Information Technology Act, 2000

AI and Indian Cyber Law: Deepfakes, SGI Rules and Liability Explained

India regulates artificial intelligence without an AI statute: the conduct sections of the IT Act are technology-neutral, so a fraud is s.66D whether a human or a cloned voice speaks, and the gap the technology actually created, undisclosed synthetic media, was answered inside the intermediary rules by the 2026 SGI amendment. The examiner's questions are therefore mapping questions, which existing provision catches which AI harm, plus the genuinely open frontiers of intermediary status, copyright and accountability. Topic 75 built the SGI regime; this note, as asked, covers the whole AI field separately.

1. The Framework Without a Statute

Five layers of Indian AI law

Figure 1: Five layers of Indian AI law

  • Technology neutrality. The IT Act speaks of computer resources, electronic records and communication, not of any technique, so generative models, their outputs and their misuse all fall within existing definitions; what is new is scale, realism and cost, not legal category.
  • The policy layer. MeitY has proceeded by advisory and rulemaking rather than legislation: advisories to platforms on under-tested models and labelling of synthetic content preceded the 2026 amendment, and India's AI governance posture has favoured innovation with targeted obligations; any dedicated AI legislation remains prospective.
  • The judicial layer. The High Courts have supplied the first Indian deepfake remedies through personality rights: injunctions restraining the AI misuse of well-known persons' names, images and voices, ordering takedown of morphing and cloning content, the Delhi High Court's celebrity personality orders being the standard citations.

2. The Harm Map

AI conduct under present sections

Figure 2: AI conduct under present sections

  • Deepfakes and synthetic media. A deepfake is synthetic media depicting a person saying or doing what they did not; the current Indian framework is a lattice: ss.66C, 66D, 66E, 67 to 67B and BNS forgery, cheating and defamation for the conduct, the 2026 SGI labelling for provenance, the two-hour removal clock for intimate and morphed imagery, personality rights injunctions for public figures, and the DPDP Act for the personal data used (Topic 75)
  • Voice cloning and AI impersonation. A cloned voice deployed to deceive is s.66D cheating by personation through a communication device, with s.66C where identity features, voiceprints, credentials, are dishonestly used, the family-emergency and executive-order scams being the running examples.
  • AI fraud. Generative tools industrialise the frauds of Topic 85, fluent phishing at scale, synthetic KYC documents, deepfaked video calls in digital arrest and BEC scams; the charges are unchanged, ss.66C, 66D, cheating and forgery, with the realism going to proof, not to category.
  • AI-generated obscenity and CSAM. Obscene synthetic content is ss.67 and 67A publication like any other; AI-generated child sexual abuse material falls squarely within s.67B, which punishes material depicting children in sexually explicit acts however created, alongside POCSO, generation, possession and sharing all caught, and no real child need have been photographed for the offence.
  • AI and privacy, identity, defamation. Training and deployment on personal data engage the DPDP regime and Puttaswamy's informational self-determination; synthetic imagery of private persons is s.66E and the intimate-imagery clocks; and a defamatory deepfake or hallucinated allegation is BNS defamation for its publisher, with platform exposure on the ordinary knowledge rules.

3. The 2026 SGI Regime in Brief

The transparency pipeline

Figure 3: The transparency pipeline

  • Mandatory labelling. Tools and intermediaries enabling creation of synthetically generated information embed visible labels or identifiers marking content as synthetic, provenance travelling with the file.
  • Verification by SSMIs. Significant platforms obtain user declarations whether uploaded content is synthetic, deploy reasonable technical measures to verify, and prominently display the synthetic label on verified content, failure inviting the due diligence consequence, loss of s.79 (Topic 75)
  • Transparency, not truth. The regime discloses how content was made, never whether it is true, the design that distinguishes it from the struck-down FCU route and anchors its constitutional defence (Topic 81)

4. Platforms, Moderation and Machines That Decide

The open liability questions

Figure 4: The open liability questions

  • AI and intermediary liability. s.79 shields third-party information: for user-uploaded deepfakes the platform is a classic intermediary, but a generative tool producing content on a prompt strains the category, since the output is arguably the tool's own, not received on another's behalf. The 2026 amendment answers practically, imposing due diligence on tools enabling synthetic creation, while the doctrinal question of a model's s.79 status awaits a court.
  • Automated content moderation. Rule 4(4) has SSMIs endeavour to deploy automated tools against child sexual abuse and previously removed content, with safeguards of human oversight, user notification and review; over-removal chills speech and under-removal breaches diligence, the accuracy-bias-scale trilemma of machine moderation.
  • Algorithmic decision-making. No Indian statute yet regulates algorithmic decisions generally; accountability is assembled from arbitrariness doctrine for State systems, consumer law for unfair automated practices, the DPDP Act's duties for the data, and sectoral regulators for credit, securities and platforms.
  • AI chatbots and cyber liability. The deployer answers for a chatbot's output under ordinary law, misstatement, defamation, unfair trade practice, consumer service deficiency, and disclaimers do not immunise; the comparative case law holding businesses to their bots' promises marks the direction, with the Indian analysis running through the same doctrines.

5. AI and Copyright

The three questions of the frontier

Figure 5: The three questions of the frontier

  • Authorship of AI output. The Copyright Act's computer-generated works clause names as author the person who causes the work to be created, yet the scheme presupposes a human author for originality and term; purely machine-generated output without human creative contribution sits outside protection on the prevailing view, and human selection, prompting and arrangement is the argued route to authorship, the question unsettled.
  • Training data. Whether training models on protected works is infringement or fair dealing is sub judice, the news agency litigation against AI developers in the Delhi High Court being the Indian lead case, with reproduction, storage and output-similarity each contested; jurisdictions abroad have split, and the Indian answer is pending.
  • Infringing output. Output substantially similar to a protected work infringes in the hands of the person exploiting it, and the provider's exposure follows the platform doctrines, knowledge, contribution and the active-passive line (Topics 67, 90)

⚠ Exam trap

Anchor every AI answer in technology neutrality: name the existing section the conduct falls under before discussing any gap, voice-clone fraud to s.66D, synthetic intimate imagery to s.66E with the two-hour clock, AI child abuse material to s.67B and POCSO with no real child required. Present the 2026 SGI rules as provenance regulation, labelling and verification, never truth adjudication, and keep the open questions honestly open: the intermediary status of generative tools, the copyright in AI output and the training data question are unsettled or sub judice, and an answer that states them as decided is wrong.

6. Frequently Asked Questions

What is the current Indian legal framework for deepfakes?

A lattice of existing law and new rules rather than a deepfake statute. The conduct falls under Sections 66C, 66D and 66E of the IT Act, Sections 67 to 67B for sexual content including AI-generated child sexual abuse material, and BNS forgery, cheating and defamation. The 2026 amendments to the intermediary rules add mandatory labelling of synthetically generated information, verification and prominent display by significant platforms, and removal clocks of three hours for ordered content and two hours for intimate or morphed imagery. Personality rights injunctions protect public figures, and the DPDP Act governs the personal data involved.

Is AI-generated content protected by copyright in India?

Largely unsettled. The Copyright Act treats the person who causes a computer-generated work to be created as its author, but originality doctrine presupposes human creativity, so purely machine-generated output is generally regarded as unprotected, with meaningful human selection and arrangement argued as the route to authorship. Whether training AI models on protected works infringes copyright is sub judice in the Delhi High Court, and infringing output is actionable against its exploiter under ordinary infringement doctrine.

7. Related Topics

  • Topic 75: Synthetically Generated Information. The 2026 regime in full detail.
  • Topic 85: Cybercrime typology. The fraud families AI now powers.