Deepfakes, AI Cloning and Personality Rights in India: The Legal Position in 2026
India’s legal response to deepfakes changed significantly in 2026. From mandatory labelling of synthetically generated content to a growing body of Delhi High Court orders protecting identity, voice and likeness, AI disputes are moving rapidly from theory into everyday legal practice.

Only a few years ago, deepfakes were discussed largely as a technology problem. In 2026, that description is no longer adequate.
A person’s face can be inserted into a video they never appeared in. A familiar voice can be cloned with remarkable accuracy. An advertisement can appear to carry the endorsement of a public figure who has never seen the product. A fabricated speech can circulate across social media before the person concerned has even become aware of it.
For businesses, creators, public personalities and ordinary individuals, the question is therefore no longer whether synthetic media can create legal problems. The more practical question is: what does Indian law now do when an AI-generated image, video or voice crosses the line?
That question has become especially important in 2026.
In February, the Central Government amended the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 to specifically address “synthetically generated information”, or SGI. The Government has since repeatedly emphasised platform accountability, labelling, traceability and faster action against unlawful AI-generated material. At the same time, The Delhi High Court case is dealing with a growing stream of personality-rights disputes involving AI, deepfakes, cloned identities, and unauthorized digital exploitation.
The result is an important shift in Indian cyber law: AI-generated content is no longer being treated as a future regulatory question. It is already interacting with privacy, reputation, intellectual property, intermediary liability, criminal law and civil remedies.
What Does Indian Law Mean by “Synthetically Generated Information”?
The 2026 amendments introduced a specific definition of synthetically generated information into the IT Rules.
In broad terms, SGI covers audio, visual or audio-visual material that has been artificially or algorithmically created, generated, modified or altered using a computer resource so that it appears real or authentic and depicts an individual or real-world event in a way that may be perceived as genuine.
This matters because the law is concerned not simply with whether artificial intelligence was used, but with the capacity of the resulting material to appear authentic.
The definition also contains sensible exclusions. Routine or good-faith editing, colour correction, compression, noise reduction, transcription, accessibility improvements and certain forms of ordinary document or educational-content preparation are not automatically treated as SGI where they do not materially distort the underlying content or create a false document or record.
That distinction is important.
Using software to improve the brightness of a photograph is very different from making a person appear to endorse an investment scheme they have never heard of. Removing background noise from an interview is different from creating an artificial recording in the interviewee’s voice containing statements they never made.
The law is increasingly concerned with that second category.
The 2026 IT Rules Have Changed the Compliance Landscape
The Information Technology Rules were amended on 10 February 2026, with the SGI framework coming into force shortly afterwards.
For intermediaries that provide computer resources capable of creating, modifying, publishing, transmitting or disseminating synthetically generated content, the rules now impose more specific due-diligence obligations.
Permissible synthetic material is expected to carry a clear indication that it is synthetically generated, together with permanent metadata or another appropriate provenance mechanism to the extent technically feasible. The framework also restricts the suppression or removal of such labels or identifiers.
This represents an important change in approach.
The regulatory focus is moving beyond simply asking platforms to react when unlawful material is reported. The emerging model combines prevention, disclosure, technical traceability and post-publication enforcement.
Significant social media intermediaries face additional obligations. The amended rules require them to obtain declarations concerning whether uploaded material is synthetically generated, deploy appropriate technical measures to assess those declarations and clearly label content identified as synthetic.
For businesses operating digital platforms, AI tools, content-generation services or large user communities, deepfake compliance is therefore becoming a product-design and governance issue, not merely a legal department issue.
The Three-Hour Rule Is Particularly Significant
One of the most practically important developments is the shortened period for acting after certain forms of “actual knowledge” of unlawful information.
MeitY's 2026 FAQ explains that where an intermediary receives actual knowledge through a court order or qualifying reasoned government intimation under Rule 3(1)(d), access to the specified unlawful information must be removed or disabled within three hours. The earlier outer limit was 36 hours.
That is an extraordinary compression of response time.
A platform may no longer have the luxury of treating serious content complaints as something that can simply move through a conventional multi-day internal escalation process.
Internal teams need to know:
who receives the notice,
who determines whether it is legally valid,
who can preserve evidence,
who is authorised to disable content,
and how the organisation records its compliance.
The distinction between a user complaint and an order or notification that triggers a statutory timeline also becomes critical. Not every objection posted on social media automatically activates the three-hour requirement.
That is precisely why businesses need properly designed grievance and escalation mechanisms rather than informal content moderation.
Deepfake Liability Does Not Begin and End with the IT Rules
A common mistake is to assume that India needs one standalone “Deepfake Act” before meaningful legal remedies can exist.
That is not the present position.
AI-generated misuse can engage several existing areas of Indian law depending on what has actually occurred.
A fabricated advertisement may raise questions of passing off, false endorsement or misuse of personality.
A cloned voice used to deceive someone financially may involve impersonation and fraud-related consequences.
A sexually explicit morphed image may involve privacy, dignity and criminal-law concerns.
False statements presented through a fabricated video may raise questions of defamation.
Unauthorised commercial exploitation of a photograph, name, voice or identifiable persona can also intersect with intellectual-property and personality-rights principles.
This means that the legal analysis has to begin with the harm, not simply with the technology used to create it.
The fact that artificial intelligence generated the material does not necessarily determine the cause of action. What matters is what the content does, whose rights it affects, how it is used, whether it deceives, whether it is commercial, whether it damages reputation and whether the applicable platform or intermediary obligations have been followed.
Personality Rights Are Becoming Central to AI Disputes
One of the most visible developments in 2026 has been the growing use of personality and publicity rights in disputes over AI-generated content.
Indian law does not place every aspect of personality rights within one standalone comprehensive statute. Instead, protection has developed through overlapping principles including privacy, dignity, passing off, intellectual property and judicial recognition of an individual’s interest in controlling identifiable aspects of his or her persona.
Those identifiable attributes can include a person’s:
name, image, likeness, voice, signature, appearance, distinctive mannerisms,
and other features closely associated with that individual.
Artificial intelligence makes these rights far more important because modern generative tools can reproduce several of those attributes simultaneously.
A conventional misuse case may involve an unauthorised photograph.
A modern AI case may involve the person’s photograph, recreated voice, facial movements, mannerisms and apparent speech — all combined into one convincing fabricated video.
That is a fundamentally different scale of impersonation.
The Delhi High Court Is Becoming an Important Forum for AI Personality-Rights Cases
The development is particularly visible before the Delhi High Court.
During 2026, the Court has passed interim orders in multiple matters involving alleged unauthorised exploitation of personality attributes through artificial intelligence, deepfakes, morphed content and other digital uses. Recent orders have restrained misuse of names, voices, images, likenesses and other identifiable aspects of individuals' personas, while also directing action against identified online content in appropriate cases.
The trend continued into July and August. The Delhi High Court granted interim protection in matters concerning AI-generated or deepfake content and personality rights, and in August directed takedown of allegedly infringing deepfake and AI-generated material in another personality-rights dispute.
These cases should not be reduced to “celebrity law”.
The underlying questions are broader.
Can someone commercially exploit another person's identity without permission?
What happens when AI makes false endorsement almost indistinguishable from genuine endorsement?
Can a platform be required to remove identified infringing URLs?
How should courts deal with anonymous creators?
What happens when the damage is reputational rather than purely financial?
As generative AI becomes cheaper and more accessible, similar questions may increasingly arise for entrepreneurs, executives, professionals, influencers, academics and ordinary individuals.
Deepfakes and False Endorsements Are a Business Risk Too
Consider a straightforward example.
A company discovers a video circulating online in which its managing director appears to recommend an investment opportunity. The face looks accurate. The voice is convincing. The video contains the company’s branding.
The managing director never recorded it.
That single incident can create several different problems at once.
Customers may be deceived.
The executive’s reputation may be affected.
The company’s trademarks or branding may be misused.
Victims may send money believing they are dealing with an authorised entity.
The fake content may be copied across dozens of platforms before the first version is removed.
For corporate India, deepfake preparedness therefore belongs alongside cybersecurity and reputation management.
Organisations with recognisable founders, senior management, spokespersons or brands should consider how they will identify, document and respond to AI impersonation.
Evidence Preservation Comes Before Takedown
When harmful synthetic content appears online, the natural instinct is to get it removed immediately.
Removal is important, but evidence preservation should not be forgotten.
A disappearing social-media post may later need to be proved.
Useful material can include:
the exact URL,
account or handle details,
date and time,
screenshots,
screen recordings,
the full video or audio file where lawfully available,
advertisements attached to the content,
comments suggesting viewers were deceived,
communications with the platform,
and copies of notices or complaints already sent.
Where financial fraud is involved, transaction records and communications may also become important.
The appropriate evidence will vary from case to case. The larger point is simple: do not destroy the evidence while trying to remove the wrong.
What Should Businesses Using Generative AI Be Reviewing?
The new framework is also relevant to legitimate businesses that use artificial intelligence every day.
AI itself is not unlawful.
A design agency may use generative tools.
A film studio may use synthetic effects.
A company may use AI narration.
An education platform may create virtual instructors.
A brand may generate synthetic advertising material.
The legal issue is responsible deployment.
A sensible 2026 compliance review should therefore examine the organisation’s use of synthetic media across marketing, customer communications and internal processes.
Among the practical questions worth asking are:
- Are AI-generated images, audio and video being properly identified where required?
- Does the organisation retain provenance or source information?
- Has the marketing team obtained necessary permissions before recreating an identifiable person?
- Can staff distinguish ordinary editing from materially synthetic content?
- Does the company have an approval process before publishing AI-generated endorsements or representations?
- What happens if a third-party agency supplies synthetic material?
- Does the contract with that agency address intellectual-property, consent and compliance responsibilities?
- Is there an incident-response process if the company itself becomes the subject of a deepfake?
For larger organisations, these are governance questions.
Leaving them entirely to the social-media team is unlikely to be sufficient.
AI Voice Cloning Deserves Special Attention
Video deepfakes attract attention because they are visually dramatic. Voice cloning may create equally serious risks.
A convincing synthetic voice can be used in a telephone call, audio message, advertisement, investment pitch or internal business communication.
The danger is obvious.
People tend to trust voices they recognise.
An employee may receive what sounds like an instruction from a senior executive. A customer may hear what appears to be a familiar public personality. A relative may receive an emergency call apparently from a family member.
The 2026 SGI framework expressly extends to audio content, not merely images and video. MeitY's official FAQ confirms that synthetic audio, including cloned voice material capable of falsely portraying a person, can fall within SGI.
Businesses should therefore stop treating deepfake risk as purely visual.
The Role of Privacy, Dignity and Reputation
Not every deepfake is created for commercial gain.
Some are created to humiliate.
Others are created to misrepresent political, personal or professional speech.
Some are sexually explicit.
Others are circulated as jokes but have serious consequences for the individual depicted.
Indian legal analysis increasingly recognises that these cases involve more than ownership of an image.
They can implicate dignity, privacy and reputation.
This distinction matters because the harm from synthetic media can occur even where nobody has made money from it.
The Delhi High Court's 2026 orders concerning personality rights have repeatedly dealt with allegations involving distorted, obscene, derogatory or deceptive AI-generated depictions alongside commercial misuse.
What About Satire, Parody and Creative AI?
The answer is not that every AI-generated depiction of a real person automatically becomes unlawful.
Context remains important.
MeitY's FAQ recognises lawful creative uses and explains that routine good-faith editing and certain creative or educational uses are not automatically captured in the same way, while lawful synthetic works may continue subject to applicable labelling and other legal requirements.
Courts may also have to balance personality, privacy and reputation interests against legitimate expression.
That balance will continue to develop.
What is increasingly difficult to defend, however, is synthetic content deliberately designed to deceive audiences into believing a person said, endorsed, performed or participated in something that never occurred — particularly where the content causes measurable reputational, privacy or commercial harm.
The Data Protection Angle Should Not Be Ignored
India's wider digital-law framework is evolving at the same time.
The Digital Personal Data Protection Rules, 2025 were notified in November 2025, with provisions of the DPDP Act and Rules following a phased commencement timetable.
Deepfake disputes and data-protection compliance are not identical subjects. Nevertheless, businesses building AI systems around personal information should consider the two together.
An organisation may ask whether it has permission to publish an AI-generated image.
It should also be asking what data was used to generate, train, customise or distribute that output.
In the coming years, some of the most difficult AI disputes may arise not from the final synthetic image alone, but from the data pipeline behind it.
Where Indian AI Law Appears to Be Heading
India's emerging approach is becoming clearer.
Rather than waiting for a single comprehensive AI statute to solve every problem, regulation is presently developing through several layers:
existing criminal and cyber laws,
the IT Act,
the amended IT Rules,
data-protection law,
intellectual-property principles,
constitutional rights,
contractual obligations,
platform governance,
and court-developed remedies.
Recent commentary has correctly observed that Indian courts are already confronting AI disputes before every aspect of AI governance has been consolidated into a single legislative framework.
That may continue.
The next generation of disputes is likely to test difficult questions concerning consent, digital identity, synthetic endorsements, training data, intermediary responsibility, automated detection, evidence and the boundary between protected expression and unlawful impersonation.
For lawyers, businesses and technology companies, AI law is therefore no longer a niche specialisation sitting somewhere in the future.
It has arrived through existing legal problems wearing a new technological form.
Frequently Asked Questions
Is creating a deepfake illegal in India?
Not every use of synthetic media is automatically illegal. Liability depends on the nature, purpose and impact of the content. A deepfake involving impersonation, privacy invasion, fraud, obscenity, false endorsement, defamation or another unlawful act may engage different legal provisions. The 2026 IT Rules also specifically regulate synthetically generated information and impose obligations on relevant intermediaries.
What is synthetically generated information under the IT Rules?
The amended rules broadly cover artificially or algorithmically created or modified audio, visual or audio-visual material that appears real or authentic and depicts an individual or real-world event in a manner capable of being perceived as genuine. Certain routine good-faith editing and accessibility uses are excluded.
Do AI-generated images and videos have to be labelled in India?
The 2026 framework imposes labelling and provenance-related obligations on intermediaries covered by the relevant provisions. Significant social media intermediaries also have additional declaration, verification and labelling responsibilities.
Can the Delhi High Court order removal of deepfake content?
Courts can grant appropriate interim or final relief depending on the facts and legal rights involved. During 2026, the Delhi High Court has passed several interim orders concerning deepfakes, AI-generated content and alleged infringement of personality rights.
Are personality rights available only to celebrities?
Personality-rights litigation is especially visible in cases involving well-known individuals because their identities often carry significant commercial value. The broader legal interests involved — privacy, reputation, identity and protection against impersonation — are not concerns limited only to celebrities. The availability and scope of a particular remedy will depend on the facts and applicable law.
What should someone do if they discover a deepfake using their identity?
The response depends on the circumstances, but preserving URLs and evidence, identifying the platform, documenting the nature of the misuse and using the relevant platform grievance mechanism can be important initial steps. Where the content involves serious impersonation, fraud, privacy violations, sexual content, threats or other unlawful conduct, additional civil or criminal remedies may need to be considered.
Conclusion
The most important change in 2026 is not that artificial intelligence has suddenly become regulated.
It is that Indian law is becoming more precise about where responsibility sits when synthetic content creates real-world harm.
Platforms now face clearer duties in relation to synthetically generated information. Courts are increasingly dealing with AI impersonation and personality-rights disputes. Businesses are being forced to think about synthetic-media governance, not merely AI adoption. And individuals have begun to confront a difficult reality: their face, voice and digital identity can be reproduced at a scale that older legal disputes rarely contemplated.
The technology will continue to improve.
The legal questions will become more difficult.
For now, the direction is clear: authenticity, consent, traceability and accountability are becoming central principles in the Indian legal response to AI-generated content.
Disclaimer:
This article is intended for general informational and educational purposes only and does not constitute legal advice. Legal rights and remedies depend on the facts and circumstances of each matter and the law applicable at the relevant time.
This article is intended for general information and does not constitute legal advice. The appropriate response depends on the facts and applicable law.