Deepfake Law in India
India regulates deepfakes through the IT Act, IT Rules, 2026 intermediary-rule amendments on AI-generated content, and the Digital Personal Data Protection Act framework.
- Status
- enacted
- Jurisdiction
- India
- Effective
- Apr 2023
- Statute
- IT Act 2000 + IT Rules 2021/2026 + DPDP Act 2023
India's deepfake regulation operates through a combination of the IT Act 2000 (amended), IT Rules 2021 and 2026 intermediary-rule amendments on synthetically generated information, and the Digital Personal Data Protection Act 2023. Dedicated standalone deepfake legislation has been debated but not enacted.
Key provisions
IT Act 2000 — Sections 66E, 67, 67A, 67B. Cover privacy violations, obscenity, and child sexual abuse material. Interpreted to apply to AI-generated content. Penalties up to seven years for specific offenses.
IT Rules 2021 and 2026 amendments. Require intermediaries (platforms, ISPs) to remove deepfake content within specified timeframes and to use reasonable efforts to prevent hosting unlawful AI-generated content targeting identified persons. The 2026 amendments add direct obligations around synthetically generated information, including user notice, due diligence, and action against unlawful deepfakes.
Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules. Allow government takedown orders for content harming sovereignty, public order, or public morality — applied to high-profile deepfake cases.
Digital Personal Data Protection Act 2023. Biometric data provisions cover voice and facial features, and implementing rules are part of the 2026 compliance backdrop.
Indian Penal Code / Bharatiya Nyaya Sanhita 2023. Defamation, impersonation, and fraud provisions apply to deepfake-enabled offenses.
MeitY advisories
The Ministry of Electronics and Information Technology (MeitY) has issued advisories specifically on deepfakes following the 2023 Rashmika Mandanna and related cases. Key expectations:
- Platforms must proactively identify and remove deepfake content.
- Failure to comply can result in loss of safe-harbor protection under Section 79 of the IT Act — exposing platforms to direct liability for hosted content.
Dedicated deepfake legislation
A standalone deepfake bill remains politically discussed, but the concrete 2026 change is through intermediary-rule amendments rather than a separate deepfake criminal code.
Practical implications
For organizations operating in India:
- Platforms: MeitY compliance is a high-visibility priority. AI-generated-content notices, reporting, takedown workflows, and repeat-offender handling should be treated as operating requirements.
- AI service providers: DPDP Act obligations plus IT Rules require careful consent management.
- Enterprises: moderate current burden; expected to increase through intermediary-rule enforcement and DPDP implementation even without a standalone deepfake statute.