Cyber crime & IT Act matters

Deepfakes and Synthetically Generated Information in India: The IT Amendment Rules, 2026 Labelling and 3-Hour Takedown

By Adv. K J Muhammed Aslam · Advocate, Ernakulam (Bar Council of Kerala)

Published 1 September 2026

India’s first binding deepfake regime is not an advisory — it is the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 notified on 10 February 2026 and in force from 20 February 2026, which insert a definition of synthetically generated information (SGI) into the IT Rules, 2021 and attach labelling and provenance duties, user-declaration and verification, and a three-hour or two-hour takedown clock to it. An intermediary that knowingly permits prohibited SGI, or that fails to label and trace lawful SGI, risks losing its safe harbour under Section 79 of the IT Act, 2000.

What is SGI — and what is not?

The definition was deliberately narrowed from the October 2025 draft after industry feedback, and misunderstanding the scope is the most common error in commentary that still cites the draft.

SGI under Rule 2(1)(wa) as inserted 10 February 2026:

Audio, visual or audio-visual information which is artificially or algorithmically created, generated, modified or altered using a computer resource, in a manner that such information appears to be real, authentic or true and depicts or portrays any individual or event in a manner that is, or is likely to be perceived as indistinguishable from a natural person or real-world event.

The Government’s FAQ emphasises that the test is content-centric, not method-centric — SGI is about whether the output realistically appears like a real person or real-world event and is capable of deceiving viewers, whether the tool was labelled AI, generative AI or otherwise.

Expressly excluded — not SGI even though a computer was used:

  • Text-only content.
  • Routine or good-faith editing, formatting, enhancement, technical correction, colour adjustment, noise reduction, transcription, translation, compression, and preparation of documents, presentations, PDFs, educational or training materials, research outputs — where the substance, context or meaning is not materially altered or misrepresented.
  • Tools for improving accessibility, clarity, quality, translation, description, searchability or discoverability — again, where material substance is not manipulated to deceive.
  • Accessibility tools such as text-to-speech and speech-to-text.

A cropped, colour-corrected photograph is not SGI. A synthetic video of a Kerala public figure appearing to announce a policy they never announced is — even if the creator says a non-AI tool was used.

What SGI is prohibited outright?

The Amendment Rules prohibit an intermediary from allowing SGI that falls in defined high-risk categories. The categories track — and are enforced alongside — existing criminal provisions:

Prohibited SGI category Parallel criminal provision where also violated Platform exposure (separate)
Child sexual abuse material Section 67B IT Act + POCSO Act Loss of safe harbour under Section 79 IT Act where due diligence fails
Non-consensual nudity, obscene or sexually explicit material, morphed intimate imagery Sections 66E, 67, 67A IT Act; Sections 75, 77 BNS Loss of safe harbour under Section 79 IT Act where due diligence fails
SGI that invades privacy through impersonation or manipulation Sections 66C, 66D IT Act; Sections 319, 353 BNS Loss of safe harbour under Section 79 IT Act where due diligence fails
SGI that creates false documents or electronic records Sections 336, 340 BNS Loss of safe harbour under Section 79 IT Act where due diligence fails
SGI that enables creation of explosives, arms or ammunition Explosive Substances Act; BNS provisions on public safety Loss of safe harbour under Section 79 IT Act where due diligence fails
SGI that falsely and deceptively depicts a natural person or real-world event Sections 353 (false information), 356 (defamation) BNS Loss of safe harbour under Section 79 IT Act where due diligence fails — s.79 is a safe-harbour/exposure analysis, not a criminal provision
Unlawful SGI more generally Rule 3(1)(b) unlawful categories + BNS/IT Act as applicable Loss of safe harbour under Section 79 IT Act where due diligence fails

Where SGI also constitutes a criminal offence, the platform’s takedown duty and the criminal investigation run in parallel — removal does not replace the FIR, and the FIR does not replace the need for rapid removal.

What must intermediaries do — the three layers of duty?

Layer 1 — Every intermediary (Rule 3)

Duties that apply to all intermediaries as defined in Section 2(1)(w) IT Act — which includes social media, video-sharing, messaging, hosting, search and cloud services that host or transmit user content:

Duty What the Rules now require
User awareness every three months — Rule 3(1)(c) Inform users at least once every three months (up from once a year) through terms, privacy policy or other means that non-compliance with platform rules on SGI — creation, modification, hosting, dissemination of unlawful information — can result in suspension or termination, content removal, and potential penalties and reporting under POCSO or BNSS
Proactive prevention — Rule 3(3) (SGI-enabling intermediaries) Deploy reasonable and appropriate technical measures, including automated tools, to prevent generation or sharing of prohibited SGI — not merely to react after it is reported
Labelling and provenance for lawful SGI — Rule 3(3) (SGI-enabling intermediaries) + Rule 4(1A) (SSMIs) Ensure that SGI that is not prohibited is prominently labelled as synthetic or AI-generated — clearly visible in visual displays, prefixed prominently in audio — and embedded with permanent metadata or provenance markers including a unique identifier of the computer resource used to generate or alter the content; platforms must not enable suppression or removal of those markers
Takedown on actual knowledge — Rule 3(1)(d) Remove or disable access to unlawful information — including unlawful SGI — within three hours of actual knowledge through a court order or a notification from the appropriate government or its authorised agency (down from 36 hours)
Individual-complaint fast track — Rule 3(2)(b) Remove or disable access within two hours on individual complaints involving private-area/nudity/sexual act/impersonation including morphed imagery (down from 24 hours)
Grievance redressal — Rule 3(2) Acknowledge complaints within 24 hours; resolve general grievances within seven days (down from 15 days); unlawful-content grievances within 36 hours (down from 72 hours)

The three-hour clock under Rule 3(1)(d) runs from actual knowledge through the two specified channels — a court order or an authorised government notification — not from a generic user report under Rule 3(2). The separate two-hour clock under Rule 3(2)(b) runs from an individual complaint involving private-area/nudity/sexual act/impersonation including morphed imagery. For the brand owner, the practical path is to file the Rule 3(2) grievance with specific URLs and proof immediately and, where the SGI is actively causing harm, to pursue the court order or government notification that triggers the three-hour Rule 3(1)(d) clock. The Sahyog portal — upheld as a takedown route in X Corp v. Union of India, W.P. No. 7405 of 2025 (Karnataka High Court, 24 September 2025) — is part of the government-notification ecosystem that starts that clock.

Layer 2 — Intermediaries that offer SGI-enabling tools (Rule 3(3))

Where the intermediary provides a computer resource that enables creation, generation, modification or large-scale dissemination of SGI — generative AI tools, video and image editors, voice-cloning services — the Rules add product-level duties: warn users against generating prohibited SGI, ensure product design does not nudge users toward prohibited SGI, and be able to restrict or suspend repeat misuse. Product flows, interfaces and user declarations must be designed for compliance, not merely for engagement.

Layer 3 — Significant social media intermediaries (SSMIs — Rule 4(1A), threshold 50 lakh registered users in India)

Additional duties for SSMIs:

  • Require users to declare whether uploaded or shared content constitutes SGI.
  • Deploy reasonable technical measures to verify the correctness of declarations before publication or display, and reject uploads where the declaration is missing or verification suggests non-compliance.
  • Ensure confirmed SGI is clearly and prominently labelled as synthetic so recipients can easily identify it.
  • Maintain provenance and traceability records, including first-originator information where required under Rule 4, so harmful SGI can be traced to its source.

Failure by an SSMI to take reasonable steps against unlawful SGI can be treated as a failure to exercise due diligence, with loss of safe harbour under Section 79 IT Act and exposure to liability for user content — the consequence the February 2026 amendment was designed to make credible.

How does SGI outside the Rules — deepfake harms in court — get addressed?

The Amendment Rules regulate intermediary distribution, not authorship or damages. Where a deepfake harms a person, the civil and criminal tracks available alongside the Rules include:

  • IT Act — Sections 66C (identity theft), 66D (personation), 66E (privacy), 67/67A/67B (obscenity) — the standard charges for impersonation and intimate-image deepfakes.
  • BNS — Sections 353 (false information causing panic or enmity), 336 (forgery of electronic record), 319 (cheating by personation), 356 (defamation), 75/77 (sexual harassment, voyeurism). Consider Section 111 (organised crime) only where its ingredients are made out on the facts — seek advice before invoking it.
  • Privacy and publicity rights — courts have granted interim relief in deepfake and personality-rights cases on privacy and publicity grounds even before the 2026 Rules, including orders restraining impersonation and directing platform takedown and disclosure.
  • Copyright — Section 51 Copyright Act — where the deepfake reproduces protected expression (voice, performance, footage) beyond the idea.

At the Supreme Court’s hearing on 28 July 2026 in the suo motu digital-arrest and deepfake cognizance (originating October 2025), the Bench observed that the IT Act, 2000 — enacted before smartphones and UPI — needs to define digital arrest and deepfakes as standalone offences with asset-freezing powers on prima facie material, indicating that further legislative definition may follow the current Rules-based regime.

What should a Kerala platform, business or creator do now?

Who you are Concrete steps
Platform or app that hosts user content in India Update terms to cover SGI expressly; implement the three-month awareness notice cycle; deploy labelling and metadata embedding; build the three-hour and two-hour escalation path with round-the-clock coverage; document reasonable technical measures for the safe-harbour file
SSMI (50 lakh+ users) Add SGI declaration at upload, verification before publication, and prominent labelling for confirmed SGI; ensure product design does not nudge toward prohibited SGI
AI tool provider Warn against prohibited SGI categories in-product, log generation with provenance, and build suspension for repeat misuse
Business that is a Data Fiduciary Treat training data that includes personal data as processing under the DPDP Act — lawful basis, Section 5 notice, Section 6 consent, Rule 6 safeguards and Rule 7 breach duties apply to model data (see the CERT-In vs DPDP breach guide and the DPDP countdown guide)
Creator Where you use synthetic media, label it clearly as synthetic — the carve-out for satire, art and research protects clearly labelled, non-deceptive uses, not undisclosed impersonation

Primary sources

FAQ

Common questions

What is synthetically generated information (SGI) under the IT Amendment Rules, 2026?
Under Rule 2(1)(wa) as inserted on 10 February 2026, SGI is audio, visual or audio-visual information that is artificially or algorithmically created, generated, modified or altered using a computer resource in a manner that it appears to be real, authentic or true and depicts or portrays any individual or event in a manner that is, or is likely to be perceived as, indistinguishable from a natural person or real-world event. The Government's FAQ clarifies the focus is on content that realistically appears like a real person or real-world event and is capable of deceiving viewers — whether or not the method was labelled AI.
Does every AI-edited image count as SGI?
No. The Amendment Rules expressly exclude routine or good-faith editing, formatting, enhancement, technical correction, colour adjustment, noise reduction, transcription, translation, compression, preparation of documents and presentations, and accessibility tools such as text-to-speech — where the substance, context or meaning of the content is not materially altered or misrepresented. An AI filter that adjusts colour is not SGI; an AI-generated video of a person saying something they never said is.
What must platforms do for SGI under the IT Amendment Rules, 2026?
Since 20 February 2026, intermediaries must: inform users at least every three months that directing creation of unlawful SGI and sharing prohibited SGI is not allowed and what consequences follow (Rule 3(1)(c) and (ca)); deploy reasonable technical measures to prevent generation or sharing of prohibited SGI; require users to declare whether content is SGI and verify declarations (for SSMIs under Rule 4(1A)); prominently label confirmed SGI as synthetic or AI-generated with embedded metadata or provenance identifiers under Rule 3(3) (SGI-enabling intermediaries) and Rule 4(1A) (SSMIs); ensure labels and identifiers cannot be suppressed or removed; and remove unlawful content within three hours of actual knowledge via a court order or authorised government notification under Rule 3(1)(d) — with a separate two-hour track under Rule 3(2)(b) for individual complaints involving private-area/nudity/sexual act/impersonation including morphed imagery.
What is the takedown timeline for deepfakes and fake content in India now?
Three hours for unlawful information — including unlawful SGI — on receipt of actual knowledge through a court order or a notification from the appropriate government or its authorised agency under Rule 3(1)(d) (down from 36 hours). Two hours under Rule 3(2)(b) for individual complaints involving private-area/nudity/sexual act/impersonation including morphed imagery (down from 24 hours). For user grievances, the general window is seven days (down from 15 days) and 36 hours for unlawful-content grievances. The Sahyog portal is an established route for government takedown directions, upheld in X Corp v. Union of India, W.P. No. 7405 of 2025 (Karnataka High Court, 24 September 2025).
What SGI is prohibited outright?
An intermediary must not allow SGI that is obscene or sexually explicit, that invades privacy through impersonation or manipulation, that constitutes child sexual abuse material, that creates false documents or electronic records, that enables creation of explosives, arms or ammunition, or that falsely and deceptively depicts a natural person or real-world event. The prohibition sits alongside criminal liability under Sections 66C, 66D, 66E, 67, 67A and 67B of the IT Act and Sections 75, 77, 318, 319, 336, 353 and 356 of the BNS where the same content also violates those provisions.
Are satire, art and research using SGI allowed?
The Rules carve out good-faith uses: accessibility tools, academic research, testing and experimentation without deceptive intent, and creative works, satire or artistic expression involving synthetic media — provided the content is clearly labelled as synthetic and does not otherwise violate Rule 3(1)(b) or other applicable laws. Labelling and non-deceptiveness are the conditions; the carve-out is not a licence to deceive even in satire.

Contact

3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction, Ernakulam, Kerala 682031 · Monday – Saturday, 10:00 – 18:30 (by appointment)

A note before you read on. In keeping with the Bar Council of India Rules, this website provides information about Adv. K J Muhammed Aslam, and general legal information, only to those who seek it of their own accord. It is not an advertisement or solicitation, and nothing here is legal advice. By continuing, you acknowledge you are visiting voluntarily. Full disclaimer.