By Adv. K J Muhammed Aslam · Advocate, Ernakulam (Bar Council of Kerala)
India’s first binding deepfake regime is not an advisory — it is the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 notified on 10 February 2026 and in force from 20 February 2026, which insert a definition of synthetically generated information (SGI) into the IT Rules, 2021 and attach labelling and provenance duties, user-declaration and verification, and a three-hour or two-hour takedown clock to it. An intermediary that knowingly permits prohibited SGI, or that fails to label and trace lawful SGI, risks losing its safe harbour under Section 79 of the IT Act, 2000.
What is SGI — and what is not?
The definition was deliberately narrowed from the October 2025 draft after industry feedback, and misunderstanding the scope is the most common error in commentary that still cites the draft.
SGI under Rule 2(1)(wa) as inserted 10 February 2026:
Audio, visual or audio-visual information which is artificially or algorithmically created, generated, modified or altered using a computer resource, in a manner that such information appears to be real, authentic or true and depicts or portrays any individual or event in a manner that is, or is likely to be perceived as indistinguishable from a natural person or real-world event.
The Government’s FAQ emphasises that the test is content-centric, not method-centric — SGI is about whether the output realistically appears like a real person or real-world event and is capable of deceiving viewers, whether the tool was labelled AI, generative AI or otherwise.
Expressly excluded — not SGI even though a computer was used:
- Text-only content.
- Routine or good-faith editing, formatting, enhancement, technical correction, colour adjustment, noise reduction, transcription, translation, compression, and preparation of documents, presentations, PDFs, educational or training materials, research outputs — where the substance, context or meaning is not materially altered or misrepresented.
- Tools for improving accessibility, clarity, quality, translation, description, searchability or discoverability — again, where material substance is not manipulated to deceive.
- Accessibility tools such as text-to-speech and speech-to-text.
A cropped, colour-corrected photograph is not SGI. A synthetic video of a Kerala public figure appearing to announce a policy they never announced is — even if the creator says a non-AI tool was used.
What SGI is prohibited outright?
The Amendment Rules prohibit an intermediary from allowing SGI that falls in defined high-risk categories. The categories track — and are enforced alongside — existing criminal provisions:
| Prohibited SGI category | Parallel criminal provision where also violated | Platform exposure (separate) |
|---|---|---|
| Child sexual abuse material | Section 67B IT Act + POCSO Act | Loss of safe harbour under Section 79 IT Act where due diligence fails |
| Non-consensual nudity, obscene or sexually explicit material, morphed intimate imagery | Sections 66E, 67, 67A IT Act; Sections 75, 77 BNS | Loss of safe harbour under Section 79 IT Act where due diligence fails |
| SGI that invades privacy through impersonation or manipulation | Sections 66C, 66D IT Act; Sections 319, 353 BNS | Loss of safe harbour under Section 79 IT Act where due diligence fails |
| SGI that creates false documents or electronic records | Sections 336, 340 BNS | Loss of safe harbour under Section 79 IT Act where due diligence fails |
| SGI that enables creation of explosives, arms or ammunition | Explosive Substances Act; BNS provisions on public safety | Loss of safe harbour under Section 79 IT Act where due diligence fails |
| SGI that falsely and deceptively depicts a natural person or real-world event | Sections 353 (false information), 356 (defamation) BNS | Loss of safe harbour under Section 79 IT Act where due diligence fails — s.79 is a safe-harbour/exposure analysis, not a criminal provision |
| Unlawful SGI more generally | Rule 3(1)(b) unlawful categories + BNS/IT Act as applicable | Loss of safe harbour under Section 79 IT Act where due diligence fails |
Where SGI also constitutes a criminal offence, the platform’s takedown duty and the criminal investigation run in parallel — removal does not replace the FIR, and the FIR does not replace the need for rapid removal.
What must intermediaries do — the three layers of duty?
Layer 1 — Every intermediary (Rule 3)
Duties that apply to all intermediaries as defined in Section 2(1)(w) IT Act — which includes social media, video-sharing, messaging, hosting, search and cloud services that host or transmit user content:
| Duty | What the Rules now require |
|---|---|
| User awareness every three months — Rule 3(1)(c) | Inform users at least once every three months (up from once a year) through terms, privacy policy or other means that non-compliance with platform rules on SGI — creation, modification, hosting, dissemination of unlawful information — can result in suspension or termination, content removal, and potential penalties and reporting under POCSO or BNSS |
| Proactive prevention — Rule 3(3) (SGI-enabling intermediaries) | Deploy reasonable and appropriate technical measures, including automated tools, to prevent generation or sharing of prohibited SGI — not merely to react after it is reported |
| Labelling and provenance for lawful SGI — Rule 3(3) (SGI-enabling intermediaries) + Rule 4(1A) (SSMIs) | Ensure that SGI that is not prohibited is prominently labelled as synthetic or AI-generated — clearly visible in visual displays, prefixed prominently in audio — and embedded with permanent metadata or provenance markers including a unique identifier of the computer resource used to generate or alter the content; platforms must not enable suppression or removal of those markers |
| Takedown on actual knowledge — Rule 3(1)(d) | Remove or disable access to unlawful information — including unlawful SGI — within three hours of actual knowledge through a court order or a notification from the appropriate government or its authorised agency (down from 36 hours) |
| Individual-complaint fast track — Rule 3(2)(b) | Remove or disable access within two hours on individual complaints involving private-area/nudity/sexual act/impersonation including morphed imagery (down from 24 hours) |
| Grievance redressal — Rule 3(2) | Acknowledge complaints within 24 hours; resolve general grievances within seven days (down from 15 days); unlawful-content grievances within 36 hours (down from 72 hours) |
The three-hour clock under Rule 3(1)(d) runs from actual knowledge through the two specified channels — a court order or an authorised government notification — not from a generic user report under Rule 3(2). The separate two-hour clock under Rule 3(2)(b) runs from an individual complaint involving private-area/nudity/sexual act/impersonation including morphed imagery. For the brand owner, the practical path is to file the Rule 3(2) grievance with specific URLs and proof immediately and, where the SGI is actively causing harm, to pursue the court order or government notification that triggers the three-hour Rule 3(1)(d) clock. The Sahyog portal — upheld as a takedown route in X Corp v. Union of India, W.P. No. 7405 of 2025 (Karnataka High Court, 24 September 2025) — is part of the government-notification ecosystem that starts that clock.
Layer 2 — Intermediaries that offer SGI-enabling tools (Rule 3(3))
Where the intermediary provides a computer resource that enables creation, generation, modification or large-scale dissemination of SGI — generative AI tools, video and image editors, voice-cloning services — the Rules add product-level duties: warn users against generating prohibited SGI, ensure product design does not nudge users toward prohibited SGI, and be able to restrict or suspend repeat misuse. Product flows, interfaces and user declarations must be designed for compliance, not merely for engagement.
Layer 3 — Significant social media intermediaries (SSMIs — Rule 4(1A), threshold 50 lakh registered users in India)
Additional duties for SSMIs:
- Require users to declare whether uploaded or shared content constitutes SGI.
- Deploy reasonable technical measures to verify the correctness of declarations before publication or display, and reject uploads where the declaration is missing or verification suggests non-compliance.
- Ensure confirmed SGI is clearly and prominently labelled as synthetic so recipients can easily identify it.
- Maintain provenance and traceability records, including first-originator information where required under Rule 4, so harmful SGI can be traced to its source.
Failure by an SSMI to take reasonable steps against unlawful SGI can be treated as a failure to exercise due diligence, with loss of safe harbour under Section 79 IT Act and exposure to liability for user content — the consequence the February 2026 amendment was designed to make credible.
How does SGI outside the Rules — deepfake harms in court — get addressed?
The Amendment Rules regulate intermediary distribution, not authorship or damages. Where a deepfake harms a person, the civil and criminal tracks available alongside the Rules include:
- IT Act — Sections 66C (identity theft), 66D (personation), 66E (privacy), 67/67A/67B (obscenity) — the standard charges for impersonation and intimate-image deepfakes.
- BNS — Sections 353 (false information causing panic or enmity), 336 (forgery of electronic record), 319 (cheating by personation), 356 (defamation), 75/77 (sexual harassment, voyeurism). Consider Section 111 (organised crime) only where its ingredients are made out on the facts — seek advice before invoking it.
- Privacy and publicity rights — courts have granted interim relief in deepfake and personality-rights cases on privacy and publicity grounds even before the 2026 Rules, including orders restraining impersonation and directing platform takedown and disclosure.
- Copyright — Section 51 Copyright Act — where the deepfake reproduces protected expression (voice, performance, footage) beyond the idea.
At the Supreme Court’s hearing on 28 July 2026 in the suo motu digital-arrest and deepfake cognizance (originating October 2025), the Bench observed that the IT Act, 2000 — enacted before smartphones and UPI — needs to define digital arrest and deepfakes as standalone offences with asset-freezing powers on prima facie material, indicating that further legislative definition may follow the current Rules-based regime.
What should a Kerala platform, business or creator do now?
| Who you are | Concrete steps |
|---|---|
| Platform or app that hosts user content in India | Update terms to cover SGI expressly; implement the three-month awareness notice cycle; deploy labelling and metadata embedding; build the three-hour and two-hour escalation path with round-the-clock coverage; document reasonable technical measures for the safe-harbour file |
| SSMI (50 lakh+ users) | Add SGI declaration at upload, verification before publication, and prominent labelling for confirmed SGI; ensure product design does not nudge toward prohibited SGI |
| AI tool provider | Warn against prohibited SGI categories in-product, log generation with provenance, and build suspension for repeat misuse |
| Business that is a Data Fiduciary | Treat training data that includes personal data as processing under the DPDP Act — lawful basis, Section 5 notice, Section 6 consent, Rule 6 safeguards and Rule 7 breach duties apply to model data (see the CERT-In vs DPDP breach guide and the DPDP countdown guide) |
| Creator | Where you use synthetic media, label it clearly as synthetic — the carve-out for satire, art and research protects clearly labelled, non-deceptive uses, not undisclosed impersonation |
Primary sources
- Information Technology Act, 2000 — India Code (Sections 2(1)(w), 66C, 66D, 66E, 67, 67A, 67B, 79, 79A)
- IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 as updated to 10 February 2026 — MeitY and Amendment Rules notified 10 February 2026, G.S.R. 120(E) — Gazette of India (Rules 2(1)(wa), 3(1)(b), 3(1)(c), 3(1)(d), 3(2), 4)
- Government FAQ on the Amendment Rules, 2026 — MeitY (February 2026)
- X Corp v. Union of India, W.P. No. 7405 of 2025 (Karnataka High Court, 24 September 2025) on the Sahyog portal
- Supreme Court suo motu cognizance on digital arrest and deepfakes — proceedings from October 2025, hearing on 28 July 2026 (reported by LiveLaw, ETV Bharat, BOOM)
FAQ
