Criminal Liability for AI-Generated Deepfakes and Digital Manipulation : Author: Shreya Das
Artificial intelligence can now create realistic audio, images and videos that falsely depict a person saying or doing something. Deepfakes can cause reputational injury, sexual exploitation, fraud, political manipulation and threats to public order. This article examines criminal liability in India by connecting deepfake misuse with the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Bharatiya Nyaya Sanhita, 2023, and recent regulatory developments concerning synthetically generated information. It argues that liability should focus on unlawful intent, harm, consent, deception and traceability, while preserving legitimate expression and innovation.
ARTICLE


Abstract
Artificial intelligence can now create realistic audio, images and videos that falsely depict a person saying or doing something. Deepfakes can cause reputational injury, sexual exploitation, fraud, political manipulation and threats to public order. This article examines criminal liability in India by connecting deepfake misuse with the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Bharatiya Nyaya Sanhita, 2023, and recent regulatory developments concerning synthetically generated information. It argues that liability should focus on unlawful intent, harm, consent, deception and traceability, while preserving legitimate expression and innovation.
Main Keywords
1. Deepfakes; Artificial
2. Intelligence
3. Cyber Crime
4. Criminal Liability
5. ; Digital Manipulation
6. IT Act
Introduction
The rapid growth of generative artificial intelligence has changed the nature of digital communication. A deepfake is synthetic audio, image or audio-visual material created or altered through computational techniques so that it appears to show a real person or event. The technology itself is not criminal. The legal problem arises when manipulation is used to deceive, impersonate, sexually exploit, defame, threaten, obtain money, or spread unlawful misinformation. In India, therefore, criminal liability must be understood through existing offences together with the developing framework for synthetic media.
Meaning and Legal Nature of Deepfakes:
Deepfakes are especially dangerous because they attack the evidentiary value of digital media. A fabricated video can make an innocent person appear to confess, a voice clone can imitate a relative asking for money, and manipulated intimate images can be circulated without consent. The same technology can also have lawful uses in education, entertainment, accessibility and creative expression.
Consequently, regulation should distinguish harmful and manipulation from ordinary synthetic content and should not treat every AI-generated image as a crime.
Criminal Liability under the Information Technology Act, 2000
The Information Technology Act, 2000 remains an important statutory foundation for cyber offences.
Depending on the facts, provisions concerning identity theft, cheating by personation using a computer resource, privacy violations and publication or transmission of obscene or sexually explicit material may become relevant. Sections 66C and 66D are particularly important where a deepfake is used to impersonate another person or commit cheating. Section 66E may apply where private images are captured, published or transmitted in circumstances involving violation of privacy. Sections 67, 67A and related provisions may become relevant where unlawful obscene or sexually explicit material is transmitted electronically.
The precise offence depends on the content, conduct, intent and evidence in each case.
Bharatiya Nyaya Sanhita And General Criminal Offences :
The Bharatiya Nyaya Sanhita, 2023 (BNS) has replaced the Indian Penal Code and provides the general criminal-law framework. Deepfake conduct may constitute an offence when the manipulated material is used as part of cheating, criminal intimidation, forgery or the making or use of false electronic records, defamation, sexual offences, or other unlawful conduct. The important principle is that AI is a method of commission, not a defence. If a person deliberately uses an AI system to create a false representation and the statutory ingredients of an offence are satisfied, the use of technology does not remove criminal responsibility.
Intermediary Duties and Synthetic Information:
Platform responsibility is a major part of the deepfake problem. MeitY advisories have warned intermediaries about synthetic content and have emphasised labelling, traceability and compliance with the IT Rules. More recent amendments to the IT Rules, 2021 introduce specific due-diligence obligations concerning synthetically generated information. The rules address unlawful synthetic content including non-consensual intimate imagery, sexually explicit material, false documents and deceptive synthetic depictions of persons or real-world events.
They also contemplate prominent labelling and permanent metadata or provenance mechanisms for synthetic information that is not itself unlawful. These measures are significant because prevention, rapid removal and identification of the source can reduce harm before criminal proceedings conclude.
Illustration: Spread and impact of digital manipulation
Victim Harm, Consent and Evidentiary Challenges:
Victims of deepfakes face both immediate harm and difficulty proving that content is false. Non-consensual intimate deepfakes can permanently affect dignity, employment and personal relationships. Fraudulent voice or video may cause financial loss, while political deepfakes can distort democratic discussion. Investigators therefore need reliable digital evidence, metadata, device information, platform records and expert analysis. Chain of custody is essential so manipulated files, original files and forensic reports can be presented credibly in court.
Liability of Creators, Users and Platforms:
Primary criminal liability should ordinarily fall on the person who intentionally creates, commissions, uploads or distributes unlawful deepfake material.
A person who merely possesses a synthetic file without the required criminal intent should not automatically be treated as an offender. Deliberate forwarding or publication can become legally significant when it contributes to the offence. Intermediary liability is more complex because the IT Act provides conditional safe-harbour protection. Platforms must comply with applicable due-diligence obligations; failure can affect legal protection and expose them to consequences under applicable law.
The law should encourage prompt complaint mechanisms, preservation of evidence and cooperation with lawful investigations.
Balancing Regulation with Freedom of Expression:
Strong enforcement must be balanced against constitutional values. Satire, parody, film-making, research and political commentary can involve synthetic media without necessarily being criminal. Overbroad rules may chill legitimate speech. A better approach is a harm-based test: whether content is unlawful, whether it deceptively impersonates a real person or event, whether there is consent or a legitimate purpose, and whether the creator or distributor acted with the mental element required by the relevant offence. Transparency, notice, appeal mechanisms and judicial oversight can improve accountability without suppressing lawful expression.
Illustration: Criminal accountability and digital evidence
Conclusion:
AI-generated deepfakes create a serious challenge for criminal law because they combine the speed of digital distribution with highly convincing deception. India does not need to treat AI as inherently criminal; instead, existing criminal offences and the evolving IT Rules should be applied to the harmful conduct produced through AI.
The strongest response combines criminal investigation, intermediary due diligence, technical provenance, rapid grievance redressal and public awareness. Clear attribution of responsibility is essential: those who intentionally use synthetic media to deceive, exploit or harm others should face consequences, while legitimate innovation and expression should remain protected. A technology-neutral, evidence-based and victim-centred approach will provide the most sustainable legal response.
References:
Information Technology Act, 2000, especially Sections 66C, 66D, 66E, 67 and 67A.
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as amended.
Bharatiya Nyaya Sanhita, 2023.
Ministry of Electronics and Information Technology (MeitY), Advisory on Deepfakes/Synthetic Content, including Advisory dated 26 December 2023.
MeitY, Draft/updated framework on synthetically generated information and amendments to the IT Rules, 2021, 2025–2026.
Constitution of India, Article 19(1)(a) and Article 21.
