Detect Deepfakesby Resemble AI
Deepfake law · India

Deepfake Law in India

India regulates deepfakes through the IT Act, IT Rules, 2026 intermediary-rule amendments on AI-generated content, and the Digital Personal Data Protection Act framework.

Status
enacted
Jurisdiction
India
Effective
Apr 2023
Statute
IT Act 2000 + IT Rules 2021/2026 + DPDP Act 2023
Platform liabilityDefamationNon-consensual imageryData protection (biometric)
Updated Jul 7, 2026 · 2 min read

India's deepfake regulation operates through a combination of the IT Act 2000 (amended), IT Rules 2021 and 2026 intermediary-rule amendments on synthetically generated information, and the Digital Personal Data Protection Act 2023. Dedicated standalone deepfake legislation has been debated but not enacted.

Key provisions

IT Act 2000 — Sections 66E, 67, 67A, 67B. Cover privacy violations, obscenity, and child sexual abuse material. Interpreted to apply to AI-generated content. Penalties up to seven years for specific offenses.

IT Rules 2021 and 2026 amendments. Require intermediaries (platforms, ISPs) to remove deepfake content within specified timeframes and to use reasonable efforts to prevent hosting unlawful AI-generated content targeting identified persons. The 2026 amendments add direct obligations around synthetically generated information, including user notice, due diligence, and action against unlawful deepfakes.

Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules. Allow government takedown orders for content harming sovereignty, public order, or public morality — applied to high-profile deepfake cases.

Digital Personal Data Protection Act 2023. Biometric data provisions cover voice and facial features, and implementing rules are part of the 2026 compliance backdrop.

Indian Penal Code / Bharatiya Nyaya Sanhita 2023. Defamation, impersonation, and fraud provisions apply to deepfake-enabled offenses.

MeitY advisories

The Ministry of Electronics and Information Technology (MeitY) has issued advisories specifically on deepfakes following the 2023 Rashmika Mandanna and related cases. Key expectations:

  • Platforms must proactively identify and remove deepfake content.
  • Failure to comply can result in loss of safe-harbor protection under Section 79 of the IT Act — exposing platforms to direct liability for hosted content.

Dedicated deepfake legislation

A standalone deepfake bill remains politically discussed, but the concrete 2026 change is through intermediary-rule amendments rather than a separate deepfake criminal code.

Practical implications

For organizations operating in India:

  • Platforms: MeitY compliance is a high-visibility priority. AI-generated-content notices, reporting, takedown workflows, and repeat-offender handling should be treated as operating requirements.
  • AI service providers: DPDP Act obligations plus IT Rules require careful consent management.
  • Enterprises: moderate current burden; expected to increase through intermediary-rule enforcement and DPDP implementation even without a standalone deepfake statute.

Sources