Author: VIDWANSHU CHAUHAN, B.A. LL.B. (4th Year ), City Academy Law College (University of Lucknow)
Abstract
Artificial intelligence has transformed the creation and dissemination of digital content. Among its most concerning applications is the production of realistic synthetic images, videos and audio commonly described as “deepfakes”. Although synthetic media has legitimate applications in education, entertainment, accessibility and creative expression, its misuse can cause serious violations of privacy, dignity, reputation and bodily and sexual autonomy. Women and children are particularly vulnerable to sexualised deepfakes, non-consensual intimate imagery, impersonation, online harassment and other forms of technology-facilitated abuse.
India does not presently regulate every form of deepfake through a single comprehensive statute. Instead, protection is distributed across the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Bharatiya Nyaya Sanhita, 2023, the Protection of Children from Sexual Offences Act, 2012 and, in relevant circumstances, the Digital Personal Data Protection Act, 2023. The regulatory landscape has, however, undergone a significant development through the 2026 amendments to the IT Rules dealing with synthetically generated information.
This article examines whether India’s existing legal framework adequately responds to AI generated gender-based violence. It analyses the intersection of privacy, dignity, sexual autonomy, intermediary responsibility, child protection and technological enforcement. It argues that the principal challenge is no longer merely the absence of legal provisions, but the fragmentation of applicable remedies, difficulties in attribution and evidence, rapid replication of harmful content, and the need to distinguish lawful synthetic expression from malicious synthetic abuse. The article proposes a rights-based and technology-neutral approach that combines stronger platform accountability, accessible remedies, victim-centred procedures and carefully defined legal standards.
Keywords:
Artificial Intelligence, Deepfakes, Gender-Based Violence, Women, Children, POCSO, Information Technology Act, Synthetic Media, Privacy, Digital Rights.
1. Introduction
The rapid development of artificial intelligence has altered the way digital information is created. Images can now be generated or modified with remarkable realism, voices can be replicated from limited recordings, and existing photographs and videos can be manipulated to portray individuals in situations that never occurred.
This technological development has created a new category of harm commonly associated with “deepfakes”. A deepfake may involve the artificial creation or manipulation of audio, visual or audio-visual information so realistically that it may appear authentic. Indian law now expressly addresses the broader category of “synthetically generated information” under the amended Information Technology Rules. The 2026 amendments define SGI in terms of artificially or algorithmically created, generated, modified or altered audio-visual information that appears authentic and portrays an individual or event in a manner likely to be perceived as indistinguishable from reality.
The problem becomes particularly serious when synthetic media is weaponised against women and children. A person’s face may be inserted into sexually explicit material without consent. A child’s photograph may be manipulated into sexualised content. A victim’s voice may be cloned to create fabricated statements. Such material can be distributed through social-media platforms within minutes and may continue circulating even after the original upload has been removed.
The harm is not confined to the falsity of the material. The victim may experience invasion of privacy, humiliation, reputational damage, harassment, threats, social consequences and psychological distress. In the case of children, the problem assumes an additional dimension because the law recognises children as a particularly vulnerable class requiring enhanced protection from sexual exploitation.
India’s response has historically been distributed among different legal instruments. The IT Act addresses, among other matters, identity theft, cheating by personation, violation of privacy and electronically transmitted obscene or sexually explicit material. Sections 66C, 66D, 66E, 67 and 67A may become relevant depending upon the nature of the conduct. Section 67B specifically concerns material depicting children in sexually explicit acts, and therefore has particular significance where synthetic content involves minors.
The emergence of AI-generated abuse therefore raises an important legal question: Can existing laws effectively protect women and children when the harmful content itself may be entirely fabricated?
2. Understanding AI-Generated Deepfakes as a Form of Digital Abuse
Deepfakes are not inherently unlawful. Artificial intelligence can be used for legitimate creative and technological purposes. The legal concern arises when synthetic technology is used to deceive, exploit, threaten, sexually objectify, impersonate or otherwise harm an identifiable individual.
The distinction between ordinary manipulation and harmful synthetic content is particularly important. The 2026 amendments to the IT Rules recognise “synthetically generated information” and introduce obligations concerning declaration, verification and labelling of qualifying synthetic content. Significant social media intermediaries are required, in specified circumstances, to require users to declare whether information is synthetically generated and to deploy appropriate technical measures to verify such declarations. This development reflects an important regulatory shift. Rather than treating AI merely as a technological tool, the regulatory framework increasingly considers the consequences of synthetic content for users and society.
However, synthetic sexual abuse presents a distinct challenge. A person may be shown in an intimate situation despite never having participated in it. The absence of an underlying real event does not necessarily eliminate the victim’s legal injury. The victim’s identity, likeness, reputation, privacy and dignity may still have been exploited.
For women, this can become a form of technology-facilitated gender-based violence. For children, the consequences are potentially even more serious because sexualised representations of minors engage India’s specialised child-protection regime.
3. Constitutional Dimensions: Privacy, Dignity and Personal Autonomy
The constitutional implications of malicious deepfakes are significant.
Article 21 of the Constitution protects life and personal liberty. The Supreme Court’s privacy jurisprudence has established privacy as a constitutionally protected right. In K.S. Puttaswamy v. Union of India, the Supreme Court recognised privacy as an intrinsic component of constitutional liberty and dignity.
The constitutional importance of dignity is particularly relevant to digitally manipulated sexual content. A victim’s right to control intimate aspects of identity and personal life cannot be understood solely as a question of data ownership.
The Supreme Court has also connected privacy and dignity with individual autonomy. In Joseph Shine v. Union of India, the Court emphasised constitutional values of dignity and autonomy while examining gender-based legal structures. The broader constitutional principle is relevant to emerging forms of digital abuse because technological manipulation can interfere with an individual’s ability to control the presentation of their identity.
Deepfake abuse therefore presents a multidimensional rights problem. It may simultaneously implicate:
1. Privacy;
2. Dignity;
3. personal autonomy;
4. Reputation;
5. Equality and non-discrimination;
6. Freedom from sexual harassment; and
7. The right to live with security and dignity.
The challenge for law is to protect these interests without treating all synthetic expression as unlawful.
4. Existing Legal Framework for Protection of Women
4.1 Information Technology Act, 2000
The Information Technology Act remains an important component of India’s cyber-law framework.
Section 66C deals with identity theft, while Section 66D addresses cheating by personation using a computer resource or communication device. These provisions may become relevant where a person uses another individual’s digital identity or impersonates that person for fraudulent purposes. 1
Section 66E deals specifically with violation of privacy. It concerns capturing, publishing or transmitting the image of a person in circumstances violating the person’s privacy, subject to the statutory conditions of the provision.
Sections 67 and 67A address publication or transmission of obscene material and material containing sexually explicit acts, respectively, in electronic form. Their relevance depends upon the actual nature of the content and the statutory requirements.
An important point is that these provisions should not be mechanically applied to every deepfake. A manipulated image may be defamatory, threatening, sexually explicit, privacy invasive or impersonating without satisfying every element of every offence.
4.2 Bharatiya Nyaya Sanhita, 2023
The Bharatiya Nyaya Sanhita, 2023 has been in force since 1 July 2024. Several provisions may become relevant depending upon the facts.
Section 75 addresses sexual harassment and includes, among other conduct, showing pornography against the will of a woman and making sexually coloured remarks.
Section 77 concerns voyeurism and covers watching, capturing or disseminating the image of a woman engaging in a private act in the circumstances specified by the provision. It should therefore be applied carefully to deepfake situations because the statutory language is directed toward particular conduct involving an image of a woman engaging in a private act.
Section 78 deals with stalking and includes monitoring the use by a woman of the internet, e mail or other forms of electronic communication in the circumstances specified by the provision.
Section 79 concerns words, gestures or acts intended to insult the modesty of a woman or intrude upon her privacy.
The BNS therefore provides several possible routes for addressing conduct surrounding digitally facilitated gender-based abuse. Nevertheless, it does not create a standalone offence called “deepfake abuse”. This illustrates the fragmented character of the present framework.
5. Protection of Children under POCSO
The legal position becomes considerably stronger where the victim is a child.
The Protection of Children from Sexual Offences Act, 2012 defines a child as a person below eighteen years and establishes a specialised framework for sexual offences against children. Its provisions cover sexual assault, sexual harassment and the use of children for pornographic purposes.
Section 11 defines sexual harassment of a child. Section 12 prescribes punishment for sexual harassment.
Section 13 deals with the use of a child for pornographic purposes. Section 14 prescribes punishment for using a child for pornographic purposes, while Section 15 addresses storage of pornographic material involving children in the circumstances specified by the provision.
This framework is especially relevant to AI-generated sexual material involving children. The fact that an image is artificially generated does not automatically answer the legal question; the precise facts, statutory definitions and nature of the material must be examined. Indian
authorities have expressly recognised that POCSO and the IT Act together provide mechanisms for dealing with online sexual abuse of children.
The IT Act further strengthens this protection. Section 67B specifically addresses publication or transmission of material depicting children in sexually explicit acts and related forms of online conduct.
The interaction between POCSO and the IT Act demonstrates an important principle: child protection cannot depend upon whether the abuse occurred physically or through a digital environment.
6. Intermediary Responsibility and the 2026 IT Rules Amendments
One of the most significant developments in this area is the strengthening of intermediary obligations.
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 already imposed due-diligence obligations upon intermediaries. Rule 3(2)(b) has particular importance for content involving nudity, sexual acts, impersonation and artificially morphed images.
The Government has stated that, following the 2026 amendments, intermediaries must address specified unlawful synthetically generated information, including deepfakes and AI-generated material. The amendments introduced requirements relating to labelling and traceability of qualifying SGI and stronger technical and due-diligence obligations.
The framework also strengthens obligations concerning unlawful AI-generated material involving children, non-consensual intimate imagery and impersonation. Government information published in August 2026 states that intermediaries are required to take action against specified categories of harmful AI-generated content and that removal timelines have been strengthened in relevant circumstances.
This represents an important movement from a predominantly reactive model toward a combination of prevention, identification, labelling and removal.
However, platform regulation alone cannot solve the problem. Deepfake content may be copied, downloaded, re-uploaded and distributed across multiple platforms. Removal from one service therefore does not necessarily eliminate the harm.
7. The Special Vulnerability of Children
Children face a distinctive risk because their digital identities are increasingly created from photographs and videos shared by parents, schools and social networks. A child’s photograph can potentially become raw material for synthetic manipulation. The consequences may include sexual exploitation, bullying, extortion, impersonation and long-term reputational harm.
The DPDP Act, 2023 recognises a child as an individual who has not completed eighteen years. It also establishes specific provisions concerning the processing of children’s personal data.
At the same time, the DPDP framework should not be presented as a substitute for criminal law. Data protection addresses processing of personal data, whereas POCSO and the IT Act address particular forms of sexual exploitation and cyber conduct. This distinction is essential. The legal response to an AI-generated sexual image of a child may require simultaneous consideration of:
• Child sexual exploitation laws;
• Cybercrime provisions;
• Intermediary obligations;
• Personal-data protection;
• Electronic evidence;
• Victim confidentiality; and
• Rehabilitation and support mechanisms.
8. Evidentiary and Enforcement Challenges
The existence of a legal prohibition does not guarantee effective enforcement. Deepfake investigations present several technical difficulties.
First, attribution may be difficult. A harmful image may be created using an anonymous account, a foreign platform or an automated service. Identifying the person responsible may require preservation of logs, metadata, account information and other electronic evidence.
Second, the evidence itself may be disputed. A victim may need to establish that the content is manipulated while the accused may challenge its authenticity or attribution.
Third, digital content is highly replicable. Even where a platform removes an original post, copies may continue circulating elsewhere.
Fourth, cross-border platforms create jurisdictional and procedural complications.
These problems make electronic evidence particularly important. Investigators must preserve evidence in a manner that permits its authenticity and chain of custody to be demonstrated during proceedings.
The legal framework must therefore be accompanied by technological capacity. Cybercrime investigators, prosecutors and courts require appropriate expertise to distinguish authentic recordings from manipulated or synthetic material.
9. The Problem of Victim-Centred Remedies
Traditional criminal law focuses primarily on identifying and punishing the offender. Deepfake abuse demonstrates why victim-centred remedies are equally important.
For a victim, the immediate priority may be removal rather than eventual conviction. A harmful image can cause significant damage during the period between publication and adjudication.
Accordingly, effective remedies should include:
1. Rapid reporting mechanisms;
2. Prompt preservation of evidence;
3. Removal or disabling of unlawful content;
4. Protection of the victim’s identity;
5. Accessible cybercrime reporting;
6. Coordination between law-enforcement agencies and platforms;
7. Specialised support for child victims; and
8. Appropriate compensation and rehabilitation mechanisms where legally available.
India’s National Cyber Crime Reporting Portal also provides mechanisms for reporting cybercrimes, including crimes against women and children. Government information further indicates that the portal has developed mechanisms relevant to suspicious digital entities and deepfake-related reporting.
The effectiveness of such mechanisms, however, depends upon public awareness and the speed with which complaints are processed.
10. Need for a Balanced Regulatory Approach
The objective should not be to prohibit synthetic media as a category.
AI-generated content has legitimate uses. Overbroad regulation could affect satire, artistic expression, education, research and technological innovation. The appropriate regulatory distinction should therefore focus on harmful use rather than technology itself.
A legally sustainable framework should consider factors such as:
• Consent;
• Sexualisation;
• Impersonation;
• Intent to deceive or harm;
• Involvement of minors;
• Privacy invasion;
• Threats or extortion;
• Dissemination scale;
• Actual or reasonably foreseeable harm; and
• Whether the content is clearly labelled as synthetic.
The 2026 IT Rules amendments already move in this direction by distinguishing synthetically generated information and introducing labelling, verification and technical obligations.
Future legislative development should continue to preserve this distinction.
11. Recommendations
11.1 Develop a Clear Legal Classification
India could consider developing clearer statutory terminology for malicious synthetic sexual content, while avoiding a definition so broad that it captures harmless AI-generated expression.
11.2 Strengthen Rapid Removal Mechanisms
Victims should have simple and accessible mechanisms for reporting non-consensual intimate imagery and synthetic sexual content. Special procedures should be available for children.
11.3 Improve Platform Accountability
Large platforms should maintain effective detection systems, preserve relevant evidence when legally required, and establish dedicated mechanisms for high-risk content involving women and children.
11.4 Build Forensic Capacity
Cybercrime units require trained personnel and technological tools capable of detecting synthetic media and establishing its provenance.
11.5 Strengthen Child-Specific Safeguards
Where children are involved, the response should integrate POCSO, IT law, data protection and child-welfare mechanisms rather than treating the incident merely as an ordinary cybercrime.
11.6 Protect Victim Identity
Legal proceedings, reporting mechanisms and media coverage should ensure that victims are not subjected to secondary exposure or further circulation of harmful material.
11.7 Promote Digital Literacy
Women, children, parents, educational institutions and the general public should be educated about synthetic media, privacy settings, reporting mechanisms and preservation of digital evidence.
12. Conclusion
AI-generated deepfakes demonstrate that technological development can create forms of harm that existing legal categories were not originally designed to address.
India’s legal framework is not without remedies. The IT Act provides provisions dealing with identity theft, impersonation, privacy violations and obscene or sexually explicit electronic material. The BNS contains offences that may apply to particular forms of sexual harassment, voyeurism, stalking and intrusion upon a woman’s privacy. POCSO establishes specialised protection for children against sexual offences and pornography-related exploitation. The IT Rules impose intermediary due-diligence obligations, while the 2026 amendments have introduced a more explicit regulatory framework concerning synthetically generated information.
The central weakness therefore lies not simply in the absence of legislation but in fragmentation, enforcement and technological complexity.
The legal response to deepfakes must recognise that digital harm can be real even when the depicted event never occurred. A fabricated sexual image may be fictional as a matter of content but genuine as a source of privacy, dignity and reputational harm to the person whose identity has been appropriated.
At the same time, regulation must avoid treating all AI-generated material as unlawful. The law should distinguish legitimate synthetic expression from content that exploits, deceives, sexually objectifies or harms identifiable individuals.
For women, this requires stronger recognition of technology-facilitated gender-based violence. For children, it requires an especially protective framework that combines POCSO, cyber law, intermediary regulation and data protection.
The future of digital regulation in India should therefore move toward a victim-centred, technologically informed and rights-compatible framework. The objective should not be to restrict artificial intelligence itself, but to ensure that technological innovation does not become a means through which privacy, dignity, equality and the safety of women and children are undermined.
References / Primary Legal Sources
1. Constitution of India, 1950.
2. Information Technology Act, 2000.
3. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as amended.
4. Bharatiya Nyaya Sanhita, 2023.
5. Protection of Children from Sexual Offences Act, 2012.
6. Digital Personal Data Protection Act, 2023.
7. K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
8. Joseph Shine v. Union of India, (2019) 3 SCC 39.
9. Gazette Notification G.S.R. 120(E), dated 10 February 2026, amending the IT Rules, 2021.
10.Ministry of Electronics and Information Technology, Government of India, materials concerning synthetically generated information and the 2026 IT Rules amendments.
Disclaimer: This article is published for educational and informational purposes only and does not constitute legal advice, legal opinion, or professional counsel. It does not create a lawyer–client relationship. All views and opinions expressed are solely those of the author and represent their independent analysis. Times Law does not endorse, verify, or assume responsibility for the author’s views or conclusions. While editorial standards are maintained, Times Law, the author, and the publisher disclaim all liability for any errors, omissions, or consequences arising from reliance on this content. Readers are advised to consult a qualified legal professional before acting on any information herein. Use of this article is at the reader’s own risk.









