Deepfakes and The Law: How Ready is India for AI Generated Misinformation?

DEEPFAKES

This article is written by Nainika Shivaram, a 3rd- year law student at MKPM RV Institute of Legal Studies, with a keen interest in Corporate law.

Introduction:

The advent of AI has enabled the generation of authentic-looking and authentic-sounding content even if it hasn’t occurred in reality. Faces can be put on his or her body, voices can be mimicked, and a completely made-up event can be made to be a true one. There are many valid applications for this technology in the entertainment, education, advertising and other sectors. The same technology can be hazardous when used for misinformation, however.

This is where deepfakes come into the picture and pose a legal issue. Unlike a plain old lie, a deepfake can give you visual and/or audio “evidence” of something that never really occurred. If they see and hear a speaker giving a statement and feel that the person can be seen and heard, he/she may feel that the statement is true. When the time comes for the video to be debunked, it could have been viewed thousands or millions of times.

The same issue has now started to become a problem in India too. Content created by AI and manipulated is utilized in political campaigns, impersonation, fraud, harassment/attacks on individual reputations. The law, however, has not taken shape in any particular piece of legislation relating to deepfakes. Rather, a number of already in place laws and regulatory provisions are being applied to various facets of the problem.

The Bharatiya Nyaya Sanhita, 2023, Information Technology Act, 2000 and the Information Technology Rules, 2021 as amended in 2026, the Digital Personal Data Protection Act, 2023 and directions of the Election Commission of India are all relevant. Today the only question to consider is if these laws are sufficient to handle technology that is able to generate and spread false information at a rate much quicker than the speed of the legal system.

What is deepfakes and fake information?

Normally, the term “deepfake” is associated with digitally manipulated or AI-generated sound, photo or video that looks like a person or event that is not. Some of the typical examples include face swapping and voice cloning. Another possible way to make a deep fake is to create an event that never occurred, and insert it into an authentic recording.

The 2026 amendments to the IT Rules have added the term “synthetically generated information (SGI)”. It includes audio, visual and audio-visual content which has been artificially or algorithmically created, generated, modified or altered and so appears real or authentic. The rules also acknowledge that any changes made for the purposes of normal editing, formatting and accessibility modifications should not be deemed to be deceptive synthetic content.

This is a significant difference. The issue isn’t AI itself; it is the people who are using it. The situation of a filmmaker who creates a fictional character and a person who creates a fake video of a political leader can’t just be equated. The litigated question is how to control deceptive practices without stifling creativity and freedom of expression. The legal issue is the proper balance of control over deceptive practices versus legitimate creativity and freedom of expression.

Criminal Law Framework:

Bharatiya Nyaya Sanhita, 2023

The Bharatiya Nyaya Sanhita does not have an offence that is clearly defined as a ‘deepfake offence’. But some of these provisions may apply if the deepfake includes, for example, a sexual image or if a person suffers from harm.

A section 353 could apply if false statements, information, rumours or reports (including through electronic communication) meet the requirements of public fear, alarm, public tranquillity and other types of harm in section 353. If criminal liability is established, for instance by a fabricated video indicating a dangerous emergency, then it could potentially lead to some criminal responsibility.

But, equally, it would be false to equate all fake videos with Section 353. The context and purpose of the text.

Other provisions could apply as well. The law about defamation could be applicable if a deepfake harms someone’s reputation. Where it is used (for impersonation, fraud, harassment or offences against women or children) other provisions of the BNS or special laws may apply.

As you can see, the most obvious drawback to the legislation is that the BNS can penalise some bad use of deepfakes, but not a general offence for the creation of a deepfake.

Information Technology Act, 2000

Deepfakes are typically created, uploaded or shared via digital platforms, making the Information Technology Act an important piece of legislation.

Section 66C is about identity theft and 66D is about cheating by personation with a computer resource. Section 66E addresses some privacy issues with private pictures. Other sections, such as Section 67, 67A and 67B may also apply depending on the type of material.

These can therefore be useful in the case of a deepfake that is based on an impersonation, a fraud, a breach of privacy or a forbidden sexual content.

But there’s one simple restriction. The IT Act was passed in 2000 before the advent of the type of generative AI that exists today. The problems of AI voice cloning, fake events or mass production of fake videos were not the intent of the Act.

What this implies is that India is trying to address a new technological problem with an old legal structure – one designed to cope with a vastly different digital world.

The 2026 IT Rules

One of the significant recent advancements in India’s countermeasure against deepfakes is the proclamation of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026.

The amendments were published on 10th February 2026 and came into force on 20th February 2026. They included certain provisions on synthetically created information and extended the duties of intermediaries.

Labelling is an important requirement. If content is synthetic the content must be identified as such, and technology can be employed, or technically possible, to demonstrate that the content is synthetic, such as by means of metadata, provenance mechanisms, etc.

In addition, the rules set forth technical measures for intermediaries to prevent the dissemination of some types of synthetic content. They also ensure that in certain circumstances unlawful content will be acted upon as fast as possible, such as within 3 hours of being made aware of the content.

That’s good as it acknowledges that platforms can’t stand by and wait for damage to be done and then only deal with the consequences with the victim.

There’s, however, a practical issue. Suppose a bogus video of a politician was posted at 8 p.m. and viewed by millions of people by midnight. Suppose a fake video of a politician was posted at 8pm. and viewed by millions by midnight. If the platform removes it during the designated time, individuals may have already downloaded it or forwarded it to someone private or uploaded it on another platform.

Thus, a quicker takedown mechanism may be helpful, but the removal of a deep fake doesn’t compensate for the harm that has already been done.

Privacy and Personal Data:

The use of a person’s personal information is also one of the forms of deepfakes. Photos, videos, and voices—along with any other identifying details can be captured and utilized to make synthetic material without the individual’s consent.

The Digital Personal Data Protection Act, 2023 might be applicable if the digital personal data is processed in relation to such activities. It is not about to be referred to as a “deepfake law,” however. Whether or not any particular activity is covered by the Act and the applicable provisions of the Act in force will determine its application.

It is vital as not all the Deepfakes issues are Deepfakes data protection issues. Falsely framing a person with an offensive association, an election or causing reputational harm are areas in which a fake video is likely to impact even in the absence of a primary legal question concerning the processing of personal data.

Hence, data protection law may be considered a part of the solution, but not the whole solution.

Deepfakes and Elections:

Video manipulation poses a major issue in election campaigns, especially when it comes to deepfakes. Political misinformation is already rampant, and AI is now enabling the creation of much more convincing misinformation.

The Election Commission of India has acknowledged the issue and has issued guidelines to the political parties about AI-generated and manipulated content. The Commission has emphasized the need for transparency and labelling in the use of synthetic content for election campaigning.

Isn’t it important that these measures are taken because a fake video can be released just prior to an election, and before voters have time to verify?

The electoral response also reflects pluralism in the Indian legal landscape, however. Deepfakes that occur in the context of elections are addressed by directions and election related regulations, and other victims may need to turn to criminal law, civil remedies or intermediary rules.

Judicial Response: Raghav Chadha v. Ashok John Doe

There have also been some developments in India where courts are now directly addressing the issues that have emerged with the use of AI-generated content.

Delhi High Court in Raghav Chadha v. Ashok Kumar John Doe & Ors addressed complaints regarding deepfakes of the plaintiff’s voice and facial images created using AI technology and similar other synthetic content that misrepresented the plaintiff’s identity.

This case was noteworthy because of the number of conflicting interests involved. There was the right to protect the individual’s identity, reputation and dignity on one hand, and on the other hand there were the individual’s right of privacy and right to self-determination (aspects of freedom of expression). The other side of the coin was the importance of freedom of speech and expression.

During its proceedings in 2026, the Court had taken into account the requirement to get rid of identified content and instructions on online platforms in time. Existing civil remedies which can be used are illustrated in the case as they are currently being applied to harms not explicitly considered when the older laws were enacted.

It’s also a bigger problem. But with no specific legislation yet in place for the case of deepfakes, courts are increasingly hearing cases in this area before Parliament.

Gaps in India’s Present Framework:

The Schemes of this type are not yet in place. However, there are a number of gaps that still need to be filled in.

The absence of a dedicated deepfake law:

There is a lack of specific laws aimed at deepfakes. However, India has yet to have a single focused law on deepfakes. The laws that apply vary depending on the content and making it complicated for the victims.

Inability to recognize threats or limitations:

Deepfakes could be posted via anonymous accounts, and then generated on a number of platforms. It can therefore be tricky to track down the creator of the original content, particularly if it goes viral quickly.

Problems with detection:

Content created with AI is continually evolving. There are also limitations of detection tools, especially with the repeated compression and re-upload of the content.

Victim remedies may not be speedy enough:

The removal of content and restriction of further uploads may be necessary immediately to protect a victim. Litigation can often not be swift enough to bring relief for online harms.

Relationship between regulation and free speech:

Regulating too broadly could not be a way to prevent legitimate satire, parody, criticism, journalism or artistic expression from being illegal. There is a need to clearly differentiate between harmful deception and lawful expression in any future legislation.

Is India Prepared?

The preparations in India are not adequate but are being made.

There are now multiple laws and regulatory regimes that can tackle various types of misuse with deepfake technology. Some of the harmful false information and offences can be addressed by the BNS. IT Act: Identity theft, Personation, Privacy and Prohibited electronic content. The 2026 IT Rules explicitly acknowledge the role of synthetically generated information, and bolster the responsibilities of platforms. The Election Commission has also made moves to combat electoral misinformation created with Artificial Intelligence, and courts are rolling out remedies, in cases like Raghav Chadha.

The trouble is, these measures aren’t yet on their own a single, coherent system.

India, then, is forced to ponder on the law that will be applicable post the creation of a deep fake causing harm. An emphasis should also be given to prevention, rapid identification, removal, identification of the perpetrators and access to remedies for the victims.

A specific legal system may provide for more clearly defined terms and sanctions. The platforms could be empowered with a more robust role in detection, labelling and preservation of evidence. The victim should be able to have easy ways to get immediate removal and to stop the recurrence of uploads. Public awareness is also a key factor since it is important for the people to know that they must see a video or hear a voice and not take it as if it were a reality.

Conclusion:

India is no more under the ‘legal silence’ of deepfakes. The laws and regulations that have been considered tackle various aspects of AI-manipulated imagery, from deepfakes production to the use of AI in the electoral process. The laws and rules are aimed at addressing different aspects of AI-generated deception. They range from deepfake creation and cover the exploitation of artificial intelligence in the campaign.

However, having multiple laws and regulations does not guarantee that India is totally prepared.

The primary challenge is to keep pace with technological advancements and the swiftness of remedies for legal procedures; if a hearing can take three years, a deep fake can reach millions in three hours. Thus, the law needs to balance between being efficient and not being too strict, allowing legitimate freedom of expression.

India has come a long way in combating deepfake technology. However, the country must focus more on issues such as attribution, detection, ownership, and victim remedies. There is a need to develop more integrated and holistic methods in addressing the challenges with AI-manipulated imagery.

Therefore, it is not the number of laws that determine the preparedness of a country in the face of deepfake technology but rather the impact that the ordinary citizen faces when dealing with the aftermath of a deepfake. If the person affected by a deepfake can detect the fake, identify the perpetrator, and move legal procedures to quickly remove the content and provide redress, then the law is functioning efficiently. At that point, the law can be considered effective in protecting people from the destructive impacts of deepfakes.

India is yet to reach that level of preparedness, being ‘born again’ into the legal challenges that deepfakes present.