AI Applications
Deepfake Laws in India: What Actually Applies Today, and What Is Still Missing
A practical breakdown of the laws India currently uses against deepfakes, the 2025 move to mandate labelling of synthetically generated content, the personality rights orders coming out of the Delhi High Court, the real gaps in enforcement, and the exact steps to take if a deepfake of you or your company is circulating.
Admin ·
A practical breakdown of the laws India currently uses against deepfakes, the 2025 move to mandate labelling of synthetically generated content, the personality rights orders coming out of the Delhi High Court, the real gaps in enforcement, and the exact steps to take if a deepfake of you or your company is circulating.
India has no dedicated deepfake law. This is what is used instead.
No Indian statute currently contains the word deepfake as a defined offence. What exists is a stack of older provisions being stretched to cover a new problem: identity theft and personation under the Information Technology Act, obscenity provisions for sexual deepfakes, the Bharatiya Nyaya Sanhita for forgery and defamation, the intermediary rules of 2021 for takedowns, and copyright law when the source footage belongs to someone else. Prosecutors pick whichever fits. That works reasonably well for a morphed pornographic video of a named person. It works badly for a synthetic voice note used to move money, or a fabricated clip of a politician released 36 hours before polling.
The table below is the working list. If you are filing a complaint, an FIR, or a legal notice, these are the hooks.
| Provision | What it covers | Exposure |
|---|---|---|
| IT Act, Section 66C | Identity theft using someone's password, electronic signature or unique identification feature | Up to 3 years and fine up to Rs 1 lakh |
| IT Act, Section 66D | Cheating by personation using a computer resource. Most face-swap and voice-clone scams get charged here | Up to 3 years and fine up to Rs 1 lakh |
| IT Act, Section 66E | Capturing or publishing images of a private area without consent | Up to 3 years or fine up to Rs 2 lakh |
| IT Act, Sections 67, 67A, 67B | Obscene, sexually explicit and child sexual material in electronic form | 3 to 7 years, steepest for child content |
| IT Rules 2021, Rules 3(1)(b)(vii) and 3(2)(b) | Bars impersonation content; platforms must remove morphed or impersonating imagery within 24 hours of a complaint | Platform loses safe harbour under Section 79 |
| BNS 2023, Sections 319, 336(4), 356 | Cheating by personation, forgery to harm reputation, defamation | Up to 3 years and fine, depending on section |
| DPDP Act 2023 | Processing a person's face, voice or other personal data without consent | Penalties up to Rs 250 crore |
| Copyright Act, Sections 51 and 57 | Using protected footage, music or a performance to build the fake, and the performer's moral rights | Civil remedies plus criminal liability |
| Representation of the People Act, Section 123(4) | False statements about a candidate's personal character or conduct | Corrupt practice, election can be set aside |
The 2025 shift: label the synthetic thing
The most significant regulatory move so far came in October 2025, when MeitY published draft amendments to the IT Rules that finally try to define the object itself. The draft introduces the term synthetically generated information and puts obligations on platforms that host or help create it. The headline requirement is visible labelling: a mark covering a meaningful portion of the visual display, and an audible disclosure in the opening stretch of any synthetic audio. Significant social media intermediaries would also have to collect user declarations on whether uploaded content is synthetic, and deploy reasonable technical measures to verify those declarations.
This is a real change in approach. Everything before it was reactive, built around taking content down after harm. Labelling is a provenance rule, closer in spirit to the EU AI Act's transparency obligations than to India's old takedown reflex. It also shifts cost onto the platforms, which is where the detection capability actually sits.
One caution. Drafting, consultation and notification of these amendments moved fast through late 2025, and the operative text and compliance dates matter more than the press coverage. Before you build a compliance process around the labelling threshold, read the notified version on the MeitY site rather than a summary of it.
Courts moved before Parliament did
India's most usable deepfake protection right now is not legislative. It is a line of Delhi High Court injunctions recognising personality and publicity rights, built on the privacy foundation from Puttaswamy in 2017.
Amitabh Bachchan got a broad protective order in November 2022. Anil Kapoor followed in September 2023, with the court restraining the use of his name, image, voice and even the word Jhakaas across GIFs, AI-generated content and merchandise. Jackie Shroff got similar relief in May 2024. Arijit Singh went to the Bombay High Court in July 2024 over AI voice cloning platforms and won an interim order. In 2025 the Delhi High Court extended this to Aishwarya Rai Bachchan and Abhishek Bachchan, and to journalist Rajat Sharma over deepfake advertisements pushing medical products using his face.
The pattern is consistent: courts grant dynamic injunctions, order platforms to pull URLs, and increasingly direct disclosure of uploader details. The obvious problem is access. This route works if you can afford a Delhi High Court petition. A college student whose face has been pasted into a pornographic clip is not filing one. That is the inequality sitting inside India's current deepfake protection, and no amount of celebrity case law fixes it.
Where the framework genuinely falls short
Start with punishment. Section 66D carries a maximum of three years. A single convincing synthetic video can end a career, swing a local election, or trigger a wire transfer worth crores. The penalty and the harm are not in the same universe.
Then jurisdiction. Most face-swap apps and nudify services are hosted outside India, run by anonymous operators, and monetised through offshore payment rails. A takedown order removes one URL. The file re-uploads in nine minutes.
There is also a definitional hole. Nothing in Indian criminal law separates non-consensual synthetic intimate imagery from ordinary obscenity, which means the offence gets framed around whether content is obscene rather than around the absence of consent. Those are different wrongs. Satire, parody, dubbing and legitimate synthetic media in film production also sit in an undefined zone, and a rule written only for harm tends to catch legitimate creators by accident.
Finally, the burden sits on the victim. You discover the content, you preserve it, you file, you chase the platform, you follow up with the cyber cell. In 2023, after the Rashmika Mandanna video, the Delhi High Court hearing a PIL by advocate Chaitanya Rohilla noted the seriousness of the gap and pushed MeitY, which set up an expert committee in November 2024. The 2025 labelling rules are the first concrete output of that pressure. It took two years.
What to do, as a person and as an organisation
If a deepfake of you is circulating, the sequence matters more than the outrage.
- Preserve evidence first. Full-page screenshots with visible URLs, timestamps, the account handle, and a downloaded copy of the file. Do not just report and let it vanish.
- File on the National Cyber Crime Reporting Portal at cybercrime.gov.in. For financial fraud, call 1930 within the first hours, because that is when a freeze on the receiving account is still possible.
- Send a written complaint to the platform's Grievance Officer, citing Rule 3(2)(b) of the IT Rules 2021 and the 24-hour removal obligation for morphed or impersonating imagery. Name the rule. It changes the response.
- Register an FIR with the local cyber cell under Sections 66C, 66D and 66E, adding 67 or 67A if the content is sexual.
- For repeat or commercial misuse of your face or voice, a civil suit seeking a dynamic injunction is the only tool that covers future uploads rather than one link.
The corporate exposure nobody budgets for
In February 2024, an employee at the engineering firm Arup in Hong Kong joined a video call with people who looked and sounded like the company's CFO and colleagues. Every participant except the employee was synthetic. About USD 25 million left the company. Indian firms have since reported cloned-voice instructions to finance teams and fake founder videos used in investment scams.
No law prevents this. Section 66D lets you prosecute afterwards, assuming you find the person, which you usually will not. The control that works is procedural: a callback rule for any payment instruction received over video or voice, a second-channel confirmation for vendor bank changes, and a finance team that has personally seen how good a five-minute voice clone is. Awareness beats policy documents here, because the failure is always a human one made under time pressure.
That is a training problem, not a legal one. Teams that have watched synthetic audio and video get generated in front of them stop trusting a familiar voice on a call, and that instinct is worth more than a circular. If you want your finance, HR, communications or compliance team to understand generative tools well enough to spot and stress-test them, a mentor-led AI Masterclass session built around your own workflows is a faster route than waiting for the law to catch up.
Regulation in India is moving, unevenly but genuinely. It will not arrive in time to protect anyone this quarter. Assume the gap is yours to cover.
FAQs
1. Is making a deepfake illegal in India?
Creating synthetic media is not itself an offence in India. It becomes illegal when used to impersonate someone, defraud, create sexual or obscene content, defame a person, or infringe copyright or personality rights, which are prosecuted under the IT Act, the Bharatiya Nyaya Sanhita and related laws.
2. What is the punishment for a deepfake in India?
It depends on the section applied. Identity theft and cheating by personation under Sections 66C and 66D of the IT Act carry up to three years imprisonment and a fine of Rs 1 lakh, while sexually explicit material under Section 67A carries up to five years for a first offence and seven years for a repeat offence.
3. How do I get a deepfake video removed quickly?
Write to the platform's Grievance Officer citing Rule 3(2)(b) of the IT Rules 2021, which requires removal of morphed or impersonating imagery within 24 hours of a valid complaint, and file a parallel complaint on cybercrime.gov.in. Preserve screenshots with URLs before reporting, because content often disappears from view without being deleted from circulation.
4. Does India have an AI law like the EU AI Act?
No. India has no comprehensive AI statute as of early 2026, and has so far regulated AI through amendments to the IT Rules, MeitY advisories, the DPDP Act 2023 for personal data, and sectoral guidance from regulators such as RBI and the Election Commission.
5. Are personality rights recognised by Indian law?
There is no personality rights statute, but Indian courts have consistently recognised them through common law and the right to privacy affirmed in Puttaswamy (2017), granting injunctions to figures including Amitabh Bachchan, Anil Kapoor, Jackie Shroff and Arijit Singh against AI-generated misuse of their name, face and voice.
6. Can a platform be held liable for hosting a deepfake?
Yes, if it fails to act. Intermediaries lose their safe harbour protection under Section 79 of the IT Act when they do not remove violating content after receiving actual knowledge or a valid complaint within the timelines set by the IT Rules 2021.