India's New IT Rules 2026: Comprehensive Regulations on Synthetically Generated Information (Deepfakes)
On February 10, 2026, India's Ministry of Electronics and Information Technology issued sweeping amendments to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. These amendments, which take effect on February 20, 2026, establish one of the world's most comprehensive regulatory frameworks for synthetically generated information, commonly known as deepfakes and AI-generated content.
The amendments introduce strict obligations on intermediaries, particularly social media platforms, to detect, label, and prevent the misuse of AI-generated content while balancing legitimate uses of such technology.
Audio-Visual Information
The amendments define this broadly as any audio, image, photograph, graphic, video, moving visual recording, sound recording, or other content, whether created through computer resources or not, with or without accompanying audio.
Synthetically Generated Information (SGI)
The rules define SGI as audio, visual, or audio-visual information that is:
- Artificially or algorithmically created using computer resources
- Appears real, authentic, or true
- Depicts individuals or events in ways indistinguishable (or likely indistinguishable) from natural persons or real-world events
Critical Exemptions
The amendments provide important carve-outs for legitimate activities. Content is NOT considered synthetically generated if it arises from:
1. Routine Editing and Technical Improvements:
- Good-faith editing, formatting, enhancement, technical correction
- Color adjustment, noise reduction, transcription, or compression
- Activities that don't materially alter the substance, context, or meaning of underlying content
2. Professional and Educational Content:
- Creation of documents, presentations, PDF files
- Educational or training materials, research outputs
- Use of illustrative, hypothetical, draft, template-based, or conceptual content
- Where such creation doesn't result in false documents or electronic records
3. Accessibility Improvements:
- Using computer resources solely to improve accessibility, clarity, quality
- Translation, description, searchability, or discoverability
- Without generating, altering, or manipulating material parts of the underlying information
Obligations on All Intermediaries
Enhanced User Notification Requirements
Intermediaries must now inform users at least once every three months (previously no specific requirement) in simple, effective language (English or any language in the Constitution's Eighth Schedule) about:
- Termination Rights: The platform's right to immediately terminate or suspend access for non-compliance, or remove/disable access to non-compliant information
- Legal Liability: Users who violate rules may face penalties under the IT Act or other applicable laws, including:
- Bharatiya Nyaya Sanhita, 2023
- Protection of Children from Sexual Offences Act, 2012
- Representation of the People Act, 1951
- Indecent Representation of Women (Prohibition) Act, 1986
- Sexual Harassment of Women at Workplace Act, 2013
- Immoral Traffic (Prevention) Act, 1956
- Mandatory Reporting: Where violations constitute offences requiring mandatory reporting (like under POCSO), such offences will be reported to appropriate authorities
Special Obligations for Platforms Enabling SGI
Intermediaries offering tools that enable creation, generation, modification, or sharing of synthetically generated information must additionally inform users that:
Violations may result in:
- Immediate removal or disabling of access to the content
- Suspension or termination of user accounts without vitiating evidence
- Disclosure of violating user's identity to victims or their representatives
- Reporting to appropriate authorities for mandatory-reporting offences
Expeditious Action Requirement
When intermediaries become aware of violations (through their own detection, actual knowledge, or complaints), they must take expeditious and appropriate action, including the enforcement measures listed above.
Drastically Reduced Response Times
The amendments significantly tighten timeframes for intermediary action:
Government Orders (Rule 3(1)(d))
- Previous: 36 hours to disable access after government notification
- New: 3 hours to disable access
- Government officers issuing such orders must now be authorized by written order
- For police administration: Officers must be Deputy Inspector General of Police rank or above
Grievance Redressal (Rule 3(2))
For complaints generally:
- Previous: Acknowledge within 24 hours, resolve within 15 days
- New: Acknowledge within 2 hours, resolve within 7 days
For specific serious violations (relating to certain sections of Bharatiya Nyaya Sanhita and POCSO):
- Previous: Remove/disable within 72 hours
- New: Remove/disable within 36 hours
Core Due Diligence for SGI-Enabling Platforms
Prohibited Content Prevention (Rule 3(3))
Intermediaries enabling SGI creation must deploy reasonable and appropriate technical measures (including automated tools) to prevent creation, generation, or dissemination of synthetically generated information that:
1. Contains illegal content:
- Child sexual exploitative and abuse material
- Non-consensual intimate imagery
- Obscene, pornographic, paedophilic content
- Privacy-invasive content, including bodily privacy violations
- Vulgar, indecent, or sexually explicit material
2. Creates false documents:
- Results in creation, generation, modification, or alteration of any false document or false electronic record
3. Relates to dangerous materials:
- Preparation, development, or procurement of explosive materials, arms, or ammunition
4. Falsely depicts persons or events:
- Misrepresents a person's identity, voice, conduct, action, or statement
- Falsely portrays events as having occurred
- In a manner likely to deceive
- With or without the person's involvement
Mandatory Labeling Requirements
For all synthetically generated information NOT covered by the prohibited categories above, platforms must ensure:
Visual Content:
- Prominent labeling ensuring visibility in visual display
- Must be easily noticeable and adequately perceivable
- Should immediately identify content as synthetically generated
Audio Content:
- Prominently prefixed audio disclosure
- Clear indication that content is AI-generated
Technical Requirements:
- Permanent metadata embedded in the content
- Unique identifier to identify the intermediary's computer resource used to create/modify the content
- Technical provenance mechanisms (to the extent technically feasible)
Anti-Tampering Provisions
Intermediaries must NOT enable the modification, suppression, or removal of:
- Labels
- Permanent metadata
- Unique identifiers
Additional Obligations for Significant Social Media Intermediaries
Platforms classified as "significant social media intermediaries" (generally those with over 5 million users in India) face additional requirements:
Pre-Publication Verification System (Rule 4(1A))
Before allowing display, upload, or publication of any information, these platforms must:
1. User Declaration:
- Require users to declare whether content is synthetically generated
2. Technical Verification:
- Deploy appropriate technical measures (including automated tools) to verify declaration accuracy
- Consider the nature, format, and source of the information
3. Mandatory Labeling:
- Where declaration or technical verification confirms content is synthetically generated
- Display clearly and prominently with appropriate label or notice
- Indicate that content is synthetically generated
4. Accountability:
- If platform knowingly permitted, promoted, or failed to act on SGI violations
- Platform deemed to have failed due diligence obligations
- Clear establishment of responsibility for taking reasonable and proportionate technical measures
Enhanced Content Moderation
These platforms must deploy appropriate technical measures (not just "endeavour to deploy") including automated tools to:
- Identify previously removed content
- Prevent re-upload of content depicting:
- Rape
- Child sexual exploitation
- Other content previously removed under government orders
Enforcement and Compliance Framework
Safe Harbor Clarification
The amendments clarify that removal or disabling of access to information (including SGI) through:
- Reasonable and appropriate technical measures
- Automated tools or suitable mechanisms
- In compliance with the rules
...does NOT violate the safe harbor conditions under Section 79(2) of the IT Act.
Scope of Application
Any reference to "information" in contexts of unlawful acts under the rules now explicitly includes synthetically generated information, unless context requires otherwise.
This applies to:
- Rule 3(1)(b) and (d) - Due diligence requirements
- Rule 4(2) and (4) - Additional diligence for significant social media intermediaries
Updated Legal References
References to "Indian Penal Code" throughout the rules have been updated to "Bharatiya Nyaya Sanhita, 2023" reflecting India's new criminal code.
Implications and Analysis
For Technology Companies
Immediate Compliance Burden:
- Platforms have only 10 days (from Feb 10 to Feb 20, 2026) to implement systems
- Requires deployment of sophisticated AI detection and labeling tools
- Need for automated content moderation at scale
Technical Challenges:
- Distinguishing between legitimate editing and prohibited manipulation
- Accurately detecting AI-generated content (an ongoing technical challenge globally)
- Implementing metadata and unique identifier systems
- Balancing automated detection with false positives
Operational Changes:
- Drastically reduced response times (3 hours for government orders, 2 hours for complaint acknowledgment)
- Need for 24/7 monitoring and response capabilities
- Enhanced grievance redressal mechanisms
For Users and Content Creators
Transparency Requirements:
- Must declare when content is AI-generated
- Content will be labeled, potentially affecting reach and credibility
- Greater accountability for misuse
Legitimate Use Protection:
- Clear exemptions for routine editing and professional content creation
- Educational, research, and accessibility uses protected
- Template-based and conceptual content creation allowed
For Digital Governance
Comprehensive Approach:
- Addresses both prevention (technical measures) and disclosure (labeling)
- Balances innovation with safety
- Considers Indian legal framework holistically
International Significance:
- Among the most detailed regulations globally on AI-generated content
- May influence regulatory approaches in other jurisdictions
- Sets precedent for balancing technology innovation with public safety
Potential Challenges
Technical Feasibility
- Current AI detection tools have accuracy limitations
- Adversarial techniques can bypass detection systems
- Metadata can be stripped through various means
- Defining "materially alter" in exemptions may be subjective
Implementation Timeline
- 10-day implementation period is extremely tight
- Global platforms must adapt systems specifically for India
- Smaller intermediaries may struggle with compliance costs
Freedom of Expression Concerns
- Broad prohibition categories may affect legitimate satire, parody, art
- Automated systems may over-censor
- Reduced response times increase risk of erroneous takedowns
Jurisdictional Questions
- Applies to intermediaries operating in India
- Cross-border content and enforcement complexities
- Coordination with international platforms
Comparative Global Context
India's approach is notably more prescriptive than most other jurisdictions:
European Union (AI Act):
- Focuses on transparency obligations
- Risk-based categorization
- Less prescriptive on technical implementation
United States:
- Sector-specific approaches (elections, financial fraud)
- No comprehensive federal framework
- State-level initiatives (California, Texas)
China:
- Similar comprehensive approach
- Strong emphasis on government control
- Strict content moderation requirements
India's framework combines elements of transparency (labeling), prevention (prohibited content categories), and accountability (user declarations and platform verification).
Compliance Roadmap for Intermediaries
Immediate Actions (Before February 20, 2026)
- Legal and Policy Updates:
- Update terms of service, privacy policies, community guidelines
- Draft user notifications in multiple languages
- Establish quarterly notification schedules
- Technical Infrastructure:
- Deploy or enhance AI detection systems
- Implement labeling mechanisms for visual and audio content
- Develop metadata and unique identifier embedding systems
- Create user declaration interfaces
- Operational Systems:
- Establish 24/7 response capabilities for 2-3 hour deadlines
- Train content moderation teams on new rules
- Set up escalation procedures for government orders
- Enhance grievance redressal mechanisms
- Compliance Monitoring:
- Create internal audit systems
- Establish compliance reporting frameworks
- Document due diligence measures
Ongoing Obligations
- Quarterly user notifications
- Continuous technical measure improvements
- Regular compliance audits
- Cooperation with law enforcement for mandatory reporting
- Grievance redressal within stipulated timelines
Conclusion
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 represent a landmark regulatory intervention in the rapidly evolving landscape of artificial intelligence and synthetically generated content.
By establishing clear definitions, comprehensive obligations, and strict timelines, India has positioned itself at the forefront of AI content regulation. The framework attempts to balance multiple competing interests:
- Public safety and prevention of harm
- Innovation and technological progress
- Freedom of expression and creative uses
- Platform accountability and user empowerment
The success of these amendments will depend on:
- Technical feasibility of implementation
- Proportionate enforcement by authorities
- Industry cooperation and innovation in compliance tools
- Public awareness and responsible user behavior
As deepfakes and AI-generated content become increasingly sophisticated and prevalent, India's regulatory approach will serve as an important case study for other nations grappling with similar challenges. The coming months will reveal whether this comprehensive framework can effectively address the risks of synthetic media while preserving the benefits of AI innovation.
Key Takeaways
- Effective Date: February 20, 2026 (10 days from notification)
- Core Innovation: Comprehensive framework for regulating synthetically generated information (deepfakes, AI content)
- Main Obligations:
- Detection and prevention of prohibited AI content
- Mandatory labeling of permissible AI content
- User declarations and platform verification
- Drastically reduced response times
- Protected Activities: Routine editing, professional content creation, educational uses, accessibility improvements
- Prohibited Content: Child exploitation, non-consensual intimate imagery, false documents, dangerous materials, deceptive impersonation
- Timeline Reductions:
- Government orders: 36 hours → 3 hours
- Complaint acknowledgment: 24 hours → 2 hours
- General resolution: 15 days → 7 days
- Serious violations: 72 hours → 36 hours
- Platform Responsibilities: Deploy technical measures, label content, verify declarations, maintain metadata, prevent tampering
- Enforcement: Safe harbor protection maintained for compliant intermediaries; clear accountability for non-compliance
This article is based on the official Gazette Notification G.S.R. 120(E) dated February 10, 2026, published by the Ministry of Electronics and Information Technology, Government of India.