Introduction
Let’s just browse what’s happening around the world; let’s pick a majority. Imagine a female ; you, a female — your mother, sister, girlfriend, wife, daughter, anyone. She wakes up to tons of messages from people she doesn’t even know, or doesn’t even speak to cousins, colleagues, professors, and more all intriguing in various tones of curiosity about a video or photo circulating of her, which she has no idea about. About her face, which she never made, and a script she never said, in a video that was never hers.
This is no longer a hypothetical. It is a Tuesday. Deepfakes and AI-generated or AI-morphed images and videos convincing enough to pass as real have moved from research-lab novelty to a routine tool of harassment, fraud, and political disinformation, and Indian law is still working out where, exactly, to draw its lines around a technology that didn’t exist when most of its relevant statutes were written.
What Makes a Deepfake Different
Morphed images are not something that has erupted today; photo manipulation predates the internet from ages but what has changed is scale, speed, and believability. Generative adversarial networks (GANs) and diffusion-based AI models are now producing synthetic video and audio realistic enough to defeat casual scrutiny, generated in minutes, at near-zero cost, using nothing more than a handful of publicly available photographs or a few seconds of voice recording. This is why precisely the law’s older assumptions that manipulation requires skill, time, and access to the original material do not hold any longer. A perpetrator today needs none of these, and a victim today has no realistic way to pre-empt being targeted, since the raw material for a deepfake is often just a public social media photo. Now if even a photo being posted is becoming a threat to someone’s existence then the reality speaks about the darks of itself. The legal system, built around the idea that fabrication takes effort and therefore leaves a discoverable trail has altered and flipped and now confronts a technology where fabrication is nearly instantaneous and the trail is often buried inside the code of the model itself and is invisible to anyone without forensic AI-detection tools that Indian law enforcement is only beginning to acquire and as we know how slow of a system indian law is.
The Legal Vacuum
The central difficulty with deepfakes is not that India lacks law ; it is that no single law was written with deepfakes in mind. Instead, a patchwork of provisions from the Information Technology Act, 2000, the Bharatiya Nyaya Sanhita, 2023 (BNS), and the Digital Personal Data Protection Act, 2023 (DPDP Act) must be stretched, combined, and reinterpreted to cover harm that is fundamentally new in form even where it resembles older offences like defamation, obscenity, impersonation in substance.
This creates two distinct problems, first, prosecutorial uncertainty: a victim or investigating officer must often choose among several loosely fitting provisions rather than invoke one clearly applicable law and second, jurisdictional and evidentiary difficulty: deepfake content spreads across platforms and borders faster than any single provision’s enforcement mechanism can act, and proving the content is synthetic rather than authentic and merely damaging requires forensic capacity that many police stations simply do not have.
Applicable Provisions
Under the Information Technology Act, 2000
- Section 66C (Identity Theft) penalises fraudulent or dishonest use of another person’s electronic signature, password, or “any other unique identification feature.” Courts and commentators have increasingly read a person’s face and voice, when digitally replicated without consent, as falling within this “unique identification feature” language, though the provision was not drafted with biometric likeness primarily in mind.
- Section 66D (Cheating by Personation using Computer Resource) applies where a deepfake is used to impersonate someone for fraudulent gain — for instance, a synthetic video or voice clone used to deceive a victim’s family into transferring money, a pattern that has already surfaced in India in voice-cloning scams.
- Section 66E (Violation of Privacy) penalises capturing, publishing, or transmitting the image of a person’s private area without consent, and has been extended in enforcement practice to cover morphed intimate images, though it was drafted primarily around unauthorised capture rather than synthetic generation.
- Sections 67, 67A, and 67B criminalise publishing or transmitting obscene material, sexually explicit material, and child sexual abuse material respectively, in electronic form ; these apply squarely where deepfake content is sexual in nature, including non-consensual synthetic intimate imagery. The provisions carry enhanced penalties for repeat offences, reflecting Parliament’s recognition even in 2000 that sexual content circulated digitally causes compounding, rather than one-time, harm — a principle that maps uncomfortably well onto how deepfakes spread today.
- Section 79, read with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, governs intermediary liability. Platforms that fail to act on flagged synthetic content within prescribed timelines risk losing the safe-harbour protection that otherwise shields them from liability for user-generated content ; a provision that has become the primary enforcement lever against deepfakes precisely because directly identifying and prosecuting an anonymous creator is often practically impossible.
Under the Bharatiya Nyaya Sanhita, 2023
The BNS, which replaced the Indian Penal Code in 2023, retains and in places sharpens provisions relevant to deepfakes:
- Provisions on defamation apply where a morphed image or video damages a person’s reputation, regardless of whether the underlying content was AI-generated.
- Provisions addressing cheating by personation and forgery extend to digitally fabricated identity documents, images, or communications used to deceive.
- Provisions on outraging the modesty of a woman and voyeurism, carried forward with amendments from the IPC, have been invoked in cases involving morphed intimate images, though their language still centres on the capturing of images rather than their synthetic creation : a gap that continues to generate interpretive difficulty.
The DPDP Act’s Indirect Relevance
The Digital Personal Data Protection Act, 2023 does not address deepfakes directly, but a person’s facial data, voice patterns, and biometric likeness fall within its definition of personal data. Unauthorised use of such data to train or generate a deepfake could, in principle, attract the Act’s consent and processing obligations though enforcement mechanisms specific to synthetic media generation remain undeveloped, and the Act’s primary focus remains data fiduciaries rather than individual malicious actors creating deepfakes.
This creates a structural mismatch worth noting: the DPDP Act is designed around the relationship between a data fiduciary (typically a company processing user data at scale) and a data principal (the individual). A deepfake creator using scraped, publicly available photographs to generate synthetic content does not neatly fit either role as the Act envisions them, since they are neither a registered fiduciary nor processing data through any consent mechanism the Act contemplates regulating. Until this gap is addressed — either through DPDP rules or a dedicated synthetic media provision victims are likely to find the Act more useful as a persuasive, background argument in litigation than as a direct standalone remedy.
Case Laws and Judicial Precedents
Anil Kapoor v. Simply Life India & Ors. (Delhi High Court, 2023) The Delhi High Court granted a wide-ranging injunction protecting actor Anil Kapoor’s personality rights, restraining unauthorised use of his name, image, voice, and even his catchphrases across AI tools, GIFs, and morphed content. The Court explicitly recognised that AI-based misuse of a person’s likeness including deepfakes could violate personality and publicity rights rooted in privacy and dignity under Article 21, marking one of the clearest judicial acknowledgments that Indian courts are prepared to extend existing constitutional doctrine to synthetic media harms without waiting for Parliament to legislate specifically.
Jaikishan Kakubhai Saraf (Jackie Shroff) v. The Peppy Store & Ors. (Delhi High Court, 2024) Following the Anil Kapoor precedent, the Delhi High Court granted similar protection to actor Jackie Shroff, restraining the unauthorised commercial exploitation of his persona, including through AI-generated content and chatbots trained to mimic his voice and mannerisms. Together with Anil Kapoor, this case signals a developing line of civil precedent that public figures can invoke against deepfake misuse, even where no specific criminal complaint has been filed.
The Rashmika Mandanna Deepfake Incident (2023) While not itself a reported judgment, the widely publicised deepfake video morphing actor Rashmika Mandanna’s face onto another woman’s body triggered significant regulatory response including a public statement from the Ministry of Electronics and Information Technology reiterating that deepfake content violates multiple provisions of the IT Rules, 2021, and warning platforms of safe-harbour consequences for non-compliance. The incident is frequently cited in policy discussions as the moment deepfakes moved from a niche technical concern to a mainstream regulatory priority in India, directly influencing the advisories that followed.
X (Twitter) Corp related enforcement actions and MeitY advisories (2023–2024) Following the Rashmika Mandanna incident and similar cases, MeitY issued advisories directing intermediaries to ensure users are informed about the consequences of hosting unlawful synthetic content, including deepfakes, and to remove such content within stipulated timeframes upon notice. While these advisories do not carry the same weight as primary legislation, non-compliance directly threatens an intermediary’s Section 79 safe-harbour protection, giving them practical enforcement teeth despite their soft-law form.
Enforcement Realities and Regulatory Response
Beyond statute, the Ministry of Electronics and Information Technology (MeitY) has, in recent years, issued advisories to social media intermediaries requiring them to identify and label AI-generated or synthetically altered content, and to remove deepfake content flagged by users within specified timeframes under the IT Rules, 2021 framework governing intermediary due diligence. Non-compliance risks the intermediary losing safe-harbour protection under Section 79 of the IT Act that is a significant enforcement lever, since it shifts practical responsibility onto platforms that are better resourced to detect synthetic media than individual victims or police stations.
However, advisories are not legislation, and their binding force has been contested. Platforms have been inconsistent in labelling and takedown speed, and victims frequently report that by the time content is removed from one platform, it has already propagated across others ; a problem inherent to how virality outruns any single enforcement mechanism, however well-designed.
Investigative capacity presents a further bottleneck. Establishing that a video or image is synthetically generated, rather than authentic and simply damaging, typically requires forensic AI-detection tools and trained personnel that remain concentrated in a handful of specialised cybercrime units, largely in metropolitan centres. A complaint filed in a smaller town may take considerably longer to receive the technical scrutiny needed to even classify the content as a deepfake in the first place, let alone trace its origin and a disparity that means the practical protection the law offers is not evenly available across the country, regardless of how the statute reads on paper.
The Consent and Personality Rights Overlap
Deepfakes intersect closely with the emerging jurisprudence on personality rights ; the right of an individual, particularly public figures, to control commercial and non-commercial use of their name, likeness, voice, and image. Indian courts have, in recent years, granted injunctive relief to celebrities against unauthorised AI-generated content misusing their likeness, treating such misuse as a violation of both privacy and personality rights rooted in Article 21’s protection of dignity and autonomy. This is a significant doctrinal development, because it means a deepfake victim may have a civil remedy , injunction and damages running parallel to any criminal complaint under the IT Act or BNS, offering a faster, if narrower, avenue of relief particularly suited to public figures with the resources to litigate quickly.
Way Forward
India’s current framework treats deepfakes as a problem to be solved through the interpretation of older statutes rather than through purpose-built legislation , a workable but fragile approach. Comparative frameworks offer some direction.
The European Union’s AI Act imposes specific transparency obligations on providers of AI systems that generate deepfake content, requiring clear disclosure that content is synthetically generated or manipulated, regardless of whether the content is harmful in itself. This shifts a portion of the compliance burden upstream, onto developers and platforms deploying generative AI tools, rather than relying entirely on after-the-fact criminal enforcement against often anonymous end users.
In the United States, several states including Texas, California, and Virginia have enacted specific deepfake statutes, particularly targeting non-consensual sexual deepfakes and election-related synthetic media, reflecting a patchwork but increasingly assertive state-level legislative response even in the absence of comprehensive federal law.
China’s administrative regulations on deep synthesis technology, in effect since 2023, require mandatory labelling of AI-generated content and impose obligations on service providers to verify user identity before permitting the generation of synthetic media depicting real persons , a notably more stringent, provider-accountability-first model compared to India’s current after-the-fact, victim-driven enforcement approach.
A dedicated legal framework whether through amendment to the IT Rules or standalone legislation addressing synthetic media specifically, with clear definitions, mandatory labelling requirements, faster takedown obligations, provider-side verification norms, and a coherent forensic evidentiary standard for courts, would close the interpretive gaps that currently leave victims dependent on provisions never designed for this harm. Given India’s position as one of the world’s largest social media markets, the cost of regulatory delay is unlikely to be evenly distributed , it will continue to fall hardest on those with the least institutional power to demand a swifter remedy, particularly women and public figures without the resources to pursue civil injunctions.
Conclusion
The law has always run behind technology, but the gap with deepfakes is unusually consequential because the harm is not abstract , it lands on a person’s face, voice, and reputation, often irreversibly, long before any provision can be cited or any platform can act. India’s patchwork approach, stitching together the IT Act, the BNS, and the DPDP Act, offers real but incomplete protection: enough to prosecute the most serious cases, as the civil relief granted in Anil Kapoor and Jackie Shroff demonstrates, but not yet enough to prevent the everyday ones that never reach a courtroom at all.
In my assessment, the judiciary has moved faster than the legislature on this issue recognising personality and dignity-based protections against synthetic media well before Parliament has enacted a dedicated statute. That is a meaningful stopgap, but it is not a substitute for legislation, since civil injunctive relief remains realistically accessible only to those with the resources and public profile to pursue it quickly, leaving ordinary victims dependent on slower, more uncertain criminal remedies. Until synthetic media is addressed by law built specifically for it with clear definitions, provider-side accountability, and evidentiary standards courts can apply consistently, the burden of proving what is real will continue to fall, unfairly, on the people whose faces were never asked for in the first place.


