Skip to Content

The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026: A Comprehensive Analysis

Chapter 1: Historical Context and Legislative Evolution

1.1 The Regulatory Journey

The regulation of digital intermediaries in India has evolved through distinct phases. The Information Technology Act, 2000, established the foundational framework, with Section 79 providing conditional safe harbor protection to intermediaries. The Information Technology (Intermediary Guidelines) Rules, 2011, outlined basic due diligence requirements, focusing primarily on prohibited content categories and takedown mechanisms.

The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, marked a paradigm shift. These rules introduced differentiated obligations based on the size and nature of intermediary operations, established grievance redressal mechanisms, and imposed specific requirements on social media platforms and digital news publishers. The framework recognized that intermediaries are not mere passive conduits but active participants in the digital information ecosystem.

1.2 The Catalysts for Amendment

Several factors necessitated the 2026 amendments. The exponential advancement in generative artificial intelligence technologies, particularly large language models and synthetic media generation tools, created unprecedented challenges. Deepfake videos of political figures making inflammatory statements proliferated during election periods. Synthetic audio recordings were weaponized for financial fraud. Non-consensual intimate imagery created through artificial intelligence devastated victims' lives.

International developments also influenced the regulatory approach. The European Union's Artificial Intelligence Act introduced comprehensive provisions for synthetic media labeling. The United States witnessed state-level legislation targeting deepfakes in electoral contexts. China had already implemented strict deepfake regulations since 2019. India's amendments represent a synthesis of these approaches, adapted to the country's constitutional framework and technological realities.

1.3 Commencement and Applicability

The Amendment Rules came into force on February 20, 2026, providing intermediaries with a ten-day implementation window. This brief transition period reflects the urgency with which the government viewed the regulatory gap. The rules apply to all intermediaries operating in India, regardless of their place of incorporation or server location, consistent with the territoriality principles established in the parent 2021 Rules.

Chapter 2: Defining the Synthetic: Key Definitional Amendments

2.1 Audio, Visual, and Audio-Visual Information

The amendments introduce a foundational definition through the insertion of clause (ca) to Rule 2(1). The term "audio, visual or audio-visual information" encompasses any audio, image, photograph, graphic, video, moving visual recording, sound recording, or other audio, visual, or audio-visual content.

This definition possesses several critical characteristics. First, it is technologically neutral, capturing content regardless of the specific format or codec employed. Whether the content is an MP3 audio file, a JPEG image, or an MP4 video is immaterial; all fall within the definitional scope.

Second, the definition explicitly includes content "with or without accompanying audio." This clarification ensures that silent videos and standalone images receive the same regulatory treatment as multimedia content, preventing potential loopholes.

Third, and most significantly, the definition extends to content "created, generated, modified or altered through any computer resource." This language establishes that the regulatory framework applies not only to entirely synthetic content but also to authentic content that has been digitally manipulated. The breadth of this provision is intentional, reflecting the reality that the line between creation and modification is often indistinct in digital media production.

2.2 Synthetically Generated Information: The Core Definition

Clause (wa), also inserted into Rule 2(1), introduces the central concept of "synthetically generated information." This provision warrants detailed analysis, as it forms the cornerstone of the entire regulatory framework.

2.2.1 The Positive Elements

Synthetically generated information is defined as audio, visual, or audio-visual information possessing four essential characteristics:

First, the content must be "artificially or algorithmically created, generated, modified or altered using a computer resource." This element captures the technological genesis of the content. The use of the disjunctive "or" establishes that content need only satisfy one of these verbs-creation, generation, modification, or alteration-to potentially qualify as synthetic.

The terms "artificially" and "algorithmically" are deliberately inclusive. "Artificial" creation encompasses rule-based systems, parametric generation, and procedural content creation. "Algorithmic" creation includes machine learning models, neural networks, and other data-driven approaches. Together, these terms ensure the definition remains relevant as technology evolves.

Second, the content must appear "real, authentic or true." This subjective element introduces a perception-based standard. The inquiry is not whether the content is actually real but whether it appears to be so. This formulation recognizes that the harm from synthetic media arises not from its synthetic nature per se but from its capacity to deceive.

Third, the content must "depict or portray any individual or event." This limitation focuses the definition on representational content. Abstract synthetic art or purely fictional animated characters that do not purport to depict real individuals or events fall outside the definition's scope.

Fourth, the depiction must be "indistinguishable from a natural person or real-world event," or "likely to be perceived as" such. This element establishes the deception threshold. Content need not be perfectly indistinguishable; likelihood of perception as real suffices. This formulation addresses the reality that even imperfect synthetic media can deceive, particularly when viewers are not predisposed to skepticism.

2.2.2 The Negative Elements: Critical Exemptions

The definition's proviso contains three crucial exemptions, collectively delineating the boundary between regulated synthetic media and permissible digital content manipulation. These exemptions reflect a sophisticated understanding that not all algorithmically generated or modified content poses deception risks.

Exemption (a): Routine or Good-Faith Editing

The first exemption shields "routine or good-faith editing, formatting, enhancement, technical correction, colour adjustment, noise reduction, transcription, or compression that does not materially alter, distort, or misrepresent the substance, context, or meaning of the underlying audio, visual or audio-visual information."

This provision recognizes that contemporary media production inherently involves digital manipulation. Every photograph captured on a smartphone undergoes computational photography processes-noise reduction, dynamic range optimization, color balancing. Every video conference call employs background blurring, lighting enhancement, and audio noise suppression. To regulate such ubiquitous processing as "synthetic" would render the definition unworkable.

The exemption contains both positive and negative elements. Positively, it enumerates specific permissible operations: editing, formatting, enhancement, technical correction, color adjustment, noise reduction, transcription, and compression. This list, while illustrative rather than exhaustive, provides concrete guidance.

Negatively, the exemption conditions itself on non-alteration of "substance, context, or meaning." These three terms create a materiality threshold. "Substance" refers to the essential content-what is depicted. "Context" encompasses the circumstances, setting, and relationships between elements. "Meaning" addresses the message or interpretation conveyed. Manipulation that preserves all three escapes regulation.

The qualifier "routine or good-faith" adds an intentionality dimension. "Routine" suggests standard practice, accepted workflows, and non-exceptional processing. "Good-faith" imports a subjective honesty requirement, excluding manipulations intended to deceive even if technically minor.

Consider illustrative applications. A journalist brightening an underexposed photograph of a protest falls within the exemption-the enhancement is routine, good-faith, and preserves substance, context, and meaning. Conversely, selectively darkening a photograph to make a subject appear more menacing, while technically a color adjustment, materially alters meaning and lacks good faith. The latter constitutes synthetically generated information subject to regulation.

Exemption (b): Document Creation and Presentation

The second exemption addresses "routine or good-faith creation, preparation, formatting, presentation or design of documents, presentations, portable document format (PDF) files, educational or training materials, research outputs, including the use of illustrative, hypothetical, draft, template-based or conceptual content."

This provision responds to the reality that generative AI increasingly assists in content creation for professional, educational, and research purposes. Large language models draft email responses, generate presentation outlines, and create illustrative diagrams. Image generation models produce conceptual artwork for business presentations and educational materials.

The exemption recognizes several content categories as inherently non-deceptive: documents, presentations, PDFs, educational materials, and research outputs. These formats typically appear in contexts where viewers understand they are consuming prepared, potentially AI-assisted content rather than unmediated reality documentation.

The inclusion of "illustrative, hypothetical, draft, template-based or conceptual content" is particularly significant. It acknowledges that AI-generated content often serves as a starting point, a conceptual visualization, or an illustrative example rather than a representation of actual events or real individuals.

However, the exemption contains a critical limitation: "where such creation or presentation does not result in the creation or generation of any false document or false electronic record." This negative condition prevents the exemption from shielding fraudulent document creation. Using AI to generate a fake university degree certificate or a falsified legal contract remains regulated synthetically generated information, regardless of the document format.

The boundary between exempt and regulated content can be subtle. A business presentation using AI-generated conceptual images of a proposed building design falls within the exemption-the images are clearly illustrative and hypothetical. An AI-generated image presented as an actual photograph of the completed building crosses into regulated territory-it falsely represents a real-world state of affairs.

Exemption (c): Accessibility and Quality Improvements

The third exemption protects "the use of computer resources solely for improving accessibility, clarity, quality, translation, description, searchability, or discoverability, without generating, altering, or manipulating any material part of the underlying audio, visual or audio-visual information."

This provision addresses the critical role of AI in making content accessible and usable. Automated speech-to-text transcription makes audio content accessible to deaf individuals. AI-powered translation makes content available across language barriers. Image upscaling improves quality without altering content. Automated alt-text generation enhances searchability and accessibility for visually impaired users.

The exemption lists specific improvement categories: accessibility, clarity, quality, translation, description, searchability, and discoverability. Each addresses a legitimate enhancement purpose that serves user needs without creating deception risks.

The critical constraint is "without generating, altering, or manipulating any material part of the underlying" content. The term "material part" creates a substantiality threshold. Adding searchable metadata to an image does not alter any material part. Translating audio into another language may technically alter the content but preserves all material parts in the new language.

Consider edge cases. AI-powered video upscaling from standard definition to high definition improves quality without materially altering content-permitted. AI-based frame interpolation that synthesizes intermediate frames in slow-motion video may technically generate new frames but preserves all material parts of the original-likely permitted. AI that "restores" damaged historical footage by synthesizing missing portions generates material parts not present in the original-likely regulated.

2.3 Interpretive Clarifications

The amendments add two critical sub-rules to Rule 2, providing interpretive guidance.

2.3.1 Rule 2(1A): Incorporation of Synthetic Information in Unlawful Content References

Sub-rule (1A) clarifies that "any reference to 'information' in the context of information being used to commit an unlawful act" includes synthetically generated information "unless the context otherwise requires."

This provision addresses a potential interpretive gap. The 2021 Rules contain numerous references to "information" in contexts such as "information that is grossly harmful" or "information that is defamatory." Without this clarification, an argument could be made that these provisions, predating the synthetic information amendments, do not apply to AI-generated content.

Sub-rule (1A) forecloses that argument through a simple but powerful default rule: synthetic information is information. All prohibitions, obligations, and procedures applicable to information generally apply equally to synthetic information unless specific context indicates otherwise.

The qualifier "unless the context otherwise requires" provides necessary flexibility. In contexts where the distinction between synthetic and authentic information is material-such as evidence authentication procedures-the context may require treating them differently.

2.3.2 Rule 2(1B): Preservation of Safe Harbor Protection

Sub-rule (1B) addresses a critical legal concern: whether compliance actions might paradoxically vitiate safe harbor protection. Section 79(2)(a) of the IT Act conditions safe harbor on the intermediary's role as a "mere facilitator" that does not "initiate, select or modify" content. A literal reading might suggest that actively removing content or deploying automated filtering constitutes prohibited "selection" or "modification."

Sub-rule (1B) dispels this concern through explicit clarification: "the removal of, or disabling of access to, any information, including synthetically generated information, data or communication link, by an intermediary in compliance with these rules" does not violate Section 79(2) conditions.

This provision extends beyond mere removal to encompass "deploying reasonable and appropriate technical measures, including automated tools or other suitable mechanisms" that result in content removal or access disablement upon "becoming aware of any violation." This language affirmatively authorizes proactive moderation technologies-content filtering algorithms, hash-matching systems, AI-based content classification-without jeopardizing safe harbor protection.

The significance of this clarification cannot be overstated. It transforms the legal landscape from one where intermediaries might fear liability for both action (removing content) and inaction (hosting violative content) to one where compliance-oriented action receives explicit legal protection. This provision incentivizes the very proactive moderation that the amendments seek to promote.

Chapter 3: Enhanced Intermediary Obligations for User Notification

3.1 The Periodic Notification Requirement

The amendments substantially revise Rule 3(1)(c), transforming a one-time notice obligation into a recurring duty. Intermediaries must now "periodically inform" users "at least once every three months" about their rights, obligations, and the potential consequences of violations.

3.1.1 Rationale for Periodic Notice

The shift from static to periodic notification reflects several behavioral insights. First, user attention is ephemeral. A single notice during account creation, when users are focused on accessing services rather than reading terms, achieves minimal effective communication. Periodic reminders ensure ongoing awareness.

Second, platform rules evolve. As intermediaries update their content policies, moderation practices, and technical measures, users must receive notice of these changes. Quarterly notifications provide a mechanism for communicating material updates.

Third, repetition reinforces compliance. Behavioral economics demonstrates that periodic reminders of consequences significantly influence behavior. Quarterly notifications create touchpoints for reinforcing platform norms and legal requirements.

3.1.2 Communication Channels and Format

The amended rule permits notification "through its rules and regulations, privacy policy, user agreement, or any other appropriate means." This flexibility acknowledges the diversity of platform architectures and communication methods.

"Other appropriate means" could include in-app notifications, email communications, dashboard messages, or even prominent homepage notices. The critical requirement is effectiveness-the chosen means must actually reach users and communicate the required information.

The rule mandates communication "in a simple and effective manner" in "English or any language specified in the Eighth Schedule to the Constitution." The "simple and effective" requirement prohibits dense legalese or deliberately obfuscatory language. The multilingual requirement ensures accessibility across India's diverse linguistic landscape. The Eighth Schedule includes twenty-two languages, enabling communication with the vast majority of Indian users in their preferred language.

3.1.3 Required Notice Content: General Provisions

The amended clause (c) requires intermediaries to inform users of three core matters applicable to all content, whether synthetic or authentic.

Sub-clause (i): Enforcement Authority

Intermediaries must notify users that "in case of non-compliance with such rules and regulations, privacy policy or user agreement, by whatever name called," the intermediary possesses the authority to:

  • Terminate or suspend user access or usage rights to the computer resource immediately
  • Remove or disable access to non-compliant information
  • Execute both actions simultaneously

This provision establishes transparency about platform enforcement powers. The phrase "by whatever name called" prevents evasion through creative naming of governing documents. Whether labeled "Community Standards," "Content Policy," or "Terms of Service," all platform rules fall within scope.

The inclusion of "immediately" merits attention. It clarifies that intermediaries need not provide advance warning or extended appeals processes before enforcement action. While natural justice principles and platform policies may voluntarily incorporate such procedural protections, the rules themselves impose no delay requirement for clear violations.

Sub-clause (ii): Legal Liability Warning

Users must be informed that non-compliance involving content creation, generation, modification, alteration, hosting, displaying, uploading, publishing, transmitting, storing, updating, sharing, or otherwise disseminating information "in contravention of any law for the time being in force" may subject them to "penalty or punishment under the provisions of the Act or any other applicable law."

This comprehensive verb list captures the full content lifecycle, foreclosing arguments that particular actions fall outside the warning's scope. The reference to "any law for the time being in force" is deliberately expansive. Platform violations may simultaneously constitute offenses under the Information Technology Act, the Bharatiya Nyaya Sanhita (India's criminal code), intellectual property laws, data protection legislation, or sector-specific regulations.

The distinction between "penalty" (typically civil or administrative monetary sanctions) and "punishment" (typically criminal sentences) encompasses the full spectrum of legal consequences. Users must understand that content violations are not merely platform policy matters subject to account suspension but potential legal violations subject to governmental enforcement.

Sub-clause (iii): Mandatory Reporting Obligation

Where violations "relate to the commission of an offence under any law for the time being in force, such as the Bharatiya Nagarik Suraksha Sanhita, 2023 or the Protection of Children from Sexual Offences Act, 2012, which requires such offence to be mandatorily reported," users must be informed that "reporting of such offence to the appropriate authority in accordance with the provisions of the applicable law" will occur.

This provision serves multiple functions. First, it creates transparency about platform cooperation with law enforcement. Users understand that platforms are not zones of anonymity where serious criminal conduct remains unreported.

Second, the specific mention of the Bharatiya Nagarik Suraksha Sanhita (the criminal procedure code) and POCSO Act (child sexual exploitation law) highlights offenses of particular governmental concern. While the language "such as" indicates these are illustrative rather than exhaustive examples, their specific mention signals priority enforcement areas.

Third, the reference to offenses "which require such offence to be mandatorily reported" addresses laws that impose affirmative reporting duties on persons who become aware of certain crimes. POCSO Section 19, for instance, mandates reporting of child sexual abuse by anyone with knowledge. This provision confirms that intermediaries will fulfill such legal obligations, and users should have no expectation that serious criminal content will remain unreported.

3.2 Additional Notifications for Synthetic Content Platforms

Clause (ca), newly inserted, imposes supplementary notification obligations on intermediaries "referred to under sub-rule (3)-that is, those whose computer resources enable, permit, or facilitate creation, generation, modification, alteration, publication, transmission, sharing, or dissemination of information as synthetically generated information.

This targeted approach recognizes that not all intermediaries facilitate synthetic media creation. A conventional web hosting service that merely stores static HTML files need not provide synthetic media warnings. Conversely, platforms offering AI image generation, deepfake creation tools, or voice cloning services must provide enhanced notices.

3.2.1 Legal Liability for Synthetic Content Creation

Sub-clause (i) of clause (ca) requires informing users that "directing, instructing or otherwise causing the computer resource of the intermediary for creation, generation, modification, alteration, publication, transmission, sharing, or dissemination of information as synthetically generated information in contravention of sub-clause (i) of clause (a) of sub-rule (3)" may attract penalties under numerous statutes.

This provision establishes clear causal responsibility. The verbs "directing, instructing, or otherwise causing" capture the various ways users might employ platform tools. Whether through direct operation of generation tools, API calls, or indirect instruction of automated systems, users who cause prohibited synthetic content creation face potential liability.

The reference to "contravention of sub-clause (i) of clause (a) of sub-rule (3)" incorporates the substantive prohibitions on synthetic content examined in detail below. In essence, this provision warns users that creating the categories of prohibited synthetic content through platform tools violates law.

The enumerated statutes warrant individual examination:

The Information Technology Act, 2000: The foundational cybercrime statute, containing offenses such as unauthorized access (Section 66), identity theft (Section 66C), and publishing obscene content in electronic form (Section 67). Synthetic media may violate multiple provisions, particularly when used for impersonation or sexually explicit content.

The Bharatiya Nyaya Sanhita, 2023: India's comprehensive criminal code, replacing the Indian Penal Code. Relevant offenses include defamation (Section 356), forgery (Sections 336-340), personation (Sections 318-320), criminal intimidation (Section 351), and sexual harassment (Section 75). Synthetic media frequently facilitates these traditional crimes through technological means.

The Protection of Children from Sexual Offences Act, 2012: Specifically targeting child sexual abuse, this Act criminalizes creation, possession, and distribution of child sexual abuse material (Section 14) and using children for pornographic purposes (Section 13). AI-generated child sexual abuse material falls squarely within these prohibitions.

The Representation of the People Act, 1951: Governing electoral processes, this Act prohibits false statements about candidates (Section 123), corrupt practices (Sections 123-124), and electoral fraud. Synthetic media creating false statements by political candidates or depicting fabricated electoral events violates these provisions, particularly during election periods when restrictions intensify.

The Indecent Representation of Women (Prohibition) Act, 1986: Prohibiting indecent depiction of women through any medium. AI-generated non-consensual intimate imagery of women constitutes precisely the harm this Act addresses, regardless of the synthetic nature of the images.

The Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013: Addressing workplace sexual harassment, including through electronic communications. Synthetic media depicting female colleagues in sexual contexts, shared in workplace settings, constitutes harassment under this Act.

The Immoral Traffic (Prevention) Act, 1956: Targeting human trafficking for prostitution and sexual exploitation. While less obviously applicable, synthetic media could potentially violate provisions against publishing content inducing prostitution or depicting trafficked persons.

The comprehensive listing of these statutes serves both informative and deterrent purposes. Users must understand that synthetic content creation implicates not merely platform policies but serious criminal law, with penalties including imprisonment.

3.2.2 Consequences of Violations

Sub-clause (ii) of clause (ca) requires informing users that violations "may lead to" four categories of consequences. This provision operationalizes the enforcement mechanisms available to platforms and authorities.

Consequence (I): Content Removal

"Immediate disabling of access to or removal of such information" establishes the primary remedial action. The term "immediate" emphasizes urgency-no extended deliberation period precedes enforcement against clear violations. "Disabling access" and "removal" are distinguished, recognizing that platforms may employ different technical approaches. Disabling access might involve delisting content from public view while preserving it for evidentiary purposes, whereas removal entails deletion.

Consequence (II): Account Action

"Suspension or termination of the user account of the user who violates this sub-rule without vitiating the evidence" addresses user-level sanctions.

"Suspension" implies temporary account restriction, potentially pending investigation or as a lesser sanction for first-time or minor violations. "Termination" signifies permanent account closure for serious or repeated violations.

The phrase "without vitiating the evidence" merits careful attention. "Vitiate" means to impair, spoil, or render invalid. This language requires platforms to preserve evidentiary integrity when taking account action. Deletion of content or account information must not destroy evidence necessary for potential criminal investigations or civil proceedings.

In practice, this likely requires platforms to maintain forensic copies of violative content, associated metadata, and user account information even after public removal and account closure. The tension between evidence preservation and user privacy rights-particularly rights to data deletion under the Digital Personal Data Protection Act, 2023-will require careful navigation.

Consequence (III): Identity Disclosure

"In accordance with applicable law, identification of such user and disclosure of the identity of the violating user to the complainant, where such complainant is a victim of, or an individual acting on behalf of a victim of, such contravention" introduces a potentially controversial mechanism.

Traditionally, intermediaries maintain user anonymity even when removing content. This provision creates an exception for victims of synthetic media abuse. Where an individual is depicted in non-consensual synthetic intimate imagery, impersonated in a fraud scheme, or defamed through synthetic media, that victim may learn the identity of the perpetrator.

Several limitations constrain this disclosure obligation. First, it must proceed "in accordance with applicable law." Data protection legislation, constitutional privacy protections, and specific legal provisions governing disclosure circumscribe when and how identity revelation may occur. Platforms cannot unilaterally disclose absent legal authorization.

Second, disclosure occurs only "to the complainant." General public disclosure remains prohibited. The victim learns the perpetrator's identity, but that information does not become publicly available.

Third, the complainant must be "a victim of, or an individual acting on behalf of a victim of" the violation. This limitation excludes third parties unaffected by the content, such as generalized morality complainants or competitors seeking user information.

Fourth, the provision uses the permissive "may lead to" rather than mandatory "shall result in." Platforms retain discretion to balance disclosure against privacy and safety concerns. Where disclosure might endanger the complainant or the violating user (who might themselves be a minor or abuse victim), platforms may withhold identification pending appropriate legal processes.

Consequence (IV): Law Enforcement Reporting

"Where such violation relates to the commission of an offence under any law for the time being in force, including the Bharatiya Nagarik Suraksha Sanhita, 2023 or the Protection of Children from Sexual Offences Act, 2012, which requires such offence to be mandatorily reported, reporting of such offence to the appropriate authority in accordance with the provisions of the applicable law" establishes mandatory reporting obligations.

This provision mirrors sub-clause (iii) of the general notification requirements but applies specifically to synthetic content violations. The specific mention of POCSO underscores the particular concern about AI-generated child sexual abuse material-a growing problem as generative models become more sophisticated.

The phrase "appropriate authority" varies by offense type. For POCSO violations, the appropriate authority is the Special Juvenile Police Unit or local police. For criminal procedure code offenses, it may be the jurisdictional police station. For specialized offenses under domain-specific laws, it may be regulatory authorities. Platforms must develop expertise in identifying the correct reporting channel for different violation types.

3.3 Proactive Action Requirement

Clause (cb), also newly inserted, imposes an affirmative duty of expeditious action when platforms become aware of violations.

3.3.1 Awareness Triggers

The provision identifies multiple pathways to awareness:

"On its own accord" addresses proactive discovery through platform monitoring, automated detection systems, or internal review processes. Platforms cannot claim ignorance when their own systems identify violations.

"Upon receipt of actual knowledge" addresses direct awareness through unambiguous information. Actual knowledge exceeds mere suspicion or possibility; it requires definitive awareness of specific violative content.

"On the basis of any grievance, complaint or information received under these rules" addresses user reports. Whether through formal grievance mechanisms, informal complaints, or general information provision, user reports trigger action obligations.

This multi-pathway approach forecloses willful blindness. Platforms cannot avoid obligations by deliberately not looking. Whether awareness arises internally or externally, the duty to act attaches.

3.3.2 Scope of Violations Covered

The obligation applies to "any violation of sub-rule (3), in relation to the creation, generation, modification, alteration, hosting, displaying, uploading, publishing, transmitting, storing, updating, sharing or otherwise dissemination of information as synthetically generated information covered under sub-clause (ii) of clause (a)."

Sub-clause (ii) of clause (a) of sub-rule (3), examined in detail below, addresses synthetic content that falsely depicts natural persons or real-world events in a deceiving manner. This represents the most problematic category of synthetic media-content that misrepresents reality for potentially harmful purposes.

The comprehensive verb list ensures no gap in coverage. Every stage of content lifecycle-from initial creation through final dissemination-falls within scope.

3.3.3 Required Action

Platforms must take "expeditious and appropriate action, including those specified in sub-clause (ii) of clause (ca)."

"Expeditious" requires speed. While no specific timeline is mandated, unreasonable delay violates the obligation. The appropriate timeframe likely varies with violation severity-child sexual abuse material demands immediate action, while potentially misleading political content may permit brief evaluation.

"Appropriate" requires fit-for-purpose response. The action must adequately address the violation type and severity. For egregious violations, content removal and account termination may be appropriate. For borderline cases, content labeling or usage restrictions might suffice.

The reference to actions "specified in sub-clause (ii) of clause (ca)" incorporates the four consequences discussed above: content removal, account action, identity disclosure to victims, and law enforcement reporting. The use of "including" rather than "limited to" suggests these are illustrative; other appropriate actions may exist.

Chapter 4: Accelerated Compliance Timelines

4.1 Government Removal Orders: From Thirty-Six Hours to Three Hours

One of the most dramatic changes in the amendments involves the timeline for complying with government removal orders under Rule 3(1)(d). The pre-amendment requirement of "thirty-six hours" is reduced to "three hours."

4.1.1 The Provision's Structure

Rule 3(1)(d) addresses situations where intermediaries receive orders from authorized government officers to remove or disable access to content. The provision operates in emergency or urgent circumstances where content poses immediate threats to public order, national security, or other critical interests.

The three-hour timeline applies specifically to the initial compliance obligation-disabling access or removing the content. It does not extend to comprehensive reporting, detailed documentation, or full investigation, which may reasonably require additional time.

4.1.2 Justification for Acceleration

The timeline reduction reflects the velocity of information dissemination in modern digital ecosystems. Content that violates law-particularly inflammatory misinformation during communal tensions, terrorist propaganda, or child sexual abuse material-can spread to millions of users within hours. A thirty-six-hour window permits extensive harm before removal.

Three hours represents a balance between immediate action and operational feasibility. Unlike a one-hour or real-time removal requirement, which might be technically infeasible for smaller platforms, three hours provides sufficient time for order receipt, legal review, technical implementation, and execution while substantially limiting harmful content's spread.

4.1.3 Authorization Requirements: Written Orders

The amendments modify the authorization language, changing "issued by an officer authorised for the purpose of issuing such intimation" to "issued by an officer authorised, by order in writing, for the purpose of issuing such intimation."

The insertion of "by order in writing" is significant. It requires formal, documented authorization of the officer issuing removal orders. Oral authorizations, implicit delegations, or assumption of authority based on position no longer suffice.

This requirement serves multiple accountability purposes. First, it creates an audit trail. Written authorization orders can be reviewed to ensure proper delegation chains and appropriate exercise of authority. Second, it prevents unauthorized officers from issuing orders beyond their competence. Third, it provides legal protection for intermediaries-compliance with a written authorization order offers stronger safe harbor than compliance with an oral directive.

4.1.4 Police Authorization: Deputy Inspector General Requirement

The proviso to sub-clause (ii) of clause (d) undergoes significant revision. The amended text provides: "where such intimation is to be issued by the police administration, there may be one or more authorised officers, each not below the rank of Deputy Inspector General of Police, especially authorised by the Appropriate Government in this behalf."

Several elements merit examination. First, the requirement that authorized officers be "not below the rank of Deputy Inspector General of Police" establishes a high rank threshold. Deputy Inspectors General (DIGs) are senior officers typically commanding ranges or specialized units within state police hierarchies. This rank requirement ensures that removal orders receive senior review and cannot be issued by junior officers acting hastily or without adequate evaluation.

Second, the phrase "one or more authorised officers" acknowledges that a single designated officer may be insufficient for a large state or for ensuring 24/7 responsiveness. Multiple authorized officers prevent bottlenecks while maintaining the high rank requirement.

Third, the phrase "especially authorised by the Appropriate Government" requires explicit governmental designation. DIGs do not automatically possess removal order authority by virtue of rank; specific authorization from the Central or State Government (depending on the subject matter) is necessary. This layered authorization-governmental designation of specific officers-adds an additional accountability safeguard.

4.2 Grievance Redressal: Tightened Timelines

Rule 3(2) governs grievance redressal mechanisms and complaint handling. The amendments accelerate several timelines, reflecting expectations of faster platform responsiveness.

4.2.1 General Grievance Timeline: Fifteen to Seven Days

Clause (a), sub-clause (i) previously required acknowledgment of complaints "within twenty-four hours" and resolution "as soon as possible, but within fifteen days." The amended provision changes "fifteen days" to "seven days."

This halving of the resolution timeline places significant operational pressure on platforms, particularly those receiving high complaint volumes. A platform receiving thousands of daily complaints must now investigate, evaluate, and resolve each within one week rather than two.

The retention of "as soon as possible" language suggests that seven days represents an outer limit, not a target. Platforms should resolve clear-cut cases within hours or days, reserving the full seven-day period for complex cases requiring investigation, expert consultation, or multi-party coordination.

4.2.2 Specified Violations: Seventy-Two to Thirty-Six Hours

The first proviso to sub-clause (i) addresses complaints regarding specific serious violations, previously requiring resolution "within seventy-two hours." The amendment changes this to "thirty-six hours."

This provision applies to particularly egregious content categories warranting expedited removal. While the specific categories vary depending on platform classification, they typically include content depicting child sexual abuse, non-consensual intimate imagery, violent extremist material, and similar high-severity violations.

The thirty-six-hour timeline-half the previous seventy-two hours-reflects governmental impatience with platforms' response times to the most harmful content. While three days might seem adequate, lived experience of victims waiting for platforms to remove non-consensual intimate imagery or impersonation has demonstrated the inadequacy of longer timelines.

4.2.3 Content Under Government Orders: Twenty-Four to Two Hours

Clause (b) of sub-rule (2) addresses content "reported by an individual or by any entity" that is "identical" to content previously subject to government removal orders under sub-rule (1)(d). The pre-amendment provision required action "within twenty-four hours of receipt of such a report." The amendment reduces this to "two hours."

This provision addresses content recidivism-the same prohibited content being re-uploaded after removal. Once content has been subjected to a government removal order, establishing its unlawfulness, re-uploads of identical content should be removed expeditiously without requiring new governmental orders or extended evaluation.

The two-hour timeline is aggressive, second only to the three-hour government order compliance timeline. It presumes that identifying content as "identical" to previously removed content is technically straightforward-typically through hash-matching or similar automated systems-requiring minimal human review.

The tension between accuracy and speed in automated matching systems will challenge platforms. Hash-matching provides high precision for identical files but fails when content undergoes even minor modifications. Perceptual hashing and AI-based similarity detection offer broader coverage but higher false-positive rates. Platforms must balance the two-hour timeline requirement against the risk of erroneously removing permitted content that appears similar to prohibited content.

Chapter 5: Due Diligence for Synthetically Generated Information

Rule 3, sub-rule (3) represents the amendments' substantive core-comprehensive due diligence obligations specific to platforms enabling synthetic content creation. This provision, entirely new, establishes a detailed regulatory framework unprecedented in Indian law.

5.1 Applicability Threshold

The opening language defines scope: "Where an intermediary offers a computer resource which may enable, permit, or facilitate the creation, generation, modification, alteration, publication, transmission, sharing, or dissemination of information as synthetically generated information."

5.1.1 The Verbs of Enablement

The provision employs three verbs-enable, permit, facilitate-to capture different relationships between platform and user conduct.

"Enable" suggests affirmative provision of capability. A platform offering an AI image generation tool directly enables synthetic content creation.

"Permit" implies allowance without active provision. A general-purpose cloud computing platform that permits users to run their own AI models might not actively enable synthetic content generation but permits it by not restricting such usage.

"Facilitate" indicates making easier or more convenient. A platform providing APIs, infrastructure, or tools that facilitate synthetic content creation, even if not purpose-built for that function, falls within scope.

The disjunctive "or" establishes that satisfying any one verb triggers applicability. This broad formulation prevents evasion through arguments that a platform "merely permits" rather than "actively enables" synthetic content creation.

5.1.2 The Covered Actions

The provision lists nine actions: creation, generation, modification, alteration, publication, transmission, sharing, dissemination, and the catch-all "otherwise" dissemination. This comprehensive enumeration covers the full content lifecycle from genesis through distribution.

"Creation" and "generation" largely overlap, both addressing initial content production. Their dual inclusion may address subtle distinctions-"creation" implies intentional production, while "generation" might suggest automated or algorithmic output.

"Modification" and "alteration" similarly overlap, addressing changes to existing content. Again, the duplication provides redundancy against interpretive gaps.

"Publication," "transmission," "sharing," and "dissemination" address distribution through different conceptual frames. Publication implies making available to the public generally. Transmission suggests point-to-point communication. Sharing connotes distribution to selected recipients. Dissemination emphasizes broad distribution. Together, these terms capture all distribution modalities.

5.2 Preventive Obligations: Prohibited Synthetic Content

Clause (a), sub-clause (i) establishes the primary preventive obligation: platforms must "deploy reasonable and appropriate technical measures, including automated tools or other suitable mechanisms" to prevent users from creating or disseminating prohibited categories of synthetic content.

5.2.1 The Technical Measures Requirement

The phrase "deploy reasonable and appropriate technical measures" creates a qualified obligation. Platforms need not implement every conceivable preventive measure, only those that are "reasonable and appropriate."

"Reasonable" imports a cost-benefit analysis and feasibility assessment. Measures must be practical, effective, and proportionate to the platform's size, resources, and risk profile. A small startup platform cannot be expected to deploy the same sophisticated detection systems as a global technology giant.

"Appropriate" suggests fit-for-purpose. The measures must actually address the relevant risks. A sophisticated AI detection system designed for photographic manipulation might be inappropriate for detecting text-based fraud.

The phrase "technical measures" emphasizes technological solutions over purely human review. Given the scale of modern platforms-millions or billions of content items daily-manual review of all content is infeasible. Technical measures provide the scalable approach necessary for effective moderation.

5.2.2 Automated Tools and Other Mechanisms

The provision explicitly includes "automated tools or other suitable mechanisms." This phrasing merits careful parsing.

"Automated tools" encompasses a wide range of technologies:

  • Machine learning classifiers trained to identify specific content types
  • Perceptual hashing systems to match content against prohibited material databases
  • Natural language processing systems to detect text-based violations
  • Computer vision systems to analyze images and videos
  • Audio analysis systems to detect voice cloning or synthetic speech
  • Metadata analysis tools to identify generation signatures

"Other suitable mechanisms" captures non-automated approaches:

  • Human review workflows for flagged content
  • Community reporting systems
  • Expert reviewer panels for complex cases
  • Hybrid human-AI systems combining automated detection with human evaluation

The use of "including" rather than "limited to" suggests these examples are illustrative. Novel mechanisms may emerge as technology evolves; the provision remains technology-neutral.

5.2.3 Prohibited Category I: Sexual and Exploitative Content

Sub-clause (I) addresses content that "contains child sexual exploitative and abuse material, non-consensual intimate imagery content, or is obscene, pornographic, paedophilic, invasive of another person's privacy, including bodily privacy, vulgar, indecent or sexually explicit."

This category consolidates multiple content types unified by sexual or exploitative character. Each term requires examination:

Child Sexual Exploitative and Abuse Material (CSEAM)

Formerly termed "child pornography," the updated nomenclature reflects recognition that such material depicts abuse, not consensual pornography. CSEAM includes any visual depiction of minors engaged in sexual conduct, sexually suggestive poses, or contexts sexualizing children.

The inclusion of AI-generated CSEAM is particularly significant. As generative models become more sophisticated, the creation of synthetic images depicting child sexual abuse becomes technically feasible. Some jurisdictions debate whether such content, not involving actual child victims, should be criminalized. India's position is unequivocal-synthetic CSEAM falls within the prohibition.

The policy rationale is multifaceted. First, synthetic CSEAM normalizes child sexualization and may facilitate grooming. Second, distinguishing synthetic from authentic CSEAM is difficult, complicating law enforcement. Third, synthetic CSEAM may incorporate elements derived from images of real children. Fourth, the mere existence of such material harms the social interest in protecting children's dignity and well-being.

Non-Consensual Intimate Imagery (NCII)

NCII, colloquially termed "revenge porn," encompasses intimate images or videos shared without the subject's consent. The AI dimension introduces new harms-synthetic intimate imagery can be created without any source imagery of the victim in intimate contexts. Generative models can produce realistic nude images of identified individuals who have never been photographed unclothed.

This technology poses profound dignity, privacy, and safety risks. Victims suffer psychological harm, reputational damage, and sometimes physical danger from synthetic NCII indistinguishable from authentic imagery. The traditional legal approach focusing on unauthorized distribution of authentic intimate images proves inadequate; synthetic NCII requires specific prohibition.

Obscene, Pornographic

These terms, while overlapping, address content depicting sexual acts or anatomy intended to arouse. The Indian legal framework historically employed the "community standards" test derived from English law-material is obscene if it depraves and corrupts persons exposed to it. Constitutional developments have somewhat liberalized this standard, but explicit sexual content lacking redeeming value remains prohibitable.

In the synthetic context, the concern is platforms becoming venues for generating pornographic content, potentially at scales and specificities impossible with traditional production. While adults consensually creating synthetic sexual content of themselves might arguably fall outside prohibition, platforms face pressure to prevent their tools from becoming pornography generation engines.

Paedophilic

Distinct from CSEAM, paedophilic content may not depict actual or synthetic children but appeals to paedophilic interests-sexualized depictions of child-like animated characters, fantasy scenarios involving minors, or content normalizing child sexualization. The prohibition recognizes that a continuum exists from fantasy material to abuse material, and preventing platforms from hosting the former serves protective purposes.

Invasive of Privacy, Including Bodily Privacy

This phrase extends beyond intimate imagery to encompass other privacy violations. "Bodily privacy" specifically addresses physical privacy-depicting individuals in vulnerable bodily states (undressed, using facilities, receiving medical treatment) without consent.

Synthetic media exponentially increases privacy invasion risks. Traditional privacy violations required actual access to private spaces. Synthetic media enables realistic depiction of individuals in private contexts without such access. An individual's face can be placed on another person's body in a bathroom or bedroom setting, creating privacy-violating imagery without any authentic source material.

The explicit inclusion of bodily privacy likely responds to this synthetic media capability. The provision ensures that synthetic depictions invading bodily privacy receive the same treatment as authentic privacy violations.

Vulgar, Indecent, Sexually Explicit

These terms provide catch-all coverage for sexual content not captured by preceding categories. "Vulgar" suggests crudeness and offensiveness. "Indecent" addresses content violating propriety standards. "Sexually explicit" encompasses graphic sexual content.

The cumulative effect of this lengthy enumeration is comprehensive prohibition of sexual content across the spectrum from exploitative (CSEAM, NCII) to offensive (vulgar, indecent) to explicit (pornographic, sexually explicit).

5.2.4 Prohibited Category II: False Documents and Records

Sub-clause (II) prohibits synthetic content that "results in the creation, generation, modification or alteration of any false document or false electronic record."

This provision addresses synthetic media's capacity to fabricate documentary evidence. The terms "false document" and "false electronic record" possess specific legal meanings under Indian law.

False Document

Section 336 of the Bharatiya Nyaya Sanhita defines a false document as one made wholly or partially by forgery, where forgery involves making a false document with intent to cause damage or injury, or to support a claim or title, or to cause someone to part with property, or to enter into an express or implied contract, or with intent to commit fraud.

Synthetic media can generate entire false documents-fabricated certificates, forged contracts, fake licenses-or modify authentic documents to alter material content. An AI system might generate a realistic university degree certificate for a non-existent institution, or modify an authentic transcript to change grades.

The "results in creation, generation, modification or alteration" language captures both direct forgery and indirect facilitation. If platform tools enable users to create false documents as outputs, the prohibition applies.

False Electronic Record

The Information Technology Act defines "electronic record" as data generated, stored, or transmitted electronically that can be retrieved. A false electronic record similarly involves fabricated or altered digital records.

Electronic records increasingly serve evidentiary purposes-email communications, digital signatures, transaction logs, system metadata. Synthetic media can fabricate convincing electronic records-fake email threads, forged digital signatures, manufactured transaction histories.

The prohibition on facilitating false electronic record creation addresses platforms' potential role in evidence fabrication. While blockchain and cryptographic verification systems provide some authentication mechanisms, synthetic media poses challenges to digital evidence integrity.

Scope and Limitations

The prohibition's scope warrants consideration. It addresses false documents and records-falsity is the crucial element. Synthetic content that openly presents itself as synthetic (clearly labeled AI-generated images used in presentations, for instance) does not result in false records. The prohibited conduct involves using synthetic media to create records that misrepresent their authenticity or content.

5.2.5 Prohibited Category III: Dangerous Materials

Sub-clause (III) prohibits synthetic content that "relates to the preparation, development or procurement of explosive material, arms or ammunition."

This provision addresses national security and public safety concerns. Synthetic media could potentially disseminate information facilitating terrorism or violence-detailed bomb-making instructions, weapons modification procedures, or sourcing information for restricted materials.

Preparation

"Preparation" suggests creation or assembly processes. Synthetic content providing step-by-step instructions for constructing explosive devices, manufacturing chemical weapons, or assembling firearms from components falls within this prohibition.

The AI dimension introduces new risks. Large language models can synthesize information from multiple sources to provide comprehensive dangerous device construction instructions. Image generation systems might create detailed visual diagrams. Video generation could produce instructional demonstrations.

Development

"Development" addresses research, refinement, and advancement of dangerous capabilities. Content providing information on improving explosive yields, increasing weapons lethality, or evading detection systems falls within this category.

Procurement

"Procurement" focuses on acquisition-where and how to obtain dangerous materials, arms, or ammunition. Synthetic content might generate lists of suppliers, provide instructions for circumventing legal restrictions on purchases, or offer guidance on illegal acquisition channels.

Scope Considerations

The provision's breadth raises questions about legitimate content. Academic research on explosives chemistry, historical documentation of weapons development, or journalistic investigation of arms trafficking might "relate to" these subjects without facilitating harmful conduct. The word "relates" provides little limiting principle.

Interpretive limitations likely derive from context and intent. Content with legitimate educational, research, journalistic, or historical purposes, particularly when presented in contexts negating harmful use, would likely fall outside the prohibition's intended scope. Content lacking such purposes, particularly when presented in how-to instructional formats, clearly falls within.

5.2.6 Prohibited Category IV: Deceptive Misrepresentation

Sub-clause (IV) prohibits synthetic content that "falsely depicts or portrays a natural person or real-world event by misrepresenting, in a manner that is likely to deceive, such person's identity, voice, conduct, action, statement, or such event as having occurred, with or without the involvement of natural person."

This represents the most comprehensive and potentially far-reaching prohibition, targeting the core harm of synthetic media-deceptive misrepresentation of reality.

Falsely Depicts or Portrays

The phrase "falsely depicts or portrays" establishes the falsity requirement. Content must not merely depict in stylized or artistic fashion but do so falsely-in a manner representing as real something that is not real.

The disjunctive "natural person or real-world event" establishes two prohibited targets:

Natural Person

A "natural person" is a human being, as opposed to a legal entity like a corporation. The prohibition protects individuals from false depiction. Importantly, it covers any natural person, not merely public figures or specific categories. Every individual enjoys protection from false synthetic depiction.

Real-World Event

A "real-world event" is an occurrence in physical reality. The prohibition covers false depiction of events-synthetic videos depicting disasters that never occurred, fabricated news footage of political developments, or manufactured evidence of historical events.

By Misrepresenting

The crucial verb is "misrepresenting"-communicating false information about something. The provision then specifies what may be misrepresented regarding persons or events.

For Natural Persons:

  • Identity: Who the person is-impersonation, attribution to the wrong individual
  • Voice: The person's speech-fabricated statements, voice cloning
  • Conduct: The person's behavior-depicting actions not performed
  • Action: Specific acts taken-showing the person doing things not done
  • Statement: Words spoken-false quotes, fabricated speeches

For Events:

  • As having occurred: Depicting events that did not happen

The phrase "with or without the involvement of natural person" clarifies that consent or participation does not cure the harm. Even if an individual cooperates in creating synthetic content falsely depicting another person, the prohibition applies.

In a Manner Likely to Deceive

The critical qualifier is "in a manner that is likely to deceive." This establishes a deception standard as the harm threshold.

"Likely to deceive" creates an objective reasonableness test. Would a reasonable person viewing the content be deceived about its authenticity? The test does not require actual deception of specific viewers or intent to deceive (though intent may be separately relevant for criminal liability). The content's inherent deceptive quality suffices.

This standard permits regulation of highly realistic deepfakes while potentially exempting obvious satire, clear parody, or artistic expression that no reasonable viewer would mistake for reality. The boundary will be context-dependent-the same synthetic content might be deceptive in a news context but obviously satirical in a comedy context.

Implications and Applications

This provision's sweep is extraordinary. It prohibits using synthetic media to falsely depict individuals saying things they didn't say, doing things they didn't do, or being places they weren't. It prohibits creating false event footage.

Applications include:

  • Political deepfakes showing candidates making statements they never made
  • Synthetic videos of celebrities endorsing products without authorization
  • Fabricated evidence of crimes or misconduct by identified individuals
  • False news footage of events (attacks, disasters, ceremonies) that didn't occur
  • Manipulated videos altering what individuals actually said or did

The provision captures the core synthetic media harms that motivated regulatory intervention-threats to truth, political manipulation, defamation, fraud, and evidence integrity.

5.3 Labeling Obligations: Permitted Synthetic Content

Clause (a), sub-clause (ii) addresses synthetic content NOT prohibited under sub-clause (i)-content that may be created and disseminated but must be labeled to prevent deception.

5.3.1 Comprehensive Labeling Requirement

The provision requires that "every such information" (permitted synthetic content) "is prominently labelled in a manner that ensures prominent visibility in the visual display that is easily noticeable and adequately perceivable."

Prominent Labeling

"Prominently labelled" requires conspicuous marking. The label cannot be hidden in obscure locations, rendered in tiny fonts, or otherwise made difficult to observe. Prominence ensures that users cannot miss the label through ordinary viewing.

Prominent Visibility in Visual Display

For visual content (images, videos), the label must be "prominent visibility in the visual display." This likely requires visible text overlay, watermarking, or interface elements that appear alongside the content itself.

Placement matters. A label at the bottom of a description field that requires scrolling to view would not achieve "prominent visibility." A label overlaid on the image or video itself, or displayed immediately adjacent in the user interface, would satisfy the requirement.

Easily Noticeable

"Easily noticeable" addresses salience. The label must stand out through color contrast, size, positioning, or other design elements that draw attention. A light gray text label on a white background, while technically visible, might not be "easily noticeable."

Adequately Perceivable

"Adequately perceivable" requires comprehensibility. Users must be able to perceive and understand the label. This implicates font size (readable at normal viewing distances), language (understandable to the audience), and clarity (unambiguous meaning).

Taken together, these requirements mandate labels that users cannot reasonably overlook or misunderstand-clear, conspicuous, and comprehensible markers of synthetic origin.

5.3.2 Audio Content Labeling

The provision addresses audio content separately: "or, in the case of audio content, through a prominently prefixed audio disclosure."

Prominently Prefixed

"Prominently prefixed" requires the disclosure to appear at the beginning of the audio content. Users must hear the synthetic content warning before or as the synthetic audio commences.

This approach prevents deception scenarios where users hear synthetic audio (a voice clone of a public figure, for instance) and form impressions before learning of its synthetic nature. Prefixing ensures contemporaneous awareness.

Audio Disclosure

The disclosure must be audible-a verbal statement such as "The following audio has been synthetically generated using artificial intelligence" or similar language. The disclosure must be clear, loud enough to hear, and in a language the audience understands.

The requirement creates practical challenges for short audio clips, where a lengthy disclosure might dominate the content itself. Platforms must balance disclosure adequacy with user experience, potentially developing standardized short-form disclosures that quickly communicate synthetic origin.

5.3.3 Purpose of Labeling

The provision explains labeling's purpose: labels enable viewers to "immediately identify that such information is synthetically generated information which has been created, generated, modified or altered using a computer resource."

"Immediately identify" establishes the temporal requirement-no investigation, metadata examination, or expert analysis should be necessary. Average users viewing labeled content should instantly recognize its synthetic nature.

The language "created, generated, modified or altered using a computer resource" provides transparent communication about the content's nature. Users learn not merely that something is "fake" or "manipulated" but specifically that AI or algorithmic processes produced it.

This transparency serves multiple purposes. It enables users to adjust credibility assessments, prevents deception, facilitates informed sharing decisions, and contributes to media literacy by helping users recognize synthetic content characteristics.

5.3.4 Technical Provenance Requirements

Beyond user-facing labels, the provision requires technical provenance mechanisms: "such information shall be embedded with a permanent metadata or other appropriate technical provenance mechanisms, to the extent technically feasible, including a unique identifier, to identify the computer resource of the intermediary used to create, generate, modify or alter such information."

Permanent Metadata

"Permanent metadata" suggests information embedded within content files that persists across copying, sharing, and format conversion. Standard metadata fields (EXIF data for images, ID3 tags for audio) provide one approach, but these are easily stripped.

More robust approaches might include steganographic embedding (hiding metadata within content data itself), cryptographic signing, or blockchain-based provenance records. The "permanent" requirement suggests methods that survive typical content manipulation.

Other Appropriate Technical Provenance Mechanisms

This phrase acknowledges that metadata may not suit all content types or use cases. Alternative mechanisms might include:

  • Perceptual hashing (fingerprints that survive content modifications)
  • Watermarking (visible or invisible marks within content)
  • Blockchain ledgers (distributed provenance records)
  • Cryptographic signatures (digital signatures verifying origin)
  • Content credentials (Adobe's Content Authenticity Initiative and similar standards)

To the Extent Technically Feasible

This crucial qualifier acknowledges technical limitations. Some content formats may not support metadata embedding. Some distribution channels strip metadata. Some technical provenance mechanisms may be cost-prohibitive or insufficiently mature.

"Technically feasible" likely means available, reliable, and implementable without unreasonable cost or disruption. As technology advances, what is technically feasible evolves, creating a progressive obligation.

Unique Identifier

The provision specifically requires "including a unique identifier" as part of the technical provenance. This identifier serves a critical tracing function.

"Unique identifier" likely means a code or signature specific to the platform, generation session, or even individual content item. This enables tracking content back to its origin-which platform created it, when, and potentially under which user account.

The identifier's purpose is accountability. If prohibited synthetic content appears on other platforms, investigators can trace it to its creation source. If synthetic content causes harm, victims and authorities can identify the originating platform.

Purpose: Identify the Computer Resource

The provenance mechanism's explicit purpose is "to identify the computer resource of the intermediary used to create, generate, modify or alter such information."

"Computer resource of the intermediary" means the platform's systems-its servers, APIs, algorithms, or tools. The requirement focuses on identifying the platform, not necessarily the individual user (though platforms may voluntarily include user identifiers).

This platform-level identification serves regulatory accountability. Platforms enabling synthetic content creation bear responsibility for ensuring that content carries provenance markers. If content lacks such markers, the creating platform has failed its obligation.

5.4 Anti-Tampering Obligation

Clause (b) establishes a critical anti-circumvention provision: "the intermediary shall not enable the modification, suppression or removal of the label, permanent metadata, including the unique identifier, displayed or embedded in accordance with sub-clause (ii) of clause (a)."

5.4.1 The Prohibition

"Shall not enable" creates an affirmative duty. Platforms must actively prevent removal of provenance markers, not merely refrain from providing removal tools.

The provision prohibits enabling three actions:

Modification

Changing labels or metadata-editing text, altering identifiers, or adjusting embedded information-is prohibited. Even if not completely removed, modifications that obscure origin or reduce clarity violate the provision.

Suppression

Hiding or concealing labels without removal-making invisible, rendering imperceptible, or otherwise preventing display-falls within the prohibition. A platform feature that allows users to toggle off synthetic content labels would violate this provision.

Removal

Complete deletion of labels or metadata-stripping EXIF data, removing watermarks, or erasing identifiers-is prohibited. Platforms cannot provide tools or features that eliminate provenance markers.

5.4.2 Technical Implications

This provision imposes significant technical obligations. Platforms must:

Prevent Export Features from Stripping Metadata

Download, export, and sharing features must preserve provenance information. If users can download synthetic content as files stripped of metadata, the platform enables removal.

Block Third-Party Tools

While platforms cannot control all user behavior, they should not facilitate use of metadata-stripping tools. API restrictions, terms of service prohibitions, and technical barriers against automated stripping tools may be necessary.

Resist Format Conversions That Remove Provenance

Format conversion features (converting images to different file types, transcoding videos) must maintain provenance markers across formats. This may require embedding provenance in multiple metadata standards or using format-agnostic steganographic approaches.

Prevent In-App Editing That Removes Markers

Built-in editing tools must not remove or obscure provenance. If a platform allows cropping synthetic images, the crop function must preserve labels and metadata.

5.4.3 Accountability and Traceability

The anti-tampering provision ensures that provenance follows content through its lifecycle. When synthetic content spreads across platforms, downstream platforms can identify its origin. When harmful synthetic content appears, investigators can trace it to its source.

This creates multi-platform accountability. Even if Content is created on Platform A but causes harm after spreading to Platforms B, C, and D, the provenance markers enable identification of Platform A as the creation source. Platform A's compliance with prevention obligations (not allowing prohibited content) can then be evaluated.

Chapter 6: Significant Social Media Intermediaries and Verification Obligations

Rule 4(1A) imposes additional obligations specifically on "significant social media intermediaries"-typically large platforms with substantial user bases (defined in the parent rules as those with over five million registered users in India).

6.1 The Pre-Publication Workflow

The provision establishes a three-stage process that must occur "prior to" display, upload, or publication of any information on significant social media intermediaries' computer resources.

This pre-publication requirement represents a significant shift from post-publication moderation. Rather than allowing content to appear and subsequently removing violations, platforms must evaluate synthetic content status before making it publicly available.

6.1.1 Stage One: User Declaration

Clause (a) requires platforms to "require users to declare whether such information is synthetically generated information."

Mandatory Declaration

"Require" establishes obligation. Platforms cannot make declaration optional or voluntary; they must mandate it as a condition of publication.

Implementation might involve checkboxes during upload ("This content was created or modified using AI"), dropdown menus for content classification, or mandatory form fields that must be completed before submission.

User Knowledge and Judgment

The provision places initial classification responsibility on users. This approach assumes users know whether their content is synthetic-a reasonable assumption when users themselves employ AI generation tools but potentially problematic for content that users receive from others or content where synthetic status is ambiguous.

Edge cases abound. If a user creates an image using AI, then manually edits it, is it synthetic? If a user uses AI to upscale an authentic photograph, is it synthetic? If content passes through multiple transformation stages, some synthetic and some traditional, how should users declare?

Platforms will need to provide guidance-definitions, examples, FAQs-helping users make accurate declarations. The quality of this guidance affects declaration accuracy.

False Declaration Risks

Users might deliberately misdeclare content-marking synthetic content as authentic to avoid labeling, or vice versa. The provision does not directly address false declarations, but subsequent clauses establish verification obligations and potential consequences.

6.1.2 Stage Two: Technical Verification

Clause (b) requires platforms to "deploy appropriate technical measures, including automated tools or other suitable mechanisms, to verify the accuracy of such declaration, having regard to the nature, format, and source of such information."

Verification Obligation

"Verify the accuracy" establishes that platforms cannot blindly accept user declarations. Some level of technical checking is required.

The verb "verify" suggests confirmation rather than mere assessment. Platforms should employ methods that can definitively determine (to reasonable confidence levels) whether content is synthetic.

Appropriate Technical Measures

"Appropriate" again imports a reasonableness and proportionality standard. Verification measures must fit the platform's capabilities and the content's characteristics.

Verification approaches might include:

Automated Detection Tools

  • Deepfake detection algorithms analyzing visual artifacts
  • AI-generated text detection models
  • Synthetic speech detection systems
  • Image forensics tools detecting generation signatures
  • Metadata analysis examining file creation information

Metadata Analysis

  • Examining EXIF data for camera versus AI generation markers
  • Checking for provenance markers from other platforms
  • Analyzing embedded unique identifiers
  • Reviewing file history and modification timestamps

Source Verification

  • Cross-referencing with known synthetic content databases
  • Checking against authentic source material
  • Reverse image/video searches
  • Digital signature verification

Hybrid Approaches

  • AI-flagging with human review
  • Community voting systems
  • Expert reviewer panels for uncertain cases

Factors for Consideration

The provision directs platforms to have "regard to the nature, format, and source of such information."

"Nature" refers to content type-image, video, audio, text-each requiring different detection approaches.

"Format" addresses technical specifications-file types, codecs, resolutions-which may contain forensic clues or complicate detection.

"Source" considers origin-content uploaded directly versus shared from another platform, original creation versus redistributed material.

These factors recognize that verification difficulty varies. Detecting synthetic images may be easier than detecting synthetic text. High-resolution video may provide more forensic evidence than low-resolution clips. Content from trusted sources may require less scrutiny than content from unknown origins.

Accuracy Limitations

No verification system achieves perfect accuracy. AI detection tools face arms races with generation tools-as detection improves, generation methods evolve to evade detection. False positives (marking authentic content as synthetic) and false negatives (missing synthetic content) are inevitable.

The "appropriate" qualifier likely permits reasonable error rates. Platforms must deploy state-of-the-art verification within feasibility constraints, but perfection is not required.

6.1.3 Stage Three: Confirmed Synthetic Content Handling

Clause (c) addresses situations "where such declaration or technical verification confirms that the information is synthetically generated." In such cases, platforms must "ensure that the same is clearly and prominently displayed with an appropriate label or notice, indicating that the content is synthetically generated."

Confirmation Triggers

The provision uses the disjunctive "or"-either user declaration OR technical verification confirming synthetic status triggers labeling obligations. This means:

  • If the user declares content as synthetic, it must be labeled (regardless of verification results)
  • If verification determines content is synthetic, it must be labeled (regardless of user declaration)

This dual-trigger approach prevents both false negatives (users misdeclaring synthetic content as authentic, bypassed by verification) and false positives that might result from verification errors (if the user declares as authentic and verification is uncertain, benefit of doubt may apply).

Display Requirements

"Clearly and prominently displayed" echoes language from Rule 3(3)(a)(ii), establishing consistent labeling standards.

"Appropriate label or notice" permits flexibility. Labels might be short text tags ("AI-Generated"), icon badges, color coding, or banner notices. The form should fit the content type and platform interface.

"Indicating that the content is synthetically generated" specifies minimum message content. The label must communicate synthetic origin. Additional information (which tool was used, how it was generated) may be helpful but is not mandated.

User Experience Considerations

Labeling requirements create user experience tensions. Prominent labels may be visually intrusive, potentially degrading aesthetic presentation. Users creating legitimate synthetic art may object to conspicuous markers.

Platforms must balance regulatory compliance with user satisfaction. Standardized, professionally designed labels that are noticeable without being garish represent optimal approaches. Industry coordination on labeling standards could reduce user confusion and platform compliance costs.

6.2 The Deemed Failure Proviso

The proviso introduces a knowledge-based liability standard: "where such intermediary becomes aware, or it is otherwise established, that the intermediary knowingly permitted, promoted, or failed to act upon such synthetically generated information in contravention of these rules, such intermediary shall be deemed to have failed to exercise due diligence under this sub-rule."

6.2.1 Awareness Standards

The proviso establishes two awareness pathways:

Becomes Aware

"Becomes aware" suggests actual knowledge acquisition through any means-user reports, media coverage, regulatory notice, internal discovery, or other information sources.

This standard is fact-specific. When did the platform actually know about specific content violations? Documentation of awareness becomes critical for liability determination.

Otherwise Established

"Otherwise established" addresses situations where awareness can be proven through circumstantial evidence even if direct knowledge documentation is absent.

If violations are widespread, sustained, and obvious, awareness may be established through inference. A platform claiming ignorance of thousands of reported deepfake violations strains credulity-awareness would be "otherwise established" through the pattern itself.

6.2.2 The Knowledge Requirement

The critical qualifier is "knowingly"-the intermediary must have knowingly permitted, promoted, or failed to act.

Knowingly Permitted

"Knowingly permitted" suggests aware allowance. The platform knew about synthetic content violations but allowed them to continue.

This might occur through deliberate policy decisions (choosing not to enforce against certain synthetic content categories), resource allocation failures (insufficient moderation staff to address known violations), or willful blindness (deliberately not implementing detection systems to avoid awareness).

Knowingly Promoted

"Knowingly promoted" suggests active advancement. The platform not only allowed violations but algorithmically promoted them through recommendations, trending features, or amplification mechanisms.

This is the most culpable scenario-actively spreading content the platform knows violates the rules. Liability would be clear and consequences severe.

Knowingly Failed to Act

"Knowingly failed to act" addresses omission. The platform knew of violations but took no remedial action-no removal, no labeling, no account sanctions, no law enforcement reporting.

This captures inadequate response. Even if the platform didn't affirmatively permit or promote violations, awareness without action constitutes knowing failure.

6.2.3 Deemed Failure of Due Diligence

The consequence is significant: "shall be deemed to have failed to exercise due diligence under this sub-rule."

"Deemed to have failed" creates an irrebuttable presumption. Once knowing permission, promotion, or inaction is established, due diligence failure follows automatically. The platform cannot argue that it exercised due diligence despite the knowing violation.

Legal Consequences

Due diligence failure vitiates safe harbor protection under Section 79 of the IT Act. The intermediary becomes liable for user-generated content as if it were the publisher.

This exposes platforms to:

  • Civil liability for defamation, privacy violations, intellectual property infringement
  • Criminal liability for hosting unlawful content
  • Regulatory sanctions including platform blocking under Section 69A
  • Reputational damage and user trust erosion

The stakes are sufficiently high to incentivize robust compliance.

6.3 The Explanatory Note

The Explanation provides critical clarification: "For the removal of doubts, it is hereby clarified that the responsibility of the significant social media intermediary shall extend to taking reasonable and proportionate technical measures to verify the correctness of user declarations and to ensure that no synthetically generated information is published without such declaration or label."

6.3.1 Scope of Responsibility

The Explanation establishes that intermediary responsibility encompasses two distinct obligations:

Verification of Declarations

Platforms must "verify the correctness of user declarations" through "reasonable and proportionate technical measures."

This confirms that user declarations alone are insufficient. Platforms cannot operate on an honor system, trusting users to accurately self-classify content. Technical verification is mandatory.

The "reasonable and proportionate" qualifier again recognizes limitations. Perfect verification is not required or achievable. Platforms must employ current best practices appropriate to their resources and capabilities.

Prevention of Unlabeled Publication

Platforms must "ensure that no synthetically generated information is published without such declaration or label."

This establishes a preventive rather than reactive obligation. Platforms should block publication of unlabeled synthetic content, not allow publication followed by post-hoc labeling.

Technical implementation might involve pre-publication queues where content awaiting verification cannot be publicly accessed, automated holds on suspected synthetic content pending review, or user interface requirements preventing submission without declarations.

6.3.2 Clarification Purpose

The Explanation addresses potential arguments that platforms bear no responsibility for user misdeclarations or that verification obligations are discretionary.

By clarifying that responsibility "extends to" verification and prevention, the Explanation establishes these as core obligations, not peripheral suggestions. Platforms cannot disclaim responsibility by arguing that users control content classification or that technical verification is merely encouraged rather than required.

Chapter 7: Proactive Content Moderation Enhancement

Rule 4(4) undergoes a subtle but significant amendment. The pre-amendment provision required significant social media intermediaries to "endeavour to deploy technology-based measures" for identifying previously removed content being re-uploaded. The amendment changes "endeavour to deploy" to simply "deploy."

7.1 From Best Efforts to Mandatory Obligation

The shift from "endeavour to deploy" to "deploy" transforms a best-efforts aspiration into a mandatory requirement.

"Endeavour" suggests trying, attempting, making good-faith efforts. If technical or practical obstacles prevent achievement, the platform can demonstrate it endeavored to deploy the required measures even if deployment ultimately failed.

"Deploy" is absolute. The platform must actually implement the required technology-based measures. Effort without achievement does not satisfy the obligation.

This change reflects regulatory impatience with platforms claiming they are "trying" to address repeat content uploading while such content continues proliferating.

7.2 Content Categories Covered

The provision addresses content "which is prima facie in the nature of any material which is in the nature of the content as specified in sub-clause (ii) of clause (a) of sub-rule (2) and identical information which is prima facie in the nature of content as specified in clause (d) of sub-rule (1)."

This complex phrasing references two content categories:

Sub-rule (2)(a)(ii) Content

This addresses particularly harmful content requiring expedited removal-typically child sexual abuse material, non-consensual intimate imagery, terrorist content, and similar high-severity violations. The specific categories may vary by platform type and are defined in the context of the parent rules.

Sub-rule (1)(d) Content

This addresses content subject to government removal orders-content that authorities have specifically directed platforms to remove due to illegality, public order threats, or similar governmental concerns.

"Identical Information"

The critical limitation is "identical information"-content that is the same as previously removed content. This implicates technical matching systems.

Hash Matching

The most straightforward approach involves cryptographic hash matching. Each file generates a unique hash-a digital fingerprint. Platforms maintain databases of hashes for removed content and automatically block any uploads with matching hashes.

This approach is highly accurate for identical files but fails when content undergoes even minor modifications-cropping, compression, format conversion.

Perceptual Hashing

More sophisticated approaches use perceptual hashing-generating fingerprints based on content appearance rather than file data. Similar-looking images produce similar hashes even if file data differs.

This broadens detection to variations of removed content but increases false-positive risks-unrelated content that happens to look similar might be erroneously blocked.

AI-Based Similarity Detection

The most advanced approach employs machine learning to assess content similarity. Neural networks trained on removed content can identify conceptually similar material even if visually or technically distinct.

This offers the broadest detection but the highest computational cost and greatest false-positive risk.

7.3 Required Technical Measures

The provision requires deployment of "appropriate technical measures, including automated tools or other suitable mechanisms."

Appropriate Technical Measures

"Appropriate" again requires fit-for-purpose solutions. The measure type must align with content characteristics and violation patterns.

For child sexual abuse material, hash matching against established databases (National Center for Missing and Exploited Children, Internet Watch Foundation) represents appropriate and effective measures.

For general copyright violations, content ID systems comparing uploaded material against rights-holder databases may be appropriate.

For misinformation or synthetic media, more sophisticated AI-based detection may be necessary.

Automated Tools

"Automated tools" emphasizes scalability. Given upload volumes-millions or billions of content items daily on major platforms-manual review of all uploads is infeasible. Automated systems provide necessary scale.

Other Suitable Mechanisms

Non-automated approaches supplement automated systems:

  • User reporting of repeat violations
  • Rights-holder notice systems
  • Moderator escalation pathways
  • Appeal and review processes

7.4 Implications for Platforms

This requirement imposes significant technical and operational obligations:

Database Maintenance

Platforms must maintain comprehensive databases of removed content, including:

  • Hashes of removed files
  • Perceptual signatures of removed visual content
  • Embeddings of removed text content
  • Metadata about removal reasons and dates

These databases must be continually updated as new content is removed and must be queried for every upload.

Computational Resources

Hash matching is computationally inexpensive, but perceptual hashing and AI-based similarity detection require significant processing power. At scale, this represents substantial infrastructure investment.

Accuracy Management

Balancing false positives against false negatives requires continuous tuning. Overly aggressive detection blocks legitimate content; overly permissive detection allows violation recurrence.

Appeals Processes

Even with sophisticated detection, errors occur. Platforms must provide mechanisms for users to appeal erroneous blocks and for rapid review of close cases.

Chapter 8: Updated Legal References

Rule 7 requires intermediaries to inform users about prohibited content, referencing applicable law. The amendment updates legal references to reflect India's 2023 criminal law reforms.

The pre-amendment provision referenced "the Indian Penal Code." The amendment substitutes "the Bharatiya Nyaya Sanhita, 2023 (45 of 2023)."

Conclusion

The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, represent a comprehensive legislative response to challenges posed by synthetically generated content. Through detailed definitions, graduated obligations based on platform type and risk, mandatory labeling requirements, technical provenance mechanisms, and accelerated enforcement timelines, the amendments establish one of the world's most developed regulatory frameworks for AI-generated content.

The amendments balance competing interests-enabling beneficial AI applications while preventing harmful misuses; protecting expression while prohibiting deception; requiring effective measures while acknowledging technical limitations; imposing platform accountability while providing compliance pathways.

Implementation will test the amendments' practical workability. Technical challenges around detection accuracy, operational burdens of rapid compliance timelines, edge cases requiring judgment, and international coordination will all challenge platforms and regulators.

As synthetic media technology continues its rapid evolution, regulatory frameworks must similarly evolve. The 2026 amendments will likely prove neither the first nor last word on synthetic media regulation but rather an important milestone in an ongoing dialogue between technology, law, and society about truth, trust, and authenticity in the digital age.

For intermediaries, the amendments impose clear obligations requiring immediate attention-technical system deployment, policy development, staff training, and compliance documentation. For users, the amendments promise clearer information about content authenticity and stronger protections against synthetic media harms. For society, the amendments represent an experiment in governing powerful technologies whose implications we are only beginning to understand.

The ultimate success of this regulatory framework will be measured not merely by compliance metrics but by whether it helps preserve the possibility of knowing truth, protecting dignity, and maintaining trust in an age when reality itself becomes increasingly negotiable through technological means.

 

🔗 Share this post: https://llmadvocates.com/blog/the-information-technology-intermediary-guidelines-and-digital-media-ethics-code-amendment-rules-2026-a-comprehensive-analysis

About LLM Advocates

LLM Advocates is a specialized law firm registered with the Punjab & Haryana High Court, focusing on cyber law, AI governance, data privacy, and technology-related legal services. Our advocates hold LLM degrees in Cyber Law and are ISO 42001:2023 Certified Lead Auditors.

Meet Our Advocates →
Bot Avatar

LLMbot

Online