Deepfake And Criminal Liability in India: Are The Existing Laws Enough? : Author: Yumnam Soviet Ningthoucha
A fake video can now show a real person doing or saying something that simply isn't true and most viewers won't be able to tell. Such “deepfakes” create difficult legal questions because the harm may involve impersonation, fraud, reputational injury, privacy violations, sexual exploitation, or the manipulation of public discourse. Indian law does not, however, approach deepfakes through a single standalone offence.
ARTICLE


Abstract
A fake video can now show a real person doing or saying something that simply isn't true and most viewers won't be able to tell. Such “deepfakes” create difficult legal questions because the harm may involve impersonation, fraud, reputational injury, privacy violations, sexual exploitation, or the manipulation of public discourse. Indian law does not, however, approach deepfakes through a single standalone offence. Instead, liability may arise under the Information Technology Act, 2000, the Bharatiya Nyaya Sanhita, 2023 (BNS), constitutional protections of privacy and speech, and the Information Technology Rules governing intermediaries. The 2026 amendments to the IT Rules have further introduced a specific regulatory framework for “synthetically generated information.” This article argues that India has moved beyond a complete legal vacuum, but the framework remains fragmented. What India needs right now is better enforcement, a way to trace who made the deepfake, and clearer evidence rules, not a brand new deepfake law.
Keywords: Deepfakes, Artificial Intelligence, Cybercrime, Information Technology Act, Bharatiya Nyaya Sanhita, Privacy
1. INTRODUCTION
A photograph, recording or video has traditionally carried a degree of evidentiary and persuasive force because viewers generally assume that it represents something that actually happened. Generative artificial intelligence has weakened that assumption. A person can now be made to appear to speak words they never uttered, perform acts they never performed, or appear in circumstances that never existed. The resulting material may be used for entertainment or satire, but the same technology can facilitate fraud, impersonation, sexual abuse, reputational attacks and the deliberate manufacture of false evidence.
The legal problem is therefore not simply that deepfakes are technologically sophisticated. It is that existing legal categories were largely developed before synthetic media became capable of appearing authentic at scale. Indian law addresses several of the harms associated with deepfakes through existing offences and intermediary obligations, but these provisions operate across different statutes and regulatory mechanisms.
This article examines whether that framework is sufficient. It argues that Indian law already provides several routes to liability, particularly where synthetic content involves cheating, impersonation, privacy violations, sexualised material or forged electronic records. The principal weakness lies elsewhere: identifying the creator, proving intention, preserving digital evidence and coordinating remedies against both users and intermediaries. The 2026 amendments to the Information Technology Rules are an important development, but they should be understood as an additional regulatory layer rather than a complete criminal-law solution.
2. THE EXISTING LEGAL FRAMEWORK
2.1 Constitutional Boundaries
Deepfake regulation must operate within the constitutional framework governing speech and privacy. Article 19(1)(a) protects freedom of speech and expression, while Article 19(2) permits reasonable restrictions on specified grounds. A law directed at synthetic media therefore cannot treat the creation or dissemination of every artificial representation as inherently unlawful. This isn't a risk unique to deepfake law. It's the same overbreadth problem that made the Supreme Court strike down Section 66A in Shreya Singhal, the Supreme Court emphasised the constitutional importance of clear legal standards when restrictions on online speech are imposed.[1] India has already learned this lesson once. A new deepfake law risks making the same mistake again if it isn't built carefully around actual harm, rather than just banning the use of the technology itself.
Privacy provides a second constitutional dimension. In Justice K.S. Puttaswamy (Retd.) v. Union of India, the Supreme Court recognised privacy as a constitutionally protected right associated with dignity, autonomy and liberty.[2] A fabricated intimate image or realistic portrayal of a person may therefore implicate interests extending beyond ordinary reputational harm.
The constitutional question is consequently not whether deepfakes should be regulated, but how regulation can distinguish harmful deception and unlawful exploitation from protected expression. So, the real constitutional question isn't whether deepfakes should be regulated, or whether current laws are enough. It's whether any law can tell the difference between harmful lies or abuse, and speech that people have a right to make.
2.2 The Information Technology Act, 2000
The Information Technology Act, 2000 does not contain a general offence titled “deepfake.” Nevertheless, several provisions may become relevant depending on the conduct involved.
Section 66D addresses cheating by personation using a communication device or computer resource.[3] This provision may be particularly relevant where synthetic audio or video is used to impersonate another person for fraudulent purposes. Section 66C separately addresses identity theft involving the fraudulent or dishonest use of another person’s electronic signature, password or other unique identification feature.[4]
Section 66E may apply where private areas of a person are captured, published or transmitted without consent in circumstances covered by the provision.[5] Sections 67 and 67A may become relevant where deepfake material involves obscene or sexually explicit content.[6]
The significance of these provisions is that liability depends on the underlying conduct, not merely on the technological method used to create the material. A manipulated video used for a joke and a manipulated video used to deceive a victim into transferring money may both technically be deepfakes, but their legal consequences are substantially different.
2.3. Forged Electronic Records under the BNS
The Bharatiya Nyaya Sanhita, 2023 provides another potentially important route. Section 336 criminalises forgery and expressly includes a “false electronic record.”[7] The provision becomes especially significant where synthetic material is created with the statutory intention to cause damage or injury, support a claim or title, induce a person to part with property or enter into a contract, or commit fraud.
Section 336(3) further addresses forgery intended to facilitate cheating, while section 336(4) deals with forgery intended to harm reputation or where the maker knows that the forged material is likely to be used for that purpose.[8]
But this law shouldn't be applied automatically to every case. Just because a photo or video was manipulated using AI doesn't mean it counts as forgery. The prosecution still has to prove all the elements of the crime, including that the person actually intended to cause harm. This matter because if courts start treating every AI-edited video as a crime just because the technology looks convincing, they'd end up punishing people for using a tool, not for what they actually did with it. For example, a harmless meme or a movie special effect could get treated the same as a scam, which isn't fair or accurate.
3. WHAT THE 2026 IT RULES CHANGE
The most significant recent development is the 2026 amendment to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
The amended Rules introduce the concept of “synthetically generated information” (SGI). The definition broadly captures audio, visual and audio-visual information that has been artificially or algorithmically created, generated, modified or altered through a computer resource so that it appears real or authentic.[9] This brings many forms of deepfake material within a regulatory framework without creating a criminal offence called “deepfake.”
The amendment is important because it moves part of the regulatory response upstream. Instead of relying entirely on criminal prosecution after harm has occurred, intermediaries and platforms facilitating relevant synthetic content are subjected to technical and procedural obligations.
The Rules require appropriate technical measures concerning unlawful SGI and establish labelling and provenance-related requirements for qualifying synthetic material.[10] The framework therefore recognises that users should be able to distinguish synthetic content from authentic material and that technological traceability can assist accountability.
Earlier approaches largely focused on removal after harmful material had already circulated. The amended framework attempts to make platform architecture itself part of the regulatory response.
4. WHERE THE FRAMEWORK STILL FALLS SHORT
4.1 Attribution Remains the First Difficulty
A law can impose liability only when the person responsible for unlawful conduct can be identified and the necessary elements proved. Deepfakes complicate this process because creation, editing, distribution and reposting may occur through different accounts, platforms and jurisdictions.
A victim may therefore know that a fabricated video exists without knowing who created it, who first uploaded it, or who deliberately altered it. The availability of platform-level obligations does not automatically solve this attribution problem.
4.2 Mens Rea and Context Matter
A central difficulty is distinguishing harmful deception from lawful or relatively harmless synthetic expression. A realistic AI-generated video used in a comedy sketch raises different concerns from a fabricated recording designed to induce a victim to transfer money.
Criminal law must therefore focus on conduct, harm and intention rather than simply the existence of artificial generation. An offence drafted too broadly could capture satire, parody, artistic experimentation or political commentary. That would create precisely the type of overbreadth that constitutional doctrine seeks to prevent.
4.3 The Problem Is Fragmented Rather Than Entirely Absent
India's laws on this are scattered across the IT Act, the BNS, the IT Rules, and the Constitution. This makes things hard for victims to navigate. A single deepfake case can involve impersonation, privacy invasion, reputational harm, sexual content, and fraud, all at once. That means different laws, different procedures, and different evidence rules can all apply to the same case.
So, the real question isn't whether India has a law against deepfakes. It's whether these different legal tools can work together fast enough, fast enough to find who spread the fake to harm someone or ruin their image, preserve the evidence, stop it from spreading further, and get the victim real relief. Speed matters because of how public belief works: once enough people have seen and believed the fake video, it becomes 'true' in the public's mind, even after it's proven false. And once someone's image is destroyed this way, there's often no going back to a normal life, especially when the legal system itself moves too slowly to catch up before the damage is already done.
5. SHOULD INDIA CREATE A STANDALONE DEEPFAKE OFFENCE?
The strongest argument for a new, standalone deepfake law is clarity. A clearly defined offence would give victims, police, and courts one common legal language to work with. It would treat harmful deepfake impersonation as its own specific crime, letting authorities act faster and giving victims a clear answer to the question: where do I even go to report this?
But there's a real counterargument too. A broad law that punishes the mere creation or sharing of synthetic content risks punishing legitimate speech along with it. Deepfake technology is just a method, not one single type of harm. The exact same technique can be used to make a film's special effects, an educational simulation, a satire video, a scam, or sexual abuse content. The technology itself is neutral; what matters is how it's used.
Because of this, the better approach, at least for now, is to strengthen the laws India already has, rather than create a brand-new offence built around a specific technology, one that could become outdated as the technology itself changes. The law should focus on the actual harm: deception, impersonation, non-consensual sexual content, privacy violations, fraud, and intentional damage to someone's reputation. At the same time, it should clearly recognise that a lot of synthetic content is legitimate and shouldn't be treated as criminal at all.
6. CONCLUSION
India isn't starting from zero on deepfakes anymore. The IT Act and the Bharatiya Nyaya Sanhita already cover several kinds of harmful synthetic media, and constitutional law puts limits on any law that goes too far. The 2026 changes to the IT Rules add another layer by officially recognising 'synthetic content' and putting more responsibility on platforms.
But having laws on paper isn't the same as actually getting justice. The real problems are: finding out who made the fake, proving they meant to cause harm, keeping the digital evidence safe before it's deleted or lost, and getting criminal law and platform rules to work together instead of separately. India might need a brand-new deepfake law eventually, if these problems can't be fixed with what already exists. But right now, the smarter move is to improve enforcement, fix how evidence is handled, build ways to trace where content came from, and give victims real, usable remedies, all while still allowing honest, legitimate uses of the technology.
In the end, the goal isn't to ban fake content altogether. It's to stop it from becoming a tool for deception and abuse, without accidentally shutting down speech that the Constitution is supposed to protect.
REFERENCES
Legislation
The Bharatiya Nyaya Sanhita, 2023.
The Constitution of India.
The Information Technology Act, 2000.
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as amended.
Cases
Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
Shreya Singhal v. Union of India, (2015) 5 SCC 1.
Government Sources
Ministry of Electronics and Information Technology, Government of India, Frequently Asked Questions: Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026.
Yumnam Soviet Ningthoucha is a first-year law student at Campus Law Centre, University of Delhi, with research interests in cyber law, technology law, constitutional law, and emerging legal issues surrounding artificial intelligence.
[1] Shreya Singhal v. Union of India, (2015) 5 SCC 1.
[2] Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
[3] The Information Technology Act, 2000, § 66D.
[4] Id. § 66C.
[5] Id. § 66E.
[6] Id. §§ 67, 67A.
[7] The Bharatiya Nyaya Sanhita, 2023, § 336(1).
[8] Id. §§ 336(3)– (4).
[9] The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, r. 2(1) (wa), as amended by G.S.R. 120(E), Ministry of Electronics and Information Technology (Feb. 10, 2026).
[10] Id. r. 3(3)(a).
