top of page

The Rise of Deepfakes and the Need for Dedicated Legislation in India

Draft Desk Publications
Jun 28
14 min read

BY KAVYA VATS


Abstract

Synthetic media generated through generative adversarial networks has, within less than a decade, evolved from a technological curiosity into a pervasive instrument of impersonation, sexual harassment, electoral manipulation and financial fraud. India, with the world's largest base of internet subscribers, has emerged as one of the most affected jurisdictions, yet it continues to address deepfake-related harms through scattered provisions of the Information Technology Act, 2000, the Bharatiya Nyaya Sanhita, 2023 and the Digital Personal Data Protection Act, 2023. The Ministry of Electronics and Information Technology has responded through successive advisories and, most recently, the Draft Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2025, mandating labelling of synthetically generated information. This article examines whether the existing framework is adequate, places the Indian position alongside legislative responses in the United Kingdom, the United States, the European Union, Singapore and China, and argues for a dedicated, technology-specific statute consistent with the privacy guarantee recognised in Justice K.S. Puttaswamy v. Union of India (2017).


Introduction

In November 2023 a manipulated video circulated on social media showing the actor Rashmika Mandanna, with her face superimposed on the body of another woman. The clip drew an immediate response from the Union Minister of State for Electronics and Information Technology and led the Delhi Police to register a First Information Report under the Information Technology Act, 2000 and the Indian Penal Code, 1860. Within weeks similar videos featuring Sachin Tendulkar, Ratan Tata and the Prime Minister appeared on consumer platforms, often promoting fraudulent gaming or investment schemes, transforming deepfakes from an abstract technological concern into a matter of national legal attention.

The expression 'deepfake' is a portmanteau of 'deep learning' and 'fake', describing audiovisual content synthetically generated by machine learning models in a manner difficult to distinguish from authentic footage. The technology has legitimate applications in cinema, education and accessibility, yet its malicious deployment threatens individual dignity, electoral integrity and national security. The Indian legal system lacks a coherent statutory definition of synthetic media and continues to rely on provisions drafted for an earlier generation of cyber offences. What follows surveys the existing position in India, examines comparative jurisdictions and proposes a framework for dedicated legislation.


Historical Development and Conceptual Framework

The technical foundation of deepfakes lies in generative adversarial networks introduced by Ian Goodfellow and his collaborators in 2014. The term entered popular vocabulary in late 2017 when an anonymous Reddit user under the handle 'deepfakes' began circulating pornographic videos in which the faces of celebrities had been digitally swapped onto performers' bodies. By 2019 the firm Deeptrace published a report estimating that ninety-six per cent of deepfake videos online were non-consensual pornography, almost entirely targeting women, and ranked India among the top six countries whose nationals featured in such content.

Conceptually, deepfakes occupy an uneasy position within existing legal categories. They are not merely defamatory statements because they implicate identity rather than reputation alone, not solely obscene material because their wrongfulness lies in fabrication rather than indecency, and not classical forgeries because the medium is audiovisual and the falsification is algorithmic. Recognising this hybrid character, the European Union's Artificial Intelligence Act, 2024 defines a deepfake in Article 3(60) as AI-generated or manipulated image, audio or video content resembling existing persons, objects or events that would falsely appear to be authentic. India, despite the proliferation of synthetic content, has yet to incorporate any comparable statutory definition.


Existing Legal Position in India

The Information Technology Act, 2000, although enacted before the emergence of generative adversarial networks, contains several provisions invoked against deepfake offenders. Section 66D, inserted by the Information Technology (Amendment) Act, 2008, punishes cheating by personation through a computer resource with imprisonment up to three years and a fine of one lakh rupees. Section 66E penalises violation of bodily privacy through the capture or transmission of images of a private area without consent. Sections 67, 67A and 67B address obscene, sexually explicit and child sexual material respectively, while Section 69A empowers the Central Government to issue blocking directions in the interest of sovereignty, defence, security or public order.

The general criminal law, recodified through the Bharatiya Nyaya Sanhita, 2023, supplements the technology-specific framework. Section 356 reproduces the offence of defamation previously contained in Section 499 of the Indian Penal Code, 1860 and includes imputations through visible representations. Section 318 addresses cheating, Section 319 cheating by personation and Sections 336 and 340 forgery and the use of forged electronic records. None of these provisions employ the language of synthetic media, and their applicability rests on judicial interpretation rather than legislative design.

Constitutional protection against misuse of personal likeness is anchored in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) 10 SCC 1, where a nine-judge bench unanimously recognised the right to privacy as an intrinsic component of the right to life guaranteed by Article 21, identifying informational, decisional and bodily privacy as distinct facets and contemplating protection of identity from non-consensual appropriation. The Digital Personal Data Protection Act, 2023 operationalises a portion of this mandate by requiring personal data to be processed only on consent or certain legitimate uses, recognising rights of correction and erasure under Section 12 and imposing penalties of up to two hundred and fifty crore rupees for failure to take reasonable safeguards. The statute, however, applies to digital personal data in a structured sense and does not directly address the generation or dissemination of synthetic audiovisual material.

Intermediary liability is regulated by Section 79 of the Information Technology Act, 2000 read with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Rule 3(1)(b) obliges intermediaries to make reasonable efforts to cause users not to host information that impersonates another person or is patently false or misleading. Following the Rashmika Mandanna incident, the Ministry of Electronics and Information Technology issued advisories dated 7 November 2023 and 26 December 2023 directing intermediaries to remove such content within twenty-four hours of complaint under Rule 3(2)(b). A further advisory in March 2024 required significant platforms to obtain prior permission before deploying under-tested generative models, although this was later softened after industry pushback.

The most recent regulatory development is the Draft Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2025, released by the Ministry on 22 October 2025, which introduces a definition of 'synthetically generated information' and proposes that intermediaries verify whether uploaded content is synthetically generated, label such content prominently and refrain from modifying or removing such labels. The draft signals a movement towards pre-emptive regulation but remains a subordinate instrument rather than a substantive penal statute.

Indian courts have begun to articulate a parallel jurisprudence of personality rights. In Anil Kapoor v. Simply Life India (2023) the Delhi High Court, by order dated 20 September 2023, restrained sixteen defendants from using the actor's name, likeness, image or voice for commercial purposes through any technological tool including artificial intelligence, observing that unauthorised use of a celebrity's persona through morphing and deepfakes had reached an alarming level. A similar protective order had earlier been granted to Amitabh Bachchan in 2022. The decision in Shreya Singhal v. Union of India (2015) 5 SCC 1, while striking down Section 66A of the Information Technology Act, 2000 for vagueness, upheld the constitutional validity of the intermediary regime under Section 79, providing the foundation on which the current notice-and-takedown architecture operates.


Comparative International Perspective

The United Kingdom has progressed further than India in criminalising specific categories of synthetic content. The Online Safety Act, 2023 created the offence of sharing or threatening to share intimate photographs or films under Sections 66A to 66D of the Sexual Offences Act, 2003 and expressly captures images altered to appear to show a person in an intimate state. In January 2025 the Ministry of Justice announced its intention to criminalise the creation of sexually explicit deepfake images of adults, irrespective of subsequent sharing, through the Crime and Policing Bill introduced in Parliament in February 2025, acknowledging that the harm is constituted at the moment of creation and not only at distribution.

In the United States the regulatory approach has been fragmented. The Disrupt Explicit Forged Images and Non-Consensual Edits Act of 2024, known as the DEFIANCE Act, was passed by the Senate in July 2024 and creates a federal civil cause of action permitting victims of non-consensual intimate deepfakes to seek statutory damages of up to one hundred and fifty thousand United States dollars. The Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act, known as the TAKE IT DOWN Act, was signed into law on 19 May 2025 and obliges platforms to remove non-consensual intimate imagery within forty-eight hours of a valid request. State legislatures in Texas, California and Minnesota have additionally enacted statutes addressing election deepfakes.

The European Union has adopted the most comprehensive horizontal framework through Regulation (EU) 2024/1689, commonly known as the Artificial Intelligence Act, 2024. Article 50(4) requires deployers of AI systems that generate or manipulate image, audio or video content constituting a deepfake to disclose that the content has been artificially generated, subject to exceptions for evidently artistic, creative, satirical or fictional works. Providers of generative systems are simultaneously obliged under Article 50(2) to ensure outputs are marked in a machine-readable format. These obligations apply in stages, with the deepfake disclosure requirements applying from 2 August 2026.

Singapore has chosen a narrowly targeted approach focused on electoral integrity. The Elections (Integrity of Online Advertising) (Amendment) Act, 2024, passed by Parliament on 15 October 2024 and brought into force on 22 January 2025, prohibits the publication, sharing or boosting of digitally generated or manipulated online election advertising that realistically depicts a candidate saying or doing something they did not in fact say or do. The People's Republic of China has implemented the most ambitious ex ante regime through the Provisions on the Administration of Deep Synthesis Internet Information Services issued by the Cyberspace Administration of China and brought into effect on 10 January 2023, requiring deep synthesis service providers to authenticate user identity, obtain consent from individuals whose biometric features are edited and apply conspicuous labels to synthetic content. Australia has criminalised the transmission of non-consensual sexual material including AI-altered content through the Criminal Code Amendment (Deepfake Sexual Material) Act, 2024.


Major Challenges and Emerging Issues

The most acute harm associated with deepfakes in India remains non-consensual intimate imagery, overwhelmingly targeting women. Although Sections 67 and 67A of the Information Technology Act, 2000 address obscene and indecent material, neither category neatly captures the wrong of fabrication. A deepfake video may not be obscene in the technical sense yet may inflict severe psychological injury by attributing to the depicted individual conduct she never engaged in. The harm is one of identity violation rather than indecency simpliciter, and the legal vocabulary at present does not reflect that distinction.

Electoral integrity constitutes a second arena of concern. During the General Election of 2024 several manipulated clips of political leaders circulated widely on messaging platforms. The Election Commission of India issued an advisory on 6 May 2024 directing political parties to refrain from using deepfakes in campaigning and to remove such content within three hours of notice. The advisory lacks the statutory force of the Singaporean regime and does not address content generated by individuals or foreign actors. Financial fraud constitutes a third category, with deepfake videos featuring Ratan Tata, Mukesh Ambani and Sachin Tendulkar promoting investment platforms exemplifying a pattern in which the credibility of trusted personalities is appropriated to lend legitimacy to fraudulent schemes.

Evidentiary challenges form a fourth difficulty. Section 65B of the Indian Evidence Act, 1872, now reproduced as Section 63 of the Bharatiya Sakshya Adhiniyam, 2023, governs admissibility of electronic records and requires a certificate authenticating production of the record. The provision presupposes that an electronic record either is or is not a faithful reproduction of an underlying source, and does not contemplate situations in which the underlying source itself has been algorithmically fabricated. The Supreme Court's decisions in Anvar P.V. v. P.K. Basheer (2014) 10 SCC 473 and Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal (2020) 7 SCC 1, while clarifying the certificate requirement, do not address the deeper authentication crisis posed by deepfakes. Cross-border enforcement compounds these difficulties, since many creators operate from servers outside India and mutual legal assistance moves too slowly to address content whose harm is consummated within hours of upload.


Critical Analysis

Three broad critiques may be levelled against the present Indian framework. The first concerns conceptual indeterminacy. Sections 66D, 66E and 67 of the Information Technology Act, 2000 and Sections 318, 319 and 356 of the Bharatiya Nyaya Sanhita, 2023 were drafted to address distinct underlying wrongs and capture deepfake conduct only by analogical extension. A prosecutor must select a provision that matches the facts imperfectly, and a defendant may legitimately argue that the conduct lies outside the textual scope of the chosen offence. The principle of strict construction of penal statutes, affirmed by the Supreme Court in Tolaram Relumal v. State of Bombay (1954) SCR 158, militates against such analogical extension.

The second critique concerns under-deterrence. The maximum punishment under Section 66D of the Information Technology Act, 2000 is three years' imprisonment and a fine of one lakh rupees. Defamation under Section 356 of the Bharatiya Nyaya Sanhita, 2023 attracts simple imprisonment of up to two years or a fine or both. These sentencing levels were calibrated for an earlier generation of offences and do not reflect the scale and immediacy of harm a viral deepfake can inflict. The third critique concerns the absence of a civil remedy designed for synthetic media. The Digital Personal Data Protection Act, 2023 creates compensation mechanisms but routes them through the Data Protection Board and limits them to violations of the data protection obligations themselves. A victim of a deepfake who seeks damages must rely on common law actions for defamation, passing off or breach of confidence, supplemented by the developing jurisprudence of personality rights illustrated by the Delhi High Court's orders in Anil Kapoor v. Simply Life India (2023) and Jaikishan Kakubhai Saraf alias Jackie Shroff v. The Peppy Store (2024). Injunctions arrive only after the depicted person has the resources to approach the High Court and after the content has typically achieved substantial circulation.

A further concern is the absence of provenance and authentication infrastructure. The European Union has built its regime around content provenance standards developed by the Coalition for Content Provenance and Authenticity, and China has imposed labelling obligations upon service providers as a condition of operation. India's Draft Rules, 2025 gesture in this direction but stop short of mandating the cryptographic watermarking or hash-based verification that would render labels tamper resistant. Without such technical underpinning, a labelling requirement may be circumvented by the simple expedient of stripping the label before redistribution.


Suggestions and Recommendations

A dedicated statute, which may be styled the Synthetic Media (Regulation and Liability) Act, would consolidate the scattered provisions presently invoked against deepfake offenders and supply the conceptual clarity that the existing framework lacks. The statute should begin by defining synthetic media in terms comparable to Article 3(60) of the European Union Artificial Intelligence Act, 2024 and should expressly distinguish between consensual creative uses, satirical or artistic uses and non-consensual harmful uses. A graduated offence structure should follow, with the most serious penalties reserved for the creation and distribution of non-consensual intimate synthetic content, election-related synthetic content and synthetic content used in financial fraud.

A statutory civil cause of action, modelled on the DEFIANCE Act of 2024 and on personality rights jurisprudence emerging from the Delhi High Court, should permit any person whose likeness or voice has been synthetically reproduced without consent to seek damages, injunctive relief and an account of profits. The intermediary regime should incorporate a verified takedown channel for synthetic media complaints, with statutory time limits not exceeding twenty-four hours for intimate imagery. The labelling obligations contemplated by the Draft Rules, 2025 should be elevated to primary legislation and supported by mandatory adoption of content provenance standards, with significant platforms required to publish transparency reports comparable to those required under the European Union Digital Services Act, 2022.

The Indian Evidence framework requires modernisation. An amendment to Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 should provide for a presumption of authenticity where an electronic record bears a verifiable provenance marker and a rebuttable presumption of inauthenticity where no such marker is present. Forensic capacity within state police forces and the Central Bureau of Investigation must be expanded, with dedicated cyber laboratories trained in detection of generative artefacts. The Election Commission of India should be empowered, through an amendment to the Representation of the People Act, 1951, to issue binding directions on synthetic election advertising, modelled on the Singaporean Elections (Integrity of Online Advertising) (Amendment) Act, 2024. The statute should be accompanied by a coordinated programme of digital literacy and victim support.


Conclusion

The Indian legal response to deepfakes has been reactive, fragmentary and dependent upon provisions that predate the technology by decades. The Rashmika Mandanna incident of November 2023, the wave of celebrity impersonation that followed and the manipulated political content of the General Election of 2024 collectively demonstrate that the existing framework, while not entirely powerless, is structurally ill suited to the task. The Information Technology Act, 2000, the Bharatiya Nyaya Sanhita, 2023 and the Digital Personal Data Protection Act, 2023 each contribute partial remedies, and the Draft Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2025 represent a welcome but subordinate intervention. Comparative experience from the United Kingdom, the United States, the European Union, Singapore, China and Australia indicates that targeted statutory responses, grounded in clear definitions and supported by both criminal sanction and civil remedy, are capable of addressing the most acute manifestations of synthetic media harm. India, having recognised privacy as a constitutional right in Justice K.S. Puttaswamy v. Union of India (2017), now requires legislation translating that recognition into protection against algorithmic appropriation of identity. A dedicated Synthetic Media (Regulation and Liability) Act, supported by evidentiary reform and institutional capacity, would supply the coherent framework that the existing patchwork cannot.




Bibliography

Primary Sources

Statutes and Subordinate Legislation

Bharatiya Nyaya Sanhita 2023 (Act 45 of 2023).

Bharatiya Sakshya Adhiniyam 2023 (Act 47 of 2023).

Constitution of India 1950.

Digital Personal Data Protection Act 2023 (Act 22 of 2023).

Indian Evidence Act 1872 (Act 1 of 1872).

Indian Penal Code 1860 (Act 45 of 1860).

Information Technology Act 2000 (Act 21 of 2000).

Information Technology (Amendment) Act 2008 (Act 10 of 2009).

Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021.

Draft Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2025 (Ministry of Electronics and Information Technology, 22 October 2025).

Representation of the People Act 1951 (Act 43 of 1951).

Criminal Code Act 1995 (Cth) (Australia), as amended by the Criminal Code Amendment (Deepfake Sexual Material) Act 2024 (Cth).

Disrupt Explicit Forged Images and Non-Consensual Edits Act of 2024, S 3696, 118th Congress (United States).

Elections (Integrity of Online Advertising) (Amendment) Act 2024 (No 34 of 2024) (Singapore).

Online Safety Act 2023 c 50 (United Kingdom).

Provisions on the Administration of Deep Synthesis Internet Information Services 2022 (People's Republic of China, in force 10 January 2023).

Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) [2024] OJ L 1689.

Sexual Offences Act 2003 c 42 (United Kingdom).

Tools to Address Known Exploitation by Immobilizing Technological Deepfakes on Websites and Networks Act 2025 (United States).

Cases

Anil Kapoor v Simply Life India CS(COMM) 652/2023 (Delhi HC, 20 September 2023).

Anvar PV v PK Basheer (2014) 10 SCC 473.

Arjun Panditrao Khotkar v Kailash Kushanrao Gorantyal (2020) 7 SCC 1.

Jaikishan Kakubhai Saraf alias Jackie Shroff v The Peppy Store CS(COMM) 389/2024 (Delhi HC).

Justice KS Puttaswamy (Retd) v Union of India (2017) 10 SCC 1.

Shreya Singhal v Union of India (2015) 5 SCC 1.

Tolaram Relumal v State of Bombay (1954) SCR 158.

Government and Official Materials

Election Commission of India, 'Advisory on Use of Social Media Platforms by Political Parties and Candidates' (6 May 2024).

Ministry of Electronics and Information Technology, 'Advisory to Intermediaries on Misinformation Enabled by AI and Deepfakes' (7 November 2023).

Ministry of Electronics and Information Technology, 'Advisory to Intermediaries' (26 December 2023).

Ministry of Electronics and Information Technology, 'Advisory on Due Diligence by Intermediaries' (1 March 2024).

Press Information Bureau, Government of India, 'Union Government Issues Advisory to Social Media Intermediaries to Identify Misinformation and Deepfakes' (Release ID 1975445, 7 November 2023).

UK Ministry of Justice, 'Government Crackdown on Explicit Deepfakes' (GOV.UK, 7 January 2025).

Secondary Sources

Books and Articles

Chesney R and Citron D, 'Deep Fakes: A Looming Challenge for Privacy, Democracy, and National Security' (2019) 107 California Law Review 1753.

Goodfellow I and others, 'Generative Adversarial Nets' in Z Ghahramani and others (eds), Advances in Neural Information Processing Systems 27 (NeurIPS 2014).

Bhandari V and others, 'An Analysis of Puttaswamy: The Supreme Court's Privacy Verdict' (2017) IndraStra Global.

Internet Freedom Foundation, 'Dealing with Deepfakes (MeitY's Version)' (December 2023).

Reports

Ajder H and others, The State of Deepfakes: Landscape, Threats and Impact (Deeptrace Labs 2019).

European Commission, 'Code of Practice on Transparency of AI-Generated Content' (2025).

Library of Congress, 'China: Provisions on Deep Synthesis Technology Enter into Effect' (Global Legal Monitor, 25 April 2023).

Newspaper and Online Reports

'Delhi Police Files FIR in Rashmika Mandanna Deepfake Case' The Hindu (Delhi, 11 November 2023).

'FIR Against Gaming Site after Sachin Tendulkar Deepfake Alert' The Times of India (16 January 2024).

'Nine Well-Known Personalities Who Were Victims of Deepfake Videos' Livemint (13 March 2024).

 
 
 

Comments


bottom of page