top of page

Adequately Inadequate: How India's Legal Framework Graciously Permits the Deepfake Epidemic to Flourish Unchecked

  • Writer: Admin
    Admin
  • 2 hours ago
  • 9 min read

Author- Aarnav Tandon, Gujarat National Law University, Silvassa

 


Abstract

This article aims to critically evaluate India's legal framework in addressing the deepfake crisis. Despite the safeguards ensured through the Information Technology Act, 2000, Bhartiya Nyaya Sanhita, 2023 and the Digital Personal Data Protection Act, 2023 , there remains a significant gap in protecting the dignity and privacy of millions of innocent individuals, especially women. The recent crisis of Grok X Ai in 2025-2026 where unregulated sexualizing of images were seen, India’ existing legal provisions’ inadequacy was being reflected in comparison to EU AI Act, China's 2023 regulations, and the US Take It Down Act. This article sharply aims at bringing the Digital social media intermediary platform in substituting their platforms to inherent safety models mechanism.

 

Keywords:

Deepfakes · Artificial Intelligence · India Cyber Law · IT Act 2000 · Digital Personal Data Protection Act 2023 · Bharatiya Nyaya Sanhita · Non-Consensual Intimate Images · Synthetic Media · Grok Deepfakes · AI-generated content · Right to Privacy · K.S. Puttaswamy · Intermediary Liability · Section 79 IT Act · Deepfake Pornography · CSAM · Digital Governance India · Consent in AI · EU AI Act · Deepfake Regulation · Victim-Centric Policy · Fake News · Image Manipulation · Cybercrime India · Free Speech Article 19

I. Introduction

Advanced AI is rapidly blurring the line between ultimate innovation and absolute deception in today's modern world. From financial frauds to setting deceptive political narratives, deepfakes have been a recent phenomenon which is creating authentic illusions. It takes the advantage of machine learning to create hyper realistic dissimulations.[1] The nasty usage of deepfake has consequences beyond say, from garnishing a person's reputation to threatening national security.

II. The Grok Crisis of 2025–2026: A Case Study in Deepfake Harm

The recent crisis of Grok in 2026 of altering and sexualizing the digital images of millions of women on its platform by several malicious users is not just merely an accidental digital upheaval, but a social, moral, technological and a legal concern for our society. It challenges our discrete conscience about how far these digital intermediaries are allowed to express their right to free speech and expression under Article 19(1)(a)[2] which is subject to reasonable restriction under Article 19(2)(b) the Indian Constitution.[3] This donnybrook began in late December 2025 when Elon Musk Ai chatbot Grok (X) led to sexual violation of the individual privacy and dignity,[4] guaranteed from the landmark precedent of K..S Puttaswamy vs. Union of India (2017).[5] This large-scale infringement of data breach was so substantial that in merely 11 days an estimated 3 million images, at an average of 190 per minute, 23 thousand of which was Child Sexual Abuse Material(CSAM), were circulated in the virtual social space, stripping, sexualizing and redistributing the audit content of innocent women through an image editing feature leaving them with no remedy.[6] Even in cases where posts had been removed, images could still be accessed via separate URLs, allowing researchers to assess content that had been removed from X.[7] 

This predicament magnified so much, that on 3rd  June, 2026,  MP Jess Asato of Labour Party of United Kingdom filed a first ever legal complaint in the High Court of London for her non-consensual sexually chloroformed images digitally circulated which is the case of deepfake cybercrime.[8] Her case draws us to an imperative concern of the dilemma between free expression and personal autonomy supported by Hon’ble apex court in the case of Indian Express Newspapers v. Union of India (1985), the Supreme Court held  that free speech must be balanced against the right to reputation and dignity.[9]

III. The Demographic Reality: Who Deepfakes Target

A similar case of deepfake of Hon'ble Finance Minister Nirmala Sitharaman arose when she was portrayed promoting fraudulent investment schemes.[10] In  Titan Industries Ltd. v. Ramkumar Jewellers (2016), Delhi High Court established that unauthorized use of an individual’s identity for gain violates  personal rights and reiterated in restraining websites from exploiting Abhishek  Bachchan’s image, finding that AI-generated misuse.[11] This reflects that it is not an event in isolation but a matter of social concern which is an expanding web of legal challenges targeting xAI’s Grok image tools across multiple countries.

When comparing statistics from 2022 and 2023, an unraveled alarming pattern has been seen. Unbelievably, the percentage increase in the production of deepfake pornographic videos within just one year was a startling 464%. A glaring trend emerges when examining the demographic landscape of deepfake content. The findings reveal that 99% of deepfake pornography features women as the primary subjects, while only 1% of the content features men.[12]

IV. India's Existing Legal Framework: A Patchwork Response

This offence is vaguely covered under the umbrella term in Information Technology Act, 2000 from Section 66C to 66E[13] and Section 356 (Defamation)[14] and 319 (cheating by personation)[15] of Bhartiya Nyaya Sanhita Act, 2023 (23 of 2023). Even the Digital Personal Data Protection Act, 2023 offers a limited protection on prohibition of non-consensual data inviting penalties Section 33.[16] This limited protection involves the data fiduciary to acquire an unconditional, unambiguous consent from the data principal. This requisite of unconditional consent makes the use of data for a purpose for which he/she might not be willing to share the risk of data breaches which might lead to Deepfakes offences. In the case of  Facebook India Online Services Pvt. Ltd. v. CCI[17], whatsapp’s privacy policy of sharing the users data along with Facebook, and non-agreement would lead to termination of its services was held to be unjustifiable and unfair by the Hon'ble Delhi High Court. The Indecent Representation Of Women (Prohibition) Act, 1986, Section 3[18] and Section 4[19] is being seen in egregious violation. This response is oriented towards a reactive model where the intermediaries are held to be liable and observe due diligence in cases of data breaches under Section 79 of the IT Act, 2000[20]. Even though India's IT Rules have joined this legal framework mandating verification through labels and empowering platforms to take action on such mishappenings,[21] but without prior approval, this model is still reactionary in nature.

 

V. Evidentiary and Enforcement Challenges

The deepfakes pose their own predicament. Its detection and proof involves cybercrimes using digital evidence, which often requires complex technical knowledge which becomes even more burdensome due to its new manipulative forms. Steering through this situation requires trained professional experts with exposure to practical experience, which currently our law enforcement lacks.

The nod of the deepfake phenomenon transcends nations, requiring international co-operation to prosecute offenders. For instance, BNS, 2023 requires that every person shall be liable under this Code if he commits an offence within Bharat.[22] However, there is no precision to the point of what exactly constitutes a crime ‘within Bharat’ regarding deepfake-related cybercrimes.

VI. Constitutional Considerations and the Limits of State Censorship

The Supreme Court struck down the 2023 “Fact Check Unit”  rule (which empowered the government to censor “fake” content without clear criteria) as unconstitutional.[23] This underlines the need for precision and due process: any deepfake  regulation must clearly define offences and ensure judicial review to satisfy Article 19.[24] The creation of such a regime requires a careful and sensitive balance between individual interests and legitimate concerns of the State.

VII. The Global Legislative Landscape: What India Must Learn

India's move is being observed towards the trajectory of international trends. EU’s AI Act of 2024[25] and China’s Cyberspace Administration (2023)[26] imposes strict transparency and liability rules, requiring  mandatory labeling of synthetic media and bans illegal deepfakes. The US, federal and state proposals have proliferated the Deepfake Accountability Act 2023[27] and Take It Down Act 2025[28] intending to weed out the malicious, non-consensual explicit deepfakes. In a collective light, these deepfakes highlight their ungovernable impact and may weaken the pillars of democracy.

India's statutory framework has not shown much promise to take measures against this matter in issue. There is not a single unified statute or judicial decree which defines the realm of deepfake in India’s legal jurisdiction. This plethora of legal provisions equates with a spine of patchwork and lacks specificity for Deepfakes related harms. This raises our attention to a need for defining the scope of the offense and providing appropriate retribution on its gravity.

VIII. Recommendations

Consent of an individual whose deepfake is created must be mandatory prior to the deepfake creation. In case of featuring one's image over another individual, consent be taken of both the individuals. It is to be taken in consideration that mere consideration does not also give way to its dissemination and be considered separately. The deepfaked individual must be informed of the prior risk and possible consequences of such generation of similarity, likeness of one's voice or visual.

The Rule 3(2)(b) the IT Rules,[29] compels a 3 hour window removal by the social media platforms, however falls short on providing mental health support to the victims of digital victims. The criminal justice system in India has been criticized for being insensitive towards the victims and their sufferings. The need for victim-centric policies has become imperative to ensure justice is delivered and to provide support and care to the victims. Victim-centric policies aim to empower and support the victims of crimes and provide them with assistance in the process of recovery. These policies recognize the victims' rights to justice and restitution, and their needs for care, support, and protection. It requires an approach that prioritizes victims' needs and experiences over the needs of the offender or the criminal justice system. One of the crucial aspects of victim-centric policies is to ensure that the justice system is responsive to victims' needs.[30]

Conclusion

In light of the above submission, the digital governance needs to be strengthened more and the digital users must be aware of their safety rights. The tech giants should adopt an approach which is not reactionary which takes cognizance of the offense after its committal, rather be developing a safety mechanism to prevent deepfakes and other tech related crimes to an end. It is concluded that the trajectory of digital India must be multi-faceted that results in the social, technological and cultural well-being of humanity and not on the path where technology becomes scourge. The tech-life harmony must be in synchronisation with the 4 C’s of consent, conduct, contact and commerce. India is now standing at a  critical existing legal crossroad. The scattered patchwork of law brings our concern for a dedicated comprehensive Deepfake Regulation Act which provides a meaningful legal recourse and not just creates an illusion of protection.


[1]Shubham Sharma & Arvind Selwal, Potential of Artificial Intelligence in Deepfake Media: From Generation to Detection Mechanisms, State-of-the-Art, and Challenges*, 60 Computer Sci. Rev. 100866 (2026).

[2] India Const. art. 19, § 1(a).

[3] India Const. art. 19, § 2(b).

[4]Every Grok Deepfake Lawsuit and Ban in 2026, Memeburn, https://perma.cc (last visited June 23, 2026).

[5] K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1 (India).

[6]Every Grok Deepfake Lawsuit and Ban in 2026, Memeburn, https://memeburn.com/every-grok-deepfake-lawsuit-and-ban-in-2026 (last visited June 23, 2026).

[7] Grok Floods X with Sexualized Images, Ctr. for Countering Digital Hate, https://counterhate.com/research/grok-floods-x-with-sexualized-images (last visited June 23, 2026).

[8]Labour MP Jess Asato Launches Legal Action over Grok Deepfakes, Computer Weekly, https://www.computerweekly.com/news/366644374/Labour-MP-Jess-Asato-launches-legal-action-over-Grok-deepfakes (last visited June 23, 2026).

[9] Indian Express Newspapers v. Union of India, (1985) 1 SCC 641 (India).

[10]News on AIR, All India Radio, https://share.google/77ipW6yv6fbDk2bly (last visited June 23, 2026).

[11] Titan Industries Ltd. v. Ramkumar Jewellers, (2016) 14 SCC 1 (India).

[12]State of Deepfakes, Security Hero, https://www.securityhero.io/state-of-deepfakes/ (last visited June 23, 2026).

[13] Information Technology Act, No. 21 of 2000, §§ 66C–66E (India).

[14] Bharatiya Nyaya Sanhita, no. 45 of 2023, § 356 (India).

[15] Bharatiya Nyaya Sanhita, No. 45 of 2023, § 319 (India).

[16] Digital Personal Data Protection Act, No. 22 of 2023, § 33 (India).

[17] Facebook India Online Services Pvt. Ltd. v. Competition Commission of India, (2021) SCC OnLine Del 1 (India).

[18] Indecent Representation of Women (Prohibition) Act, No. 60 of 1986, § 3 (India).

[19] Indecent Representation of Women (Prohibition) Act, No. 60 of 1986, § 4 (India).

[20] Information Technology Act, No. 21 of 2000, § 79 (India).

[21]Lexology, Lexology, https://share.google/SN4YQ5COL0dgwHmhR (last visited June 23, 2026).

[22] Bharatiya Nyaya Sanhita, No. 45 of 2023, § 1(3) (India).

[23]Record of Law, Record of Law, https://share.google/Q1qwXVUtEZnn1zWCd (last visited June 23, 2026).

[24] India Const. art. 19

[25] Commission Regulation 2024/1689, Artificial Intelligence Act, 2024 O.J. (L 1689) 1 (EU).

[26] Cyberspace Administration of China, Provisions on the Management of Deep Synthesis Internet Information Services (2023) (China).

[27] Deepfake Accountability Act, H.R. 4364, 118th Cong. (2023).

[28] Take It Down Act, Pub. L. No. 119-___, 139 Stat. ___ (2025).

[29] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, r. 3(2)(b) (India).

[30] Volume IV Issue I | ISSN: 2583-0538 Page: 707 CONCEPT OF VICTIMOLOGY IN INDIAN CRIMINAL JUSTICE ADMINISTRATION


Note - The information contained in this paper is for general informational purposes only. We endeavour to keep all content accurate, updated, and free from any form of misinformation or objectionable material. However, we shall not be responsible for any claims arising out of copyright infringement, plagiarism, or related issues; such responsibility lies solely with the respective authors. If you find any misinformation or objectionable content on this website, please report it to us at: editors.ilw@gmail.com

Comments


bottom of page