Parth Bhatia is student at National Law University, Odisha
Introduction
What happens when seeing is no longer believing?
Artificial Intelligence has transformed the very way information is created and shared online. Among its most controversial developments is the rise of deepfakes, AI-generated audio, video and images capable of portraying individuals saying or doing things they never actually said or did. What was once restricted to sophisticated technological settings is today accessible to everyone and, the production of convincing synthetic media is easier than ever.
India has already witnessed several instances involving manipulated videos of public figures, celebrity deepfakes and AI-generated misinformation circulating on social media platforms such as the 2023 deepfake video of actor Rashmika Mandanna, which led Delhi Police to register an FIR. These aren’t hypothetical scenarios, they have happened and they will keep happening if no action is taken. In response, the Government has increasingly emphasised the responsibility of intermediaries to address harmful AI-generated content through existing IT regulations. Whether this approach actually works is a different question. Holding platforms responsible for the content they did not create is not a simple solution to a not-so-simple problem. It reveals the limitations of the current regulatory approach used.
While stronger regulations may be necessary, it also raises an important question: Can deepfakes be effectively regulated without undermining free speech and the safe harbour protections available to online platforms?
Deepfakes and the Growing Threat to Digital Trust
The serious threat posed by deepfakes is the spread of false information. A fabricated video of a political leader saying something he never said can be circulated two days before polling which would reach millions of voters before a single fact check catches up with it. The correction, when it comes, never travels as fast as the original lie, as seen during the Election Commission of India’s advisory on AI-generated content during the 2024 general elections. It’s the asymmetry itself that’s the issue, not the fact that there is false content.
Besides elections, deepfakes have also become tools for cybercrime. Voice cloning technology has been used in impersonation scams and financial fraud, where people believing they are speaking to a known person, end up getting scammed because of a lack of differentiation between the real and the AI-generated cloned voice, such as the AI voice-cloning scam reported from Hyderabad.
What makes all of this particularly difficult to counter is that, deepfakes work precisely because they appear genuine. A viewer cannot distinguish between genuine and manipulated content simply by looking carefully. The outcome is a growing mistrust of digital communication, including the trust in authentic content that could be perceived as suspicious.
India’s Regulatory Framework
India currently does not have a dedicated law governing deepfakes. The issue is addressed through a combination of existing provisions. Sections 66E, 66D and 67 of the Information Technology Act, 2000 cover the publication of private images without consent, cheating by personation through computer resources and obscene electronic content respectively. The IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 provide the operational framework for platform obligations.
A major provision of this framework is Section 79 of the Information Technology Act providing safe harbour protection for intermediaries for third-party content as long as they meet certain obligations for due diligence. The provision recognizes that digital platforms cannot keep track of every piece of content uploaded by millions of users.
The Supreme Court in Shreya Singhal v. Union of India, (2015) made clear that platforms should not be expected to independently adjudicate whether content is lawful. The logic used was sound: a platform that hosts billions of pieces of content cannot practically review each one.
The problem is that deepfakes fit awkwardly into this framework. MeitY’s advisories issued in late 2023 directed platforms to remove deepfake content within 24 hours of a complaint and signalled that safe harbour protection could be withdrawn from platforms that fail to comply. This is a meaningful shift, as even if the advisories themselves do not create new binding law, there is still some protection to those affected.
The government is clearly no longer satisfied with purely reactive moderation and is concerned whether the legal system will ever be able to catch up.
The Problem with Expanding Platform Liability
It is natural to expect a higher level of accountability of platforms in relation to deepfakes. The problem with this is that the process isn’t as straightforward as it sounds.
The first challenge is technological. Deepfake detection tools are not foolproof and frequently fail to identify malicious manipulated content from authentic content. As a result, platforms find it difficult to determine which content should be removed and which shouldn’t.
If a platform has to face serious legal liability every time a deepfake is detected, the immediate response should be to remove the content rather than checking it carefully. The Delhi High Court’s decision in MySpace Inc. v Super Cassettes Industries Ltd. recognised the practical limitations faced by intermediaries and, observed that platforms cannot reasonably be expected to monitor every piece of user-generated content due to the high volume of submissions. Although the dispute concerned copyright infringement, the Court’s reasoning remains relevant in the context of AI-generated content.
The second challenge is over-censorship. When platforms become the primary enforcers of content standards, their internal moderation policies, often drafted by companies headquartered outside India, effectively become the binding law for Indian users.
This concern is especially significant because social media platforms have become important spaces for public discussions. Decisions regarding content moderation can therefore affect an individual’s right to freedom of speech and expression since the moderators wouldn’t actually know if the content written is lawful or harmful in the individual’s country.
Free Speech, Privacy and the Need for Balance
The debate surrounding deepfake regulation ultimately involves balancing competing constitutional interests.
The case for regulating deepfakes is not just about misinformation. It is about something more basic, which is the right to not have your face, voice and identity used without your knowledge or consent to say things you never said. In Justice K.S. Puttaswamy (Retd.) v Union of India, the Supreme Court recognised privacy as a fundamental right and emphasised the importance of individuals having control over their personal data in the digital era. Deepfakes pose a direct challenge to these interests by allowing individuals to be digitally manipulated without their consent.
This concern has now received judicial recognition. In a recent interim order, the Bombay High Court directed the immediate removal of AI-generated deepfakes of the actress Preity Zinta. Justice Madhav J. Jamdar observed that “the plaintiff’s personality rights, publicity rights and moral rights are violated by the creation of such morphed deepfake and/or superimposed content” and held that these rights flow from Articles 19(1)(a) and 21 of the Constitution. The order shows that the Indian Courts are increasingly relying upon personality and fundamental rights in the absence of dedicated legislation on deepfakes to provide immediate protection.
On the other hand, excessive moderation may undermine freedom of speech and expression. In Anuradha Bhasin v. Union of India, the Supreme Court emphasised that restrictions affecting digital communication must satisfy the pre-requisites of legality, necessity and proportionality. A provision that prohibits ‘misleading AI-generated content’ without defining its terms is not a solution. It increases the chances for selective enforcement.
The constitutional difficulty here is real but it is not irresolvable. Targeting the harms that are clearly established such as non-consensual intimate imagery, electoral manipulation, impersonation frauds is a balanced approach. Trying to regulate synthetic media as a general category is not.
From the EU AI Act to India: Lessons for Reform
The European Union (EU)’s AI Act spreads accountability over the entire AI value chain. It requires providers of generative AI systems to comply with its transparency framework and imposes obligations on deployers separately if they use generative AI systems to create or manipulate deepfakes. Responsibility therefore does not arise only when synthetic content reaches an online intermediary.
India’s 2026 amendments by contrast, address synthetically generated information primarily through intermediary due diligence. They place duties on intermediaries that offer computer resources that can facilitate the creation or dissemination of SGI, such as labelling and provenance requirements. This certainly increases the specificity of the accountability of the platform but it also brings up a wider issue about the direct responsibility of developers of powerful generation tools for the foreseeable misuse.
India might then augment its intermediary-driven approach with specific requirements of deepfake generators, such as reasonable protections against particular types of misuse and mechanisms for maintaining provenance information. This would spread the burden throughout the AI system, instead of solely placing the regulatory burden over the platform where the final content appears.
Conclusion
Deepfakes are not going away anytime soon, hence, instead of ignorance or vague decisions like removing the challenged deepfake without any analysis, the government should look for measures to tackle generative AI with sincerity. Deepfakes are among the most significant challenges brought about by the swift advancement of generative AI. They are capable of spreading misinformation, scams and privacy breaches, which require a sense of urgency for new regulations. The rise in intermediary liability, meanwhile, could result in over-censorship and less legitimate speech online.
The problem with India is not if it should regulate deepfakes but how it should do so. The current approach is based on advisories and extended interpretations of provisions that were drafted prior to the advent of this type of technology and is not viable at all. What is required is an honest framework that: identifies the boundaries of platform accountability; is accurate in describing harms it would address; is realistic in regard to providing a remedy to victims. The effective framework must take into account the fact that digital safety and free speech are not mutually exclusive objectives but rather complementary ones. India can neutralise the impact of synthetic media without compromising the openness and democracy of a free internet by being transparent, targeted in its approach to enforcement and by taking measures to ensure the processes are protected.
