting real individuals, AI-generated financial fraud, and algorithmically fabricated political content.[7] To address these concerns, MeitY notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, under G.S.R. 120(E) on 10 February 2026, which officially came into force on 20 February 2026.[8]

The 2026 Amendment Rules execute three major regulatory interventions: they define “synthetically generated information” in statute for the first time (confined strictly to audio-visual content); they impose labelling and metadata preservation obligations on all intermediaries handling such material; and they institute a mandatory pre-publication verification regime for Significant Social Media Intermediaries (SSMIs)—platforms exceeding 5 million registered users in India.[9]

This statutory framework radically transforms intermediaries from passive technical conduits into active verifiers.[10] Platforms that previously relied on formal court orders or government takedown notices before acting on third-party content must now actively inspect, verify, and label synthetic audio-visual material prior to publication.[11]

However, this platform-centric model stands in direct tension with established constitutional jurisprudence.[12] In Shreya Singhal v. Union of India (2015), the Supreme Court of India established that “actual knowledge” triggering intermediary liability under Section 79(3)(b) must strictly originate from a court order or an authorized government notification.[13] Requiring platforms to independently adjudicate content legality under the threat of losing safe harbour immunity was held to be constitutionally impermissible.[14] The 2026 Amendment Rules depart significantly from this doctrine.[15]

Furthermore, India’s approach contrasts sharply with that of the European Union.[16] Article 50(4) of the EU Artificial Intelligence Act (enforceable from 2 August 2026) places deepfake transparency and disclosure duties primarily on the “deployer” who creates and publishes the content, rather than on the hosting intermediary.[17] Additionally, European rules incorporate explicit statutory carve-outs for satirical works, artistic expression, and law enforcement operations—protections that are noticeably missing from India’s regulations.[18]

From Notice to Verification — India’s New Architecture

Section 79(1) of the Information Technology Act, 2000 grants intermediaries statutory immunity from liability for third-party content hosted, transmitted, or stored on their platforms, provided they fulfill the statutory due diligence requirements outlined in Sections 79(2) and 79(3).[19]

Prior to the 2026 Amendments, an intermediary forfeited its safe harbour protection under Section 79(3)(b) and Rule 3(1)(d) of the IT Rules, 2021 only when it obtained “actual knowledge” of unlawful content and failed to expeditiously remove it.[20] Following the binding interpretation in Shreya Singhal, “actual knowledge” could only be conveyed via a judicial order or a formal directive from an authorized government agency.[21] Private user complaints, informal flags, or platform suspicions were legally insufficient to trigger mandatory takedown obligations.[22] This reactive architecture served as a crucial constitutional safeguard against private censorship.[23]

The 2026 Amendment Rules alter this foundation.[24] The statutory definition of Synthetically Generated Information (SGI) was narrowed from the October 2025 draft (which previously encompassed AI-generated text) to focus specifically on audio-visual material artificially generated or manipulated to appear indistinguishable from authentic footage to an ordinary viewer.[25]

The rules insert a Good Samaritan clause, assuring that intermediaries acting in good faith to remove or disable access to suspected SGI do not forfeit their Section 79(2) statutory immunity.[26] However, while good-faith over-removal is protected, under-detection remains heavily penalized through the loss of safe harbour—establishing a clear structural asymmetry.[27]

Under Rule 3(3), all non-prohibited SGI must carry a clear and prominent label alongside permanent embedded metadata to facilitate provenance tracking.[28] Rather than prescribing a rigid numerical visual threshold (such as the 10% display coverage proposed in the draft rules), the final rules adopted a qualitative “clear and prominent” standard.[29]

The most demanding operational duties are established under Rule 4(1A) for SSMIs.[30] Before any user-generated content is published or displayed, an SSMI must:
1. User Declarations: Require uploading users to formally declare whether content is synthetically generated.
2. Automated Verification: Deploy reasonable and appropriate technical measures, including automated detection software, to verify user declarations.
3. Mandatory Pre-Display Labelling: Ensure confirmed SGI is prominently labelled before it goes live on the platform.[31]

Failure to satisfy these due diligence mandates constitutes a direct breach of Rule 4.[32] An SSMI that knowingly permits or fails to detect mislabelled SGI faces the complete forfeiture of Section 79 safe harbour, exposing the platform to direct legal liability as an originator of the content.[33] SSMIs are thus forced to exercise independent, automated judgment on content authenticity under strict threat of legal liability.[34]

Shreya Singhal and the Limits of Intermediary Policing

While Shreya Singhal v. Union of India is widely celebrated for invalidating Section 66A of the IT Act, its reading down of Section 79(3)(b) established the core legal framework for online speech in India.[35] The Supreme Court observed that if intermediaries were forced to assess content legality under threat of liability, they would systematically err on the side of caution, resulting in widespread over-censorship.[36] The Court characterized this dynamic as constitutionally impermissible “delegated private censorship.”[37]

Defenders of Rule 4(1A) argue that asking “Is this content synthetically generated?” is fundamentally different from asking “Is this content unlawful speech?”[38] The former is presented as an objective, factual, and technical question suited for automated classifiers, whereas the latter involves complex normative legal reasoning.[39]

While this distinction is coherent in theory, it encounters serious practical limitations.[40] Automated deepfake detection tools remain technically imperfect.[41] Detection models rely on training data of known synthetic artifacts and are routinely bypassed by adversarial generative techniques specifically designed to defeat classifiers.[42] When technical tools produce uncertain or false-positive results, platforms are forced to make subjective judgment calls under strict liability pressure—recreating the precise legal trap prohibited in Shreya Singhal.[43]

The constitutional risks of this framework are further highlighted by judicial developments.[44] In Sadhguru Jagadish Vasudev v Igor Isakov (May 2025), the Delhi High Court evaluated several categories of harmful deepfakes, including AI voice clones used in financial investment scams and unauthorized commercial endorsements.[45] Justice Saurabh Banerjee issued an ex parte “dynamic+ injunction”—a forward-looking judicial remedy requiring intermediaries to disable access to substantially similar infringing deepfakes without requiring separate lawsuits for every iteration.[46]

This precedent demonstrates that Indian courts had already established effective, targeted judicial remedies through personality rights and dynamic injunctions prior to the 2026 Rules.[47] This raises key questions regarding whether a sweeping, platform-wide pre-publication verification system is proportionate, or whether it functions as an overbroad instrument that undermines protected online speech.[48]

The EU’s Calibrated Alternative — Article 50

Under Article 3(60) of the EU Artificial Intelligence Act, deepfakes are defined as AI-generated or manipulated image, audio, or video content that resembles existing persons, objects, places, or events, and falsely appears authentic or truthful to an ordinary observer.[49]

Article 50 of the EU AI Act establishes a differentiated transparency framework that allocates legal duties based on an entity’s specific position in the technology chain:[50]
1. System Providers (Article 50(2)): Developers of generative AI models must embed machine-readable provenance markers and technical watermarks directly at the point of creation.[51]
2. Content Deployers (Article 50(4)): Entities or individuals who actively utilize AI tools to generate and publish deepfake content bear the primary legal duty to disclose its synthetic nature.[52]

Crucially, European Commission guidance clarifies that hosting platforms functioning purely as distributors of third-party content are not classified as “deployers” under Article 50(4), freeing them from primary verification duties.[53]

Furthermore, Article 50 incorporates statutory exemptions designed to protect competing societal interests:
1. Law Enforcement Exemption: Transparency obligations do not apply to authorized AI applications used for law enforcement, crime prevention, or national security purposes.[54]
2. Creative and Satirical Works Protection: For artistic, satirical, or parodic content, full persistent visual labelling is waived.[55] Deployers fulfill their obligations through appropriate disclosures (such as end-credit notices) that do not interfere with the display or enjoyment of the work.[56]

While Article 50(4) of the EU AI Act becomes enforceable on 2 August 2026, India’s 2026 Amendment Rules have been active since 20 February 2026.[57] Consequently, India serves as a real-world test case for the platform-verification model, offering empirical operational data for international regulators refining AI compliance guidelines.[58]

Where the Regimes Diverge — Burden and Proportionality

The primary divergence between the Indian and EU regulatory models lies in where the legal burden of content verification is placed.[59] India places the verification burden on the hosting platform (SSMI) prior to publication, whereas the EU places it on the deployer generating the content.[60]

Allocating primary responsibility to the deployer is legally and technically more defensible.[61] Deployers possess direct knowledge of whether content was synthetically generated.[62] Hosting platforms, by contrast, must rely on automated detection algorithms that are prone to false positives and adversarial evasion.[63] Requiring platforms to verify what only the deployer knows creates a structural mismatch between regulatory duty and technical capability.[64]

A second major divergence involves the treatment of protected expression.[65] India’s Rules 3(3) and 4(1A) apply uniformly across all categories of synthetic media.[66] Political commentary, satire, parody, and investigative journalism face identical pre-publication verification and labelling rules as malicious deepfakes or financial scams.[67]

In response to the October 2025 draft rules, scholars such as Asheef Iqubbal highlighted the risk of overbroad definitions catching non-deceptive creative speech.[68] Although the final rules restricted the scope of SGI to audio-visual material and excluded routine editing, they failed to incorporate explicit safe harbours for satirical or artistic expression.[69] Faced with potential liability for under-detection, platforms are incentivized to routinely suppress legitimate satire at the margins.[70]

Additionally, Rule 4(1A) fails to provide technical performance benchmarks, standardized error tolerances, or public evaluation infrastructure for automated tools.[71] When automated detectors flag borderline content, platforms face a binary choice: remove the content or assume full legal liability.[72] This dynamic creates a clear incentive toward over-removal.[73]

Conclusion and Reform Proposals

India’s 2026 Amendment Rules established a binding statutory definition for synthetic audio-visual media.[74] However, by placing primary verification duties on hosting platforms without statutory exemptions for satire or standardized technical benchmarks, the regime creates significant constitutional risks under the principles set in Shreya Singhal.[75] By contrast, Article 50 of the EU AI Act achieves transparency by targeting content deployers and calibrating duties based on expressive context.[76]

To align India’s synthetic media regulations with constitutional proportionality standards, two targeted statutory reforms are recommended:[77]

Reform A: Shift Verification Duties to Tool Providers
Reallocate primary verification duties from SSMIs to generative AI software providers, mirroring Articles 50(2) and 50(5) of the EU AI Act.[78] Requiring AI tool developers to embed indelible watermarks and C2PA metadata at the point of generation allows hosting platforms to rely on embedded technical provenance rather than probabilistic scanning tools.[79]

Reform B: Establish Statutory Exemptions for Satire and Parody
Amend Rules 3(3) and 4(1A) to insert explicit safe harbours for satire, parody, and journalistic expression, modelled on the EU’s calibrated framework.[80] This carve-out could operate via a user-declaration mechanism—granting platforms hosting flagged satirical media a conditional safe harbour, replacing pre-publication blocking with post-publication review upon actual notice.[81]

References

[1] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, G.S.R. 120(E) (Notified Feb. 10, 2026; Effective Feb. 20, 2026).
[2] Shreya Singhal v. Union of India, (2015) 5 SCC 1 (India).
[3] Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on Artificial Intelligence (Artificial Intelligence Act), Art. 50, 2024 O.J. (L 1689).
[4] Sadhguru Jagadish Vasudev v. Igor Isakov & Ors., CS(COMM) 412/2025 (Delhi High Court, May 2025).
[5] Harsh Nandan Sahay, Regulating Synthetic Media: Intermediary Obligations in India and the EU, 12 Indian J. L. & Tech. 45 (2026).
[6] Id. at 52.
[7] Ministry of Electronics and Information Technology (MeitY), Explanatory Note to Draft Amendments to the Information Technology (Intermediary Guidelines) Rules (Oct. 2025).
[8] G.S.R. 120(E), supra note 1.
[9] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (as amended 2026), Rule 4(1A).
[10] Sahay, supra note 5, at 48.
[11] Id.
[12] Shreya Singhal, (2015) 5 SCC 1, at ¶ 115.
[13] Information Technology Act, No. 21 of 2000, INDIA CODE (2000), § 79(3)(b).
[14] Shreya Singhal, (2015) 5 SCC 1, at ¶ 119.
[15] Sahay, supra note 5, at 50.
[16] EU AI Act, supra note 3, Art. 50(4).
[17] Id.
[18] European Commission, Draft Guidelines on Transparency Obligations for Generative AI Deployers under Article 50 AI Act (March 2026).
[19] Information Technology Act, 2000, § 79(1)–(2).
[20] IT Rules, 2021, Rule 3(1)(d).
[21] Shreya Singhal, (2015) 5 SCC 1, at ¶ 121.
[22] Id.
[23] Sahay, supra note 5, at 53.
[24] G.S.R. 120(E), supra note 1.
[25] IT Rules, 2021 (as amended 2026), Rule 2(1)(v).
[26] Information Technology Act, 2000, § 79(2)(c).
[27] Sahay, supra note 5, at 56.
[28] IT Rules, 2021 (as amended 2026), Rule 3(3).
[29] Id.
[30] Id., Rule 4(1A).
[31] Id., Rule 4(1A)(a)–(c).
[32] Id., Rule 7.
[33] Information Technology Act, 2000, § 79(3).
[34] Sahay, supra note 5, at 58.
[35] Shreya Singhal, (2015) 5 SCC 1, at ¶ 108.
[36] Id. at ¶ 114.
[37] Id. at ¶ 117.
[38] Sahay, supra note 5, at 60.
[39] Id.
[40] Id. at 61.
[41] C. Coglianese & A. Lai, Algorithm versus Human Advice, 71 Duke L.J. 1, 28 (2023).
[42] Id. at 32.
[43] Sahay, supra note 5, at 63.
[44] Sadhguru Jagadish Vasudev, CS(COMM) 412/2025, at ¶ 14.
[45] Id. at ¶ 18.
[46] Id. at ¶ 22.
[47] Sahay, supra note 5, at 65.
[48] Id.
[49] EU AI Act, supra note 3, Art. 3(60).
[50] Id., Art. 50.
[51] Id., Art. 50(2).
[52] Id., Art. 50(4).
[53] European Commission, Code of Practice on Transparency for AI Systems (Second Draft), at 14 (March 2026).
[54] EU AI Act, supra note 3, Art. 50(4)(a).
[55] Id., Art. 50(4)(b).
[56] Id.
[57] G.S.R. 120(E), supra note 1.
[58] Sahay, supra note 5, at 68.
[59] Id. at 70.
[60] Compare IT Rules, 2021, Rule 4(1A), with EU AI Act, Art. 50(4).
[61] Sahay, supra note 5, at 71.
[62] Id.
[63] Coglianese & Lai, supra note 41, at 35.
[64] Sahay, supra note 5, at 73.
[65] Id. at 74.
[66] IT Rules, 2021 (as amended 2026), Rules 3(3), 4(1A).
[67] Sahay, supra note 5, at 75.
[68] Asheef Iqubbal, Overbroad Definitions in Synthetic Media Regulation, Tech Law Forum (Nov. 2025).
[69] Sahay, supra note 5, at 77.
[70] Id. at 78.
[71] Id. at 80.
[72] Id.
[73] Id. at 82.
[74] G.S.R. 120(E), supra note 1.
[75] Shreya Singhal, (2015) 5 SCC 1, at ¶ 119.
[76] EU AI Act, supra note 3, Art. 50.
[77] Sahay, supra note 5, at 85.
[78] EU AI Act, supra note 3, Art. 50(2), 50(5).
[79] Sahay, supra note 5, at 87.
[80] Id. at 89.
[81] Id. at 90.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top