Sunday, October 4, 2026
spot_img

AI, Deepfakes and Synthetic Media: Legal Challenges

Legal Challenges in the Age of Artificial Intelligence, Deepfakes and Synthetic Media

Abstract

Generative artificial intelligence has removed the cost, skill and time barriers that once made convincing audio-visual forgery rare. The legal consequence is twofold: false material is believed, and true material is disbelieved. Here we will try to map the law as it stands on 31 August 2026. It takes India as its anchor — the Information Technology Amendment Rules, 2026, the India AI Governance Guidelines, the Digital Personal Data Protection framework, and the rapidly expanding line of personality-rights injunctions from the Delhi and Bombay High Courts — and reads that framework against the European Union’s AI Act, the United States’ fragmented federal and State response and its First Amendment ceiling, China’s labelling regime, and the emerging international instruments. It argues that India has legislated ably for platforms but not yet for victims: the country has a fast takedown architecture, a judge-made publicity right available in practice only to the famous, no calibrated criminal provision, no technical labelling standard, and no evidentiary protocol for authenticity challenges. It closes with seven concrete proposals.

Introduction: The Collapse of a Working Presumption

For most of the modern history of adjudication, a photograph, a sound recording or a video carried a quiet evidentiary privilege. Lawyers have always known that images can be staged and tapes spliced, but the effort required to fabricate persuasive audio-visual material was high enough that the presumption of authenticity did useful work, and courts, regulators, banks, newsrooms and voters all relied on it. Generative artificial intelligence has removed the cost, the skill and the time that sustained that presumption. What once required a studio now requires a prompt.

The legal harms that follow divide into two families, and they pull in opposite directions. The first is the familiar one: the false is believed. Synthetic intimate imagery destroys reputations and safety, principally of women; cloned voices defeat bank and corporate authentication; fabricated video of a candidate circulated in the last hours of a campaign cannot be answered before the poll closes. The second harm is subtler and, for the courts, more corrosive: the true is disbelieved. Once every recording might be synthetic, the guilty acquire what has been called the liar’s dividend — the ability to dismiss genuine evidence as a deepfake. The first family of harms can be met with prohibitions and takedowns. The second cannot; it can only be met by rebuilding provenance and by reforming the law of evidence.

This paper takes Indian law as its anchor and reads it against the principal comparative and international instruments. Its argument in short is this. India has moved quickly and competently on the platform-facing side of the problem — the Information Technology Amendment Rules, 2026 are among the most demanding intermediary obligations anywhere. It has moved very slowly on the rights-and-remedies side. The gap has been filled, ad hoc, by High Courts granting personality-rights injunctions to celebrities. That is a functioning remedy for a few hundred people and no remedy at all for everyone else.

What, Precisely, Is Being Regulated

“Deepfake” is a colloquialism, not a legal term, and no major jurisdiction uses it as the operative trigger. Four drafting strategies are now visible, and the differences between them are not cosmetic.

India uses “synthetically generated information” (SGI): audio, visual or audio-visual information that is artificially or algorithmically created, generated, modified or altered using a computer resource in a manner that appears real and authentic. Text is excluded, as are routine editing that does not alter substance, good-faith preparation of presentational or educational material, and accessibility adaptations.[1]

The European Union regulates the “deep fake” as content generated or manipulated by AI that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful — three cumulative elements: resemblance, an existing referent, and a false appearance of authenticity.[2] China regulates “AI-generated synthetic content” and, uniquely, includes text within the labelling duty.[3] The United States avoids a general definition and legislates by harm, using “digital forgery” for non-consensual intimate imagery and “digital replica” for the proposed likeness right.[4]

Two drafting cautions follow. First, a technology-triggered definition systematically under-covers the harm actually observed in elections, which is dominated by “cheapfakes” — selectively cut, mislabelled or speed-altered authentic footage that no generative model touched. Second, the Indian exclusion of text is defensible on scale grounds but removes fabricated quotations, forged correspondence and synthetic press releases from the labelling regime altogether.

The Indian Framework

A.  The pre-2026 patchwork: borrowed provisions

Until February 2026 India had no provision addressed to synthetic media as such. Practitioners assembled a case from instruments drafted for other purposes. Under the Information Technology Act, 2000: section 66C (fraudulent use of another’s electronic signature, password or unique identification feature), section 66D (cheating by personation using a computer resource), section 66E (capturing or publishing an image of a private area without consent), and sections 67, 67A and 67B (obscene material, sexually explicit material, and material depicting children). Under the Bharatiya Nyaya Sanhita, 2023: section 319 (cheating by personation), section 336(3) (forgery intended to harm reputation), section 340 (using a forged document or electronic record as genuine), and section 356 (defamation). The Copyright Act, 1957 supplies performers’ rights and moral rights where a performance or a work is appropriated.[5]

Each fits imperfectly. Personation offences contemplate deception of a person and are awkward where the deception is of an automated system or of the public at large; forgery offences turn on a document or electronic record with legal significance; the obscenity provisions engage only where the content is obscene, leaving a defamatory but decorous synthetic video of a public figure to the general law of defamation. Nothing in the criminal law makes it an offence, as such, to create a non-consensual synthetic likeness of an identifiable living person.

The data-protection layer is likewise incomplete. The Digital Personal Data Protection Act, 2023 was operationalised by the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 with a phased commencement: the Data Protection Board from November 2025, consent-manager registration from 13 November 2026, and the substantive obligations — notice, consent, security safeguards, breach reporting within seventy-two hours, significant data fiduciary duties — from 13 May 2027.[6] Two features limit its usefulness here. The Act does not apply to personal data that the data principal has made publicly available, which is precisely the material scraped to train likeness and voice models. And the Act nowhere addresses the synthesis of a person’s likeness or voice: whether a wholly generated face that resembles an identifiable individual is that individual’s “personal data” is an open and consequential question.

The constitutional backdrop is more helpful than the statutes. K.S. Puttaswamy v. Union of India recognised informational privacy and decisional autonomy as facets of Article 21, and dignity as the organising value of the privacy right.[7] It is on that foundation, rather than on any statute, that the High Courts have built the personality-rights jurisprudence discussed below.

B.  The Information Technology Amendment Rules, 2026

The 2026 Amendment Rules, notified on 10 February 2026 and effective from 20 February 2026, are India’s first direct legislative response. They insert a definition of synthetically generated information at Rule 2(wa), and their principal operative elements are four.[8]

Labelling and provenance. Permitted SGI must be clearly and prominently labelled — visually for visual content and audibly for audio — and must carry embedded permanent metadata or provenance identifiers linking the content to the computer resource that generated it. Removal, alteration or suppression of such labels is prohibited.

Verification by large platforms. A significant social media intermediary must require the uploading user to declare whether the content is synthetically generated, must deploy reasonable and appropriate technical measures to verify that declaration rather than accept it at face value, and must display the label prominently.

Compressed takedown windows. Under Rule 3(1)(d) the time to act on a court order or government notice falls from thirty-six hours to three; under Rule 3(2)(b) the categories of intimate imagery and impersonation must be actioned within two hours rather than twenty-four; under Rule 3(1)(b) unlawful content must be removed within thirty-six hours rather than seventy-two; and under Rule 3(2)(a)(i) grievances must be disposed of within seven days rather than fifteen.

Safe harbour. Failure to observe the due-diligence obligations, or knowingly permitting unlawful synthetic content, forfeits the protection of section 79 of the IT Act.

The design borrows visibly from China rather than the European Union: granular, platform-facing and speed-driven, with nothing on risk tiers. Three difficulties follow. First, a two-hour window enforced by the threat of losing safe harbour will be met by automated removal, and Shreya Singhal v. Union of India read down section 79(3)(b) precisely to stop intermediaries being pressed into adjudicating legality.[9] Second, unlike Article 50(4) of the AI Act, the Rules contain no proviso for satire, parody or evidently artistic work. Third, the obligations bind intermediaries; the individual who generates and posts the material is still left to the pre-2026 patchwork.

C.  The India AI Governance Guidelines, 2025

On 5 November 2025 the Ministry of Electronics and Information Technology released the India AI Governance Guidelines, built on seven “sutras” — trust as the foundation, people first, innovation over restraint, fairness and equity, accountability, understandable by design, and safety, resilience and sustainability — and six pillars spanning infrastructure, capacity building, policy and regulation, risk mitigation, accountability and institutions. Three bodies are proposed: an AI Governance Group, a Technology and Policy Expert Committee, and an AI Safety Institute. The Guidelines conclude expressly that separate AI legislation is not required at this stage, existing law being adequate, and recommend India-specific frameworks for risk assessment, deepfake detection and incident reporting.[10] For the practitioner the essential point is that the Guidelines are not law. They create no cause of action, no standard of care that a court is bound to apply, and no remedy. A governance framework without a remedy shifts the entire burden of enforcement onto the intermediary rules and onto private litigation.

D.  The courts: personality rights as India’s de facto deepfake law

In the absence of a statute, the operative Indian law of deepfakes has been made by two High Courts. The line is now substantial. Amitabh Bachchan v. Rajat Nagi granted a broad ad-interim injunction protecting name, image and voice.[11] Anil Kapoor v. Simply Life India extended protection to catchphrase, mannerism and, expressly, to AI-generated morphing.[12] Jaikishan Kakubhai Saraf (Jackie Shroff) v. Peppy Store followed in 2024.[13] The Bombay High Court’s order in Arijit Singh v. Codible Ventures LLP was India’s first squarely on AI voice cloning, restraining platforms offering “voice conversion” tools trained on the singer’s voice and holding that personality rights extend to vocal identity.[14]

The pace accelerated sharply thereafter. Global Health Limited v. John Doe addressed deepfaked videos of Dr Naresh Trehan dispensing medical advice, which had accumulated over a million views; the Court ordered takedown and directed platforms to disclose the identifying particulars of the uploaders.[15] In September 2025 the Delhi High Court decided the two Bachchan matters within a day of each other: Aishwarya Rai Bachchan v. Aishwaryaworld.com on 9 September and Abhishek Bachchan v. The Bollywood Tee Shop on 10 September, the latter directing Google and YouTube not merely to remove the material but to furnish subscriber information in a sealed cover within seven days.[16] In early October the Bombay High Court protected Asha Bhosle against an AI voice-cloning service, holding that making tools available to convert any voice into that of a celebrity without permission is itself a violation of personality rights,[17] and the Delhi High Court had granted comparable relief to Akkineni Nagarjuna the week before.[18] Through 2026 the docket has continued to grow, with orders protecting, among others, Ravi Kishan, Yuvraj Singh, Tabu, and Janhvi and Khushi Kapoor. The volume is itself the finding.

Four doctrinal observations follow. First, the right is entirely judge-made. India has no statutory right of publicity or personality; the right is assembled from Article 21 dignity and privacy after Puttaswamy, from passing off, from trade mark, and from performers’ rights. Its contours — the identifiability threshold, the line between commercial and expressive use, satire, post-mortem duration and assignability — remain undecided. Second, the remedy is almost invariably an ex parte ad-interim John Doe order coupled with dynamic URL blocking. That is fast and effective, but it presupposes a commercial suit in a High Court. Third, and consequently, the jurisprudence is a jurisprudence of celebrities. There is no meaningful body of Indian case law on synthetic depiction of ordinary people. Fourth, that distributional failure is grave, because the overwhelming majority of synthetic media in circulation is non-consensual sexual imagery, and its victims are overwhelmingly women who cannot fund a commercial suit.[19]

E.  The public interest litigation that produced the Rules

The 2026 Rules did not appear spontaneously. Two writ petitions before the Delhi High Court — by Advocate Chaitanya Rohilla and by the journalist Rajat Sharma, heard by a Division Bench of Chief Justice Manmohan and Justice Tushar Rao Gedela — pressed the Union to act. The Court declined to legislate but directed the Ministry to convene providers and deployers of the technology, telecom service providers, intermediaries and, notably, victims, and to examine European frameworks. A committee constituted on 20 November 2024, drawing on MeitY, the Indian Cybercrime Coordination Centre, C-DAC, the Data Security Council of India and IIT Madras, was given three months to report.[20] The Rules of February 2026 are the visible output of that process, and the sequence is worth noting: in India, on this subject, the courts have been the regulator of first resort.

F.  Elections and synthetic media

The Election Commission issued an advisory in January 2025 requiring political parties to label AI-generated campaign material and carry disclaimers. It went considerably further on 24 October 2025, ahead of the Bihar Assembly elections, requiring that synthetic content carry a clear and legible label — “AI-Generated”, “Digitally Enhanced” or “Synthetic Content” — occupying at least ten per cent of the visible display area or the first ten per cent of an audio track; that the responsible entity be identified in metadata or caption; that no synthetic material misrepresent a person’s identity in a manner likely to deceive voters; that reported violations be removed within three hours; and that parties maintain internal records of AI-generated material with creator details and timestamps for verification.[21]

Three difficulties. The Commission retained the ten-per-cent label that MeitY abandoned four months later, so a party complying with the Rules may still breach the advisory. The advisory rests on Article 324 and the Model Code of Conduct; it is not statutory, and enforcement runs through party discipline and, indirectly, sections 123 and 126 of the Representation of the People Act, 1951. Most seriously, Indian election law has no rapid adjudicatory mechanism: a fabricated video released seventy-two hours before polling and removed a week later has done its work.

The Comparative and International Landscape

A.  European Union: a transparency regime, not a likeness right

The AI Act approaches synthetic media through disclosure. Article 50(2) requires providers of generative systems to ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, with exceptions for trivial or assistive functions. Article 50(4) requires deployers of deepfakes to disclose that the content is artificially generated or manipulated, clearly and distinguishably, at first exposure; where the content forms part of an evidently artistic, creative, satirical or fictional work, disclosure need only be made in an appropriate manner that does not hamper the display or enjoyment of the work. Deployers cannot discharge the duty by pointing to the provider’s machine-readable mark: a human-perceivable label is required.[22]

Article 50 applies from 2 August 2026. The Digital Omnibus, Regulation (EU) 2026/1744, published on 24 July 2026 and in force from 27 July 2026, deferred the Annex III high-risk obligations to 2 December 2027 in the absence of harmonised technical standards, but deliberately left Article 50 on its original timetable, granting only a transitional grace period to 2 December 2026 for machine-readable marking by systems already on the market. The Omnibus also did something the original Act had not: it added a prohibition on the use of AI systems to generate non-consensual intimate or sexually explicit material depicting identifiable persons — the so-called “nudifier” applications — in image, video and audio form.[23] Breach of Article 50 attracts penalties of up to €15 million or three per cent of worldwide turnover.[24] A voluntary Code of Practice on Transparency of AI-Generated Content supplies a compliance route. Alongside the AI Act, Articles 34 and 35 of the Digital Services Act require very large platforms to assess and mitigate systemic risks to civic discourse and electoral processes — the provision under which most European enforcement against synthetic political content has actually proceeded. The essential comparative point is that the Union regulates disclosure rather than creation. The nudifier prohibition introduced by the Omnibus is its first and so far only step across that line; there is still no European likeness right, and the injured individual is otherwise left to national personality-rights law and to the GDPR.

B.  United States: harm-specific statutes and a constitutional ceiling

The TAKE IT DOWN Act, enacted 19 May 2025, criminalises publication of non-consensual intimate visual depictions and expressly extends to “digital forgeries”. It also imposes a platform duty: covered services must maintain a clear and conspicuous notice-and-removal process and remove the material, with known identical copies, within forty-eight hours of a valid request. That duty became enforceable by the Federal Trade Commission on 19 May 2026, with civil penalties of over $53,000 per violation and a public reporting portal.[25]

The NO FAKES Act, reintroduced on 20 May 2026 as S. 4591 and H.R. 8915, would create a federal, licensable property right in an individual’s voice and visual likeness, enforceable against unauthorised digital replicas, with a DMCA-style notice-and-takedown and, new to the 2026 text, a counter-notification procedure triggering a fourteen-day restoration window unless suit is filed, backed by liability of $25,000 or actual damages for knowing misrepresentation. It carries carve-outs for news, commentary and parody and, in the 2026 version, for non-commercial activity by libraries, archives and accredited educational institutions. It is further advanced than any previous version: the Senate Judiciary Committee reported it favourably on a unanimous vote in June 2026, though it has not been enacted.[26] At State level, Tennessee’s ELVIS Act of 2024 extended the right of publicity expressly to voice, and every State now has some form of non-consensual intimate imagery provision.

The constitutional ceiling is set by Kohls v. Bonta. The Eastern District of California preliminarily enjoined California’s AB 2839 on 2 October 2024 and halted enforcement of AB 2655 on 3 January 2025; on 29 August 2025 Judge Mendez held AB 2839 unconstitutional on summary judgment. The statute was content-based (it turned on the subject matter of the speech), viewpoint-based (it reached deepfakes harming a candidate but not those helping one), speaker-based (candidates could post the same material with a disclaimer), and overbroad, capturing satire and requiring only that harm be “reasonably likely”. Strict scrutiny applied and counter-speech was a less restrictive alternative.[27]

The lesson generalises beyond the First Amendment. Statutes that turn on the deceptiveness of political content are the most vulnerable; statutes that turn on non-consensual intimate depiction, impersonation for fraud, or unlicensed commercial exploitation of a likeness are the most durable. India’s Article 19(2) is more permissive than the First Amendment, but Shreya Singhal and Anuradha Bhasin v. Union of India impose their own discipline of proportionality, necessity and reasoned orders.[28]

C.  China: the labelling maximalist

China legislated earliest and most specifically: the Deep Synthesis Provisions in force from 10 January 2023, the Interim Measures for Generative AI Services from 15 August 2023, and the Labelling Measures from 1 September 2025. These distinguish explicit labels — human-perceivable text, icon or audio cue, with an image label required to be not less than five per cent of the shortest side — from implicit labels, being mandatory metadata carrying an “AIGC” field, the provider’s identity and a unique content identifier. Obligations run not only to generators but to distribution platforms, which must verify metadata and add their own identifiers, and to app stores, which check labelling compliance at review. Users must declare synthetic uploads, and malicious deletion, alteration, forgery or concealment of labels is prohibited.[29]

Two things make this workable in China and not elsewhere: a mandatory national technical standard, GB 45438-2025, which renders the duties testable, and a real-name identity infrastructure that makes traceability meaningful. India’s 2026 Rules adopt the architecture without the standard. That absence — nothing defining what “clear and prominent” and “permanent metadata” actually require — is the single largest implementation gap in the Indian regime.

D.  Other national responses

The United Kingdom has no general AI statute: the Online Safety Act 2023 imposes illegal-content duties and treats non-consensual intimate image offences as priority offences, and section 138 of the Data (Use and Access) Act 2025 inserted new sections 66E to 66H into the Sexual Offences Act 2003, creating offences of creating, and of requesting the creation of, a purported intimate image without consent — in force from 6 February 2026, and closing the gap left by the earlier focus on sharing rather than making. Denmark has taken the boldest step, amending its Copyright Act to insert a new section 65a for performers and section 73a for everyone else, conferring on each individual a neighbouring right in their own voice and physical appearance, running for fifty years after death and subject to carve-outs for caricature, satire, parody and pastiche. The bill was notified to the European Commission under the single-market transparency procedure, the standstill closing on 3 February 2026 and entry into force expected in July 2026. It is the first European instrument to treat likeness as a transferable, commercially exploitable intellectual property asset rather than an inalienable personality right, and the criticism is precisely that: where the dominant harm is sexual and dignitary, a property frame may be the wrong instrument.[30] South Korea, responding to mass offending in school and university networks, amended the Act on Special Cases Concerning the Punishment of Sexual Crimes in 2024 to criminalise not merely production and distribution but possession and viewing of sexually explicit deepfakes — the most aggressive criminal response in any democracy. Australia enacted the Criminal Code Amendment (Deepfake Sexual Material) Act 2024, creating Commonwealth offences of transmitting sexual material of an adult without consent, whether or not artificially generated.

E.  International instruments and the cross-border gap

The Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, CETS No. 225, was opened for signature at Vilnius on 5 September 2024 and has around twenty signatories, including the European Union, the United Kingdom, the United States, Canada, Japan and Israel. It binds parties to ensure that activities within the lifecycle of AI systems are consistent with human dignity, autonomy, equality and non-discrimination; to conduct risk and impact assessment; to document; and to provide effective remedies and procedural safeguards, including notice that one is interacting with an AI system rather than a person. National security is excluded, and parties may satisfy the private-sector obligation by alternative measures. It is not yet in force: entry into force requires five ratifications, of which three must be by Council of Europe member States. The European Union ratified on 15 May 2026.[31]

Alongside it sit General Assembly Resolution 78/265 of 21 March 2024, the UNESCO Recommendation on the Ethics of Artificial Intelligence (2021), the G7 Hiroshima Process code of conduct and the Global Digital Compact of September 2024. None creates an enforceable cross-border takedown, disclosure or attribution mechanism. That is the structural weakness: synthetic media is generated in one jurisdiction, hosted in a second and injures in a third, and there exists no instrument for it equivalent to the Budapest Convention’s mutual assistance machinery — to which, in any event, India is not a party.

Eight Problems the Current Instruments Do Not Solve

  1. Attribution. Open-weight models are downloadable and run locally; generation leaves no server-side trace; a screenshot destroys metadata. Labelling duties attach to providers and platforms, which are visible and solvent, while the anonymous creator is reached only if identified. Pushing identification onto intermediaries, as the traceability and safe-harbour conditions do, imports the whole encryption and anonymity debate into deepfake regulation, where it has not been separately argued.
  2. Provenance is fragile. Content Credentials under the C2PA standard are stripped by re-encoding, cropping, screenshotting and by many platforms’ own pipelines, so a statutory duty to embed “permanent” metadata is, on present technology, aspirational. Detection models are in an arms race they periodically lose, and their false positives fall on innocent speakers who have no appeal.
  3. Labelling addresses the wrong deception. Disclosure regimes assume the harm is deception about origin; frequently it is deception about fact. A correctly labelled synthetic video showing a politician accepting a bribe still defames him: the label cures provenance and leaves the injury untouched. Both the Indian and the European regimes leave the labelled-but-defamatory case entirely to general law.
  4. Over-removal and proportionality. Two- and three-hour windows, combined with forfeiture of safe harbour, create a structural incentive to remove on notice and ask later. There is no statutory, time-bound appeal from a wrongful takedown to a judicial forum, the Grievance Appellate Committees being executive bodies. The tension with Shreya Singhal and Anuradha Bhasin is real and, so far, untested.
  5. Satire, parody and political speech. India’s Rules contain no equivalent of the Article 50(4) proviso. Kohls shows what happens to a statute drafted around “materially deceptive” political content. The drafting discipline it teaches is transferable even where the constitutional standard is not: target impersonation, non-consensual intimate depiction and fraud, and leave the truth or falsity of political claims to counter-speech and to defamation law.
  6. Evidence — in both directions. Fabricated material is beginning to enter court records, and genuine material is being challenged as fabricated. The American experience is instructive precisely because it remains unresolved. The Advisory Committee on Evidence Rules voted in May 2025 to publish for comment a draft Rule 707, under which machine-generated evidence offered without a sponsoring expert, and which would be subject to Rule 702 if a witness testified to it, would be admissible only if it satisfied Rule 702(a)–(d) — applying the Daubert reliability criteria to the machine as they would to the expert. The comment period closed on 16 February 2026. At its meeting of May 2026 the Committee declined to send the rule forward, concluding that the revised text would require re-publication, and tabled it for further study by technology and AI-law experts at its autumn meeting. A companion proposal, Rule 901(c), which would have required a proponent to establish authenticity on the balance of probabilities once an opponent adduced sufficient evidence of fabrication, was not put to a vote at all and was referred to the same exercise. The most experienced evidence-rulemaking body in the common law world has, in short, not yet been able to settle a deepfake rule.[32] India has nothing comparable. Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 and the certificate regime it inherits from Arjun Panditrao Khotkar address the integrity of the copy, not the authenticity of the content.[33] A certificate that a video file was correctly extracted from a phone says nothing about whether the video was ever recorded.
  7. The non-celebrity victim. Every element of the Indian system is calibrated for a plaintiff with counsel and a commercial suit. The ordinary victim of synthetic intimate imagery has a criminal complaint under sections 66E and 67A of the IT Act and section 336(3) of the Sanhita, a grievance officer, and a defamation action that will outlive the harm. What she does not have is a summary, low-cost order compelling removal within days. This is the most serious deficiency in Indian law on the subject, and the 2026 Rules do not address it: they give her a faster platform process but no adjudicated right.
  8. Copyright, training data and outputs. On 24 July 2026 Justice Amit Bansal of the Delhi High Court delivered India’s first substantive ruling on AI training in ANI Media v. OpenAI. The Court upheld territorial jurisdiction notwithstanding that the servers were abroad, treating the foreign server as the terminal step in a chain beginning in India; held that storing protected works for training engages the reproduction right under section 14(a)(i); but found that the training prima facie fell within fair dealing under section 52(1)(a), reading “private use” to extend to a corporate entity and “research” to include machine-led research, holding the use transformative and commercial purpose not by itself disqualifying, and finding no prima facie case of memorisation — the articles relied on post-dated the training cut-off, so the outputs were more likely the product of live retrieval than of copying. Interim injunction was refused on the footing that damages would be an adequate remedy and that the plaintiff could have deployed technical measures against crawling. The suit proceeds to trial.[34] The significance here is narrow but real: Indian law now has a first, provisional answer on inputs and no answer at all on outputs that reproduce a living person’s face or voice. Parallel litigation in the United States and the United Kingdom is heading, on the whole, in a similar direction on inputs and remains unsettled on outputs.

To these should be added the plainest commercial risk. The 2024 incident in which an employee of a multinational engineering firm in Hong Kong transferred roughly US$25 million after a video conference in which every other participant was a deepfake of a colleague is not exotic; it is a controls failure. Boards, banks and insurers in India should now treat voice and video authentication as compromised and payment authority as requiring out-of-band verification, irrespective of what the content rules require of platforms.

A Workable Design for India: Seven Proposals

  1. A statutory civil right against non-consensual synthetic depiction. Elements: an identifiable living person, absence of consent, and either falsity or intimate character. Remedies: injunction, statutory damages and — critically — a summary removal order obtainable from a District Judge within days, subject to express defences for parody, satire, criticism, news reporting and academic or artistic use. This converts a celebrity remedy into a citizen’s remedy.
  2. A calibrated criminal provision, graded by harm. (a) Creating or publishing non-consensual synthetic intimate imagery; (b) synthetic impersonation for pecuniary gain or fraud, building on section 66D; (c) synthetic impersonation of a public servant, judicial authority or electoral candidate during a notified campaign period. Each with a defined mental element and a consent defence. Nothing broader: an offence of “publishing deceptive synthetic content” would not survive Article 19(2) scrutiny and should not.
  3. A technical standard, not an adjective. A Bureau of Indian Standards or TEC standard specifying explicit label geometry and audio-cue duration, implicit metadata fields, provenance identifier format and C2PA interoperability, so that “clear and prominent” and “permanent metadata” become auditable rather than argued.
  4. Proportionate takedown with a judicial exit. Retain two- and three-hour windows for the narrow, objectively identifiable categories — non-consensual intimate imagery, impersonation for fraud, court orders — and restore longer, reasoned processes elsewhere. Provide a statutory, time-bound appeal from a takedown to a judicial forum, and mandate publication of takedown and restoration statistics.
  5. Election machinery with teeth and speed. Place the Commission’s advisories on a statutory footing under the Representation of the People Act; align the label specification with the MeitY standard; constitute a twenty-four-hour adjudicatory desk for the campaign period with power to order removal and corrective publication; and require disclosure of synthetic campaign content in expenditure returns.
  6. An evidentiary protocol. A practice direction, or an amendment to the rules under the Bharatiya Sakshya Adhiniyam, requiring a party challenging the authenticity of audio-visual evidence to raise it at the first case-management hearing with a factual foundation; requiring preservation and production of provenance metadata and original device files; empanelling forensic examiners; and giving trial courts a structured route for assessing machine-generated material. Judicial academies should treat this as an urgent training priority.
  7. A cross-border strategy. Domestic rules stop at the border; the harm does not. India should pursue mutual legal assistance arrangements for synthetic media offences and give serious consideration to signing the Council of Europe Framework Convention, which is open to non-member States and would cost little in regulatory autonomy while buying interoperability.

Conclusion

Law’s instinct when confronted with a new medium is to ask which old cause of action it resembles, and on that instinct India has done tolerably well: personation, forgery, defamation, passing off, performers’ rights and the constitutional right to privacy have all been made to carry weight they were not designed for, and the Amendment Rules of 2026 place India among the more demanding jurisdictions in the world on platform obligations.

But the deeper task is institutional rather than doctrinal. What synthetic media threatens is not any particular right so much as the shared capacity of a court, a voter, a regulator or a bank to establish that something happened. Regulation here is therefore only incidentally about content; it is fundamentally about maintaining a chain of provenance and a functioning remedy — the first so that authenticity can be proved, the second so that the proof is worth having. Europe’s transparency model addresses the first and neglects the second; India’s, at present, addresses neither completely, having speed without standards and injunctions without a statute.

The question this workshop should put is therefore not whether Indian law can be applied to deepfakes: it plainly can, and it is being applied weekly in two High Courts. It is whether a remedy requiring a commercial suit, senior counsel and a famous name is a remedy at all for the overwhelming majority of those this technology injures. Until an ordinary person can obtain, cheaply and within days, an enforceable order that a synthetic depiction of her be taken down and kept down, India will have a law of deepfakes for the well-known and a governance framework for everyone else.

References

[1] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, notified by MeitY on 10 February 2026 and in force from 20 February 2026. See Freshfields, “India targets deepfakes and AI-generated content: key changes under MeitY’s 2026 amendments to the IT Rules” (2026).

[2] Regulation (EU) 2024/1689 (the AI Act), Article 3(60) read with Article 50(4).

[3] Measures for Labelling of Artificial Intelligence-Generated Synthetic Content, issued by the Cyberspace Administration of China with three other departments on 14 March 2025, in force 1 September 2025, together with the mandatory national standard GB 45438-2025.

[4] TAKE IT DOWN Act, Pub. L. No. 119-12 (19 May 2025); NO FAKES Act of 2026, S. 4591 / H.R. 8915 (introduced 20 May 2026).

[5] Copyright Act, 1957, ss. 38A, 38B and 57. Section 38B(ii) — the performer’s right to restrain distortion or mutilation prejudicial to reputation — has obvious application to voice cloning of singers and actors.

[6] Digital Personal Data Protection Rules, 2025 (notified 13 November 2025); see Squire Patton Boggs, Privacy World, “India Passes the Digital Personal Data Protection Rules” (November 2025).

[7] K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1.

[8] The Rules followed a draft released for consultation in October 2025. Notably, the draft’s requirement that a visual label occupy at least ten per cent of the display surface was dropped in the final text in favour of a “clear and prominent” standard.

[9] Shreya Singhal v. Union of India, (2015) 5 SCC 1, holding that an intermediary’s obligation under s. 79(3)(b) is triggered only by a court order or a government notification.

[10] India AI Governance Guidelines, MeitY, released 5 November 2025; see Saikrishna & Associates, “Decoding the India AI Governance Guidelines” (2025).

[11] Amitabh Bachchan v. Rajat Nagi, CS(COMM) 819/2022, Delhi High Court, order dated 25 November 2022.

[12] Anil Kapoor v. Simply Life India, 2023 SCC OnLine Del 6914 (Delhi High Court, 20 September 2023).

[13] Jaikishan Kakubhai Saraf alias Jackie Shroff v. The Peppy Store & Ors., 2024:DHC:4046, Delhi High Court, order dated 15 May 2024.

[14] Arijit Singh v. Codible Ventures LLP, Bombay High Court, order dated 26 July 2024 (Comm IPR Suit).

[15] Global Health Limited & Anr. v. John Doe & Ors., CS(COMM) 6/2025, Delhi High Court, order dated 8 January 2025.

[16] Aishwarya Rai Bachchan v. Aishwaryaworld.com & Ors., CS(COMM) 956/2025, Delhi High Court, order dated 9 September 2025; Abhishek Bachchan v. The Bollywood Tee Shop & Ors., CS(COMM) 960/2025, Delhi High Court (Tejas Karia J.), order dated 10 September 2025.

[17] Asha Bhosle v. Mayk Inc. & Ors., Interim Application (L) No. 30382 of 2025 in Commercial IP Suit (L) No. 13215 of 2025, Bombay High Court (Arif S. Doctor J.), order dated 3 October 2025.

[18] Akkineni Nagarjuna v. Bfxxx.org & Ors., 2025 SCC OnLine Del 6331, Delhi High Court (Tejas Karia J.), order dated 25 September 2025.

[19] Estimates that around ninety-six per cent of deepfake material online is non-consensual pornography originate in the 2019 Deeptrace study and have been repeated in subsequent literature; the proportion should be treated as indicative rather than current, but no serious study contradicts the direction.

[20] Chaitanya Rohilla v. Union of India and Rajat Sharma v. Union of India, Delhi High Court; see India Legal, “Delhi High Court directs Centre to conduct meeting with all stakeholders on regulation of deepfakes” (2024).

[21] Election Commission of India advisory dated 24 October 2025, reiterating and expanding the advisory of January 2025; see MediaNama, “ECI Cracks Down On Deepfakes Before Bihar Polls” (October 2025).

[22] Regulation (EU) 2024/1689, Article 50(2) and (4); European Commission, “Transparency obligations under Article 50 of the AI Act” (FAQ) and Guidelines on transparency obligations, 2026.

[23] Regulation (EU) 2026/1744 (the Digital Omnibus); see Cooley, “Digital AI Omnibus Delays Key Deadlines, Introduces New Rules” (2026).

[24] Regulation (EU) 2024/1689, Article 99(4).

[25] TAKE IT DOWN Act, Pub. L. No. 119-12; Federal Trade Commission, “Take It Down Act enforcement starts now” (business guidance blog, May 2026) and press release of 19 May 2026.

[26] NO FAKES Act of 2026, S. 4591 and H.R. 8915, 119th Congress; see Manatt, “Congress Reintroduces the NO FAKES Act: What’s New in the 2026 Bill” (2026).

[27] Kohls v. Bonta (E.D. Cal.), consolidated with The Babylon Bee, LLC v. Bonta and X Corp.’s challenge; preliminary injunction 2 October 2024, order staying AB 2655 enforcement 3 January 2025, summary judgment on AB 2839 dated 29 August 2025 (Mendez J.).

[28] Anuradha Bhasin v. Union of India, (2020) 3 SCC 637, requiring that orders restricting internet access be reasoned, proportionate, published and subject to periodic review.

[29] Bird & Bird, “New AI Content Labelling Rules in China: what are they and how do they compare to the EU AI Act” (2025); China Law Translate, “Measures for Labeling of AI-Generated Synthetic Content”.

[30] European Parliamentary Research Service, “The Danish approach to copyright and deepfakes”, ATA(2026)782611; see also “Copyrighting Voice and Image”, Verfassungsblog (2025).

[31] Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, CETS No. 225, opened for signature at Vilnius on 5 September 2024, Article 30 (entry into force); accompanied by the HUDERIA risk and impact assessment methodology. India is neither a signatory nor a party.

[32] Advisory Committee on Evidence Rules, agenda book and report, meeting of May 2026 (uscourts.gov); the draft rule was published for comment following the Committee’s vote of May 2025, the comment period closing on 16 February 2026. Neither Rule 707 nor Rule 901(c) has been adopted, and neither has been transmitted to the Supreme Court or to Congress.

[33] Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1; Bharatiya Sakshya Adhiniyam, 2023, s. 63.

[34] ANI Media Pvt. Ltd. v. Open AI OpCo LLC & Anr., CS(COMM) 1028/2024, Delhi High Court (Amit Bansal J.), interim order dated 24 July 2026. The order is interim; questions of the scope of copying, memorisation and ownership of individual works remain open for trial.

Dr. Vidyottma Jha
Dr. Vidyottma Jha
ADVOCATE, SUPREME COURT OF INDIA
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular