Deepika Kapoor is a third-year student at Ram Manohar Lohiya National Law University, Lucknow.
Introduction
By now, we must have come across a video, image, or audio clip generated through Artificial Intelligence (AI), and have likely been amazed by how far technological innovation has advanced. What appears to be a fascinating leap in technology also brings with it troubling implications. From instances such as Akshay Kumar’s deepfake case, where a morphed video of him was nearly perceived as genuine, raising little doubt about its authenticity, to AI recreations of Studio Ghibli’s signature art style, the misuse of artificial intelligence has raised serious concerns about privacy, ownership, and authenticity in the digital age. Recognising these risks, the Government of India has made its first major move to regulate AI-generated content by introducing draft amendments to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
This draft amendment represents an initial attempt to regulate AI-generated content. These rules impose a “due diligence” responsibility on intermediaries when dealing with synthetically generated information (SGI), defined as content “created, generated, modified or altered using a computer resource” that “reasonably appears to be authentic or true,” marking a crucial step toward striking a balance between innovation and accountability.The rules propose that visual AI-generated media must bear a synthetic-content label covering at least 10% of the display area, and synthetic audio must be labelled during the initial 10% of its duration.
Labelling can be defended as informational, as it equips end-users to evaluate content more critically. In principle, mandatory labelling of AI-generated content is analogous to mandatory disclosures in advertising or satire warnings commonly used today. However, such satire warnings and disclosures are specifically tailored to a particular type of content. For instance, content labelled as “sensitive content” includes graphic material such as violence, nudity, and sexual content. Flagging such content as sensitive allows users to make an informed choice to either proceed or skip it.
However, in its current form, the amendment mandates intermediaries to label or embed a mark on all synthetically generated content. The proposal conflicts with the limited remit of intermediary liability under Section 79 of the Information Technology Act, 2000 (IT Act), and threatens free expression protected by Article 19(1)(a) of the Constitution.
From Unlawful Acts to All Acts: The Perils of an Overbroad AI Labelling Mandate
The draft amendments require intermediaries to label every piece of SGI, regardless of its intended purpose or actual impact. The regulation treats both deeply harmful disinformation and innocent creative expression alike. For instance, synthetically generated content such as recent deepfake videos falsely depicting Akshay Kumar alongside Maharishi Valmiki and Yogi Adityanath without his consent clearly violates his rights to personality, privacy, and dignity under Article 21 and would justifiably fall within the scope of the rules, warranting flagging. However, this one-size-fits-all approach also extends to benign uses, such as the recent trend in which individuals use AI tools to create videos featuring conversations between their childhood and present selves (“Hug Your Younger Self”), a format that has captured the internet’s imagination and evoked strong emotional responses.
The blanket approach takes a contradictory stance towards Section 79 of the IT Act, which uses the term ‘unlawful act’ and imposes liability on intermediaries when they facilitate such an unlawful act. However, the proposed rules blur the standard established by Section 79 of the IT Act by encompassing all SGI regardless of its nature, lawful or unlawful. This disconnects liability from the statutory trigger of an unlawful act.
Absent “unlawful intent or effect,” the obligations by the rules lack the “intelligible differentia” required under Article 14 of the Constitution. Any classification must bear a rational connection to its objective. Here, if the goal is to prevent harm from malicious deepfakes and misinformation, a rule that also sweeps in harmless satire or personal experimentation is not closely tailored to that aim. Without such intelligible differentia, the rule risks being struck down as arbitrary or excessive.
Safe Harbour Under Siege: The Expanding Burden on Intermediaries
The new amendment, if incorporated into the IT Intermediary Rules as they currently stand, would cast a shadow on Section 79 of the IT Act, which provides a safe harbour to social media intermediaries by exempting them from liability for third-party-generated content. This erosion can occur in two ways. First, the rules impose a due-diligence labelling mandate on intermediaries with respect to third-party synthetically generated content, undermining the position intermediaries previously enjoyed under Section 79(3), which triggers liability only upon receipt of actual knowledge or notification by the appropriate Government, as upheld in Shreya Singhal v UOI.
These rules further burden intermediaries by extending obligations to all SGI, going beyond the scope of amended Rule 3(1)(b), which required intermediaries to make “reasonable efforts” not to host information limited to prohibited content.
Secondly, the safe-harbour exemption under Section 79(2)(iii) is conditioned on the intermediary not selecting or modifying the information contained in the transmission. However, the labelling requirement may bring intermediaries within the ambit of “modification” under Section 79(2)(iii), pushing them beyond their traditionally passive role. While the government has introduced a proviso shielding platforms from liability for removing SGI in good faith, no equivalent statutory protection exists for the act of labelling. Thus, intermediaries may lose their safe harbour protection.
Further, the proposed amendment is problematic due to the wording “failed to act upon” such SGI, which exposes intermediaries to liability for failure to exercise due diligence. This wording can have potential implications as it simply means that if an intermediary does not detect or label a given piece of SGI (even unknowingly, due to technical limits), that omission is a violation, and the possibility of such failure is not rare as it’s now evident even to the layperson and more so to technological experts, that AI generation represents a far more advanced and dynamic stage than AI moderation or regulation. Consequently, users can often deploy countermeasures or technical tools swiftly enough to bypass the ‘reasonable and appropriate technical measures’ mandated under the Rules.
These rules indicate a shift from content-specific fault to system-wide regulatory accountability and, in doing so, diminish intermediary safe-harbour protection.
Towards a Balanced Framework: Introducing Intelligible Differentia and Risk-Based Regulation
Although the proposed amendment raises several structural and constitutional challenges, the government can still address these challenges and take a more measured and informed approach. The exact framework of an AI regulation statute must ultimately be developed through careful consultation with legislators, technologists, and policy experts; however, the following recommendations may provide a foundation for that process.
The regulation must pass the intelligible differentia test, as it must have a logical relationship to the objective sought by the relevant amendment. This distinction should differentiate between SGI that is harmful and violates statutory provisions, and synthetically generated creative content that does not.
Further, where intermediaries are subjected to an SGI labelling mandate, a clarifying provision could specify that such labelling does not amount to “modification”, thereby preserving the safe-harbour standard.
India could draw from a more proportionate framework such as the European Union AI Act. The EU AI Act deploys differentiated obligations based on risk levels, placing primary duties on users and providers rather than intermediaries. It follows a risk-categorization model that distinguishes between unacceptable risk, high risk, and transparency obligations. This structure clearly separates generative AI systems such as ChatGPT from higher-risk categories. Article 50 of the EU AI Act requires synthetically generated content to be marked; however, with the necessary caveat that this obligation does not apply to AI tools assisting in standard editing with no substantial alteration in the input provided. The Act recognises freedom of expression and cultural enjoyment while providing exemptions for evidently artistic, creative, satirical, fictional, or analogous work or programmes, thereby exempting them from the need to maintain the transparency obligation.
India is indeed moving in the right direction by recognising the need to codify a statute addressing the growing issues arising from AI. However, progress must also be calibrated and this requires a regulatory framework that ensures a clear and distinct standard, defining what must be regulated, to what extent, and by whom, thereby maintaining accountability without stifling innovation.
Conclusion
While India’s move to regulate AI-generated content is timely, the current labelling mandate risks overbreadth and undermines both intermediary safe harbour and free expression. By treating all synthetically generated content alike, the regulation departs from the “unlawful act” standard under Section 79 and fails the intelligible differentia test. The mandate, in its current form, shifts intermediary liability from a fault-based to a system-wide compliance model without clear statutory backing.
While AI-generated content regulation is a must in the present times, it should not come at a cost of innovation and legitimate creative expression. A more resilient and practical approach would be to adopt a risk-based framework grounded in intelligible differentia, where regulatory boundaries correspond to the demonstration of harm. While drawing on models like the EU AI Act, India can craft a regime that targets malicious deepfakes and misinformation while preserving space for creativity, satire, and innovation. Ultimately, India’s AI regulation success lies not in how much it controls, but in how effectively it targets the right instances of harm.
