Skip to Content

Regulating Deepfakes in India

Bridging the Gap Between Artificial Intelligence and Criminal Law
26 August 2026 by
Siddhi Tiwari, BA.LLB.Hons 2nd year, Maharaja Surajmal Institute
​

1. Abstract

The rapid escalation of generative artificial intelligence has birthed a sophisticated class of synthetic media known as deepfakes, posing existential threats to individual privacy, democratic discourse, and digital trust. As India navigates the seismic shift from the colonial-era Indian Penal Code to the Bharatiya Nyaya Sanhita (BNS) 2023, a critical academic inquiry emerges regarding the adequacy of this new penal framework in the face of algorithmic manipulation. This research identifies a profoundly fragmented legal response, characterized by a “temporal gap” in which laws designed for a “captured” reality struggle to govern “synthetically generated” simulations. Utilizing a doctrinal research methodology, this article evaluates the efficacy of the BNS 2023, the Information Technology (IT) Act 2000, and the Digital Personal Data Protection (DPDP) Act 2023. The analysis reveals that existing provisions regarding forgery, defamation, and obscenity are being intellectually overextended to address AI-generated likenesses, leading to significant interpretive friction. By examining the transparency mandates of the European Union's AI Act and judicial precedents like Puttaswamy, the study concludes that India's current regime remains reactive. The article argues for a dedicated statutory framework that introduces a harm-specific definition of “synthetic media” and mandates transparency through digital watermarking. Ultimately, this research seeks to propose concrete legislative reforms to ensure that technological acceleration does not come at the expense of human dignity and the right to control one's digital identity.

2. Introduction

In late 2023, the Indian digital landscape was jolted by a viral deepfake involving a prominent actress, which highlighted the terrifying ease with which non-consensual intimate imagery can be manufactured. This was followed by a wave of political disinformation and financial “CEO fraud” incidents that utilized AI-generated voice cloning to siphon millions from unsuspecting victims. These incidents are not merely technological anomalies; they represent a “doctrinal and temporal gap” where our jurisprudence, rooted in physical evidence and captured records, meets the mathematical generation of hyper-realistic falsehoods. The legal system was constructed to regulate the “capture” of reality, yet deepfakes offer a seamless “simulation” that requires no original physical act. Laws drafted in 2000, and even the revised statutes of 2023, encounter significant friction when forced to classify an algorithmically generated likeness as a “document” for forgery or an “electronic record” for cheating.

The core of the legal crisis lies in the fact that deepfakes do not simply edit existing content; they synthesize entirely new data points using deep learning. This distinction creates a fundamental disconnect: the law searches for a tangible origin or a “false making,” while the technology offers a groundless, high-fidelity impersonation. It is submitted that India's current fragmented regime split between the IT Act, the BNS, and the DPDP Act—provides only indirect and often insufficient remedies for these harms. Relying on “stretching” definitions designed for a pre-generative era leads to inconsistent judicial outcomes and leaves victims in a state of legal limbo. The thesis of this research asserts that while the current architecture provides foundational hooks, it lacks the specificity required to address the unique harms of synthetic media, necessitating a proactive, harm-specific statutory framework.

3. Background and Objectives

Deepfakes, a portmanteau of “deep learning” and “fake,” refer to synthetic media where a person in an existing image or video is replaced with someone else's likeness using artificial neural networks. From a legal perspective, however, deepfakes must be conceptualized as “identity-based harm.” They represent a shift from traditional manipulation to a form of digital personation that is often indistinguishable from reality to the human eye, thereby undermining the evidentiary value of digital media. In the Indian context, the proliferation of these tools has outpaced the legislative cycle, leaving the judiciary to rely on general criminal provisions to address hyper-specific digital violations.

The objectives of this research are fourfold:

1. To critically examine the provisions of the Bharatiya Nyaya Sanhita (BNS) 2023 and the Information Technology (IT) Act 2000 to determine their applicability to synthetic media.

2. To assess the adequacy of current privacy protections in light of the Justice K.S. Puttaswamy v. Union of India judgment and the Digital Personal Data Protection (DPDP) Act 2023.

3. To analyze the transparency mandates and satire exceptions within the European Union (EU) AI Act to identify legislative lessons for India.

4. Methodology

This research adopts a doctrinal legal research methodology, focusing on the rigorous analysis of primary and secondary legal sources. The primary sources include the Bharatiya Nyaya Sanhita 2023, the Information Technology Act 2000, the Digital Personal Data Protection Act 2023, and landmark judicial precedents such as Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) and Shreya Singhal v. Union of India (2015). The secondary sources consist of Ministry of Electronics and Information Technology (MeitY) advisories issued between 2023 and 2024, the official text of the EU AI Act, and academic commentary on the “doctrinal and temporal gaps” created by emerging technologies. By synthesizing these sources, the article identifies the “research gap” where traditional cybercrime law ends and the specific challenges of generative AI begin.

5. Criminal Liability Framework

The transition to the BNS 2023 was intended to modernize Indian criminal law, yet the application of its provisions to deepfakes reveals that the “electronic record” remains tethered to traditional notions of forgery and personation.

A. Bharatiya Nyaya Sanhita (BNS) 2023

The BNS 2023 provides the backbone for addressing traditional crimes such as forgery (Section 336), cheating (Section 316), and defamation (Section 356). However, applying forgery provisions to deepfakes creates a doctrinal friction regarding the nature of a “document.” Forgery traditionally requires the “making” of a false document or electronic record with the intent to cause damage. While a deepfake is technically an electronic record, it is a generated simulation rather than an alteration of an existing digital original. This raises a critical question: does a mathematical representation of a human likeness constitute a “document” in the same sense as a forged signature? Furthermore, the speed of AI content renders traditional criminal defamation suits which are notoriously slow ineffective at preventing the reputational damage that occurs within the first 24 hours of a viral release. This gap is further compounded by the difficulty of proving the “imputation” in a visual simulation compared to written words.

B. Information Technology Act, 2000

The IT Act 2000 contains more specific cyber provisions, but these suffer from a lack of definitional precision regarding generative AI. Sections 66C (identity theft) and 66D (cheating by personation) are the primary tools for prosecuting deepfake-related financial fraud[1]. However, Section 66E, which addresses privacy violations by “capturing” or “publishing” images of private areas, faces a significant linguistic hurdle. The provision uses the word “capturing,” which implies a factual act of recording a real event. Because a deepfake is “generated” algorithmically from training data rather than “captured” in the moment, a strict judicial interpretation could exclude non-consensual intimate deepfakes from the scope of Section 66E. Furthermore, MeitY advisories issued in 2023 and 2024 have attempted to fill this gap by mandating that intermediaries remove such content within 24 hours, yet these advisories lack the statutory force of a dedicated penal provision[2].

C. The Doctrinal Gap

The following table synthesizes the specific limitations within the current statutory framework when applied to the reality of synthetic media.

Table 1. Statutory Limitations in the Deepfake Context

Statutory Provision

Traditional Legal Requirement

Reality of Deepfakes

Doctrinal / Temporal Gap

BNS Forgery

Making a false “document” or “electronic record.”

Content is generated by AI, not necessarily “altered” from an original.

Uncertainty if AI-generated likeness meets the traditional definition of a document.

IT Act Sec. 66E

Violating privacy by “capturing” an image without consent.

Images are synthetically generated from existing data, not “captured” in the moment.

The word “capturing” may exclude purely generated synthetic media.

IT Act Sec. 66D

Cheating by personation using a computer resource.

Requires proof of “cheating” and specific financial or personal gain.

Does not cover malicious deepfakes used for harassment where no “cheating” (theft) occurs.

BNS Defamation

Publication of a “statement” or “imputation.”

Visual simulations can imply meanings without explicit verbal statements.

Visual “imputation” is harder to prove than written or spoken words.

 

6. Privacy Concerns

Deepfakes represent the ultimate violation of “informational privacy,” a concept that has become a cornerstone of Indian constitutional law following the recognition of privacy as a fundamental right.

Judicial Foundation: Puttaswamy and Shreya Singhal

In Justice K.S. Puttaswamy v. Union of India (2017), the Supreme Court declared privacy as a fundamental right under Article 21, identifying “informational privacy” and the “right to control one's digital identity” as essential components of personal liberty. Deepfakes directly assault this right by stripping individuals of the ability to control their likeness and voice. When an AI generates a realistic video of an individual performing acts they never consented to, it violates the “inviolability of the person”[3]. However, any regulation must also account for the principles established in Shreya Singhal v. Union of India (2015), which struck down Section 66A of the IT Act for being overbroad and vague. The lesson from Shreya Singhal is that deepfake regulation must be narrowly tailored to address specific harms—such as non-consensual imagery—without chilling legitimate free speech or political satire[4].

Statutory Framework: The DPDP Act 2023

The Digital Personal Data Protection (DPDP) Act 2023 was designed to regulate the processing of personal data. However, there is a critical debate on whether “personal data” definitions sufficiently protect against the creation of a “synthetic likeness.” If a deepfake is generated using publicly available images, it may fall into exceptions that bypass the Act's consent framework. Furthermore, the DPDP Act focuses on “Data Fiduciaries” and “Data Processors,” but it may not adequately address the “Data Creator” the individual who uses a local AI tool to generate a malicious deepfake. The Act's focus on structured data processing leaves a gap in the regulation of unstructured generative outputs that mimic human identity without using “data” in the traditional database sense[5].

7. Comparative Analysis

Looking toward international standards reveals how other jurisdictions are moving from “victim-focused” remedies to “generator-focused” regulations, shifting the burden of proof and disclosure.

The EU AI Act, specifically Article 50, provides a robust model for India to consider. It shifts the responsibility from the victim to the technology provider and user through strict transparency obligations:

Mandatory Disclosure: Users of AI systems that generate or manipulate content that resembles existing persons must disclose that the content has been artificially generated.

Watermarking: Requirements for providers to ensure that AI outputs are marked in a machine-readable format.

Exception for Satire: A clear carve-out for content that is part of an evident creative, satirical, or artistic work, provided the disclosure does not hamper the display[6].

The “Lesson for India” is that current domestic laws are reactive, waiting for harm to manifest before intervening. The EU model suggests a proactive approach where the act of generating synthetic content without disclosure is itself a regulatory violation. However, the “Satire Exception” is vital for India, given our vibrant tradition of political mimicry and parody. Without such a carve-out, a dedicated deepfake law could inadvertently become a tool for political censorship, violating the free speech standards set in Shreya Singhal.

8. Reform Suggestions

The research indicates that India's regulatory response is “fragmented and reactive.” Law enforcement is forced to “stretch” statutes like Section 66E of the IT Act or the forgery provisions of the BNS to address harms they were never meant to cover. This leads to inconsistent judicial outcomes and a lack of deterrence. To bridge this doctrinal and temporal gap, the following four concrete reforms are suggested:

1. Statutory Definition: The IT Act should be amended to include a statutory definition of “synthetic media” and “deepfakes.” This would resolve the interpretive ambiguity surrounding terms like “capturing” and “electronic record,” ensuring that generated content is legally equivalent to captured content in cases of harm.

2. Disclosure Mandates: Inspired by the EU AI Act, India should mandate the labelling of AI-generated content. AI tool providers must be required to embed machine-readable watermarks, and social media intermediaries must provide visible tags for synthetic media.

3. Expedited Takedown Mechanisms: Building on the MeitY 2023-2024 advisories, the IT Rules should be updated to provide a statutory 24-hour takedown window specifically for non-consensual intimate deepfakes. This “fast track” is necessary because the speed of viral transmission outpaces traditional judicial remedies.

4. Institutional Capacity and I4C: There is an urgent need to empower the Indian Cyber Crime Coordination Centre (I4C). Legal reform is meaningless without technical forensic tools to detect and verify synthetic media at the district level. Training specialized cybercrime cells under the I4C framework will ensure that police can distinguish between real and synthetic evidence.

9. Conclusion

The transition from traditional digital media to AI-generated synthetic content has created a legal vacuum in India that existing statutes are ill-equipped to fill. While the BNS 2023 and the IT Act 2000 provide a foundational framework for cybercrime, they suffer from significant doctrinal gaps when confronted with the reality of algorithmically generated falsehoods. The fundamental right to privacy, as established in Puttaswamy, and the free speech protections in Shreya Singhal, demand a more robust, narrowly tailored statutory response that protects digital integrity without stifling innovation.

India must move beyond stretching old laws and toward a coherent, harm-specific regulatory regime. By adopting transparency mandates similar to the EU AI Act and refining our statutory definitions to include “synthetic media,” we can balance the benefits of AI innovation with the essential protection of human dignity. The goal is not to stifle technology, but to ensure that our legal lexicon evolves at the same pace as the algorithms it seeks to govern, securing the digital future for all citizens.

Reference

[1]Information Technology Act, 2000, ss. 66C–66D, India Code, www.indiacode.nic.in.

[2]Ministry of Electronics and Information Technology. Advisory on Deepfakes and AI-Generated Content. Government of India, 2024, www.meity.gov.in.

[3]Justice K.S. Puttaswamy (Retd.) v. Union of India. (2017) 10 SCC 1, Supreme Court of India, 24 Aug. 2017, p. 45. Indian Kanoon, indiankanoon.org/doc/91938676/.

[4]Shreya Singhal v. Union of India. (2015) 5 SCC 1, Supreme Court of India, p. 12. Indian Kanoon, indiankanoon.org/doc/110813550/.

[5]Digital Personal Data Protection Act, 2023. India Code, www.indiacode.nic.in.

[6]European Parliament. EU AI Act (Official Text). 2024, art. 50, www.artificialintelligenceact.eu.

Siddhi Tiwari, BA.LLB.Hons 2nd year, Maharaja Surajmal Institute 26 August 2026
Share this post
Category
Sign in to leave a comment