India’s IT Amendment Rules 2026 Explained: How the New Law Regulates Deepfakes and AI-Generated Content

Quick Summary: On 10 February 2026, the Ministry of Electronics and Information Technology notified the IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, through Gazette Notification G.S.R. 120(E). Effective 20 February 2026, the amendment brings AI-generated content — legally termed “synthetically generated information” — squarely within platform due diligence obligations for the first time. Platforms must now label synthetic media, preserve provenance metadata, and remove the most harmful deepfakes within as little as two hours, or risk losing the safe harbour that has shielded them since 2000.

Key Highlights

What ChangedBefore (2021 Rules)After (2026 Amendment)
AI content statusNot specifically addressedDefined as “synthetically generated information” (SGI)
LabellingVoluntaryMandatory, clear and prominent
ProvenanceNo requirementMetadata/identifiers where technically feasible; cannot be stripped
Takedown windowRoughly 24–36 hours3 hours for ordered removals; 2 hours for non-consensual intimate imagery
Safe harbourPresumed on due diligenceConditional on real-time compliance

Table of Contents 1. Background: Why India Acted Now 2. What Counts as Synthetically Generated Information 3. The New Obligations, One by One 4. The Takedown Clock: Two Hours to Act 5. Safe Harbour on the Line 6. Who Must Comply — Including Foreign Platforms 7. Expert Analysis: A Distribution-Layer Strategy 8. The Criticism: Speed vs. Speech 9. International Perspective 10. Challenges Ahead 11. Future Outlook 12. FAQs 13. Key Takeaways


Background: Why India Acted Now

India has debated AI regulation for years without passing a standalone AI statute. What forced the government’s hand was not abstract policy debate but a flood of very concrete harms: deepfaked celebrities endorsing scams, cloned voices used in extortion calls, and synthetic political content circulating during sensitive electoral periods. The existing IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 were built for a pre-generative-AI internet. They assumed the main problem was hosted content created by humans; they had no vocabulary for content manufactured by machines at industrial scale.

The February 2026 amendment closes that gap. It is widely regarded as the most significant intervention in India’s content governance regime since the 2021 Rules themselves — and it arrived within days of the AI Impact Summit in New Delhi, where the government also unveiled its AI Governance Guidelines built around seven guiding principles, or “sutras”. The sequencing was deliberate. India is signalling that it will govern AI outputs firmly even while its broader AI legislation, including the proposed Digital India Act, remains under development.

A Short Timeline

  • 2000: IT Act enacted; Section 79 creates intermediary safe harbour.
  • 2021: Intermediary Guidelines and Digital Media Ethics Code Rules introduce due diligence and grievance officers.
  • 2023–2025: Deepfake incidents multiply; MeitY issues advisories; DPDP Act and Rules take shape; a draft amendment proposes visible watermarks covering a portion of the frame.
  • 10 February 2026: Amendment Rules notified via G.S.R. 120(E).
  • 20 February 2026: Rules take effect, giving platforms a ten-day runway.

What Counts as Synthetically Generated Information

The amendment’s central innovation is definitional. “Synthetically generated information” covers audio, visual, or audiovisual content that has been created or algorithmically altered using computer tools in a manner that makes it appear real — content a reasonable viewer could mistake for an actual person or an actual event.

Two features of the definition deserve attention. First, it is technology-neutral: it does not name any particular model, tool, or company, which means it will survive several generations of AI development without amendment. Second, it is harm-focused rather than technique-focused. The rules expressly carve out ordinary, good-faith editing — trimming a clip, correcting captions, translating text, improving accessibility, or producing routine documents, presentations and educational material. If your edit does not deceive, you are outside the net. The target is deception, not creativity.

The New Obligations, One by One

Mandatory labelling

Platforms that permit the creation or sharing of synthetic content must ensure it is labelled so that users can immediately recognise it as AI-generated. Here the government showed some flexibility. An earlier draft floated a prescriptive requirement that a watermark occupy a fixed share of the visual frame; the final rules abandon that in favour of a principle-based standard — the label must simply be clear and prominent. That shift matters for product designers, because it allows labelling to be adapted to format (a spoken disclosure in audio, an overlay in video, a tag in feeds) rather than forcing one clumsy visual solution everywhere.

Provenance and metadata

Where technically feasible, platforms must embed permanent provenance markers or metadata that allow the origin of synthetic content to be traced. Crucially, once a label or provenance marker is applied, intermediaries are prohibited from enabling its removal or suppression. India has effectively legislated tamper-resistance into the content pipeline.

User declarations and verification

Users uploading synthetic content must declare it as such, and platforms are expected to deploy reasonable technical measures to verify those declarations. This converts platforms from passive hosts into active authenticators — a genuine philosophical departure from the 2021 framework.

The Takedown Clock: Two Hours to Act

The most operationally demanding change is speed. For serious violations — non-consensual intimate deepfakes, deceptive impersonation, child sexual abuse material and similar unlawful synthetic content — platforms must act within three hours of an authorised notification. For non-consensual intimate imagery reported by a victim, the window compresses to two hours. Compare that with the 24-to-36-hour norms of the earlier regime and the scale of the shift is obvious.

There is a procedural safeguard worth noting: removal directions from law enforcement must be issued in writing by officers of at least Deputy Inspector General rank. That requirement is designed to prevent junior officials from firing off casual takedown demands, and it will likely become an early battleground in any constitutional challenge.

In practice, a two-hour clock cannot be met by a legal team reviewing tickets in the morning. It demands 24/7 trust-and-safety operations, automated detection classifiers, escalation workflows and real-time alerting. Compliance has moved from the legal department into the product architecture itself.

Safe Harbour on the Line

Section 79 of the IT Act has protected intermediaries from liability for user content since 2000, provided they observe due diligence. The 2026 amendment redefines what due diligence means. Miss a takedown deadline, fail to label, or allow provenance data to be stripped, and a platform risks forfeiting safe harbour — exposing it to direct civil and even criminal liability for the underlying content. Virality is no defence; the obligation attaches regardless of how far the content has already spread.

Who Must Comply — Including Foreign Platforms

The rules apply to any intermediary offering services to Indian users or targeting the Indian market, irrespective of where the company is incorporated. Encryption does not excuse compliance, and significant social media intermediaries may face traceability demands in defined circumstances. For global AI companies, generative platforms and content hosts, India is now a jurisdiction where compliance must be engineered into the product before launch, not retrofitted afterwards.

Expert Analysis: A Distribution-Layer Strategy

The design logic here is subtle and, in my assessment, quite deliberate. India has not regulated AI models. It has regulated what happens when AI outputs meet distribution. As Supratim Chakraborty of Khaitan & Co has observed, the rules effectively govern the rules pragmatically govern AI outputs at the distribution layer in the absence of a standalone AI law. The state’s leverage sits with a manageable number of large platforms rather than millions of model developers — enforcement follows the choke point.

This is analytically distinct from the EU AI Act, which classifies and regulates AI systems by risk tier. India’s bet is that most real-world AI harm materialises at the moment of publication, and that publication is where the law can bite fastest. Whether that bet holds for harms that never touch a platform — private voice-clone fraud, for instance — is an open question the Digital India Act will eventually have to answer.

The Criticism: Speed vs. Speech

Digital rights advocates have raised three substantive objections. First, compressed timelines will push platforms toward automated removal with minimal human review, and automated classifiers make mistakes; the predictable result is over-removal of lawful speech, including satire and political commentary that merely resembles synthetic deception. Second, detection technology for AI-generated content is immature, so both false positives and false negatives are inevitable at scale. Third, the compliance burden lands hardest on Indian startups, which must now build watermarking, metadata and monitoring infrastructure that global giants can absorb far more easily.

Supporters answer that a deepfake’s damage is done within hours, sometimes minutes, and that a leisurely takedown regime is functionally no regime at all. Both positions have force. This is a genuine trade-off between velocity of harm and breathing space for speech, and Indian courts will almost certainly be asked to strike the balance under Articles 19(1)(a) and 21.

International Perspective

Globally, India’s move places it among the most interventionist jurisdictions on synthetic media. The EU addresses deepfakes through transparency obligations in the AI Act; the United States remains a patchwork of state statutes; China requires labelling of synthetic content through its deep synthesis provisions. India’s combination — mandatory labelling plus tamper-proof provenance plus two-to-three-hour takedowns backed by safe-harbour forfeiture — is arguably the most demanding package anywhere. Other governments wrestling with AI content proliferation are watching, and India’s condensed takedown windows could well become a template for the Global South.

Challenges Ahead

Three friction points stand out. Enforcement capacity: grievance systems must now operate at ambulance speed, around the clock, in a country generating staggering volumes of content daily. Definitional litigation: the boundary between deceptive SGI and protected creative expression will be contested case by case. And constitutional review: expect writ petitions testing whether two-hour timelines and compelled labelling are proportionate restrictions on speech.

Future Outlook

The 2026 amendment is best read as the opening move of a longer game. The Digital India Act, still in consultation, is expected to bring risk-based classification of platforms and deeper AI-specific provisions; a Private Member’s Bill on AI ethics and accountability introduced in December 2025 signals parliamentary appetite for binding obligations on developers themselves. For now, the message to every platform serving Indian users is unambiguous: label it, trace it, and be ready to take it down before your coffee gets cold.


Frequently Asked Questions

1. What are the IT Amendment Rules 2026? They are amendments to the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, notified by MeitY on 10 February 2026 and effective 20 February 2026, regulating AI-generated content, deepfake takedowns and platform due diligence.

2. What is synthetically generated information (SGI)? Audio, visual or audiovisual content created or algorithmically altered by computer tools so that it appears real — content that could be mistaken for an actual person or event.

3. Are deepfakes now illegal in India? Deepfakes are not banned outright. Unlawful synthetic content — impersonation, non-consensual intimate imagery, fraud — must be labelled where permitted at all, and removed rapidly once flagged. Harmless, clearly labelled synthetic creativity remains legal.

4. How quickly must platforms remove harmful deepfakes? Within three hours of an authorised order for serious unlawful content, and within two hours for reported non-consensual intimate imagery.

5. Do the rules apply to foreign companies? Yes. Any platform serving Indian users or targeting the Indian market must comply, regardless of where it is incorporated.

6. What happens if a platform doesn’t comply? It risks losing safe harbour under Section 79 of the IT Act, opening the door to direct civil and criminal liability, alongside consequences under other applicable laws.

7. Does ordinary photo or video editing count as SGI? No. Good-faith edits — trimming, captions, translation, accessibility improvements, routine documents and educational material — are excluded, provided they do not mislead or create false records.

8. Can AI labels be removed after they are applied? No. Platforms are prohibited from enabling the removal or suppression of labels and provenance metadata once applied.

9. Who can order a takedown? Courts and authorised government agencies; law-enforcement removal requests must be in writing from officers of at least Deputy Inspector General rank.

10. Is this India’s AI law? Not quite. It regulates AI outputs at the platform level. A comprehensive framework — likely through the Digital India Act — is still in the pipeline.


Key Takeaways

India’s IT Amendment Rules 2026 mark the country’s decisive entry into binding AI-content regulation. The framework defines synthetic media in law for the first time, converts labelling and provenance from courtesy into obligation, and compresses takedown windows to hours. Safe harbour, once near-automatic, is now earned continuously through real-time compliance. The rules apply globally to anyone serving Indian users, and they will shape — and be shaped by — the constitutional litigation and the Digital India Act that follow. For platforms, lawyers and policymakers alike, the era of treating AI content governance as optional ended on 20 February 2026.

This article is for general information and does not constitute legal advice. Readers should consult qualified counsel for compliance decisions.

This Post Has One Comment

  1. Clear and very readable explanation of a complicated notification. The comparison with the EU AI Act and China’s deep synthesis rules was helpful for placing India’s approach in context. The takedown clock and conditional safe harbour are going to be the real compliance headache for smaller Indian platforms. Looking forward to your coverage of the Digital India Act when it moves.

Leave a Reply