A Lok Sabha reply lays out India's deepfake legal architecture: IT Act 2000 provisions (identity theft S.66C, impersonation S.66D, obscene content S.67/67A, blocking orders S.69A), BNS 2023 (public mischief S.353, organised cybercrime S.111), and IT Rules 2021 obligating intermediaries to prevent deepfake/impersonation content.
A 10 February 2026 IT Rules amendment mandates clear labelling/traceable metadata for AI-generated content and slashes takedown timelines — from 36 hours to 3 hours for unlawful content on valid intimation, and to as little as 2 hours for sensitive categories like non-consensual intimate imagery.
13 Responsible AI projects approved for deepfake detection (e.g. 'Saakshya' by IIT Jodhpur & IIT Madras) under the IndiaAI Mission's Safe & Trusted AI pillar; CERT-In ran 10 AI-threat cyber exercises (June-July 2026, 1,470 participants from 345 organisations) and ISEA awareness workshops reached 11.37 lakh+ people via 6,650 sessions.
Covers identity theft, impersonation, obscene/sexual content, blocking orders and intermediary takedown notices
Penalises public mischief via false/misleading statements and organised cybercrime, applicable to deepfake misuse
Casts due-diligence obligations on intermediaries; mandates AI-content labelling, faster takedowns, and additional obligations for Significant Social Media Intermediaries (50 lakh+ users in India)
National nodal agency for cybersecurity incident response; issues AI-threat advisories, runs AI-driven threat detection and exercises
Handle user appeals against intermediary grievance-officer decisions (via gac.gov.in), ensuring content-moderation accountability
GS Paper 2/3 > Cyber Law, AI Governance, Internal Security
Very high — AI/deepfake regulation is one of the fastest-evolving current-affairs areas
Significant Social Media Intermediary — a platform with 50 lakh+ registered Indian users, subject to additional IT Rules obligations
The IT Rules' formal term for AI-generated/deepfake content, now requiring labelling and traceable metadata