← Concept Library · Polity & Governance
Polity & Governance GS 2 In the news 2 times

Deepfakes and Synthetic Media Governance

A deepfake is a fake photo, video or audio clip made with artificial intelligence (AI) that looks or sounds real. It can show a real person saying or doing something they never said or did. The wider term synthetic media covers all content that is created or changed by computers so that it appears real. Governing deepfakes means making rules and tools to label, detect and remove harmful fake content, while still allowing harmless uses like films, satire and education.

Why are deepfakes a problem?

Earlier, making a convincing fake video needed a film studio. Now free apps can do it in minutes. This creates serious harms:

  • Fraud: criminals copy a family member's voice to ask for money, or fake a company boss's video call to order a payment.
  • Sexual abuse and harassment: fake intimate images of women made without consent. This is one of the most common misuses.
  • Misinformation: fake speeches of leaders or fake news clips, especially around elections, riots or wars, which can spread fear or violence.
  • Damage to reputation: fake videos of celebrities or ordinary people used to embarrass or blackmail them.
  • The "liar's dividend": when fakes are everywhere, a guilty person can claim that a real video of them is "just a deepfake". So trust in all evidence falls.

Where did deepfakes come from?

The technology grew out of a type of AI called Generative Adversarial Networks (GANs), introduced by researcher Ian Goodfellow and colleagues in 2014. The word "deepfake" (from "deep learning" + "fake") became popular in 2017, when a user on the website Reddit shared face-swapped videos under that name. Since then, newer AI methods such as diffusion models and voice-cloning tools have made fakes much more realistic and cheaper.

How is a deepfake made?

In a GAN, two AI programs compete like a forger and a detective:

  1. The generator (the forger) creates a fake image.
  2. The discriminator (the detective) checks whether it is real or fake.
  3. Each time the detective catches the fake, the forger learns and improves.
  4. After thousands of rounds, the fakes become so good that even the detective cannot tell them apart.

For voice cloning, an AI needs only a short sample of someone's voice to copy its tone and accent.

How can deepfakes be detected?

No method is perfect, so a mix of tools is used:

  • Detection software looks for tiny errors, like unnatural blinking, mismatched lighting, odd lip movement or strange pixel patterns.
  • Watermarking: the AI tool adds a hidden mark to everything it creates.
  • Provenance metadata: information stored inside the file that records where, when and with which tool it was made. Global standards like C2PA (Coalition for Content Provenance and Authenticity) work on this.
  • Labelling: a visible tag such as "AI-generated" on the content.

How does Indian law deal with deepfakes?

India has no single "deepfake law". Instead, several laws apply depending on the harm.

Under the Information Technology (IT) Act, 2000:

  • Section 66C: identity theft (misusing someone's identity, such as their digital signature or password), up to 3 years in jail and a fine up to ₹1 lakh.
  • Section 66D: cheating by personation using a computer (pretending to be someone else online), up to 3 years in jail and a fine up to ₹1 lakh.
  • Section 66E: violating privacy by capturing or publishing private images of a person without consent, up to 3 years in jail or a fine up to ₹2 lakh, or both.
  • Sections 67 and 67A: publishing obscene or sexually explicit material electronically.
  • Section 79: "safe harbour" for intermediaries (platforms like social media sites). They are not liable for what users post, but only if they follow due diligence rules made by the government.

Under the Bharatiya Nyaya Sanhita (BNS), 2023 (India's criminal code, which replaced the Indian Penal Code from 1 July 2024):

  • Section 319: cheating by personation, up to 5 years in jail, or a fine, or both.
  • Section 356: defamation (harming someone's reputation).
  • Section 353: statements that cause public mischief, such as spreading false reports to cause fear or disorder.

The Digital Personal Data Protection Act, 2023 may also apply, because a person's face and voice are personal data.

The IT Rules and the 2026 amendment on synthetic content

The detailed duties of platforms are in the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, made under the IT Act. The government first sent advisories to platforms on deepfakes in November 2023 and later. Then, after a draft in October 2025, MeitY notified the IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 on 10 February 2026. They came into force on 20 February 2026. The key points:

  • Definition: "Synthetically generated information" means audio, visual or audio-visual content made or changed by a computer so that it looks real, showing a person or event in a way that is, or seems, indistinguishable from reality. The test is how real it looks to an ordinary viewer, not just whether AI was used.
  • What is excluded: routine editing (colour correction, noise reduction, compression), accessibility features like translation, and good-faith educational, research or design material, as long as no false document or record is created.
  • Labelling: synthetic content must carry a prominent, easily noticeable label. Audio must have a spoken disclosure at the start. A fixed rule in the draft that the label must cover 10% of the screen was dropped in the final rules.
  • Provenance: where technically possible, platforms that offer AI tools must embed permanent metadata or a unique identifier. Users must not be able to remove or hide the label or the metadata.
  • Big platforms: "Significant social media intermediaries" (very large platforms) must ask users to declare whether their upload is synthetic, and use technical tools to check that declaration.
  • Faster takedown: content flagged by a court or the government must be removed within 3 hours (earlier 36 hours). Complaints about non-consensual intimate images, including morphed or deepfake nudity, must be acted on within 2 hours (earlier 24 hours). General grievances must be resolved in 7 days (earlier 15 days).
  • Safe harbour: a platform that removes content in line with these rules does not lose its Section 79 protection. A platform that fails to act after it knows about a violation can lose it.

How do other countries deal with deepfakes?

  • European Union: the EU AI Act defines a "deep fake" and, under Article 50, requires those who create deepfakes with AI to disclose that the content is artificially made. AI providers must make generated content machine-readable and detectable. These transparency duties apply from 2 August 2026.
  • China: has had rules on "deep synthesis" services since January 2023, requiring labels on AI-made content.
  • United States: relies mostly on state laws and a federal law against non-consensual intimate deepfakes.

Commonly confused concepts

  • Deepfake vs cheapfake (shallowfake): A deepfake uses AI to create new, realistic content. A cheapfake uses simple editing, like slowing down a video, cutting it, or giving a real clip a false caption.
  • Misinformation vs disinformation: Misinformation is false content shared without knowing it is false. Disinformation is false content spread on purpose to deceive.
  • Watermark vs label: A label is a visible tag that users can see. A watermark is often hidden inside the file and read by software.
  • Intermediary vs publisher: An intermediary (like a social media platform) carries content made by others and gets safe harbour if it follows the rules. A publisher creates or edits content itself and is directly responsible for it.
  • Section 66D IT Act vs Section 319 BNS: both deal with cheating by pretending to be someone else. Section 66D specifically covers doing it using a computer or communication device.

Issues, criticism and the way forward

  • Free speech concerns: Very short takedown times (3 hours) may push platforms to remove content quickly without checking, which could hit satire, parody and political criticism. Article 19(1)(a) protects free speech, with reasonable limits under Article 19(2). The government's view is that fast removal is needed because harmful fakes go viral within hours.
  • Detection is hard: Detection tools often fail on new types of fakes, and watermarks can sometimes be removed. So no single technical fix is enough.
  • Burden on platforms: Checking every upload for synthetic content is costly, especially for smaller Indian companies.
  • Victims need quick help: Many victims, mostly women, do not know where to complain. Police cyber cells need training and tools. The national cybercrime portal (cybercrime.gov.in) and helpline 1930 help, but awareness is low.
  • No single law: Experts are divided. Some want a dedicated deepfake law with clear offences. Others say the present mix of the IT Act, BNS, DPDP Act and IT Rules is enough if enforced well.
  • Way forward: Digital literacy (teaching people to question what they see), common global standards for watermarks and provenance, quicker police response, and working with industry on detection tools.

Concepts to Know

  • Deep learning: A type of AI that learns patterns from huge amounts of data using layered "neural networks", loosely inspired by the human brain.
  • Generative AI: AI that creates new content, such as text, images, music or video, instead of only analysing existing content.
  • Intermediary: A company that stores or carries other people's content, such as social media platforms, messaging apps, internet providers and search engines.
  • Safe harbour: Legal protection that stops a platform from being punished for what its users post, as long as the platform follows the due diligence rules.
  • Metadata: "Data about data". Hidden information in a file, such as when it was made, on which device or with which tool.
  • Significant social media intermediary: A social media platform with a very large number of users in India (the threshold is 50 lakh registered users), which must follow extra duties under the IT Rules, 2021.
  • Morphed image: A photo changed to put someone's face or body into a scene that never happened.
Key details
  • GANs introduced in 2014 (Ian Goodfellow and colleagues); term "deepfake" popular from 2017
  • IT Act 2000: Section 66C (identity theft), 66D (cheating by personation using computer), 66E (privacy violation), 67/67A (obscene/sexually explicit content), 79 (safe harbour)
  • BNS 2023: Section 319 (cheating by personation, up to 5 years), Section 356 (defamation), Section 353 (statements causing public mischief)
  • IT Amendment Rules 2026: notified 10 February 2026, in force 20 February 2026
  • Takedown: 3 hours for court or government orders (was 36 hours); 2 hours for non-consensual intimate imagery (was 24 hours); grievances in 7 days (was 15)
  • Prominent label required; the draft's 10% size rule dropped; permanent metadata where feasible
  • EU AI Act Article 50 transparency duties for deepfakes apply from 2 August 2026
In the news

● Tracked since August 06, 2026 · last seen October 08, 2026 · updates as the daily brief publishes

Related concepts
See it in today’s brief. Daily current affairs with every static concept explained in place.
Read the daily brief