The IT Rules 2026, notified as G.S.R. 120(E) on 10 February 2026 and in force from 20 February 2026, amend the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 to bring deepfakes and other synthetic media inside the intermediary due-diligence framework. Under the amended Rule 3(1)(d), a platform must remove or disable court-flagged or government-flagged unlawful content within three hours, down from thirty-six. The rules also create a category called synthetically generated information, which must carry a prominent label and permanent provenance metadata that cannot be stripped out. A separate two-hour window applies to complaints about non-consensual sexual imagery, including morphed and deepfake nudity.
This article sets out what the IT Rules 2026 change for deepfakes, synthetic media, and the platforms that host them, who has to comply, and by when.
The amendment answers a problem that had outrun the old law. A convincing deepfake can be made in minutes and reach millions before a grievance officer opens the complaint, and the 2021 rules gave platforms up to thirty-six hours to act on a court or government order. By February 2026 the Ministry of Electronics and Information Technology (MeitY) had decided that window was too wide, and it rewrote the timelines and added a labelling regime aimed squarely at AI-generated content.
What follows separates the two headline changes, the accelerated takedown clock and the labelling duty, from the compliance machinery that sits under them. A law student, a compliance officer at a social media company, and a creator posting AI art each have a different stake in these rules, so the sections below are written so that each can take away the part that matters.
Scope and timeline of the IT Rules 2026 amendment
The IT Rules 2026 are the amendment that MeitY notified as G.S.R. 120(E) on 10 February 2026 and brought into force on 20 February 2026. They do not replace the earlier framework. They amend the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, which are themselves made under the Information Technology Act, 2000, and they graft a synthetic-media regime onto the due-diligence obligations that intermediaries already carried.
The gap between notification and commencement was ten days. That is a short runway for a compliance change of this size, and platforms that host user content had to move quickly to update their reporting flows, their takedown queues, and their upload systems before 20 February. The tight timeline is itself a signal of how urgently the government treated the deepfake problem.
Two changes carry most of the weight. The first tightens the clock for removing unlawful content once a competent authority flags it. The second introduces labelling, declaration, and provenance duties for content that is artificially generated. Around these sit shorter grievance-redressal timelines and firmer verification obligations, which together push more of the burden onto the larger platforms.
The direction of travel is not new. India has been building toward AI-specific regulation for a while, a trajectory covered in this explainer on the AI Ethics and Accountability Bill 2025. The 2026 amendment is narrower than a standalone AI statute, but it is the first hard rule that most Indian platforms actually have to comply with today.
Who has to comply with the new rules?
Compliance falls on intermediaries, and most heavily on the larger ones. An intermediary is any service that stores or transmits third-party content, from a small forum to a global social network, and every intermediary must meet the faster takedown timelines. The heavier labelling and verification duties are targeted at significant social media intermediaries, the platforms that cross the user threshold the government sets for that category.
A third group sits alongside them. Services that themselves let users create synthetic media, the generative tools rather than the platforms that distribute the output, are drawn into the labelling and provenance duties for what they produce. The point of covering both the tool and the distribution platform is to close the gap where a piece of synthetic content could otherwise travel without any label attaching to it at either end.
What counts as synthetically generated information?
Synthetically generated information, the term the amendment uses instead of “deepfake”, is defined as audio, visual, or audio-visual information that is artificially or algorithmically created, generated, modified, or altered using a computer resource, in a manner that makes it appear real, authentic, or true. The definition is deliberately built around the effect on the viewer rather than the tool used to make it. A clip does not have to fool an expert. It has to be capable of passing as genuine to an ordinary person.
Two features of this drafting matter in practice. First, it captures modification, not just creation, so an edited real video can be synthetic information if the editing crosses into making a false thing look true. Second, it is medium-specific: the definition reaches sound and pictures, which is where the harm from impersonation and fabricated events actually lands. A cloned voice on a fraudulent call and a fabricated video of a public figure both sit inside it.
The choice of a content-based test has a cost and a benefit. The benefit is that it does not go stale every time the underlying technology changes, because it does not name any particular model or method. The cost is that the line between ordinary editing and synthetic generation has to be drawn case by case, which is exactly why the amendment carves out a set of routine activities that would otherwise be swept in.
Content the definition leaves out
The definition leaves out several categories that would otherwise be caught by its wide wording. Text-only content is the largest exclusion: an AI-written article or chatbot reply is not synthetically generated information, because the definition reaches audio and visual material only. That keeps the regime focused on the media where deepfake harm is sharpest and away from the far larger volume of machine-written text.
Three activity-based carve-outs follow. Routine or good-faith editing, such as changing formatting, adjusting colour, or compressing a file, is excluded. So is ordinary document creation, like building a presentation, a PDF, or teaching material. And so are accessibility and quality improvements, such as sharpening clarity, adding translation, or making content searchable. The common thread is that none of these manipulates the underlying material to make a false thing look true, which is the mischief the definition is aimed at.
How does the 3-hour deepfake takedown rule work?
The three-hour rule works through the amended Rule 3(1)(d), which cuts the removal window from thirty-six hours to three. When an intermediary receives a court order, or a reasoned notification from an authorised government agency, that identifies unlawful content, it must remove or disable access to that content within three hours of receipt. The categories that trigger it are the familiar ones: content touching public order, the security of the state, sexual offences, and child sexual abuse material.
The compression from thirty-six hours to three is the operational heart of the amendment. Thirty-six hours assumed a human review queue working through complaints at office pace. Three hours assumes a monitored channel, staffed to act on a lawful order almost as soon as it lands. For a large platform, meeting it means treating a government or court order as a live incident rather than a ticket, which is a structural change in how content moderation is resourced.
One point is worth holding onto, because coverage of the rule sometimes blurs it. The three-hour clock runs from a formal trigger, a court order or an authorised government notification, not from any single user’s complaint. A user report starts the grievance process, which has its own separate timelines. The three-hour obligation is the sharp end reserved for content that a competent authority has already assessed as unlawful.
What is the two-hour rule for intimate deepfakes?
The two-hour rule, under the amended Rule 3(2)(b), gives platforms just two hours to act on complaints about the most damaging category of synthetic content. It covers material that shows nudity or a sexual act, and electronic impersonation, including morphed images and deepfake sexual imagery of a person without consent. The window here drops from twenty-four hours to two.
The reason for the shorter window is the nature of the harm. Non-consensual intimate imagery spreads fastest and does damage that a later takedown cannot undo, so the amendment treats it as the emergency case. For a victim, the difference between a two-hour and a twenty-four-hour response is the difference between containment and a day of uncontrolled circulation.
How have the other grievance timelines changed?
The other grievance timelines have been shortened as well, so that the whole complaint system runs faster, not just the emergency categories. The amendment compresses the ordinary grievance-resolution window and tightens the acknowledgement and action duties that sit around it. The result is a graded clock, where the required speed of response scales with the severity of the content.
The table below sets out the tiers that matter most for synthetic media.
| Content or trigger | Rule | Earlier window | Amended window |
|---|---|---|---|
| Court or authorised government order (unlawful content) | Rule 3(1)(d) | 36 hours | 3 hours |
| Non-consensual sexual imagery, morphed or deepfake nudity | Rule 3(2)(b) | 24 hours | 2 hours |
| General user grievance resolution | Rule 3(2) | 15 days | 7 days |
The takedown clock under the IT Rules 2026
How fast a platform must act, by trigger. In force 20 February 2026.
2HOURS
Non-consensual sexual imagery
Complaints about nudity, sexual acts, or impersonation, including morphed and deepfake nudity. Rule 3(2)(b).
down from 24 hours
3HOURS
Court or government order
Unlawful content flagged by a court order or an authorised government notification (public order, state security, sexual offences, CSAM). Rule 3(1)(d).
down from 36 hours
7DAYS
General user grievance
Ordinary grievance resolution through the platform’s grievance officer. Rule 3(2).
down from 15 days
Source: IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, G.S.R. 120(E). iPleaders
What are the AI labelling and provenance rules?
The labelling rules require that synthetically generated information carry a clear, prominent label and permanent provenance metadata, so that a viewer and a machine can both tell the content is artificial. Visual synthetic media must display a visible label. Audio synthetic media must carry an audio disclosure. And in both cases the platform is expected to embed permanent metadata, or a unique identifier or technical provenance mark, that travels with the file.
The provenance requirement has a hard edge that the labelling requirement alone does not. The label and the embedded metadata must not be capable of being removed, suppressed, or modified. That is what turns a label from a courtesy into a control: a synthetic clip is not meant to be able to shed its marking as it is re-uploaded, cropped, or re-shared. Legal commentators have described this as one of the first binding synthetic-content provenance mandates anywhere, precisely because it fixes the marking to the content rather than leaving it to the honesty of the next uploader.
For creators, the labelling duty changes the housekeeping around AI-assisted work rather than banning it. Content that is clearly artistic, satirical, or otherwise lawful is not prohibited; it just has to be marked as synthetic. The same discipline of documenting and clearing AI-generated material also protects the creator’s own position, a point developed in this guide to licensing AI-generated content for commercial use. Marking and provenance are becoming part of the basic paperwork of publishing synthetic media, in the same way that attribution and rights clearance already are. The intellectual-property questions that sit underneath, covered in this analysis of copyright issues entailing deepfakes in India, run in parallel to the new labelling duty rather than being displaced by it.
Did the 10% watermark rule survive?
The 10% watermark rule did not survive into the final amendment. The draft that MeitY circulated had proposed a fixed size: a label covering at least ten per cent of the surface area of a visual work, or a disclaimer running through the first ten per cent of an audio clip. That numeric threshold was dropped from the notified rules.
In its place the final text uses a qualitative standard. A label must be prominent, clearly visible or audible, and adequately noticeable to an ordinary viewer or listener, without a fixed percentage attached. The change trades a bright-line rule that was easy to measure for a flexible standard that is harder to game but also harder to audit, and it leaves platforms to judge what counts as prominent enough.
Label, declare, verify: the synthetic-media duty chain
What must happen to synthetically generated audio and visual content on a large platform.
Label
A visible label on visual content and an audio disclosure on audio content. It must be prominent and clearly noticeable. The draft’s fixed 10% size rule was dropped for this qualitative standard.
Embed provenance
Permanent metadata, or a unique identifier or provenance mark, travels with the file. It cannot be removed, suppressed, or modified as the content is re-uploaded or re-shared.
User declares
On upload, the user must declare whether the content is synthetically generated. This is the first-line duty on the person posting.
Platform verifies
A significant social media intermediary must deploy technical measures, including automated tools, to verify the declaration. The wording was hardened from “endeavour to deploy” to “deploy”.
Source: IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, G.S.R. 120(E). iPleaders
What must platforms and users do to comply?
Compliance runs on a two-step chain: the user declares, and the platform verifies. When a user uploads content to a significant social media intermediary, the platform must require the user to declare whether the content is synthetically generated. That declaration is the entry point, and it puts a first-line duty of honesty on the person doing the uploading.
The platform’s duty is the harder one, because it cannot stop at trusting the declaration. A significant social media intermediary must deploy appropriate technical measures, including automated tools, to verify whether the declaration is accurate. The wording here was deliberately hardened from an earlier “endeavour to deploy” to a plain “deploy”, which removes the room a platform once had to say it had tried. In practice this means running detection systems against uploads, not just showing users a checkbox.
That verification burden is where the amendment meets the wider compliance world that platforms already live in. A social media company running deepfake detection is doing the same kind of systematic, documented, auditable work that data-protection compliance already demands of it, and the two regimes increasingly overlap. The operational discipline is close to what businesses have been building for the data-protection rules, mapped out in this operational compliance guide to the DPDP Rules 2025. A platform that has already stood up a compliance function for personal data has most of the muscle it needs for synthetic-media verification.
Can a platform still claim safe harbour?
A platform can still claim safe harbour, but the amendment makes that protection conditional on doing the new work. Safe harbour is the shield in Section 79 of the Information Technology Act, 2000 that stops an intermediary from being held liable for content its users post, provided it meets its due-diligence obligations. The 2026 amendment folds the takedown timelines, the labelling duties, and the verification duty into those obligations.
The consequence is direct. Removing content in compliance with a lawful order does not cost a platform its safe harbour; that action is protected. But failing the due-diligence duties, missing the three-hour window, ignoring the labelling regime, or skipping verification, puts the shield at risk, and with it the platform’s protection from liability for user content. For a large intermediary, losing safe harbour is the real penalty behind the rules, far more than any fixed fine.
How do the 2026 rules differ from the earlier deepfake law?
Before the 2026 amendment, India had no dedicated deepfake law, so synthetic media was handled by stretching a patchwork of existing provisions. Identity theft and cheating by personation under the Information Technology Act, 2000, criminal provisions on forgery and defamation under the Bharatiya Nyaya Sanhita, 2023, privacy and personality-rights actions, and copyright claims were each pressed into service depending on the facts. Where personal data was misused, the Digital Personal Data Protection Act, 2023 could apply. None of these was designed for synthetic media, and the gaps showed.
The clearest gap was definitional and preventive. The older framework could punish some deepfakes after the harm, but it had no shared definition of synthetic media, no labelling requirement, and no provenance duty, so nothing forced a deepfake to announce itself before it spread. The strengths and limits of that pre-2026 position are set out in this piece on whether Indian law is equipped to deal with deepfakes, which maps the provisions that used to carry the whole load.
The 2026 amendment changes the posture from reactive to preventive. It adds the missing definition, a labelling and provenance layer that operates before content circulates, and a takedown clock fast enough to matter once content is flagged. It does not repeal the older provisions; a criminal deepfake can still draw a prosecution under the penal law. What it adds is a front end, a set of duties that attach at the point of upload and distribution, which the earlier patchwork never had.
What the IT Rules 2026 mean for creators, businesses, and lawyers
For creators, businesses, and lawyers, the IT Rules 2026 land in three different places. For a creator, the practical change is a labelling habit: synthetic or heavily AI-altered audio and video needs to be declared and marked, and lawful creative or satirical work is not blocked as long as it carries that mark. The cost is disclosure, not prohibition.
For a business that hosts user content, the change is a compliance load. It has to run detection, staff a fast-response channel for court and government orders, shorten its grievance timelines, and document all of it well enough to defend its safe harbour if challenged. Boards and senior management are increasingly expected to own this kind of AI-related risk directly, a shift explored in this playbook on AI in corporate governance for board directors. Synthetic-media compliance is moving from a purely operational concern to a governance one.
For a lawyer, the amendment opens a new advisory and litigation surface. There is compliance work in helping platforms build conforming systems, contentious work in takedown disputes and safe-harbour arguments, and victim-side work in enforcing the two-hour intimate-imagery route. The rules are recent enough that much of the interpretation, especially around what counts as a prominent label and how far the verification duty extends, is still open. That openness is where the early practitioners will do the shaping.
Frequently asked questions
When did the IT Rules 2026 amendment come into force?
The amendment came into force on 20 February 2026. MeitY notified it as G.S.R. 120(E) on 10 February 2026, which left in-scope platforms a ten-day window to prepare. The rules amend the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, rather than replacing them.
Does the 3-hour takedown apply to every deepfake?
No. The three-hour window under Rule 3(1)(d) applies when a court order or an authorised government notification identifies unlawful content, such as material touching public order, state security, or sexual offences. A separate two-hour window under Rule 3(2)(b) covers complaints about non-consensual sexual imagery, including morphed and deepfake nudity. An ordinary user complaint runs through the grievance process on its own timeline, not the three-hour clock.
Do individual creators have to label AI-generated content?
The labelling and declaration duties run through platforms, but they reach the creator at the point of upload. A significant social media intermediary must require an uploading user to declare whether the content is synthetically generated, and must then label it and verify the declaration. So a creator declares on upload, and the platform is responsible for the visible label and the provenance metadata.
Is AI-generated text covered by these rules?
No. The definition of synthetically generated information is limited to audio, visual, and audio-visual content. AI-written text, such as a machine-generated article or a chatbot reply, falls outside it. The labelling and provenance duties therefore attach to synthetic media, not to written output.
What happens if a platform misses the deadline?
A platform that fails its due-diligence obligations, including the takedown timelines, the labelling regime, and the verification duty, risks losing safe harbour under Section 79 of the Information Technology Act, 2000. Losing that protection exposes the intermediary to liability for the user content it hosts, which is a heavier consequence than a fixed penalty. Removal done in compliance with a lawful order, by contrast, does not breach safe harbour.
References
Statutes and rules
- Information Technology Act, 2000 (section referred to: 79)
- Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (the principal rules amended, including Rule 2, Rule 3(1)(d), and Rule 3(2)(b))
- Digital Personal Data Protection Act, 2023
- Bharatiya Nyaya Sanhita, 2023
Regulatory and primary sources
- Ministry of Electronics and Information Technology, Notification G.S.R. 120(E) dated 10 February 2026, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, in force 20 February 2026
- The Gazette of India, for the notified text of the amendment
- Ministry of Electronics and Information Technology, explanatory material on synthetically generated information and intermediary due diligence
This article is for informational purposes only and does not constitute legal advice. For specific legal guidance, consult a qualified legal professional.



