Information Technology Act, 2000

Deepfakes under the IT Act: Offences, Platform Duties and Remedies

A deepfake is a convincing fake: a video, image or voice recording, generated or altered by AI, that shows a real person saying or doing something they never said or did. Deepfakes have been used to create intimate images of women, to clone the voices of relatives for fraud, to fabricate political speeches, and to sell products using celebrities' faces. India has no deepfake statute, but the IT Act, the BNS, the IT Rules as amended in 2026, election advisories and the law of personality rights together provide a substantial framework. This note explains each part and sets out what a victim can do.

1. A Mask That Fits Perfectly

A mask at a fancy dress party fools no one; everyone knows there is a person behind it. A deepfake is a mask so perfect that viewers believe they are seeing the real face. The law's response is threefold: punish the person who wears the mask to cause harm, require the platforms where masks are displayed to label them and take them down quickly, and let the person whose face was copied go to court to stop it.

2. Meaning and Harms

  • Meaning. Synthetic media created with machine learning, typically generative adversarial networks or diffusion models, that replaces or fabricates a person's face, body or voice so realistically that it appears authentic.
  • Legal definition. The IT Rules, as amended in 2026, define 'synthetically generated information' for regulatory purposes: information artificially or algorithmically created, generated, modified or altered using a computer resource in a manner that makes it appear reasonably authentic or true.
  • The liar's dividend. Once deepfakes are common, genuine recordings can be dismissed as fake, which harms accountability as much as the fakes themselves.

Seven harms caused by deepfakes

Figure 1: Seven harms caused by deepfakes

3. The Offences That Apply

Deepfake harms and the provisions that apply

Figure 2: Deepfake harms and the provisions that apply

  • Intimate deepfakes. Publishing or transmitting an image of a person's private area without consent is punishable under Section 66E; obscene or sexually explicit material under Sections 67 and 67A; voyeurism and insulting the modesty of a woman under Sections 77 and 79 BNS.
  • Children. Section 67B punishes creating, publishing or transmitting material depicting children in a sexually explicit manner, including digital images, alongside the POCSO Act.
  • Fraud. A cloned voice or face used to obtain money is cheating by personation using a computer resource (s.66D) and may be identity theft (s.66C), besides cheating and cheating by personation under Sections 318 and 319 BNS.
  • Defamation and forgery. A fabricated video harming reputation is defamation under Section 356 BNS; creating a false electronic record with intent to cause damage or support a false claim may be forgery under Sections 335 and 336 BNS.
  • Illustration. The Delhi Police arrested the creator of a widely circulated deepfake of actor Rashmika Mandanna in January 2024 under provisions on forgery and Sections 66C and 66E of the IT Act.

4. Platform Duties under the IT Rules

  • Before 2026. Rule 3(1)(b) already required intermediaries to inform users not to host content that impersonates another person or is obscene, and Rule 3(2)(b) required removal of non-consensual intimate imagery within 24 hours of a complaint. MeitY advisories of November and December 2023, issued after viral deepfakes, reminded platforms of these duties.
  • The February 2026 amendment. In force from 20 February 2026, it adds specific duties for synthetically generated information.

Platform duties for synthetic content under the 2026 amendment

Figure 3: Platform duties for synthetic content under the 2026 amendment

  • All intermediaries enabling synthetic content. Must deploy reasonable technical measures to prevent synthetic content that violates the law, label synthetic content prominently, embed permanent metadata and a unique identifier, and not allow labels or metadata to be removed or suppressed.
  • Significant social media intermediaries. Must obtain a declaration from users on whether content is synthetically generated, deploy technical measures to verify the declaration, and ensure that synthetic content is clearly displayed with a label.
  • Faster removal. Intimate, sexual and deepfake content must be removed within two hours of a complaint, court or government orders acted on within three hours, and other grievances resolved within seven days.
  • Safe harbour. Removing content through reasonable technical measures or automated tools does not cost an intermediary its protection; failure to comply with the Rules does (Rule 7)

5. Deepfakes and Elections

  • Election Commission advisories. During the 2024 general election the Election Commission told parties to remove fake and deepfake content within three hours of it being brought to their notice. In October 2025, for the Bihar elections, it required parties and candidates to label AI-generated content as 'AI-Generated', 'Digitally Enhanced' or 'Synthetic Content' and to disclose its source, and repeated these requirements for the 2026 Assembly elections.
  • Corrupt practice. Publishing a false statement about a candidate's personal character or conduct to prejudice their election is a corrupt practice under Section 123(4) of the Representation of the People Act, 1951, which can apply to deepfakes.

6. Personality Rights: The Civil Remedy

Personality rights cases and the rules on synthetic content

Figure 4: Personality rights cases and the rules on synthetic content

📖 Aishwarya Rai Bachchan v. Aishwaryaworld.com (Delhi High Court, 9 September 2025)

Facts: Websites and channels sold merchandise with the actor's image, published AI-generated deepfake videos, and ran a chatbot impersonating her.

Held: Unauthorised use of a famous person's identity causes commercial harm and also affects the right to live with dignity. The Court granted an interim injunction against use of her name, image and likeness, and directed removal of merchandise, takedown of deepfake channels and blocking of infringing URLs within fixed periods.

Significance: Confirms that personality rights protect both commercial value and dignity, and extend to AI-generated likenesses.

  • Amitabh Bachchan v. Rajat Negi (Delhi High Court, 2022). Protected the actor's name, image, voice and likeness from unauthorised commercial use.
  • Anil Kapoor v. Simply Life India (Delhi High Court, 2023). Restrained misuse of the actor's persona, including through AI tools, deepfakes, face morphing and GIFs.
  • Jaikishan Kakubhai Saraf v. Peppy Store (Delhi High Court, 2024). Protected Jackie Shroff's name, voice, image and distinctive expressions.
  • Arijit Singh v. Codible Ventures LLP (Bombay High Court, 2024). Restrained AI platforms from cloning the singer's voice (see Topic 20)
  • Beyond celebrities. Ordinary victims rely on privacy, defamation and the criminal law rather than personality rights, but the same courts can order takedown and blocking.

7. The Evidence Problem

  • Proving a deepfake. Forensic analysis of artefacts, metadata and provenance; the 2026 labelling and metadata duties should make synthetic origin easier to establish.
  • Proving genuine evidence. When a party claims a real recording is a deepfake, the certificate under Section 63 BSA, hash values and chain of custody become decisive, and courts may seek the opinion of an Examiner of Electronic Evidence under Section 79A of the IT Act.

8. Remedies for a Victim

Five steps for a deepfake victim

Figure 5: Five steps for a deepfake victim

  • Preserve. Save screenshots, links, dates and, if possible, hash values before content disappears.
  • Platform. Complain to the grievance officer; intimate and deepfake content must be removed within two hours.
  • Police. Report on the National Cybercrime Reporting Portal or the 1930 helpline and lodge an FIR under the relevant IT Act and BNS provisions.
  • Court. Seek an injunction, blocking orders against unknown defendants and damages; for intimate images, courts can direct search engines to de-index the content.
  • Appeal. A user dissatisfied with a platform's decision may appeal to the Grievance Appellate Committee.

⚠ Exam trap

Do not say that India has no law on deepfakes. There is no single deepfake statute, but the IT Act (ss.66C, 66D, 66E, 67 to 67B), the BNS (ss.77, 79, 318, 319, 335, 336, 356), the IT Rules as amended in 2026, election rules and personality rights together cover the field. A strong answer names the provision for each harm and adds the platform's duties.

9. Quick Revision and Memory Aids

  • 'A mask that fits perfectly'. What a deepfake is.
  • 'Punish, label, remove, restrain'. The four legal responses.
  • '66E private, 66D money, 67B child'. Key IT Act offences.
  • 'Label, embed, declare, verify'. The 2026 platform duties.
  • 'Two hours intimate, three hours orders'. Removal deadlines.
  • 'Bachchan, Kapoor, Shroff, Singh, Rai'. The personality rights line.

10. Frequently Asked Questions

Is creating a deepfake an offence in India?

Not in itself, but most harmful deepfakes are: intimate deepfakes under Sections 66E, 67 and 67A, child deepfakes under Section 67B, fraud under Sections 66C and 66D, and defamation and forgery under the BNS.

What must platforms do about deepfakes?

Under the IT Rules as amended in February 2026, label synthetic content, embed permanent metadata, prevent removal of labels, and, for significant platforms, obtain and verify user declarations; intimate and deepfake content must be removed within two hours of a complaint.

11. Related Topics

  • Topic 20: IT Act and Artificial Intelligence. The wider AI framework.
  • Topic 17: IT Act and Freedom of Speech. Where regulation of synthetic content meets Article 19.