ABSTRACT
Artificial intelligence has transformed the way information is created, communicated and consumed. One of its most controversial developments is the emergence of deepfake technology, which makes it possible to create highly realistic but entirely fabricated images, videos and audio recordings. Deepfakes can imitate a person's face, voice, expressions and mannerisms with increasing accuracy, often making it difficult for ordinary individuals to distinguish manipulated content from reality. While this technology has legitimate applications in entertainment, education and digital innovation, its misuse presents serious threats to privacy, dignity, consent and personal identity.
India has witnessed a growing concern regarding the misuse of deepfake technology, particularly in cases involving impersonation, non-consensual intimate content, financial fraud and misinformation. The legal response to these harms is currently spread across different statutes and regulatory mechanisms, including the Information Technology Act, the Bharatiya Nyaya Sanhita, the Digital Personal Data Protection framework and the Information Technology Rules governing intermediaries.
This article examines whether India's existing legal framework is sufficient to address the unique challenges created by deepfakes. It argues that although existing laws provide several remedies, they were largely designed before the emergence of sophisticated generative artificial intelligence. The article therefore highlights important gaps relating to consent, victim protection, platform accountability and the identification of synthetic content. It concludes that India requires a clearer and more victim-centred approach that balances technological innovation with the protection of fundamental rights.
Keywords: Deepfakes, Artificial Intelligence, Digital Identity, Privacy, Consent, Dignity, Cyber Law, India
1. INTRODUCTION
The development of artificial intelligence has changed the digital world at an extraordinary pace. Artificial intelligence is now capable of writing text, generating photographs, creating videos, reproducing voices and even imitating human behaviour. While these developments have created new opportunities in areas such as education, healthcare, entertainment and communication, they have also created serious legal and ethical concerns. One of the most significant concerns is the rise of deepfake technology.
A deepfake refers broadly to artificially generated or manipulated digital content that is made to appear authentic.[1] A person's face may be placed into a video in which they never appeared, their voice may be copied to create statements they never made, or their image may be digitally altered in a manner that appears completely real. The danger of deepfakes lies in their ability to blur the distinction between truth and fabrication.
Earlier forms of digital manipulation were often easy to identify. Edited photographs and poorly altered videos could usually be recognised through visible inconsistencies. Modern artificial intelligence, however, has made manipulation significantly more sophisticated. A convincing deepfake may appear genuine to an ordinary viewer and can spread across social media within minutes.[2]
The consequences can be deeply personal. A person's likeness can be used without permission to create sexually explicit material, spread false information, damage their reputation or commit financial fraud. Public figures may be falsely shown making controversial statements, while ordinary individuals may become victims of impersonation or non-consensual digital exploitation. Women and children are particularly vulnerable to certain forms of deepfake abuse because manipulated intimate content can cause long-term psychological, social and reputational harm.[3]
The problem is therefore not merely technological. It directly concerns fundamental legal values such as privacy, dignity, autonomy and consent. In India, the right to privacy has been recognised as an important aspect of individual liberty and dignity.[4] Deepfake technology challenges these principles because it allows a person's identity to be digitally reproduced and manipulated without their participation or approval.
The central question is whether India's present legal framework is capable of responding effectively to this new form of harm. Although several existing laws can be applied to cases involving deepfakes, India does not rely on a single, comprehensive legal framework dealing exclusively with every aspect of synthetic identity and deepfake misuse. Instead, protection is provided through a combination of cyber law, criminal law, data protection principles and intermediary regulation.[5]
This article examines the adequacy of this framework and argues that while India has made important regulatory progress, significant legal and practical challenges continue to exist.
2. UNDERSTANDING DEEPFAKES AND DIGITAL IDENTITY
The term “deepfake” is commonly associated with the use of deep learning and artificial intelligence to generate or manipulate digital content. Such content may include videos, photographs or audio recordings. The technology can analyse large amounts of data relating to a person's appearance or voice and use that information to create a realistic imitation.[6]
Deepfakes are not inherently unlawful. Artificially generated content can be used for legitimate purposes. Film industries may use digital technology to recreate historical figures or improve visual effects. Educational institutions may use artificial intelligence to create interactive learning material. Businesses may use synthetic voices for accessibility and communication. Therefore, the law must not treat every use of synthetic media as harmful.[7] The legal difficulty arises when a person's identity is used without consent in a manner that causes or is likely to cause harm.
Digital identity includes the various characteristics through which an individual is recognised in the digital environment. A person's name, photograph, voice, facial features and online presence may all form part of their digital identity. Traditionally, identity was associated with physical documents and personal interactions. In the modern world, however, an individual's identity exists across social media platforms, databases, photographs, recordings and other digital spaces.
Deepfake technology creates a new threat because it allows another person to manufacture an apparently authentic version of someone else's identity. The victim may not have participated in the creation of the content at all. Their face may be taken from publicly available photographs, while their voice may be copied from interviews, videos or social media recordings. This raises an important question: should individuals have greater legal control over the use of their likeness and voice?[8]
The issue becomes particularly serious when deepfakes involve non-consensual intimate imagery. In such situations, the victim may suffer humiliation and reputational damage even though the content itself is fabricated. The fact that the video is not real does not necessarily reduce the harm. In some cases, the victim may actually face additional difficulties because they are required to convince others that the content is false.[9]
Deepfakes also create risks beyond personal exploitation. Artificial intelligence can be used to imitate the voices of family members, employers or public officials. Such technology can facilitate financial scams and fraud.[10] Similarly, manipulated political content can influence public opinion and undermine trust in democratic institutions.[11]
The deeper problem is therefore the erosion of trust. If people can no longer confidently distinguish genuine content from artificial content, the value of digital evidence itself may be affected. Deepfakes can make false information appear true, but they can also allow genuinely recorded information to be dismissed as fake.[12]
3. INDIA'S EXISTING LEGAL FRAMEWORK
India currently addresses deepfake-related harms through a combination of existing laws and regulatory mechanisms. These include constitutional protections, the Information Technology Act, criminal law, data protection principles and obligations imposed upon online intermediaries.
3.1 Privacy and Dignity under Article 21
The Constitution of India provides an important foundation for protecting individuals against serious forms of digital harm. Article 21 protects life and personal liberty and has been interpreted broadly to include values such as dignity, autonomy and privacy.[13]
Privacy is particularly important in the context of deepfakes because artificial intelligence can reproduce aspects of a person's identity without their knowledge. A person's image and voice are closely connected to their personality and individual identity. The unauthorised use of these characteristics can interfere with their control over their own representation.[14]
Dignity is equally relevant. A deepfake may portray an individual engaging in conduct that never occurred. Even if the victim later proves that the content was fabricated, the damage caused by its circulation may be difficult to completely reverse.
The constitutional recognition of privacy and dignity therefore provides an important basis for understanding why deepfake misuse should not be viewed merely as a technological inconvenience. It can amount to a serious interference with personal autonomy.
3.2 The Information Technology Act, 2000
The Information Technology Act remains one of the most important statutes dealing with cyber offences in India. Although it was enacted before the development of modern generative artificial intelligence, several of its provisions may apply to deepfake-related misconduct.[15]
Provisions dealing with identity theft and cheating by personation may be relevant when a person's identity is digitally misused to deceive others. For example, an artificially generated voice recording may be used to impersonate an individual and obtain money through fraud.[16]
The Act also contains provisions relating to violations of privacy and the publication or transmission of unlawful sexually explicit material. These provisions can become particularly important in cases involving non-consensual deepfake imagery.[17]
However, the difficulty is that these provisions were not originally drafted with synthetic media in mind. Traditional identity theft usually involves the misuse of passwords, credentials or other identifying information.[18] Deepfakes, on the other hand, involve the creation of an entirely artificial representation of a person.
Therefore, while existing provisions can provide remedies in particular situations, their application to deepfake technology may not always be straightforward.
3.3 Criminal Law and the Bharatiya Nyaya Sanhita
Criminal law may also apply when deepfakes are used for cheating, impersonation, forgery, defamation or the spread of harmful misinformation.[19]
For instance, if a deepfake is created to deceive another person and obtain money, criminal provisions dealing with cheating and personation may become relevant.[20] Similarly, fabricated electronic material created with the intention of harming a person's reputation may potentially attract legal consequences.[21]
Deepfakes used to create panic, spread false information or disturb public order can also create broader concerns beyond individual privacy.[22]
Nevertheless, criminal law generally requires the facts of each case to fit within specific statutory offences.[23] This creates a practical problem because deepfake technology does not always fit neatly into traditional legal categories. A person may create harmful synthetic content without committing what was historically understood as forgery or impersonation.
This demonstrates the challenge of applying laws designed for an earlier technological environment to a rapidly evolving form of artificial intelligence.
3.4 The Digital Personal Data Protection Framework
The use of personal data is also closely connected with deepfake technology. Artificial intelligence systems often require access to information such as photographs, videos, voice recordings and other digital material.
The Digital Personal Data Protection framework is therefore relevant because it is based on the broader principle that personal data should be processed lawfully and responsibly.[24]
Consent is particularly significant.[25] If an individual's personal information is used to create harmful synthetic content without their permission, questions arise regarding whether they exercised meaningful control over the use of their data.
However, data protection alone cannot solve every deepfake-related problem. A deepfake may be created using material that is publicly available online.[26] The harm caused by synthetic content may also extend beyond the initial collection of data and involve issues of dignity, reputation and personality.
Therefore, data protection should be considered one part of the legal response rather than a complete solution.
3.5 Platform and Intermediary Responsibility
Social media platforms play a central role in the spread of deepfake content. A fabricated video can reach thousands or even millions of users within a short period. For this reason, the responsibility of intermediaries is one of the most important aspects of deepfake regulation.[27]
The Information Technology Rules impose due diligence obligations upon intermediaries and require them to take action against certain forms of unlawful content.[28] Recent regulatory developments have also placed greater attention on synthetically generated information and the need for clearer identification of artificial content.[29]
This represents an important development because users should be able to distinguish between authentic material and content generated or significantly manipulated through artificial intelligence.
However, platform regulation raises difficult questions. Companies must act quickly to remove harmful content, but excessive or inaccurate moderation may affect legitimate expression.[30] A balanced approach is therefore necessary.
The challenge is to ensure that platforms do not become passive spaces through which harmful content spreads without accountability while also protecting lawful speech and creative uses of technology.
4. MAJOR LEGAL CHALLENGES AND GAPS
Despite the existence of multiple legal remedies, several significant gaps remain in India's approach to deepfakes.
The first problem is the absence of a simple and universally understood legal framework specifically designed around the realities of synthetic media.[31] Victims may have to rely on several different laws depending on whether the harm involves privacy, fraud, obscenity, defamation or impersonation. This can make the legal process confusing, particularly for ordinary individuals who may not know which authority to approach.
The second problem concerns consent. Existing laws recognise the importance of consent in different contexts, but deepfake technology creates new questions about what meaningful consent should involve. A person may consent to having a photograph uploaded online without consenting to their face being used to create artificial videos.[32] Similarly, an actor may agree to participate in a film without agreeing to unlimited future reproduction of their likeness through artificial intelligence.[33]
The third problem is speed. Digital content spreads quickly, while legal remedies can take time. By the time a victim receives a formal legal remedy, the content may already have been copied and circulated across multiple platforms.[34] Rapid takedown mechanisms are therefore essential.[35]
The fourth problem is cross-border enforcement. The creator of a deepfake may be located outside India, while the platform hosting the content may operate from another jurisdiction. This makes investigation and evidence collection more complicated.[36]
The fifth problem is the availability of detection technology. Law enforcement agencies and platforms must be able to identify sophisticated synthetic content. As artificial intelligence improves, detection becomes increasingly difficult.[37]
Finally, there is the problem of public awareness. Many people are still unfamiliar with the capabilities of deepfake technology. Individuals may trust fake videos because they appear realistic. Greater public education is therefore necessary to reduce the effectiveness of deepfake-based fraud and misinformation.
5. A COMPARATIVE PERSPECTIVE
Several jurisdictions have begun developing more specific approaches towards artificial intelligence and synthetic media. A comparative examination demonstrates that India can learn from different regulatory models.
The European approach places considerable emphasis on transparency, accountability and the identification of artificial intelligence-generated content. This reflects the idea that users should be informed when they are interacting with or viewing synthetic material.[38]
Other jurisdictions have adopted targeted laws dealing with specific harms such as non-consensual intimate deepfakes and election-related manipulation.[39]
China has also developed rules requiring the identification of certain forms of synthetic media and placing obligations on service providers.[40]
The most important lesson from comparative developments is that a single legal solution may not be sufficient. Effective regulation generally requires a combination of transparency obligations, platform responsibility, victim protection and technological safeguards.[41]
India should not simply copy another country's model. Its legal framework must reflect Indian constitutional values, the scale of the country's digital population and the realities of its social media environment. However, comparative experiences clearly demonstrate the importance of developing specific responses to harms created by synthetic media.
6. FINDINGS AND DISCUSSION
The existing Indian legal framework is not entirely inadequate. India already possesses several laws capable of addressing different forms of deepfake misuse. Privacy violations, identity theft, cheating, sexually explicit content and unlawful digital conduct can be addressed through existing legal provisions.
Recent developments relating to intermediary responsibility and synthetically generated information also demonstrate that the legal system is beginning to respond directly to artificial intelligence-related harms.[42]
However, the present framework remains fragmented. A victim may have to navigate several different laws and authorities before obtaining relief. This can be particularly difficult in urgent cases involving non-consensual intimate content.
The law also continues to face a conceptual challenge. Traditional legal categories were developed at a time when it was difficult to artificially reproduce another person's appearance or voice with such accuracy. Deepfakes therefore challenge traditional understandings of identity and authenticity.
Another important finding is that the harm caused by deepfakes cannot be measured only in financial terms. A fabricated video may affect a person's dignity, relationships, employment and mental well-being.[43] The law must therefore recognise the human consequences of synthetic identity misuse.
The issue of consent is especially important. Individuals should have meaningful protection against the use of their likeness or voice in harmful artificial content. Simply because information is publicly available should not mean that another person has unlimited freedom to transform it into deceptive or exploitative synthetic media.[44]
India's legal response should therefore become more focused, accessible and victim-centred.
7. CONCLUSION
Deepfake technology represents one of the most significant challenges created by the modern development of artificial intelligence. Its ability to create realistic but fabricated images, videos and voices threatens traditional ideas of authenticity and personal identity.
For India, the challenge is particularly important because of the country's enormous digital population and rapidly expanding use of artificial intelligence. Deepfake misuse can affect individuals through privacy violations, non-consensual intimate content, financial fraud, reputational harm and misinformation.
India's existing legal framework provides important remedies through constitutional protections, cyber law, criminal law, data protection principles and intermediary regulation. However, these protections remain dispersed across different legal instruments and were, in many cases, developed before the emergence of sophisticated generative artificial intelligence. Recent regulatory developments show that India is increasingly recognising the need to address synthetically generated content. Nevertheless, the law must continue to evolve alongside technology.
The most important objective should be the protection of human dignity and autonomy. A person's face, voice and identity should not become freely exploitable merely because artificial intelligence makes imitation easy. The future of deepfake regulation in India should therefore focus on three essential principles: meaningful consent, effective accountability and rapid victim protection. A clear legal framework, stronger technological capacity and greater public awareness can help ensure that artificial intelligence remains a tool for innovation rather than a mechanism for exploitation.
Ultimately, the challenge posed by deepfakes is not simply about determining what technology can create. It is about deciding what a legal system must protect when technology can convincingly manufacture reality itself.
References
[1] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) [2024] OJ L 2024/1689 (‘AI Act’), art 3(60) (defining a ‘deep fake’ as AI-generated or manipulated image, audio or video content that resembles real persons, places or events and would falsely appear authentic to a viewer). For the Indian counterpart, see the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026, G.S.R. 120(E) (notified 10 February 2026; in force 20 February 2026), inserting r 2(1)(wa) (‘synthetically generated information’) (‘Amendment Rules 2026’).
[2] On the speed at which fabricated material travels online, see Soroush Vosoughi, Deb Roy and Sinan Aral, ‘The Spread of True and False News Online’ (2018) 359 Science 1146 (finding that false news diffused significantly farther and faster than true news).
[3] Henry Ajder and others, The State of Deepfakes: Landscape, Threats, and Impact (Deeptrace, September 2019) (finding that about 96 per cent of the deepfake videos then online were pornographic, and that the pornographic material targeted women almost exclusively); Danielle Keats Citron, ‘Sexual Privacy’ (2019) 128 Yale Law Journal 1870. On offences involving children, see Information Technology Act 2000, s 67B, and Protection of Children from Sexual Offences Act 2012, ss 13–15.
[4] Justice KS Puttaswamy (Retd) v Union of India (2017) 10 SCC 1 (nine-judge bench holding that privacy is a fundamental right, protected as part of the guarantee of life and personal liberty under art 21 and of the freedoms in Part III of the Constitution).
[5] The absence of a dedicated deepfake statute is the premise of the writ petitions before the Delhi High Court in Rajat Sharma v Union of India WP(C) 6560/2024 and Chaitanya Rohilla v Union of India WP(C) 15596/2023, in which (order of 21 November 2024) the Union informed the Court that a committee on deepfakes had been constituted; see ‘Centre To Form Committee To Frame Regulations On Deepfakes: Delhi HC Told’ Verdictum https://www.verdictum.in/court-updates/high-courts/deepfake-central-government-committee-chaitnaya-rohilla-rajat-sharma-v-union-of-india-1558673 (accessed 19 September 2026).
[6] Mika Westerlund, ‘The Emergence of Deepfake Technology: A Review’ (2019) 9(11) Technology Innovation Management Review 39; Robert Chesney and Danielle Keats Citron, ‘Deep Fakes: A Looming Challenge for Privacy, Democracy, and National Security’ (2019) 107 California Law Review 1753.
[7] Chesney and Citron (n 6) (discussing beneficial uses in education, art and personal autonomy alongside the harms). Indian and EU law build the same distinction into their rules: r 2(1)(wa) of the Amendment Rules 2026 (n 1) excludes routine or good-faith editing, accessibility work and educational or training material from ‘synthetically generated information’, and art 50(4) of the AI Act limits the disclosure duty for evidently artistic, satirical or fictional works.
[8] Indian courts have begun to answer through personality and publicity rights: Anil Kapoor v Simply Life India CS(COMM) 652/2023 (Delhi HC, 20 September 2023) (interim injunction restraining misuse of the actor’s name, image and voice, including through AI tools and face-morphing); Amitabh Bachchan v Rajat Nagi CS(COMM) 819/2022 (Delhi HC, 25 November 2022). On the recognition of privacy in matters of personal life under art 21, see R Rajagopal v State of Tamil Nadu (1994) 6 SCC 632.
[9] Mrs X v Union of India WP(Crl) 1505/2021 (Delhi HC, 26 April 2023) (recognising the trauma caused by non-consensual intimate imagery and the burden on victims of repeatedly locating and reporting re-uploads); Citron (n 3).
[10] Catherine Stupp, ‘Fraudsters Used AI to Mimic CEO’s Voice in Unusual Cybercrime Case’ Wall Street Journal (30 August 2019); Kathleen Magramo, ‘British Engineering Giant Arup Revealed as $25 Million Deepfake Scam Victim’ CNN (17 May 2024).
[11] Chesney and Citron (n 6) (treating election manipulation and the erosion of trust in public institutions as societal harms of deepfakes).
[12] This is what Chesney and Citron call the ‘liar’s dividend’: as public awareness of deepfakes grows, those confronted with authentic recordings can plausibly deny them. Chesney and Citron (n 6) 1785.
[13] Constitution of India, art 21; Puttaswamy (n 4); Francis Coralie Mullin v Administrator, Union Territory of Delhi (1981) 1 SCC 608 (art 21 includes the right to live with human dignity).
[14] See Anil Kapoor (n 8); Puttaswamy (n 4) (recognising informational privacy and individual autonomy over personal information).
[15] Information Technology Act 2000 (Act 21 of 2000). The offences discussed below (ss 66C–66E) were inserted by the Information Technology (Amendment) Act 2008 (Act 10 of 2009), in force from 27 October 2009.
[16] Information Technology Act 2000, s 66C (fraudulent or dishonest use of another person’s electronic signature, password or other unique identification feature) and s 66D (cheating by personation by means of a communication device or computer resource).
[17] Information Technology Act 2000, s 66E (capturing, publishing or transmitting an image of a person’s private area without consent, in circumstances violating privacy), s 67 (obscene material in electronic form), s 67A (sexually explicit material) and s 67B (material depicting children in sexually explicit acts). Section 66E is framed around the capture of an actual image, so its application to synthetic imagery is open to argument.
[18] Section 66C is textually anchored in the misuse of an ‘electronic signature, password or any other unique identification feature’ (n 16); a synthetic likeness fits that language only by analogy.
[19] Bharatiya Nyaya Sanhita 2023 (Act 45 of 2023), in force from 1 July 2024, replacing the Indian Penal Code 1860 (‘BNS’).
[20] BNS, s 318 (cheating) and s 319 (cheating by personation); see also Information Technology Act 2000, s 66D (n 16).
[21] BNS, s 336 (forgery of documents and electronic records, including where intended to harm reputation) and s 356 (defamation).
[22] BNS, s 353 (statements conducing to public mischief) and s 196 (promoting enmity between groups).
[23] This follows from the rule that penal statutes are strictly construed and an offence cannot be created by analogy: Tolaram Relumal v State of Bombay AIR 1954 SC 496.
[24] Digital Personal Data Protection Act 2023 (Act 22 of 2023), s 4(1) (personal data may be processed only for a lawful purpose, on the basis of consent or a specified legitimate use). The Act is being brought into force in phases under the Digital Personal Data Protection Rules 2025, G.S.R. 846(E) (13 November 2025); the notice, consent and other substantive obligations of data fiduciaries (rr 3, 5–16, 22 and 23) apply only from 13 May 2027.
[25] Digital Personal Data Protection Act 2023, s 6(1) (consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action for a specified purpose and limited to the data necessary for that purpose).
[26] Digital Personal Data Protection Act 2023, s 3(c)(ii): the Act does not apply to personal data that the data principal herself has made publicly available, or that another person has made public under a legal obligation. A photograph the victim posted openly may therefore fall outside the Act; see also s 3(c)(i) (processing for a personal or domestic purpose).
[27] Information Technology Act 2000, s 79 (conditional exemption of intermediaries from liability for third-party content, subject to due diligence and to acting on actual knowledge); Shreya Singhal v Union of India (2015) 5 SCC 1 (reading ‘actual knowledge’ in s 79(3)(b) as knowledge acquired through a court order or a government notification).
[28] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, G.S.R. 139(E) (25 February 2021), r 3 (‘IT Rules 2021’).
[29] Amendment Rules 2026 (n 1): r 2(1)(wa) (definition of synthetically generated information); r 3(3) (technical measures against unlawful synthetic content, and labelling and embedded provenance metadata for other synthetic content); r 4(1A) (user declaration and verification by significant social media intermediaries); r 3(1)(d) (removal within three hours of a court order or government direction, reduced from 36 hours); r 3(2)(b) (removal within two hours of a complaint about intimate or impersonating content, including morphed images, reduced from 24 hours). For a summary, see ‘IT Amendment Rules 2026: AI & Intermediary Compliance’ SCC Times (12 February 2026) https://www.scconline.com/blog/post/2026/02/12/it-rules-2026-ai-and-intermediary-compliance/ (accessed 19 September 2026).
[30] Shreya Singhal (n 27) (striking down s 66A and reading down the intermediary takedown provisions because low-threshold removal regimes chill speech protected by art 19(1)(a)). On the compressed timelines under the 2026 amendments, see Bhatt & Joshi Associates, ‘MeitY’s 2-Hour Deepfake Takedown Window Under IT Amendment Rules 2026: Constitutionally Proportionate or Operationally Impossible?’ https://bhattandjoshiassociates.com/meitys-2-hour-deepfake-takedown-window-under-it-amendment-rules-2026-constitutionally-proportionate-or-operationally-impossible/ (accessed 19 September 2026).
[31] See Rajat Sharma and Chaitanya Rohilla (n 5) (writ petitions seeking dedicated regulation of deepfakes, in which the Union constituted a committee to examine the question).
[32] The point is one of purpose and context: consent to one use of personal data does not extend to another. See Digital Personal Data Protection Act 2023, s 6(1) (n 25) (purpose-specific consent); cf Helen Nissenbaum, ‘Privacy as Contextual Integrity’ (2004) 79 Washington Law Review 119. On the limit created by public availability, see s 3(c)(ii) (n 26).
[33] Copyright Act 1957, ss 38–38B (performers’ rights, including the moral right under s 38B to restrain distortion or modification of a performance that is prejudicial to the performer’s reputation); Anil Kapoor (n 8).
[34] Vosoughi, Roy and Aral (n 2); on the consequences for victims of delayed removal, Mrs X (n 9).
[35] Amendment Rules 2026 (n 1), r 3(2)(b) (removal within two hours of a complaint about intimate or impersonating content, including artificially morphed images) and r 3(1)(d) (three hours from a court order or government direction). On victim-centred removal, see Mrs X (n 9) (intermediaries must remove offending content and not merely the URLs a victim reports), and Ministry of Electronics and Information Technology, Standard Operating Procedure to Curtail Dissemination of Non-Consensual Intimate Imagery (NCII) Content (October 2025).
[36] Information Technology Act 2000, s 75 (extra-territorial application where the contravention involves a computer, computer system or network located in India). The Delhi High Court has itself asked how Indian law can reach platforms located abroad: ‘Deepfake Going To Be Serious Menace In Society, Antidote Of Fake AI Would Be Technology Only: Delhi High Court’ LiveLaw https://livelaw.in/amp/high-court/delhi-high-court/delhi-high-court-deepfake-ai-technology-267918 (accessed 19 September 2026).
[37] Brian Dolhansky and others, ‘The DeepFake Detection Challenge (DFDC) Dataset’ (arXiv, 2020) arXiv:2006.07397 (reporting that even the best models in a large public challenge performed modestly on previously unseen deepfakes); Chesney and Citron (n 6) (on the contest between generation and detection technologies).
[38] AI Act (n 1), art 50: providers must ensure that people know when they are interacting with an AI system (art 50(1)) and mark synthetic outputs in a machine-readable, detectable form (art 50(2)); deployers must disclose deepfakes (art 50(4)). Article 50 has applied since 2 August 2026, with a transitional period to 2 December 2026 for the art 50(2) marking duty for systems already on the market under the Digital Omnibus on AI. See ‘EU AI Act: Transparency Obligations Take Effect 2 August 2026’ (Cooley, 3 August 2026) https://www.cooley.com/news/insight/2026/2026-08-03-eu-ai-act-transparency-obligations-take-effect-2-august-2026 (accessed 19 September 2026).
[39] For example, in the United States: TAKE IT DOWN Act, Pub L No 119-12 (2025) (criminalising the publication of non-consensual intimate imagery, including digital forgeries, and requiring covered platforms to remove reported material on notice); Tex Elec Code § 255.004(d) (inserted by SB 751, 2019) (offence of creating and publishing a deceptive deepfake video within 30 days of an election with intent to injure a candidate or influence the result). In the United Kingdom: Online Safety Act 2023, s 188 (inserting s 66B into the Sexual Offences Act 2003, on sharing intimate images, including images that appear to show a person).
[40] Provisions on the Administration of Deep Synthesis Internet Information Services (Cyberspace Administration of China, Ministry of Industry and Information Technology and Ministry of Public Security; effective 10 January 2023); Measures for Labeling AI-Generated Synthetic Content (issued March 2025; effective 1 September 2025). On the latter, see ‘New AI Content Labelling Rules in China: What Are They and How Do They Compare to the EU AI Act?’ (Bird & Bird, 2025) https://www.twobirds.com/en/insights/2025/new-ai-content-labelling-rules-in-china-what-are-they-and-how-do-they-compare-to-the-eu-ai-act (accessed 19 September 2026).
[41] Chesney and Citron (n 6) (surveying legal, technological and market responses and concluding that none suffices alone).
[42] See n 29.
[43] Citron (n 3) (on the intimate and psychological injury caused by invasions of sexual privacy, including deepfake sex videos); Chesney and Citron (n 6) (on reputational, psychological and economic harms to individuals).
[44] See Digital Personal Data Protection Act 2023, s 3(c)(ii) (n 26); Nissenbaum (n 32).
[45] The definition of ‘synthetically generated information’ in r 2(1)(wa) of the Amendment Rules 2026 and that of ‘deep fake’ in art 3(60) of the AI Act (n 1) offer two models for defining the category while carving out routine or good-faith uses. The Delhi High Court has also directed the deepfake committee to consider foreign regulatory frameworks (n 5).
[46] Cf Digital Personal Data Protection Act 2023, s 6(1) (n 25); Anil Kapoor (n 8) (protecting name, image and voice against unauthorised use).
[47] See n 35.
[48] Amendment Rules 2026 (n 1), rr 3(3) and 4(1A); AI Act (n 1), art 50(2) and (4); China’s labelling measures (n 40).
[49] On the admissibility of electronic records, see Bharatiya Sakshya Adhiniyam 2023, s 63 (certificate requirement; successor to s 65B of the Indian Evidence Act 1872); Arjun Panditrao Khotkar v Kailash Kushanrao Gorantyal (2020) 7 SCC 1 (certificate under s 65B(4) generally a condition for admitting secondary electronic evidence).
[50] Intermediaries must already inform users periodically of the consequences of unlawful content: IT Rules 2021 (n 28), r 3(1)(c), as amended by the Amendment Rules 2026 (n 1) (notice at least once every three months).