Deepfake Regulations & Digital Identity Protection: Legal Framework, Emerging Laws and the Indian Position

  • Post category:Blog
  • Reading time:27 mins read

Deepfake regulations and digital identity protection, including India’s 2026 IT Rules, privacy and impersonation laws, EU AI Act, US developments, legal remedies and future regulatory challenges.

Introduction

Artificial intelligence has transformed the ability to create realistic digital representations of people. A person’s face, voice, mannerisms or apparent actions can now be synthetically generated or manipulated with increasing accuracy.

This technology has legitimate applications in entertainment, education, accessibility, advertising, filmmaking and creative industries. At the same time, the misuse of deepfakes creates serious legal risks involving impersonation, fraud, privacy violations, reputational damage, misinformation, identity theft and non-consensual intimate imagery.

The legal challenge is therefore broader than regulating artificial intelligence itself.

It concerns the protection of an individual’s digital identity.

A person’s identity is no longer limited to their physical presence or official documents. In a digital environment, a recognisable face, voice, biometric characteristic, image, name and behavioural identity can all become targets for manipulation.

India has recently moved toward a more specific regulatory framework. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, notified by the Ministry of Electronics and Information Technology (MeitY), introduced a dedicated framework for synthetically generated information (SGI), covering qualifying deepfakes, AI-generated or altered media and realistic voice cloning. The amendments came into force on 20 February 2026.

The development is significant because Indian law is moving from a framework based primarily on general prohibitions against impersonation, deception and privacy violations toward one containing specific obligations concerning synthetic content, labelling, provenance, technical measures and rapid grievance redressal.

This article examines the emerging legal framework for deepfakes and digital identity protection, with particular emphasis on India and comparative developments in the European Union and United States.

1. What Is a Deepfake?

deepfake is synthetic or manipulated media generated or altered using artificial intelligence or other computational techniques so that it realistically appears to depict a real person, event or circumstance.

Deepfakes can involve:

  • facial manipulation;
  • face swapping;
  • AI-generated photographs;
  • synthetic videos;
  • voice cloning;
  • lip-sync manipulation;
  • digitally altered speeches;
  • fabricated interviews;
  • simulated public appearances; and
  • other realistic synthetic audio-visual content.

The important legal characteristic is not simply that AI was used.

The concern arises where the resulting content is sufficiently realistic that it may be perceived as authentic or truthful.

India’s 2026 amendments to the IT Rules use the broader concept of “synthetically generated information” (SGI). MeitY describes SGI as audio, visual or audio-visual information artificially or algorithmically created, generated, modified or altered using a computer resource in a manner that appears real, authentic or true and depicts an individual or event in a way that is, or is likely to be perceived as, indistinguishable from a natural person or real-world event.

2. Deepfake Regulation Is Not the Same as AI Regulation

A crucial legal distinction must be made between:

AI regulation and deepfake regulation.

AI regulation addresses broader questions such as:

  • safety;
  • transparency;
  • risk classification;
  • automated decision-making;
  • data governance;
  • cybersecurity; and
  • accountability.

Deepfake regulation focuses more specifically on synthetic representations and their effects on individuals, institutions and society.

A deepfake can therefore implicate several areas of law simultaneously:

AI law + privacy law + criminal law + intermediary regulation + intellectual property + consumer protection + defamation + personality rights.

This makes deepfake disputes inherently interdisciplinary.

3. Why Deepfakes Create a Digital Identity Problem

Traditional identity theft generally involves misuse of information such as:

  • passwords;
  • account credentials;
  • identification numbers;
  • financial information; or
  • other identifying data.

Deepfakes introduce another dimension.

An attacker may not need to obtain a person’s password.

Instead, the attacker can attempt to simulate the person themselves.

For example:

  • a synthetic voice may appear to come from an executive;
  • a manipulated video may appear to show a public figure making a statement;
  • an AI-generated image may falsely depict an individual in a compromising situation;
  • a cloned voice may be used to impersonate someone during a communication.

The legal system must therefore increasingly protect not only identity information, but also identity representation.

4. Digital Identity as a Legal Interest

“Digital identity” is not necessarily a single, universally defined legal right.

Instead, it may consist of several overlapping interests:

4.1 Privacy

Individuals have an interest in controlling the use and dissemination of personal information and representations.

4.2 Reputation

False synthetic content can damage a person’s reputation.

4.3 Personality rights

A person’s name, image, likeness and other attributes may receive legal protection in appropriate circumstances.

4.4 Data protection

Facial images, voice recordings and other information may constitute personal data depending on the applicable legal framework and circumstances.

4.5 Intellectual property

Photographs, recordings, performances and other creative works may be protected by copyright.

4.6 Consumer and fraud protection

Synthetic impersonation may be used to deceive consumers or induce financial transactions.

The resulting legal framework is therefore best understood as a layered protection system rather than a single “deepfake law”.

5. India’s Deepfake Regulatory Framework

India’s legal framework has evolved significantly.

The starting point is the Information Technology Act, 2000, supplemented by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, along with other applicable legislation.

The 2026 amendments to the IT Rules represent a particularly important development.

MeitY stated that the amendments were introduced because AI technologies have made it easier to create realistic synthetic audio, visual and audio-visual material, including deepfakes, which can facilitate misinformation, impersonation, identity fraud, privacy violations and other harms.

6. The 2026 IT Rules and “Synthetically Generated Information”

The 2026 amendments introduced a dedicated framework concerning SGI.

The rules distinguish qualifying synthetic information from ordinary digital editing.

The definition can cover:

  • realistic AI-generated images;
  • AI-generated videos;
  • realistic voice cloning;
  • AI-altered audiovisual material; and
  • other synthetic media that can reasonably appear authentic.

At the same time, the framework excludes certain routine or good-faith forms of editing where the underlying meaning is not materially altered.

MeitY gives examples such as:

  • brightness adjustment;
  • sharpening;
  • compression;
  • ordinary noise reduction;
  • colour correction;
  • transcription; and
  • stabilisation of shaky footage.

Such routine alterations do not automatically become SGI merely because a computer was used.

This distinction is important because regulation that treats every form of digital editing as a deepfake would unnecessarily restrict legitimate creative and technological activity.

7. Deepfakes and the Existing IT Rules

Even before the dedicated SGI framework, the IT Rules already contained restrictions relevant to synthetic impersonation.

The existing framework addressed categories including information that:

  • invades privacy;
  • deceives or misleads;
  • impersonates another person;
  • is patently false and intended to mislead or cause injury; or
  • violates other applicable laws.

The 2026 amendments build upon this framework by expressly addressing synthetic information.

MeitY has clarified that references to unlawful “information” under the Rules include relevant SGI.

This is legally important because a platform cannot necessarily argue that synthetic content falls outside existing intermediary obligations simply because it was generated through AI.

8. New Due-Diligence Obligations for Intermediaries

The 2026 amendments introduce a dedicated due-diligence framework for intermediaries dealing with SGI.

Among other things, intermediaries that provide computer resources capable of facilitating creation, generation, modification, alteration, publication or dissemination of SGI are subject to specified obligations.

The framework requires reasonable and appropriate technical measures aimed at preventing unlawful or prohibited synthetic content.

It also introduces obligations concerning:

  • labelling;
  • provenance information;
  • metadata;
  • identifiers; and
  • user awareness.

This represents a shift from a purely notice-and-takedown model toward a more proactive approach.

9. Labelling of AI-Generated Content

One of the central principles of modern deepfake regulation is:

Users should be able to distinguish synthetic content from authentic content.

India’s 2026 rules require specified SGI to carry prominent labelling and technical provenance mechanisms.

The amended framework provides for labels that make synthetic information identifiable and requires permanent metadata or other appropriate technical provenance mechanisms, where technically feasible, including a unique identifier associated with the relevant intermediary’s computer resource.

This creates two complementary forms of transparency:

Visible transparency

A user should be able to see that content is synthetic.

Machine-readable transparency

Technical metadata or provenance information can help systems identify the synthetic origin of content.

The combination is important because visual labels can be removed or ignored, whereas machine-readable provenance may support automated verification.

10. Significant Social Media Intermediaries

The regulatory burden is greater for certain large or significant social media intermediaries.

MeitY’s 2026 framework includes additional due-diligence obligations for Significant Social Media Intermediaries (SSMIs).

These include mechanisms involving:

  • user declarations;
  • technical verification before publication or display of SGI; and
  • prominent labelling.

The policy rationale is straightforward.

A platform with enormous reach can amplify synthetic misinformation far more rapidly than a small private service.

Therefore, regulatory obligations may reasonably increase with the platform’s scale, reach and systemic impact.

11. Faster Takedown and Grievance Redressal

Speed is particularly important in deepfake cases.

A false image or video can be copied across platforms within minutes.

By the time a traditional legal proceeding begins, the harmful material may already have been:

  • downloaded;
  • reposted;
  • mirrored;
  • altered;
  • circulated through messaging services; or
  • indexed by search engines.

The 2026 amendments therefore tighten certain compliance and grievance timelines.

MeitY specifically describes the amendments as reducing timelines for removal or disabling access and for grievance redressal, including special categories such as nudity and impersonation.

This reflects a broader principle:

Digital harm often requires digital-speed remedies.

12. Deepfakes and Privacy Law in India

Deepfake regulation cannot be analysed independently of privacy law.

The Digital Personal Data Protection Act, 2023 (DPDP Act) defines personal data broadly as data about an individual who is identifiable by or in relation to that data.

It also defines processing broadly to include operations such as collection, storage, adaptation, retrieval, use, sharing, disclosure, dissemination and destruction.

This is potentially relevant to AI systems that process:

  • facial photographs;
  • voice recordings;
  • videos;
  • identity-linked information; and
  • other digital information associated with identifiable individuals.

However, an important legal distinction must be maintained:

Not every deepfake automatically constitutes a violation of the DPDP Act.

The applicability of data-protection law depends upon whether the relevant processing falls within the Act’s scope and whether the statutory requirements and exemptions are engaged.

13. Consent and Digital Identity

Consent is particularly important where a person’s likeness or other personal information is used to create synthetic media.

The DPDP Act states that consent must be:

  • free;
  • specific;
  • informed;
  • unconditional;
  • unambiguous; and
  • given through clear affirmative action.

It must also relate to the specified purpose and be limited to personal data necessary for that purpose.

This raises a significant issue for AI developers.

Consent to use a photograph for one purpose should not automatically be treated as unlimited permission to:

  • create a digital replica;
  • train a facial model;
  • generate synthetic videos;
  • clone a voice; or
  • commercially exploit an individual’s likeness.

The legal validity of such processing must be assessed against the applicable statutory framework and the precise purpose for which the data was obtained.

14. Deepfake, Privacy and the Right to Control One’s Image

Indian constitutional jurisprudence recognises privacy as a fundamental right.

In Justice K.S. Puttaswamy (Retd.) v. Union of India, the Supreme Court recognised privacy as a constitutionally protected right under Article 21.

Deepfake technology adds a new dimension to privacy.

The issue is not simply:

“Who has access to my personal information?”

It can become:

“Who has the technological ability to manufacture a false digital representation of me?”

That distinction may become increasingly important in future Indian litigation.

15. Personality Rights and Digital Likeness

Public figures and celebrities have increasingly sought protection against unauthorised commercial exploitation of their:

  • name;
  • image;
  • likeness;
  • voice;
  • persona; and
  • other distinctive attributes.

Indian courts have recognised aspects of personality and publicity rights through a combination of privacy, passing off and related legal principles.

The Delhi High Court’s decisions involving celebrities have been particularly significant in this developing area.

The growing use of AI makes these rights more important because digital replicas can now be created without requiring the individual to participate in a recording session.

16. AI Voice Cloning and Digital Identity

Voice cloning presents a distinct legal challenge.

A person’s voice can be a powerful identity marker.

An AI-generated voice may potentially be used to:

  • impersonate an individual;
  • falsely attribute statements;
  • create fraudulent communications;
  • damage reputation;
  • manipulate financial transactions; or
  • create misleading commercial endorsements.

The legal analysis may involve:

privacy + personality rights + fraud + passing off + consumer protection + criminal law.

Voice cloning therefore demonstrates why deepfake regulation cannot be limited to visual media.

17. Deepfakes and Criminal Law

Depending upon the conduct involved, deepfake misuse may potentially implicate criminal provisions relating to:

  • cheating;
  • personation;
  • forgery;
  • defamation;
  • obscenity;
  • harassment;
  • stalking;
  • extortion;
  • threats; and
  • privacy violations.

The precise offence depends upon the facts and the applicable statutory provisions.

The introduction of AI does not necessarily create a completely separate category of criminal liability.

Instead, existing criminal law may apply to the underlying unlawful conduct.

The 2026 IT Rules reinforce this principle by expressly treating SGI as falling within references to information in the context of unlawful acts.

18. Non-Consensual Intimate Deepfakes

One of the most serious forms of deepfake abuse involves synthetic intimate imagery.

A person may be falsely depicted in intimate or sexualised content without consent.

The resulting harms can include:

  • reputational damage;
  • harassment;
  • coercion;
  • extortion;
  • emotional distress;
  • social consequences; and
  • long-term digital persistence of the content.

Indian law can potentially engage several legal provisions depending on the facts, including criminal law, IT law, intermediary rules and privacy/personality rights.

The regulatory objective should be especially strong in this category because the harm may be both immediate and difficult to reverse.

19. The U.S. TAKE IT DOWN Act

The United States has also moved toward federal legislation addressing certain forms of deepfake abuse.

The TAKE IT DOWN Act became federal law on 19 May 2025.

The law addresses non-consensual publication of intimate visual depictions and expressly includes certain AI-generated “digital forgeries.” It also establishes a notice-and-removal mechanism for covered platforms.

The legislation is significant because it recognises that AI-generated intimate imagery can create harms comparable to the unauthorised distribution of authentic intimate images.

It also illustrates an important regulatory technique:

criminal prohibition + platform notice-and-removal obligations.

20. The EU AI Act and Deepfake Regulation

The European Union has adopted a particularly explicit approach.

The EU AI Act defines a “deep fake” as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear authentic or truthful.

Article 50 imposes transparency obligations concerning certain AI-generated or manipulated content.

Providers of systems generating synthetic audio, image, video or text content must ensure that outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, subject to the conditions and exceptions in the Regulation.

Deployers of AI systems generating or manipulating deepfake image, audio or video content must disclose that the content has been artificially generated or manipulated.

The rules contain particular treatment for evidently artistic, creative, satirical or fictional works.

21. Comparing India, the EU and the United States

IssueIndiaEuropean UnionUnited States
Deepfake/synthetic content definitionSGI framework under IT RulesExplicit “deep fake” definitionFederal law covers certain digital forgeries
LabellingYes, under 2026 IT Rules for specified SGIYes, under AI ActSector-specific rather than universal
Machine-readable provenanceRequired under specified Indian SGI rules where technically feasibleRequired for AI-generated outputs under specified AI Act provisionsDeveloping through legislation and industry measures
Platform obligationsEnhanced intermediary due diligenceRisk/transparency frameworkNotice/removal for covered intimate imagery under TAKE IT DOWN Act
Privacy/data protectionDPDP Act plus other lawsGDPR and AI Act interactionFragmented federal/state framework
Non-consensual intimate deepfakesMultiple legal routesMultiple legal routesFederal TAKE IT DOWN Act
General deepfake prohibitionContext-dependentTransparency-focused with other restrictionsFragmented and category-specific

The comparison demonstrates that jurisdictions are converging on transparency, provenance and accountability, but they differ substantially in how they allocate responsibility.

22. Deepfakes and Elections

Political deepfakes create a special regulatory challenge.

Synthetic media can falsely depict a candidate:

  • making a statement;
  • endorsing a position;
  • accepting money;
  • behaving improperly;
  • appearing at an event; or
  • making statements that never occurred.

The potential consequences extend beyond individual reputation.

They can affect:

  • electoral integrity;
  • democratic discourse;
  • public trust;
  • national security; and
  • social stability.

The legal response must nevertheless balance these concerns against constitutional protections for:

  • political speech;
  • satire;
  • criticism;
  • artistic expression; and
  • journalism.

A blanket prohibition on synthetic political content could therefore raise significant free-expression concerns.

23. Deepfakes and Freedom of Speech

Deepfake regulation must answer an important constitutional question:

When does synthetic expression become unlawful deception?

Not every manipulated video is harmful.

Deepfakes may be used for:

  • satire;
  • parody;
  • cinema;
  • political commentary;
  • education;
  • artistic expression;
  • historical reconstruction; and
  • accessibility.

A sophisticated regulatory system should therefore distinguish between:

harmful deception and legitimate synthetic expression.

The EU AI Act expressly recognises this concern by providing special treatment for evidently creative, satirical, artistic and fictional content while retaining transparency requirements.

India’s framework similarly distinguishes qualifying SGI from routine and good-faith editing.

24. Provenance: The Future of Deepfake Regulation

One of the most promising regulatory technologies is content provenance.

Provenance systems attempt to preserve information about:

  • who created content;
  • which tool generated it;
  • whether it was modified;
  • when modifications occurred; and
  • what transformations were performed.

The objective is not necessarily to prevent synthetic media.

Instead, it is to make the origin and history of media more transparent.

India’s 2026 SGI framework expressly incorporates provenance-oriented mechanisms such as metadata and unique identifiers where technically feasible.

This could become a major component of future digital identity protection.

25. Why Labelling Alone Is Not Enough

A label saying “AI-generated” is useful, but it cannot solve every problem.

A sophisticated deepfake may be:

  • reposted without its label;
  • screen-recorded;
  • cropped;
  • compressed;
  • modified;
  • uploaded to another platform; or
  • distributed through private channels.

This is why a comprehensive framework should combine:

visible labels + metadata + provenance + detection + rapid takedown + legal accountability.

No single technological solution can guarantee authenticity.

26. The Problem of Deepfake Detection

Deepfake detection itself presents difficulties.

AI-generated content is evolving rapidly.

A detector that performs effectively today may become less reliable as generation technology improves.

This creates a legal risk:

Should a person’s rights depend upon whether an automated detection system correctly identifies a deepfake?

The answer should be no.

Detection technology should support legal decision-making, not replace it.

Courts should consider:

  • technical evidence;
  • provenance;
  • metadata;
  • expert testimony;
  • source records;
  • platform logs; and
  • surrounding circumstances.

27. Evidentiary Challenges in Deepfake Litigation

Deepfake disputes create difficult questions under evidence law.

Suppose a video appears to show a person making a statement.

The court may need to determine:

  1. Is the recording authentic?
  2. Has it been altered?
  3. Was AI used?
  4. Who created it?
  5. When was it created?
  6. Where did the original file originate?
  7. Was metadata preserved?
  8. Has the file been edited or compressed?
  9. Can the alleged speaker establish that they were elsewhere?
  10. Can a technical expert establish synthetic manipulation?

The authenticity of digital evidence may therefore become increasingly contested.

28. Digital Identity Protection and Authentication

The deepfake problem demonstrates the importance of stronger authentication systems.

Digital identity protection may increasingly rely upon:

  • cryptographic signatures;
  • trusted credentials;
  • verified accounts;
  • secure biometric authentication;
  • content provenance;
  • device-level authentication;
  • multi-factor authentication; and
  • secure digital identity frameworks.

However, biometric technologies themselves raise privacy concerns.

A system designed to protect identity can create new risks if it collects excessive biometric information.

Therefore:

Identity security must be balanced with data minimisation and privacy.

29. Digital Identity and the DPDP Framework

The DPDP Act provides an important foundation for regulating digital personal data in India.

The Act applies concepts such as:

  • Data Principal;
  • Data Fiduciary;
  • Data Processor;
  • personal data;
  • processing; and
  • personal data breach.

It also provides rights relating to access, correction and erasure and establishes a regulatory architecture for data protection.

For deepfake governance, this framework may become relevant where personal data is collected or processed for purposes such as:

  • facial recognition;
  • voice modelling;
  • identity verification;
  • AI-generated avatars; or
  • other digital-replica technologies.

The precise applicability must, however, be determined according to the statutory scope and commencement of the relevant provisions.

30. Digital Replicas and Consent

The concept of a digital replica is likely to become increasingly important.

Imagine a company creates a highly realistic digital avatar of an individual that can:

  • look like them;
  • sound like them;
  • speak like them; and
  • perform actions associated with their identity.

The legal question is not simply whether a photograph was copied.

It becomes:

Who controls the commercial exploitation of a person’s digital identity?

Future legal disputes may therefore involve contracts governing:

  • digital avatars;
  • voice licences;
  • AI-generated performances;
  • virtual influencers;
  • digital twins;
  • celebrity replicas; and
  • posthumous digital representations.

31. Liability of AI Developers

AI developers may face liability where they:

  • knowingly enable unlawful impersonation;
  • fail to implement legally required safeguards;
  • ignore foreseeable misuse;
  • design systems specifically for deceptive synthetic content; or
  • fail to comply with applicable regulatory requirements.

However, liability should not automatically attach merely because a general-purpose AI tool can technically be misused.

A legally sound framework should consider:

  • intended use;
  • foreseeability;
  • safeguards;
  • warnings;
  • technical controls;
  • actual knowledge;
  • user conduct; and
  • applicable statutory duties.

32. Liability of Platforms

Platforms occupy a central position because they control distribution.

Their legal responsibilities may include:

  • receiving complaints;
  • responding to lawful notices;
  • implementing detection mechanisms;
  • preserving evidence;
  • removing unlawful material;
  • labelling synthetic content;
  • preventing repeat uploads where required; and
  • providing grievance mechanisms.

India’s 2026 IT Rules significantly strengthen this aspect of intermediary governance for SGI. MeitY expressly describes the amendments as creating stronger due-diligence, labelling, provenance, technical-measure and reporting requirements.

33. Liability of Users

The person who creates or distributes a deepfake may face the most direct legal exposure.

Potentially unlawful conduct includes:

  • impersonation;
  • fraud;
  • harassment;
  • extortion;
  • non-consensual intimate imagery;
  • defamation;
  • deceptive commercial advertising; or
  • unlawful political manipulation.

The use of AI should not itself be treated as a defence.

The key question remains:

What did the person intentionally or negligently do with the technology?

34. The “AI Did It” Defence

A recurring legal problem may be the argument:

“I did not create the deepfake—the AI did.”

This should generally not end the legal inquiry.

AI is a tool.

Where a person intentionally instructs an AI system to impersonate another individual and then distributes the result for fraudulent or harmful purposes, the fact that a machine generated the content does not necessarily eliminate human responsibility.

Similarly, platforms cannot necessarily avoid all obligations by arguing that the content was generated by users.

The law increasingly focuses on conduct, knowledge, control and statutory duties, rather than simply identifying the technology used.

35. Remedies for Deepfake Victims

A victim may potentially require several forms of relief.

35.1 Immediate removal

The first priority is often removal from the platform.

35.2 Injunction

A court may potentially restrain further publication where legal requirements are satisfied.

35.3 Damages

Victims may seek compensation for legally recognised losses.

35.4 Criminal remedies

Where the conduct constitutes an offence, criminal proceedings may be available.

35.5 Reputation protection

Defamation and related remedies may become relevant.

35.6 Identity protection

Personality or publicity rights may provide additional protection, particularly for commercial exploitation.

The most effective framework is therefore one that allows rapid administrative remedies alongside judicial remedies.

36. Challenges in Enforcing Deepfake Laws

Deepfake enforcement faces several practical difficulties.

36.1 Anonymous creators

The person who created the content may use:

  • anonymous accounts;
  • fake identities;
  • foreign platforms; or
  • temporary accounts.

36.2 Cross-border distribution

The creator, platform and victim may be located in different jurisdictions.

36.3 Rapid replication

Removing one copy does not necessarily remove every copy.

36.4 Technical sophistication

Determining whether content is synthetic may require specialised expertise.

36.5 Freedom of expression

Overbroad regulation could suppress legitimate satire, parody or political commentary.

These problems demonstrate that effective deepfake regulation requires both law and technological infrastructure.

37. A Proposed Framework for Digital Identity Protection

A future-ready digital identity framework should contain at least eight components.

Individuals should have meaningful control over high-risk uses of their likeness, voice and identity-linked data.

2. Transparency

Synthetic media should be identifiable where required by law.

3. Provenance

Technical systems should preserve information concerning the origin and modification of content.

4. Accountability

Developers, deployers, users and platforms should have clearly defined responsibilities.

5. Rapid redress

Victims should have accessible and fast removal mechanisms.

6. Evidence preservation

Platforms should preserve appropriate evidence for lawful investigations.

7. Cross-border cooperation

International mechanisms should facilitate enforcement against foreign-based actors.

8. Freedom of expression safeguards

Satire, art, journalism and legitimate political expression should receive appropriate protection.

38. Policy Recommendations for India

India’s 2026 framework is an important step, but several policy questions remain.

38.1 Create greater clarity around personality rights

Indian law would benefit from clearer statutory treatment of:

  • name;
  • likeness;
  • voice;
  • digital replicas;
  • commercial identity; and
  • posthumous identity.

38.2 Establish clear standards for AI provenance

Technical standards should ideally be interoperable across platforms.

38.3 Protect victims through rapid procedures

A victim should not need to pursue lengthy litigation merely to obtain initial removal of an obviously unlawful deepfake.

38.4 Strengthen cross-platform cooperation

Deepfake material frequently moves from one platform to another.

38.5 Preserve evidence

Removal procedures should be designed so that lawful investigations are not frustrated by automatic deletion.

38.6 Maintain safeguards for legitimate expression

Regulation should distinguish deceptive impersonation from satire, parody, artistic expression and legitimate commentary.

38.7 Encourage responsible AI development

Compliance should be designed proportionately so that legitimate AI research and innovation are not unnecessarily restricted.

39. Deepfake Regulation and the Future of Digital Trust

The deepest issue created by deepfakes may be erosion of trust.

If people begin to assume that every photograph, video or voice recording could be artificial, authentic evidence itself becomes harder to trust.

This creates what scholars sometimes describe as the “liar’s dividend”:

A person accused of genuine misconduct may simply claim that authentic evidence is an AI-generated fake.

Therefore, deepfake regulation is not merely about preventing false information.

It is also about preserving confidence in authentic information.

This makes provenance, authentication and reliable evidence increasingly important.

40. Future Legal Developments

The next phase of deepfake regulation is likely to address increasingly sophisticated technologies, including:

  • real-time face replacement;
  • real-time voice cloning;
  • AI-generated digital humans;
  • autonomous avatars;
  • virtual influencers;
  • biometric identity manipulation;
  • AI-generated political communications;
  • synthetic witnesses;
  • digital resurrection of deceased individuals; and
  • AI-generated evidence.

The law will increasingly have to answer a fundamental question:

What does it mean to legally prove that a digital representation is actually attributable to the person it appears to represent?

41. Key Legal Questions for Future Courts

Courts are likely to confront questions such as:

  1. Does a person have an enforceable right over an AI-generated replica of their face?
  2. Is a person’s voice legally protectable against AI cloning?
  3. When does synthetic content amount to impersonation?
  4. What level of knowledge should create intermediary liability?
  5. How should courts authenticate AI-generated evidence?
  6. Can a victim obtain immediate removal without proving the entire underlying case?
  7. How should personality rights interact with freedom of expression?
  8. Who is responsible when a deepfake crosses international borders?
  9. Can AI-generated political content be regulated without violating free speech?
  10. What technical standards should establish provenance?
  11. How should the law treat digital replicas of deceased individuals?
  12. Should AI-generated content always be labelled?
  13. How should synthetic content be treated in criminal investigations?
  14. What remedies should be available when the creator cannot be identified?

These questions will shape the next generation of digital identity law.

42. Conclusion

Deepfakes represent a fundamental transformation in the relationship between identity, technology and law.

Traditional identity protection assumed that a person’s physical characteristics and identifying information could be reasonably controlled. Artificial intelligence has changed that assumption.

A person’s face, voice and apparent actions can now be synthetically reproduced at scale.

The legal response must therefore extend beyond traditional privacy and impersonation rules.

India’s 2026 amendments to the IT Rules are an important development. They introduce a dedicated framework for synthetically generated information, including qualifying deepfakes, with obligations concerning prevention of unlawful synthetic content, labelling, provenance, technical identifiers, user awareness and enhanced due diligence.

The DPDP Act adds another layer by establishing a framework for the processing and protection of digital personal data.

Internationally, the EU AI Act has adopted explicit transparency obligations for deepfakes, while the United States has enacted the TAKE IT DOWN Act addressing certain non-consensual intimate imagery and AI-generated digital forgeries.

Yet regulation alone will not solve the problem.

The future of digital identity protection will depend upon a combination of:

law + technology + provenance + platform accountability + privacy + effective remedies.

The ultimate objective should not be to prohibit synthetic media.

AI-generated content can have enormous legitimate value in art, entertainment, education, accessibility and innovation.

The objective should instead be to ensure that synthetic identity cannot become a tool for deception, exploitation or unlawful appropriation without meaningful accountability.

The central principle for future digital identity law should therefore be:

A person’s digital identity should not become ownerless merely because technology makes it easy to reproduce.

As AI becomes increasingly capable of replicating human appearance, voice and behaviour, protecting digital identity will become one of the central legal challenges of the emerging digital economy.

Frequently Asked Questions

What is a deepfake?

A deepfake is synthetic or manipulated media that uses AI or computational techniques to realistically depict a person, event or circumstance in a way that may appear authentic.

Are deepfakes illegal in India?

Not every deepfake is automatically illegal. However, deepfakes that involve unlawful impersonation, deception, privacy violations, harassment, defamation or other prohibited conduct may attract legal consequences. India’s 2026 IT Rules also establish specific obligations concerning qualifying synthetic information.

What are India’s latest deepfake regulations?

The IT Rules were amended in February 2026 to introduce a dedicated framework for synthetically generated information. The amendments came into force on 20 February 2026 and include requirements concerning prevention, labelling, provenance, technical measures and intermediary due diligence.

What is synthetically generated information (SGI) in India?

Under the amended IT Rules, SGI broadly covers realistic audio, visual or audio-visual information artificially or algorithmically created, generated, modified or altered using a computer resource so that it appears real or authentic and can be perceived as indistinguishable from a real person or real-world event.

Can a person sue someone for creating a deepfake?

Potentially. Depending upon the facts, legal remedies may arise under criminal law, privacy law, intermediary rules, defamation principles, personality rights, consumer law or other applicable legislation.

Does Indian law protect a person’s face and voice from AI cloning?

Protection may arise through multiple legal doctrines rather than one comprehensive statutory “digital likeness right.” Privacy, personality/publicity rights, data protection, passing off and other legal principles may become relevant depending upon the facts.

What is the EU approach to deepfakes?

The EU AI Act imposes transparency obligations on specified providers and deployers of AI systems producing or manipulating synthetic content, including deepfakes.

What is the TAKE IT DOWN Act?

The U.S. TAKE IT DOWN Act, enacted in May 2025, addresses the non-consensual publication of certain intimate visual depictions, including specified AI-generated digital forgeries, and establishes notice-and-removal obligations for covered platforms.

Keywords

Primary Keyword:
Deepfake Regulations & Digital Identity Protection

Secondary Keywords:

  • deepfake regulations
  • deepfake law India
  • deepfake regulation India 2026
  • AI deepfake laws
  • digital identity protection
  • AI impersonation law
  • deepfake privacy law
  • synthetic media regulation
  • synthetic media law India
  • AI identity theft
  • voice cloning law
  • AI-generated identity
  • digital likeness rights
  • personality rights India
  • deepfake legal remedies
  • AI regulation India
  • deepfake laws in India
  • deepfake and privacy
  • AI digital identity protection

Long-Tail Keywords:

  • What are the deepfake laws in India?
  • latest deepfake regulations in India 2026
  • legal remedies against deepfakes in India
  • deepfake and digital identity protection
  • AI-generated impersonation laws in India
  • legal protection against AI voice cloning
  • personality rights and deepfakes in India
  • deepfake privacy laws India
  • IT Rules 2021 deepfake regulations
  • synthetically generated information India
  • AI deepfake regulation under IT Rules
  • legal consequences of creating a deepfake
  • how does Indian law regulate deepfakes?
  • deepfake regulation and freedom of speech
  • AI-generated digital identity legal issues