Information Technology Act, 2000
Synthetically Generated Information and Deepfakes: The 2026 Rules
Until 2026, deepfakes were governed only by the general offences and takedown clocks; the amendment to the IT Rules in force from 20 February 2026 gives synthetic content a regime of its own: a definition, technical measures at the tools that create it, a labelling mandate for what may circulate, and declaration and verification duties on the biggest platforms, all wired into the Section 79 safe harbour. Topic 21 covered deepfakes as a phenomenon; this note, as asked, is the dedicated study of the synthetically generated information framework, ending with the offence mapping for every deepfake situation.
1. The Definition
Figure 1: Synthetically generated information and its exclusions
- Synthetically generated information. Audio, visual or audio-visual information that has been artificially or algorithmically created, generated, modified or altered using a computer resource in a manner that it appears real, authentic or true, and depicts or portrays what a reasonable person would take for a genuine recording.
- What falls in. AI generated content made from a prompt; AI modified content, a real recording altered in a material respect; deepfake video swapping or animating faces; synthetic images of persons and events; and synthetic audio, including voice cloning of a real person's speech.
- The exclusions. Routine and good faith editing: retouching and enhancement, colour and clarity correction, filters, compression, captioning and accessibility processing, and ordinary creative or documentary work that does not present itself falsely as an authentic record. The line is deception about authenticity, not the use of software.
- SGI as information. The amendment declares that synthetic content is information for the purposes of the Rules, so every unlawful content category, takedown clock and grievance route of Rule 3 applies to it in full (Topic 74), closing the argument that generated material is nobody's statement.
2. Due Diligence Against Unlawful SGI
Figure 2: The duties in sequence
- Technical measures at the tools. An intermediary whose computer resource enables the creation, generation, modification or alteration of SGI must deploy reasonable and appropriate technical measures, including automated tools, to ensure the resource does not produce the listed unlawful content.
- The listed content. Child sexual exploitative and abuse material in synthetic form; non-consensual intimate imagery of any person; obscene, pornographic or privacy invasive SGI; content amounting to a false electronic record under the forgery provisions; and content relating to arms, explosives and like material whose creation the law restricts.
- The deception line. SGI that falsely depicts a natural person, saying or doing what they never said or did, or falsely depicts a real world event, or is otherwise likely to deceive users about authenticity, engages the unlawful content obligations even where the underlying category is not itself criminal, and remains subject to ordered removal on the three hour clock and complaints on the two hour clock.
3. The Labelling Mandate
- Mandatory labelling of permissible SGI. Synthetic content that may lawfully circulate must be prominently identified as synthetically generated, through three channels together: a visible label embedded on or across a substantial part of the visual display; an audible disclosure at the beginning of synthetic audio, so a cloned voice announces itself; and a permanent metadata identifier embedded in the file recording its synthetic origin and, where applicable, the tool that produced it.
- Label integrity. Neither the intermediary nor any user may remove, suppress or alter the label, disclosure or identifier; stripping the mark is itself a breach of the Rules, and platforms must not provide tools whose function is label removal.
- Why provenance. The visible label informs the viewer; the embedded identifier survives resharing and lets platforms and investigators establish origin after the visual label is cropped away, the same provenance logic as international content credential standards.
4. The SSMI Layer
Figure 3: Declaration, verification, label, consequence
- User declaration. Before displaying uploaded content, a significant social media intermediary must obtain the user's declaration whether the content is synthetically generated.
- Technical verification. The SSMI must deploy reasonable and proportionate technical measures to verify the accuracy of the declaration, automated detection checking the user's word, calibrated to the platform's scale and the state of technology rather than demanding perfection.
- The prominent label. Content declared or detected as synthetic is displayed with a clear and prominent label or notice informing every viewer of its synthetic character.
- Deepfake regulation and the safe harbour. The duties are due diligence under the Rules, so Rule 7 attaches: an intermediary that knowingly permits, promotes or fails to act on unlabelled SGI, or skips the declaration and verification apparatus, loses the s.79 protection for that content and answers under the applicable law, while an intermediary that maintains the apparatus in good faith keeps the harbour even when a deepfake slips through (Topic 67)
5. Deepfakes Against the Offences
Figure 4: Every deepfake situation mapped
- Deepfake impersonation complaints. A deepfake presenting itself as a real person is impersonation content under Rule 3(1)(b), and where it takes the form of morphed imagery of the complainant it rides the two hour Rule 3(2)(b) clock; criminally it is cheating by personation under s.66D with s.66C for any use of the person's identity features, and BNS cheating and forgery where records or transactions follow.
- Deepfake sexual content. Synthetic sexual imagery of an identifiable person engages ss.67 and 67A as published obscene and sexually explicit material, and s.66E where the depiction shows the person's private areas, with BNS defamation and insult of modesty alongside; consent to none of it exists by definition, and the two hour complaint clock applies (Topic 61)
- Deepfakes and s.66E. The section punishes capturing, publishing or transmitting the image of a person's private area without consent; a morphed image mapping a real person's face onto intimate imagery is treated as an image of that person for the complaint route, and prosecutions pair s.66E with ss.67 and 67A rather than testing it alone.
- Deepfakes and ss.67, 67A. The content offences ask what the material shows, not how it was made, so fully synthetic obscene and sexually explicit material is punishable as published content, with the maker, uploader and knowing forwarder each within publish or transmit.
- Deepfakes and the BNS. Forgery fits squarely: a synthetic recording made to be believed genuine is a false electronic record under ss.335 and 336, used as genuine under s.340; public mischief (s.353) reaches false event depictions likely to cause fear or ill will; defamation and criminal intimidation cover reputational and threat uses; and cheating provisions catch voice clone frauds.
- Deepfakes and POCSO. Synthetic child sexual content needs no real child: s.67B(b) expressly punishes creating digital images and text, and POCSO ss.13 to 15 apply to material depicting a child, with s.42 selecting the higher punishment and the 2024 CSEAM ruling extending strict treatment to viewing and possession (Topic 61)
- AI content and intermediary liability. Liability separates cleanly: the creator and uploader answer for the offences; the tool provider answers for its technical measures; the platform answers for labelling, verification and the clocks, and only its own failures cost it the harbour.
⚠ Exam trap Fix the architecture: the definition with its good faith editing exclusion, the three channel labelling of visible label, audio disclosure and embedded identifier that no one may strip, and the SSMI pair of user declaration plus reasonable and proportionate verification, all effective 20 February 2026 and all enforced through Rule 7's loss of safe harbour. On the offences, remember that the content provisions ask what the material depicts, not how it was made, that s.67B(b) and POCSO reach wholly synthetic child material, and that the two hour clock is the complaint route for morphed intimate imagery. |
6. Frequently Asked Questions
What is synthetically generated information and what must platforms do about it?
Audio, visual or audio-visual information artificially or algorithmically created or altered so that it appears real, excluding routine and good faith editing. Tools that create it must run technical measures against the listed unlawful content; permissible synthetic content must carry a prominent visible label, an audible disclosure for audio and an embedded metadata identifier, none of which may be removed; and significant social media intermediaries must obtain a user declaration on every upload, verify it with reasonable and proportionate technical measures, and label declared or detected content, on pain of losing the Section 79 safe harbour.
Which offences apply to a sexual deepfake of a real person?
Publication or transmission is punishable under Sections 67 and 67A, with Section 66E for depiction of the person's private areas without consent, Section 66D where the deepfake works an impersonation, and BNS defamation, intimidation and insult of modesty as the facts supply. If the person depicted is a child, Section 67B and POCSO apply even though the imagery is wholly synthetic. On the civil side, the two hour removal clock under Rule 3(2)(b) governs the complaint.
7. Related Topics
- Topic 21: IT Act and Deepfakes. The phenomenon, harms and case law.
- Topic 74: Rule 3 Due Diligence. The clocks and categories SGI now rides.