Deepfake law in India stopped being a grey area on 20 February 2026. That is the day the Ministry of Electronics and Information Technology’s amended IT Rules — the ones built around a new legal category called “synthetically generated information” — actually came into force. If you are reading this because a video, audio clip, or image using your face or voice has shown up somewhere you never posted it, you are not stuck waiting for Parliament to “eventually” pass a law. The law already exists, it has teeth, and this guide walks through exactly how to use it — from the emergency takedown request you should send today to the criminal complaint and civil suit you can file this week.
I run a media publication, which means I sit on both sides of this problem: I know how easily synthetic content spreads through the same distribution channels that make real journalism travel, and I know which legal levers actually move a platform to act versus which ones just generate a polite auto-reply. I’ve written before about the legal lessons I learned running Malik Times — content ownership and platform liability look very different once you’re the one publishing, and that lens shapes everything below. This is the guide I wish existed the first time a client asked me, “someone made an AI video of me — what do I actually do?”
What Legally Counts as a “Deepfake” in India Now
Until October 2025, “deepfake” was a media term with no fixed legal meaning in India — courts borrowed language from privacy, defamation, and copyright law to deal with each case individually. That changed when MeitY notified a formal definition under the amended IT Rules, 2021. The law now uses the term synthetically generated information (SGI) — content that is artificially or algorithmically created, generated, modified, or altered using a computer resource in a way that appears reasonably authentic. That single definition now covers face-swapped videos, cloned voices, algorithmically retouched photographs, and even AI-generated text designed to pass as human-written.
This matters practically because it closes the old argument platforms used to make: “our rules only cover real photos/videos, not AI-generated ones.” Under Rule 2(1)(wa) and Rule 3(1A) of the amended IT Rules, every reference to “information” in the intermediary due-diligence framework now explicitly includes synthetic content. A deepfake is no longer legally invisible just because no camera was involved.
If you publish or edit content professionally, this same “synthetic vs. authentic” line also runs straight through IP law — if you’re unclear on where AI-assisted editing ends and infringing reuse begins, our breakdown of copyright vs. fair use in India’s digital publishing rules is a useful companion read.
The 2026 IT Rules Amendment: Labeling, Takedowns, and Platform Duty
Here is the timeline, because dates matter when you’re arguing compliance obligations with a platform’s legal team:
- 22 October 2025 — MeitY released the draft amendment to the IT Rules, 2021, for public comment, introducing the SGI definition and labeling framework.
- 10 February 2026 — MeitY formally notified the amendment.
- 20 February 2026 — The deepfake-specific provisions came into force, with only a ten-day compliance runway for platforms.
What the rules actually require:
Mandatory labeling. Any intermediary offering a tool that can create or alter synthetic content must label the output. For visual content, the label has to be prominent and permanently embedded — not a watermark a user can crop out in five seconds. For audio, a disclosure has to run at the start of the clip. Labels must include a unique identifier tracing the content back to the tool or platform that generated it, so provenance survives even after re-uploads.
User declarations on big platforms. Significant Social Media Intermediaries (those with 5 million-plus monthly users — think the major social apps) must now ask users to declare whether uploaded content is synthetic, and must run reasonable technical checks on that declaration rather than simply trusting it.
Faster, senior-level takedowns. Removal orders for unlawful SGI can only be issued by officers at Joint Secretary or DIG rank or above, which was designed to prevent frivolous mass takedown abuse — but it also means a properly escalated deepfake complaint now moves through a defined, senior channel instead of disappearing into a generic support queue.
Carve-outs for ordinary editing. Routine photo touch-ups, filters, and accessibility tools (like text-to-speech for visually impaired users) are explicitly excluded, so the law targets deceptive synthetic media, not every Instagram filter.
If a platform is hosting a deepfake of you and refuses to act, you now have a specific rule number to cite in your legal notice — Rule 3(3)(a) — rather than a vague appeal to “community guidelines.”
These same obligations sit right next to a platform’s data-handling duties. If you run a platform yourself and are trying to work out where synthetic-content compliance ends and your broader data obligations begin, see our DPDP Act 2023 privacy policy compliance checklist and our note on why cybersecurity is now a legal requirement, not just an IT problem.
Personality Rights: Your Face and Voice Are Legally Yours
Even before the 2026 amendment, Indian courts had been building a parallel — and in some ways more powerful — remedy: personality rights, sometimes called publicity rights. India has no standalone Personality Rights Act, but the Delhi High Court has spent the last three years turning this into one of the fastest-moving areas of Indian civil litigation, almost entirely because of AI misuse.
The pattern is now well established through a string of celebrity cases:
- Anil Kapoor v. Simply Life India (2023) — the Delhi High Court granted an ex-parte, “in rem” injunction (binding the whole world, not just named defendants) restraining the use of the actor’s name, image, voice, and even his catchphrase in AI-generated GIFs and deepfakes.
- Amitabh Bachchan v. Rajat Nagi (2022) — the first blanket “John Doe” order in India protecting personality rights, stopping unauthorized commercial use of the actor’s voice, name, and likeness.
- Jackie Shroff (2024) — the court protected not just his image but his nicknames and voice from AI chatbots and merchandising misuse.
- Aishwarya Rai Bachchan (2025) and a “dynamic+” injunction protecting spiritual leader Sadhguru — both extending the same doctrine to newer forms of ongoing, hard-to-pin-down synthetic misuse.
The legal theory courts rely on traces back to Article 21 of the Constitution — the right to life and personal liberty, which the Supreme Court has already read to include dignity, autonomy, and privacy (via the landmark K.S. Puttaswamy privacy judgment). Courts have extended that reasoning to say your voice, face, mannerisms, and digital likeness belong to you, and using an AI tool to replicate them without consent is a violation of that same constitutional core — not just a technical rule-breach.
You do not need to be a celebrity for this to apply. The “John Doe” / “Ashok Kumar” order mechanism — where a court restrains not just the named defendant but “the world at large,” including future unknown infringers — is exactly the tool ordinary victims should ask their lawyer to seek, because it means you don’t have to identify every anonymous account re-uploading the content; the order already covers them.
Personality rights sit in an interesting overlap zone with formal IP protection — your name and catchphrases can often be trademarked even while your face and voice rely on this separate, judge-made doctrine. If you want the fuller picture of how these protections differ, our guide to trademark registration in India walks through where each form of protection applies, and our piece on brand licensing agreements is worth reading if you ever plan to license your name or likeness commercially — the same consent-based logic that protects you here is what makes licensing enforceable in the first place.
Criminal Remedies: What You Can File a Police Complaint Under
Because deepfake abuse usually involves fraud, impersonation, or sexual harassment, several existing criminal provisions apply directly — you don’t need to wait for a “deepfake-specific” criminal statute, because the conduct is already illegal under general law:
Under the Bharatiya Nyaya Sanhita (BNS), 2023 — India’s criminal code that replaced the IPC on 1 July 2024:
- Section 356 (Defamation) — the direct successor to the old IPC Section 499, applicable when a fabricated video or image damages your reputation.
- Section 319 (Cheating by personation) — covers impersonation used to deceive, including deepfake scams involving fake endorsements or fraudulent solicitations made in your name.
- Section 77 — voyeurism-related provisions, relevant where a deepfake sexualizes a person’s image without consent.
- Section 351 — criminal intimidation, where the deepfake is used to threaten or extort.
Under the Information Technology Act, 2000:
- Section 66C — punishes identity theft using another person’s electronic signature, password, or “unique identification feature” (courts have read this to extend to biometric and likeness-based identifiers).
- Section 66D — cheating by personation using a computer resource, directly applicable to AI-impersonation scams.
- Section 66E — violation of privacy through capturing, publishing, or transmitting images of a person’s private area without consent, relevant for synthetic intimate imagery.
- Section 67 / 67A — publishing or transmitting obscene or sexually explicit material electronically, which applies squarely to non-consensual sexualized deepfakes.
Practical tip: file under both the BNS and IT Act sections in your FIR wherever the facts fit. Cyber cells are increasingly experienced with this overlap, and citing the correct combination signals to the investigating officer that you’ve done your homework — which genuinely speeds up how seriously a complaint is triaged.
Civil Remedies: Defamation Suits and Injunctions
Alongside a criminal complaint, you (or your lawyer) can pursue:
- A civil defamation suit seeking damages, where the deepfake has harmed your reputation, business relationships, or employability.
- An interim injunction — an urgent court order stopping further circulation while the case proceeds. Courts have repeatedly shown willingness to grant these within days, sometimes hours, when the harm is ongoing and irreversible.
- A “John Doe” / “Ashok Kumar” order, as described above, when the infringing content is spreading across multiple anonymous accounts and platforms.
- A personality rights claim, run alongside defamation, specifically targeting unauthorized commercial or reputational use of your name, voice, image, or likeness.
Civil and criminal routes are not mutually exclusive — most effective deepfake responses run both in parallel, because a criminal FIR creates pressure and evidence while a civil injunction gets the content removed faster than waiting for a criminal investigation to conclude.
Step-by-Step: What to Do the Moment You Discover a Deepfake of Yourself
- Preserve evidence before you do anything else. Screen-record the content (not just a screenshot) so it captures the URL, timestamp, view count, and username. Deepfakes get taken down or edited quickly, and courts and cyber cells need the original, not your description of it.
- Do not engage the poster directly. Responding publicly often triggers algorithmic amplification and can escalate harassment. Document, don’t debate.
- Report to the platform immediately using their impersonation/synthetic-media reporting flow, and explicitly cite the amended IT Rules and Rule 3(3) labeling/removal obligations in your report — this pushes it out of the generic queue.
- File a complaint on the National Cyber Crime Reporting Portal (cybercrime.gov.in) or at your nearest cyber cell. This is the fastest official route into a police investigation and creates a paper trail even if the platform is slow.
- Send a legal notice to the platform’s Grievance Officer, whose contact details every intermediary is legally required to publish. Cite Rule 3(3)(a) for unlawful SGI and demand removal within the statutory window. (If you’re ever drafting these disclosures for your own platform rather than sending one, our explainer on Terms of Service vs. Privacy Policy covers where grievance-officer clauses actually belong.)
- Consult a lawyer about an urgent injunction, especially if the content is spreading, sexualized, financially damaging, or being used for scams in your name. Ask specifically about a John Doe order if multiple anonymous accounts are involved.
- File the FIR citing the relevant BNS and IT Act sections above, and attach your preserved evidence.
- Keep a public statement simple, if you choose to make one at all: state clearly that the content is fabricated, avoid amplifying the original clip by re-sharing it, and direct people to a factual clarification instead.
How Fast Can You Actually Get a Takedown?
Under the amended rules, intermediaries are expected to act far faster on flagged unlawful SGI than under the old general grievance timelines, and the requirement that removal orders for unlawful SGI come from a Joint Secretary/DIG-rank officer or above is meant to make the process both faster and harder to abuse or ignore once escalated. In practice, expect meaningfully quicker responses from major platforms compared to pre-2026, but expect smaller platforms and offshore hosts to lag — which is exactly when the civil injunction route becomes essential, since a domestic court order can be served on domain registrars and ISPs directly.
For Creators, Influencers, and Founders: A Few Extra Considerations
If you build a public-facing brand — as a creator, founder, or media personality — a few things are worth doing proactively, not just reactively:
- Register your trademarks for your name, catchphrases, and channel/brand identity where possible; several of the celebrity cases above succeeded partly because trademark and personality rights arguments reinforced each other.
- Watermark and metadata-tag your own official content so audiences (and courts) can distinguish it from fabricated material at a glance.
- Set up a standing Google Alert / social listening search for your name plus terms like “AI,” “deepfake,” or “cloned voice” so you catch misuse early, when takedown is easiest.
- Keep a documented consent policy if you ever license your likeness commercially (ads, brand deals), so any AI-generated content bearing your image can be clearly shown as either authorized or not.
If you regularly work with brands or collaborate with other creators, this is also exactly the gap I see most often in loosely worded collaboration paperwork — our guide on influencer and creator collaboration agreements covers the consent, IP ownership, and usage-rights clauses that determine who can legally use your image or voice, and how, long after a campaign ends.
A Quick Global Comparison
India’s approach — a definitional amendment bolted onto existing intermediary rules, backed by judge-made personality rights — sits between two other major models. The EU AI Act takes a broader, risk-tiered regulatory approach to AI systems generally, with transparency obligations for synthetic content baked into a wider AI governance framework rather than an intermediary-rules amendment. The United States relies heavily on state-level right of publicity laws, which vary significantly — some states have specific deepfake statutes (particularly for election and intimate-image misuse), while others rely on older common-law publicity torts. If you’re dealing with cross-border distribution — a deepfake hosted on a foreign server but targeting an Indian victim — Indian courts have shown willingness to issue orders against domain registrars and hosting providers regardless of where they’re based, so jurisdiction is less of a shield for bad actors than it used to be.
Frequently Asked Questions
1. Is making a deepfake illegal in India? Creating synthetic content itself isn’t automatically illegal — the law targets deceptive, non-consensual, or harmful use. Once a deepfake is used to defame, impersonate, defraud, sexually exploit, or otherwise harm someone, it becomes actionable under the BNS, the IT Act, and the amended IT Rules.
2. What law covers deepfakes in India right now? Primarily the amended Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (in force since 20 February 2026), alongside the Bharatiya Nyaya Sanhita, 2023, the IT Act, 2000, and judge-made personality rights jurisprudence from the Delhi High Court.
3. Can I sue someone for cloning my voice without consent? Yes. Voice cloning without consent can support a personality rights claim, a defamation suit if it damages your reputation, and criminal charges under IT Act Section 66C/66D if used for impersonation or fraud.
4. Do I need to be a celebrity to claim personality rights? No. While the landmark cases involve celebrities, the underlying constitutional right (Article 21) applies to everyone. Ordinary individuals can and do pursue similar claims, though celebrities often have stronger commercial-loss arguments for damages.
5. How long does a platform have to take down a reported deepfake? The amended rules push for faster action through senior-officer-level takedown orders for unlawful SGI, though no single universal countdown applies to every scenario. For the fastest results, combine a platform report citing Rule 3(3)(a) with a legal notice to the Grievance Officer.
6. What is a “John Doe” order and how does it help deepfake victims? It’s a court injunction that binds not just named defendants but unnamed, unknown, and even future infringers — meaning you don’t need to identify every account re-uploading your deepfake for the order to cover them.
7. Where do I report a deepfake in India? Start with the platform’s in-app reporting tool for impersonation/synthetic media, then file at cybercrime.gov.in or your local cyber cell for a formal police record.
8. Can AI companies or tool providers be held liable for deepfakes made with their tools? Increasingly, yes. The amended IT Rules place upstream labeling and traceability obligations directly on tool providers, and courts (notably in an Arijit Singh voice-cloning matter before the Bombay High Court) have signaled that platforms enabling unauthorized cloning can face liability, not just the end user.
9. Is a deepfake automatically defamation? Not automatically — defamation requires that the content damages your reputation in the eyes of others. A clearly labeled parody or satire may not qualify, while a fabricated video presented as real, especially one implying criminal, immoral, or professionally damaging conduct, generally will.
10. What evidence should I collect before filing a complaint? Screen recordings (not just screenshots) showing the URL, username, timestamp, and engagement metrics; the original unedited file if you can obtain it; and a timeline of when and where you first noticed it. Preserve everything before reporting, since flagged content often gets edited or removed before your case is reviewed.
The Bottom Line
Deepfake law in India moved from theory to enforceable rule in a single stroke on 20 February 2026, and it now sits on top of a genuinely fast-moving body of court precedent that treats your face and voice as legally yours to control. If you’re dealing with this right now: preserve the evidence first, report through both the platform and the official cybercrime portal, and talk to a lawyer about an injunction if the content is spreading — don’t wait for a “perfect” moment to act, because takedown speed is the single biggest factor in limiting real-world damage.
This article is for general informational purposes and reflects the law as of September 2026. It is not a substitute for advice from a licensed advocate familiar with the specific facts of your situation — cyber law, defamation, and personality rights cases are highly fact-dependent, and procedural rules can change.
Related Reading on parvezali.me
- Copyright vs. “Fair Use” in the Digital Age: What Every Publisher Needs to Know
- Trademark Registration in India – A Founder’s Practical Guide
- Influencer & Creator Collaboration Agreements – What’s Often Missing
- DPDP Act 2023 – Privacy Policy Compliance Checklist
- Cybersecurity Is Now a Legal Requirement — Not Just an IT Problem
- Brand Licensing Agreements – Letting Someone Else Use Your Name
- Terms of Service vs. Privacy Policy – What’s the Difference?
- Legal Lessons from Running Malik Times — Content Ownership, Contributor Agreements & Platform Liability

