AI Cybercrime in India: Legal Remedies

This article is written by Ahona Das from Sister Nivedita University, Kolkata.

Artificial Intelligence (AI) is revolutionizing our working and living lives every day. It is used in numerous sectors, such as education, healthcare, banking, and business. Saves time, improves service and makes daily activities easier. As with any technology, AI has its potential risks and can be misused. AI is being exploited to make videos, voice recordings, photos and messages that are fake – all for criminal purposes. Some of these crimes can damage a person’s reputation and take money, as well as use personal information which can cause emotional stress.

In recent years, India has seen an increase in AI-related cyber-crimes. Deepfake videos, voice cloning, online financial fraud and other instances have made many people victims of these acts. Crimes against children are increasingly prevalent, but many victims do not know what to do after they have been horrified by these crimes. Some run for their lives, some remove vital evidence and many fail to report a crime. This leads to the perpetrators of crimes getting away with it and the victims not receiving any prompt legal protection.

This article is an attempt to understand the first steps that citizens should take following being a victim of a cyber-crime using AI. It is crucial to first make clear that AI does not constitute a novel type of crime. In nearly all instances, AI is used as a means or instrument for committing a pre-existing crime (e.g., cheating, forgery, defamation, criminal intimidation or privacy violation) and not as a crime unto itself. This article therefore refers to the term “AI-facilitated cyber-crime” instead of “AI-generated crime” and the relevant legal provision in each instance will have to be dependent on the actions of the criminal and the actual damage caused. 

Keywords: AI-Generated, Cyber-Crimes, Legal Protections, Digital Evidence, FIR, Rights, Remedies. 

Understanding AI-Facilitated Cybercrime 

An AI-facilitated Cyber-Crime is a crime using the assistance of Artificial Intelligence on a computer, mobile phone or the internet. The offender employs AI to trick, threaten or harm someone else. These materials can easily appear authentic and people can find it hard to recognize them at first glance. This increases the dangers of committing crimes using AI and makes them harder to solve. 

One common example is a deepfake. A computer-generated image, video or audio that appears to be or sound like a real person, but is actually entirely false. This material can be used to provide false information, tarnish someone’s reputation or blackmail the victim. 

Another AI-generated cyber-crime is AI voice cloning. AI copies a person’s voice and creates fake phone calls or voice messages. AI is also used to create fake websites, fake customer care numbers, fake job offers and fake investment advertisements. Many people believe these scams because they look genuine. As a result, they may lose money or unknowingly share their personal information. 

An offender may use AI to create fake social media accounts, fake emails or fake documents by using another person’s name, photograph or other personal details. This may affect the victim’s privacy, reputation and financial security.

These crimes can happen to anyone. Students, professionals, business owners, senior citizens and even public figures have become victims. It is important for every citizen to know what to do immediately after such a crime and how Indian law can help.

The First Legal Steps after an AI-Crime

The first few hours after discovering an AI-generated crime are very important. The actions taken during this time can make a big difference in the investigation. The first step is not to panic and stay calm while making decisions. Many victims delete messages, videos or photographs because they feel embarrassed or frightened. This should be avoided because those files may later become important evidence. 

Secondly, save every piece of digital evidence by taking screenshots, saving videos, voice recordings, emails, chat messages, website links, phone numbers and bank transaction details which may help the police identify the offender. If money has been stolen through online banking, UPI or any digital payment method you have to contact your bank immediately and report the transaction. Quick action may help prevent further financial loss. You should also note down the date, time and other important details of the incident. These details often help the investigating agency understand how the crime was committed. Most importantly, silence of victims is the main strength of the offender because victims feel ashamed of social stigmas and lose their belief from the legal system. 

Where should you report the crime?  

Where the victim has suffered an online financial fraud, immediate action is critical. The victim should contact the bank or payment service provider immediately and report the transaction through the National Cyber Crime Helpline at 1930. The complaint should also be submitted through the National Cyber Crime Reporting Portal, along with the transaction details, UTR or transaction ID and other relevant evidence. Prompt reporting may assist in initiating measures to trace or freeze the transferred funds, although recovery of the money cannot be guaranteed. 

Your Rights under Indian Law

The Constitution of India does not create a separate fundamental right specifically against AI-generated content. However, constitutional rights may become relevant depending on the nature of the harm and the identity of the person responsible. Article 14 guarantees equality before the law and equal protection of the laws. The right to freedom of speech and expression is protected under Article 19(1)(a) with reasonable restrictions as provided under Article 19(2) including restrictions on defamation and public order. However, the constitutional right to free speech does not extend to acts which, apart from their nature as speech, constitute a criminal offense or civil liability.

It is enshrined in Article 21 that life and personal liberty are protected and the Supreme Court has interpreted Article 21 to include the right to privacy. In K.S. Puttaswamy (Retd.) v. Union of India (2017), the Supreme Court had declared privacy as a fundamental right. Therefore, misuse of a person’s identity, personal information or private material can give rise to constitutional concerns, depending on the facts of the case, but the statutory remedy will vary. Where there is State action, constitutional rights are of special importance, but where the dispute is between two private parties, then the usual remedies to be followed include the provisions of criminal, civil and statutory law.

The Information Technology Act, 2000 still does not recognize the concept of ‘AI-generated crimes’ and still covers a variety of crimes committed using cyberspace. Section 66C is about ID theft through the use of a false or deceptive electronic signature, password or other means of identification unique to another person. Thus, the use of this for impersonation by artificial intelligence will depend on the existence of the two elements of identity theft: mens rea and the statutory elements.

Section 66D relates to cheating by personation (by a computer resource or communication device) and may be relevant to any instance where cheating by personation involves a computer resource or communication device (such as the use of AI generated voice, video or other digital content to impersonate another person for the purpose of cheating). The issue for Section 66E is the capture, publication or transmission of an image of the private area of a person without their consent, in a situation which breaches privacy. It cannot be interpreted as a blanket ban on any use of artificial intelligence that infringe on privacy.

Sections 67 and 67A could be engaged if electronic versions of AI-generated or manipulated obscene or sexually explicit material are published or transmitted. The use of AI must therefore be considered in the context of the content and circumstances of each case, and not just because AI was used.

The Bharatiya Nyaya Sanhita, 2023 (BNS) could be applied where AI is being used as a tool to commit offences that are recognized by the general criminal law. AI assisted behaviour might include offences of cheating, cheating by personation, forgery, use of forged documents/electronic records, criminal intimidation or defamation, depending on the facts. The provision to be applied should be determined by the acts and substance of the offence in question. The production of AI-generated content is not sufficient for itself to constitute a crime. The prosecution is required to prove all the elements of the specific offence charged. 

The Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS) governs criminal procedure applicable to offences investigated and prosecuted under the prevailing criminal law framework. It is relevant to the reporting of offences, investigation, collection of evidence, arrest, prosecution and trial. The BNSS does not create a separate procedural regime exclusively for AI-facilitated offences. Accordingly, the ordinary criminal procedure applies, subject to the specific facts and nature of the offence involved. 

The Bharatiya Sakshya Adhiniyam, 2023 (BSA) provides the framework governing the admissibility and proof of electronic and digital records. Electronic or digital records are recognised within the evidentiary framework, but their production before a court is subject to the statutory requirements governing admissibility and proof. In AI-related disputes, questions of authenticity, integrity, source and possible manipulation may be particularly significant.

For this reason, victims should preserve original files wherever possible, retain the devices on which material was received or stored, preserve relevant URLs and account information, and avoid altering or deleting the original material. Screenshots may be useful for documenting the incident, but they should not be treated as automatically sufficient proof in every case. The evidentiary value of digital material will depend upon the applicable provisions of the BSA and the facts of the particular case.

The Digital Personal Data Protection Act, 2023 (DPDP Act) should not be treated as a general criminal law against deepfakes or AI-generated content. Its primary focus is the regulation of the processing of digital personal data and the obligations of relevant Data Fiduciaries and Data Processors. Its applicability to a particular incident will therefore depend upon whether the conduct falls within the scope of the Act and whether the relevant statutory conditions are satisfied.

For example, the unauthorised use of a person’s photograph, voice or other personal information in an AI-generated deepfake may raise privacy and data-protection concerns, but the DPDP Act does not automatically provide a criminal remedy for every such misuse. Depending on the circumstances, victims may instead need to rely on criminal law, civil remedies, constitutional protections, platform grievance mechanisms or other applicable legal frameworks. The precise applicability of the DPDP Act must be assessed in light of its statutory scope and the implementation of the data-protection framework.

Civil Remedies and Personality Rights

Not every AI-related harm will necessarily result in a criminal prosecution. In appropriate cases, victims may also seek civil remedies. These may include interim injunctions, removal or disabling of unlawful content, protection against unauthorised commercial exploitation of one’s identity, and remedies relating to privacy, reputation, passing off or other applicable rights.

This distinction is important in cases involving deepfakes of public figures or other identifiable individuals. A victim may simultaneously pursue criminal remedies where the conduct constitutes an offence and civil remedies where the objective is to restrain further dissemination of the content or protect personal, privacy or personality interests. The availability of a particular remedy will depend upon the facts and the legal rights affected.

Reporting AI-Generated Content to Online Platforms

Victims should also report unlawful AI-generated content directly to the relevant social media platform, website or hosting service. The complaint should identify the specific content, provide the relevant URL or account details and explain the nature of the violation. Where the content involves impersonation, non-consensual intimate material, harassment or other unlawful conduct, the victim should use the platform’s designated reporting mechanism and preserve evidence before requesting removal.

Platform reporting does not replace criminal or civil remedies. Where necessary, a victim may pursue legal proceedings or seek appropriate judicial directions for removal or disabling of unlawful content. The legal responsibility of intermediaries is governed by the applicable statutory framework and the specific circumstances of the case and should not be treated as automatic liability for every piece of user-generated content.

Judicial Developments 

The Delhi High Court’s decision in Ankur Warikoo & Anr. v. John Doe & Ors., CS(COMM) 514/2025, illustrates the availability of civil judicial protection against unauthorised deepfake content. The proceedings concerned the unauthorised use of the plaintiff’s identity and likeness in digitally manipulated content. The Court granted interim protection restraining the unauthorised use and dissemination of such content and issued directions concerning the removal or disabling of identified unlawful material. The case is significant because it demonstrates that victims of deepfake misuse may seek civil remedies, including interim injunctions and directions against online dissemination. It should not, however, be described as establishing a separate criminal offence of creating an AI-generated deepfake. 

A similar approach can be seen in Sri Ravi Shankar v. John Doe & Ors., CS(COMM) 889/2025, before the Delhi High Court. The plaintiff alleged that unidentified persons were circulating deepfake content using his name, voice, facial expressions, persona and likeness without authorisation. The Court recorded that a prima facie case had been made out in favour of the plaintiff and found that the balance of convenience and the risk of irreparable harm justified interim protection. The order restrained the unauthorised circulation of the alleged deepfake content pending further proceedings. The case demonstrates the use of civil injunctive relief to protect personality and publicity interests against unauthorised deepfake content. It does not, by itself, establish a separate criminal offence specifically for the creation of AI-generated content. 

Conclusion

With the rampant misuse of AI, it is clear that technology can be a huge tool for existing threats like cybercrime, impersonation, fraud, harassment, or privacy violations. The core issue now is not only the lack of a new “AI crime” law, but whether existing criminal, civil, evidentiary and data-protection laws are adequate to deal with offenses enabled or committed via rapidly changing technology.

Immediate action is crucial to victims. Original digital evidence should be preserved, financial fraud should be reported immediately, use of available platform and civil remedies, or reporting to the National Cyber Crime Reporting Portal and/or police can enhance the chances of effective intervention. Meanwhile, courts and law enforcement need to keep evolving their investigative and evidentiary processes in order to keep up with the rapid changes in the quality and sophistication of synthetic and manipulated content.

Ensuring an effective legal response to cybercrime enabled by AI thus needs attention to both awareness and precision. One shouldn’t assume that because there is no one comprehensive AI-crime statute, there’s no legal protection for victims. The remedies may be available under existing laws, but the application of these will depend on the nature of the conduct, the harm, and the legal rights. 

Frequently Asked Questions

1. What is AI-facilitated cybercrime?

AI-facilitated cybercrime refers to the use of artificial intelligence as a tool to facilitate or perpetrate cybercrime or other offences. Indian law does not currently recognise a single standalone offence called “AI-generated cybercrime.” 

2. WWhat should I do first after becoming a victim?

Preserve the original digital evidence, record relevant URLs, account details and transaction information, and avoid deleting or altering the material. In cases involving financial fraud, immediately contact your bank or payment service provider and report the incident through 1930. 

3. Where can I report an AI-facilitated cybercrime?

Victims can report cybercrime through the National Cyber Crime Reporting Portal, approach the local police or cybercrime police station, and, where appropriate, report the content directly to the relevant online platform. Financial cyber fraud should be reported immediately through 1930 and the NCRP. 

4. Is there a separate law specifically dealing with AI-generated crimes in India?

No. India does not currently have one comprehensive criminal statute that creates a general offence of “AI-generated crime.” Depending on the conduct, existing provisions under criminal law, the Information Technology Act, evidentiary law and other applicable legal frameworks may apply. 

5. Can victims obtain legal protection even without a specific AI-crime law?

Yes. Depending on the facts, victims may pursue criminal remedies, civil injunctions, takedown requests, platform grievance mechanisms and other statutory remedies. The specific remedy will depend upon the nature of the AI-facilitated conduct and the rights affected.