This article is written by Divyanshu Tyagi, Vivekananda Institute of Professional Studies
Indian law lacks a dedicated framework for deepfakes and synthetic media. This article examines the fragmented application of the Copyright Act, 1957, the Information Technology Act, 2000, the Bharatiya Nyaya Sanhita, 2023, and the Bharatiya Sakshya Adhiniyam, 2023 to AI-generated synthetic content. It identifies key legislative gaps and proposes a graduated intermediary liability model, a dedicated statutory framework for deepfakes, and a Digital Identity and Personality Rights Act as possible legislative reforms.

Keywords: Deepfakes, Synthetic Media, Copyright Authorship, Intermediary Liability, Artificial Intelligence and Indian Law
I. Introduction
When a Bengaluru woman transferred ₹3.7 crore after receiving a video call from a synthetic reconstruction of a spiritual leader, or when cloned voices of corporate executives in Mumbai authorised fraudulent fund transfers, it became clear that deepfakes had moved from novelty to a serious legal threat. Generative AI can synthesise audiovisual content of a person saying things they never said, with fidelity that defeats ordinary scrutiny.
India’s legal response, spread across the Copyright Act, 1957, the IT Act, 2000, the Bharatiya Nyaya Sanhita, 2023 (BNS), and the Bharatiya Sakshya Adhiniyam, 2023 (BSA), is fragmented. Who owns a deepfake? Who bears criminal liability for it? Can a platform be held liable for hosting it? Indian law offers partial, inconsistent answers and no coherent framework. This article examines these frameworks, identifies the gaps, and proposes original legislative reforms.
II. Understanding Deepfakes and Synthetic Media
The IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 introduced “synthetically generated information” (SGI) under Rule 2(1)(wa): any audio, visual, or audiovisual content algorithmically created or altered to deceive an average viewer. Three exclusions apply: purely textual content, routine non-deceptive editing, and accessibility tools.
Crucially, “deepfake” itself has no statutory definition in Indian law, even though it describes the most harmful subset of SGI content falsely depicting identifiable persons. Courts must currently improvise. A secondary problem concerns authorship. Section 2(d)(vi) of the Copyright Act defines the author of a computer-generated work as “the person who causes the work to be created,” a formula that becomes uncertain when a generative model acts on a minimal prompt. The Supreme Court in Eastern Book Company v. D.B. Modak (2008) adopted a modicum-of-creativity standard; whether a two-word prompt satisfies even this threshold remains unsettled.
III. Copyright Issues Raised by AI-Generated Deepfakes
A deepfake from frames of a copyrighted film infringes the producer’s reproduction right under Section 14; voice-cloned audio reproducing a recognisable melody infringes the underlying musical work.
The harder case arises where AI trained on copyrighted works produces original-seeming output, a question under active examination in ANI Media Pvt. Ltd. v. OpenAI Inc. & Anr. (CS(COMM) 1028/2024, Delhi HC). India’s Section 52 is a closed list, and commercial AI training fits none of its exceptions. The Copyright Office’s withdrawal of co-authorship status for AI system RAGHAV in the ‘Suryast’ case confirmed that machines cannot hold copyright, meaning a deeply AI-generated deepfake may legally belong to no one, yet simultaneously harm the person depicted.
As the Bombay High Court noted in Arijit Singh v. Codible Ventures LLP (2024), AI voice cloning generates a new performance never actually given by the artist, placing it outside Section 38A and leaving the ordinary deepfake victim without statutory protection.
IV. Civil Liability under Indian Law
Copyright owners can seek injunctions under Section 55 and account of profits under Section 58, but the Act provides no statutory damages, making it difficult to quantify reputational harm from a viral deepfake. The most significant civil remedy has come through judicial personality rights under Article 21, recognised in Puttaswamy v. Union of India (2017).
In Amitabh Bachchan v. Rajat Nagi & Ors. (2022), the Delhi High Court restrained unauthorised use of the actor’s name, voice, and image. In Anil Kapoor v. Simply Life India & Ors. (2023), the court held that deepfake-generated content exploiting a celebrity’s likeness harmed reputation and dignity, and that genuine satire remains protected under Article 19(1)(a).
The Madras High Court in Shivaji Rao Gaikwad v. Varsha Productions held that persona exploitation is actionable without proof of consumer confusion. These decisions, however, require High Court litigation, making them practically accessible only to public figures; an ordinary individual has no codified statutory right against identity-based deepfake exploitation.
V. Criminal Liability
The BNS, 2023 expands criminal coverage of digital wrongdoing. Section 2(8) includes electronic records within “document,” enabling prosecution under Chapter XVIII’s forgery provisions. Section 336(3) imposes seven years’ imprisonment for forgery with intent to cheat, applicable to deepfake voice scams and “digital arrest” extortion. Section 336(4) covers forgery intended to harm reputation, carrying up to three years. Section 340 extends liability to those who knowingly use a forged electronic record as genuine, capturing distributors not only creators.
The IT Act supplements this: Section 66C covers biometric identity theft; Section 66D covers computer-based impersonation; Sections 67 and 67A address obscene electronic content. Three enforcement gaps persist. First, there is no standalone deepfake offence; every prosecution requires fitting synthetic media into categories designed for different wrongs. Second, proving intent is operationally difficult when deepfakes circulate anonymously through encrypted platforms. Third, jurisdictional enforcement against foreign actors remains functionally limited.
VI. Intermediary Liability under the IT Act
Section 79 of the IT Act grants platforms conditional immunity for third-party content, provided they observe due diligence and act on actual knowledge of unlawful material. In Shreya Singhal v. Union of India (2015), the Supreme Court held that actual knowledge can only arise from a court order or government notification not a private complaint.
The IT Amendment Rules, 2026 impose new obligations: automated SGI detection, metadata embedding, and removal of unlawful synthetic content within three hours. Non-consensual intimate imagery must be removed within two hours. Safe-harbour retention is tied directly to this compliance. Rule 3(3)(a) effectively imposes a constructive knowledge standard which Shreya Singhal’s reasoning would not sustain. The Bombay High Court in Kunal Kamra v. Union of India (2024) struck down the Fact-Checking Unit provision because tying safe harbour to executive content classification was ultra vires Section 79 and violated Article 19(1)(a). The SGI proactive-filtering mandate replicates this same structural defect.
VII. Existing Gaps in Indian Law
Five structural gaps demand attention. First, no standalone deepfake offence exists in any statute. Second, ordinary individuals have no codified personality right; the gap between copyright protection for works and statutory identity protection remains entirely unbridged. Third, the Copyright Act has no text-and-data-mining exception, leaving AI training on copyrighted material in legal limbo. Fourth, the BSA 2023’s Section 63(4) certification framework was not designed for evidence that is itself algorithmically fabricated; courts have no forensic guidelines for evaluating deepfake evidence. Fifth, the IT Act has no statutory notice-and-counter-notice mechanism, so takedown disputes resolve through platform discretion alone.
VIII. Comparative Position
| Jurisdiction | Key Instrument | Primary Obligation | Free Speech Safeguard |
|---|---|---|---|
| EU | EU AI Act Art. 50(4); May 2026 Guidelines | Disclosure of AI-generated content; machine-readable watermarks by providers | Lighter obligations for artistic, satirical, or fictional works |
| USA | Take It Down Act (2025); No FAKES Act (proposed) | 48-hour NCII takedown; FTC enforcement; proposed federal performer rights | Stringent First Amendment balancing; satire broadly protected |
| UK | Online Safety Act 2023 (amended) | Creation of non-consensual deepfake intimate images criminalised | Existing defamation law; statutory fair dealing for parody |
| China | CAC Deep Synthesis Provisions (Jan 2023) | Mandatory user verification; labelling of all synthetic content | Minimal exceptions; political satire heavily restricted |
| India | IT Rules 2026; Copyright Act 1957; BNS 2023; BSA 2023 | 3-hour SGI takedown; metadata labelling; no standalone deepfake offence | No explicit carve-outs; satirical content subject to same takedown rules |
The EU AI Act (Article 50(4)) and the May 2026 Commission Guidelines require disclosure of AI-generated content and define deepfakes by their capacity to deceive, with lighter obligations for clearly artistic or satirical works — a calibrated constitutional model India could adapt. The UK’s Online Safety Act 2023 specifically criminalises the creation of non-consensual deepfake intimate images. The US Take It Down Act (2025) mandates 48-hour removal for non-consensual intimate imagery. China’s CAC Deep Synthesis Provisions (January 2023) require mandatory user verification and content labelling. India’s 2026 Rules are prescriptive in takedown timelines but weak in substantive offence creation and free-expression safeguards.
IX. Proposed Liability Framework
Parliament should enact a Digital Identity and Personality Rights Act conferring on every individual an exclusive right over their name, image, voice, and persona, with fifty-year posthumous protection — and Section 38A should be amended to cover algorithmic vocal replication regardless of whether a specific recording was copied. Chapter XVIII of the BNS should insert a graduated deepfake offence: three years for deceptive synthetic content; seven years where it facilitates fraud, electoral manipulation, or reputation destruction; and a strict-liability minimum of three years for non-consensual sexually explicit imagery. Section 79 safe harbour should be reformed as a three-tier model: two-hour removal for NCII and CSAM; six-hour removal for electoral and fraud deepfakes with a 48-hour counter-notice window; and 24-hour removal for general SGI with a seven-day counter-notice window. Rule 3(4)’s open-ended advisory mechanism should be repealed. Section 52 should be amended to permit AI training on lawfully accessed works, subject to attribution disclosure and an opt-out right for rights holders.
X. Procedural Safeguards
Private forensic experts may now certify electronic evidence under Section 63(4) of the BSA 2023, enabling independent deepfake forensic analysis. Courts lack guidelines on reliable detection methodologies. CERT-In and C-DAC should develop accredited forensic standards. AI system providers operating in India should be required to implement C2PA-compliant provenance standards, embedding cryptographically signed watermarks in all AI-generated output. Absence of a verifiable provenance marker in contested content should raise a rebuttable presumption of synthetic origin. Legislation must include self-activating carve-outs for satire, parody, journalism, and academic research. An independent Digital Media and Synthetic Content Authority should be established with adjudicatory and standard-setting functions, insulated from MeitY’s administrative control.
XI. Conclusion
India’s legal encounter with deepfakes is a collision between rapidly evolving technology and statutory frameworks designed for a different era. The Copyright Act protects works but not identities. The IT Act shields platforms under conditions that the 2026 Rules are pushing toward constitutional incoherence. The BNS provides general criminal tools requiring creative application for synthetic media harms. The BSA improves evidentiary procedure but offers nothing where the evidence is itself a fabrication. Courts have compensated through personality rights jurisprudence effective only where litigants are resourceful, and defendants are traceable. The reforms proposed a codified personality rights statute, a three-tier intermediary liability model, a standalone BNS deepfake offence, a text-and-data-mining exception, digital provenance obligations, and an independent regulatory authority forming a coherent legislative architecture anchored in constitutional rights. Parliament must act before the harm outpaces every available remedy.
References
DPIIT Working Paper on Generative AI and Copyright: One Nation, One License (December 2025) — https://www.dpiit.gov.in/static/uploads/2025/12/ff266bbeed10c48e3479c941484f3525.pdf
MeitY Advisory on Deepfakes (February 2024) — https://www.meity.gov.in/static/uploads/2024/02/9f6e99572739a3024c9cdaec53a0a0ef.pdf
European Commission Draft Guidelines on Art. 50 EU AI Act (May 2026) — https://www.twobirds.com/en/insights/2026/uk/when-marketing-meets-genai-update–the-eu-ai-acts-draft-deep-fake-guidelines-and-what-they-mean-for
WIPO on Deepfakes in Copyright — https://www.wipo.int/export/sites/www/about-ip/en/artificial_intelligence/conversation_ip_ai/pdf/ind_a.pdf
Synthetic Media and Deepfakes: Legal Responses, The Legal 500 — https://www.legal500.com/developments/thought-leadership/synthetic-media-and-deepfakes-legal-responses-to-identity-dignity-and-truth-in-the-age-of-ai/
IT Rules 2026: Regulating Synthetic Media in India, KS&Co — https://ksandk.com/information-technology/it-rules-2026-regulating-synthetic-media/
SFLC.in Comments on Draft IT Second Amendment Rules, 2026 — https://sflc.in/sflc-ins-comments-on-the-draft-it-second-amendment-rules-2026/
EU AI Act: New Rules on Deepfakes, Freshfields — https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/eu-ai-act-unpacked-8-new-rules-on-deepfakes-102jb19
Parmar, D. G. (2025). AI voice cloning: How a Bollywood veteran set a legal precedent. WIPO Magazine. https://doi.org/10.34667/TIND.59061
Vidhi Centre for Legal Policy — From Intermediaries to Individuals — https://vidhilegalpolicy.in/blog/from-intermediaries-to-individuals/
Deepfake Laws: Is AI Outpacing Legislation? Entrust (2024) — https://www.entrust.com/blog/2024/02/deepfake-law


