← Resources · July 22, 2026
Science & Technology GS3GS2 5 min read

AI law may cover agent autonomy, deepfakes

What happened
01

Indian policymakers are reportedly considering provisions on AI "agent autonomy" and deepfakes as part of a prospective AI-specific legal framework

02

Such a framework would build on the existing Information Technology Act, 2000 and its subordinate rules rather than function as a wholly separate, standalone statute

03

The reported discussions reflect two distinct regulatory concerns: assigning legal responsibility for actions taken by autonomous AI agents, and curbing the misuse of AI-generated synthetic media (deepfakes)

04

India currently has no enacted, comprehensive AI-specific law; regulation so far has proceeded through amendments to existing IT Rules and non-binding governance guidelines

Static topic 1 of 3 · Science & Technology

India's Layered AI Governance — IT Act 2000, the 2026 IT Rules Amendment, and the Stalled Digital India Act

India regulates AI-related harms today through a patchwork built on the IT Act, 2000, rather than a single comprehensive AI statute. A long-anticipated Digital India Act — meant to replace the IT Act, 2000 entirely — has been under public consultation since 2023 but remains unenacted, leaving sector-specific rule amendments as the primary regulatory tool.

Key Details

  • The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 were issued under Sections 79 (intermediary safe harbour) and 87 (rule-making power) of the IT Act, 2000
  • MeitY notified the IT Rules (Amendment), 2026 on February 10, 2026, effective February 20, 2026: it defines "Synthetically Generated Information" (SGI) in law for the first time, cuts the takedown timeline for flagged unlawful content from 36 hours to 3 hours, and mandates prominent labelling plus permanent provenance metadata for AI-generated content
  • MeitY's India AI Governance Guidelines (released November 2025) under the IndiaAI Mission are explicitly non-binding — officials clarified they carry no legal enforceability and are meant to guide, not regulate
  • The Digital India Act remains under consultation and has not been enacted as a standalone AI/digital law as of mid-2026
Connection to this news

A reported law covering "agent autonomy" would be a step beyond the current amendment-and-guideline approach, since neither the 2026 IT Rules amendment nor the non-binding AI Governance Guidelines create binding liability rules for autonomous AI decision-making specifically.

Static topic 2 of 3 · Science & Technology

Deepfake and Synthetic Media Regulation Under Existing Law

Even without a dedicated AI statute, India already penalises several deepfake-related harms through provisions of the IT Act, 2000, the Bharatiya Nyaya Sanhita, and the Digital Personal Data Protection Act, 2023 — a framework any new AI law would supplement rather than replace.

Key Details

  • IT Act Section 66D (cheating by personation using a computer resource) and Section 66C (identity theft) are the primary provisions currently invoked against deepfake-enabled fraud, each carrying up to three years' imprisonment plus a fine
  • Section 66E penalises capturing, publishing, or transmitting images of a person's private area without consent — the provision most often applied to non-consensual intimate deepfakes — carrying up to three years' imprisonment and a minimum fine of ₹2 lakh
  • Sections 67 and 67A penalise publishing obscene or sexually explicit material, with Section 67A carrying up to five years' imprisonment plus a ₹10 lakh fine
  • The Digital Personal Data Protection Act, 2023 does not mention deepfakes directly, but a person's facial, voice, or biometric data used without consent to generate synthetic content falls within its definition of "personal data," triggering the Act's consent and processing obligations
Connection to this news

The February 2026 IT Rules amendment added platform-level labelling and takedown duties on top of this existing criminal-law patchwork; a reported new law explicitly naming "deepfakes" suggests a further, more codified layer specifically targeting synthetic media rather than relying on general cheating, privacy, and obscenity provisions.

Static topic 3 of 3 · Science & Technology

Liability for Autonomous AI Agents — A New Legal Frontier

"Agentic" AI systems can take multi-step actions — such as initiating transactions or sending communications — without step-by-step human confirmation for each action, raising questions of legal attribution that go beyond earlier, purely conversational AI tools. India currently has no AI-specific tort or liability statute addressing such harms.

Key Details

  • In the absence of a dedicated AI liability law, harms from autonomous AI agents are currently assessed under existing general principles: vicarious liability for the employer or deployer of the AI tool, and platform intermediary liability under Section 79 of the IT Act, 2000 (subject to the safe-harbour conditions and due-diligence obligations set out in the IT Rules)
  • Legal analyses note that, with no codified AI tort regime, such cases currently turn on facts such as foreseeability of harm and the degree of human control retained over the system, rather than a fixed statutory standard
  • A reported provision naming "agent autonomy" specifically would mark India's first attempt at a purpose-built statutory liability framework for harms caused by autonomous AI decision-making, rather than continuing to rely on general tort and intermediary-liability doctrines
Connection to this news

Naming "agent autonomy" as a distinct subject for the prospective law signals a shift from applying pre-existing liability doctrines to AI harms, toward a framework written specifically for autonomous, multi-step AI decision-making — a genuinely new category in Indian regulatory practice.

Key facts & data
  • IT Rules (Amendment), 2026: notified February 10, 2026; effective February 20, 2026
  • Takedown timeline for flagged unlawful content under the 2026 amendment: cut from 36 hours to 3 hours
  • IT Act Section 66D: up to 3 years' imprisonment plus fine (cheating by personation)
  • IT Act Section 66E: up to 3 years' imprisonment plus a minimum ₹2 lakh fine (non-consensual privacy violation)
  • IT Act Section 67A: up to 5 years' imprisonment plus ₹10 lakh fine (publishing sexually explicit material)
  • India AI Governance Guidelines released: November 2025, under the IndiaAI Mission — explicitly non-binding
  • Digital India Act: under public consultation since 2023; not enacted as of mid-2026
Read it? Now lock it in. The quiz for this day’s brief covers this story.
Take the quiz