Deepfake & AI Impersonation Fraud in India 2026: Voice Cloning, Fake Videos, IT Rules, BNS, Takedown, FIR & Evidence
By Adv. Govind Bali
Deepfake fraud has moved from a reputational-risk problem to a mainstream cybercrime problem. In 2026, a person may receive a cloned voice message apparently from a family member asking for urgent money, a video call that appears to show a senior executive authorising a transfer, an AI-generated advertisement falsely using a well-known person’s likeness, a synthetic video designed to extort or intimidate, or a manipulated clip used to impersonate police, CBI, ED, RBI or another authority.
Indian law now has a substantially more specific framework for dealing with this problem. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 were amended in February 2026 to regulate synthetically generated information (SGI). The amended rules came into force on 20 February 2026 and impose specific duties relating to unlawful synthetic media, labelling, provenance, user declarations, technical verification and expedited grievance handling.
At the same time, criminal liability remains fact-specific. Depending on what the deepfake is used to achieve, the conduct may attract provisions relating to cheating, cheating by personation, forgery, use of forged electronic records, criminal intimidation and conspiracy under the Bharatiya Nyaya Sanhita, 2023, together with Sections 66C and 66D of the Information Technology Act, 2000.
This guide explains the current 2026 position from the perspective of victims, businesses, professionals, platform users and investigating agencies.
Quick Answer: What Should You Do If Someone Creates or Uses a Deepfake of You?
- Preserve the evidence before seeking deletion. Save URLs, usernames, profile IDs, screenshots, screen recordings, message headers, transaction details, dates and timestamps.
- If money has been transferred, immediately call 1930 and file an NCRP complaint. Speed matters because banks and financial intermediaries may be able to hold funds in the transaction chain.
- File a police/cybercrime complaint. If the facts disclose a cognizable offence, seek registration under the applicable BNS and IT Act provisions.
- Use the platform grievance mechanism immediately. Under the amended IT Rules, certain impersonation and morphed-content complaints carry an expedited removal timeline.
- Ask the platform to preserve account and subscriber data. Removal is useful, but evidence should not disappear with the post.
- Where reputational, commercial or personality-right harm is serious, consider civil injunctive relief. Indian courts have increasingly granted orders against AI-generated impersonation, deepfakes and voice cloning.
- Do not rely only on an AI-detection website. Preserve the original media and chain of custody for forensic examination.
If the deepfake is linked to a cyber-fraud transaction, also read our Cyber Financial Fraud Recovery in India 2026. For the distinction between NCRP reporting and FIR registration, see our Cybercrime Complaint vs FIR guide.
1. What Is a Deepfake Under Indian Law in 2026?
The February 2026 IT Rules amendments introduced a statutory concept of synthetically generated information. Rule 2(1)(wa), as amended, covers audio, visual or audio-visual information that is artificially or algorithmically created, generated, modified or altered using a computer resource so that it appears real, authentic or true and depicts a person or event in a manner likely to be perceived as indistinguishable from a natural person or real-world event.
This is broader than the colloquial term “deepfake.” It can include:
- AI-generated realistic video of a person saying something never said;
- voice cloning that reproduces a person’s voice and speaking style;
- AI-generated photographs portraying a person at an event that never occurred;
- synthetic news footage;
- morphed or manipulated audio-visual material made to appear genuine; and
- combined synthetic audio/video accompanied by misleading text intended to make the fabrication credible.
The Rules also exclude routine and good-faith editing that does not materially distort meaning, ordinary document formatting, accessibility improvements, translation, noise reduction and similar benign uses.
2. The 2026 IT Rules Changed the Deepfake Compliance Landscape
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 were notified on 10 February 2026 and came into force on 20 February 2026. They create a dedicated due-diligence framework for SGI.
The framework is significant for victims because it gives far greater legal structure to platform complaints involving synthetic impersonation, morphed media, fake voices and AI-generated content.
Key changes include:
- a statutory definition of SGI;
- specific due diligence for intermediaries that enable creation or dissemination of SGI;
- mandatory labelling and provenance requirements for permissible SGI;
- enhanced obligations for significant social media intermediaries;
- shorter grievance-redressal timelines;
- faster action on impersonation and morphed content; and
- stronger technical-verification duties.
3. Permitted AI Content and Unlawful Deepfakes Are Not the Same Thing
Indian law does not prohibit every AI-generated image, audio clip or video. Synthetic content can be lawful when it is not deceptive or otherwise unlawful and is handled in accordance with the applicable labelling and due-diligence rules.
The legal problem arises where synthetic media is used for conduct such as:
- impersonation;
- identity fraud;
- cheating;
- extortion;
- non-consensual intimate imagery;
- forgery of documents or electronic records;
- commercial misappropriation of personality attributes;
- defamation;
- public-order deception; or
- financial fraud.
Accordingly, the correct question is not merely “Was AI used?” It is: What was created, how was it represented, what was the intent, what harm was caused, and what did the recipient or platform understand it to be?
4. What Must Platforms Do About Synthetic Content?
New Rule 3(3) of the IT Rules creates due diligence obligations for intermediaries that enable or facilitate creation, generation, modification, publication, sharing or dissemination of SGI.
For lawful SGI, the Rules contemplate clear labelling and permanent metadata or technical provenance mechanisms, including unique identifiers to the extent technically feasible. The Rules also seek to prevent removal or suppression of SGI labels and provenance information.
For significant social media intermediaries, new Rule 4(1A) requires a user declaration about whether uploaded content is SGI and reasonable technical verification of that declaration before publication. Where the content is confirmed as SGI, it must carry a clear and prominent label.
5. Deepfake Takedown Timelines in 2026
The amended IT Rules materially shortened intermediary timelines. The precise route depends on the nature of the complaint and how the intermediary receives legal notice.
| Situation | Current Timeline | Practical Meaning |
|---|---|---|
| Ordinary grievance | 7 days | General user grievance disposal period under amended Rule 3(2)(a)(i) |
| Certain removal/disablement grievances linked to Rule 3(1)(b) | 36 hours | Expedited action for specified unlawful-content grievances |
| Complaint involving specified nudity, sexual content, impersonation or morphed content under Rule 3(2)(b) | 2 hours | Rapid victim-protection route |
| Actual knowledge through a court order or prescribed reasoned government intimation | 3 hours | Removal or disablement of specified unlawful information after formal actual knowledge |
A victim should therefore identify the specific rule relied upon rather than sending only a generic “please remove this” email.
6. Does a Deepfake Automatically Amount to a Criminal Offence?
No. Criminal liability depends on the facts. A labelled satirical AI image and a cloned voice used to induce a bank transfer are not legally equivalent.
Where a deepfake is used to deceive, impersonate, extort, intimidate or fabricate electronic records, several criminal provisions may become relevant.
7. Section 66C IT Act: Identity Theft
Section 66C of the Information Technology Act, 2000 punishes fraudulent or dishonest use of another person’s electronic signature, password or other unique identification feature.
It may become relevant where the fraud involves misuse of digital credentials or identity attributes falling within the provision. Not every voice clone or face imitation automatically fits Section 66C, so the ingredients should be pleaded carefully.
8. Section 66D IT Act: Cheating by Personation Using a Computer Resource
Section 66D is particularly relevant to AI-enabled impersonation. It punishes cheating by personation through a communication device or computer resource.
Common examples may include:
- a cloned CEO voice directing the finance team to transfer money;
- a fake video call posing as a police officer;
- a synthetic celebrity video promoting a fraudulent investment platform;
- a fake family-member voice requesting emergency funds; or
- an AI-generated profile used to deceive a victim into sending money.
9. BNS Section 319: Cheating by Personation
Section 319 of the Bharatiya Nyaya Sanhita, 2023 applies where a person cheats by pretending to be another person or by representing one person to be someone else. The provision expressly covers personation of a real or imaginary person.
A deepfake that makes the victim believe they are dealing with a real executive, relative, police officer, regulator, celebrity or business counterparty can therefore raise a straightforward personation issue.
10. BNS Section 318(4): Cheating That Induces Delivery of Property
Section 318(4) is relevant where deception causes the victim to transfer money or deliver property. It applies where cheating dishonestly induces the deceived person to deliver property or deal with valuable security and carries a punishment that may extend to seven years together with fine.
In a financial deepfake case, this is often one of the most important BNS provisions because the fabricated voice, video or identity is the mechanism used to cause the monetary transfer.
11. BNS Sections 336 and 340: Forgery and Forged Electronic Records
Deepfakes can also intersect with forgery law where a false document or false electronic record is created or used as genuine.
Section 336 covers forgery, including making a false electronic record with intent to cause damage, support a claim, induce a person to part with property or commit fraud. Where the forgery is intended for cheating, the punishment may extend to seven years and fine.
Section 340 addresses forged documents and electronic records and punishes fraudulent or dishonest use of a forged document or electronic record as genuine in the same manner as if the person had forged it.
This can become significant where fraudsters circulate fabricated warrants, court orders, bank notices, police notices, identity cards or official electronic communications along with AI-generated audio or video.
12. Criminal Intimidation and Extortion
Deepfake scams often use fear. Section 351 BNS defines criminal intimidation to include threats to person, reputation or property made with intent to cause alarm or compel an act the victim is not legally bound to perform.
Where money is demanded through threats, extortion provisions may also be examined. The exact section and sub-section depend on the nature of the threat and resulting delivery.
This is especially common in fake-police, sextortion and fabricated-investigation scams.
13. Deepfakes and the “Digital Arrest” Scam
Deepfake technology can make digital-arrest fraud more convincing by generating fake police officers, cloned voices, synthetic court-room backgrounds and fabricated official documents.
There is no concept of “digital arrest” under Indian law. I4C has expressly warned that real law-enforcement agencies do not arrest people digitally. Fraudsters commonly impersonate police, CBI, ED, NCB, RBI or other authorities and pressure victims to remain on video calls while transferring money.
Fastrack already has a dedicated guide on Digital Arrest Scam in India.
14. Deepfake Voice Fraud: The CEO, Family-Member and Vendor Scenarios
Voice cloning is one of the most difficult frauds to detect because a victim may hear a familiar voice and react before verifying the request.
Common scenarios include:
- “The CEO” urgently directs a finance employee to transfer funds;
- “A child or spouse” says they have been arrested or injured and need money;
- “A vendor” sends changed bank details supported by a cloned voice confirmation;
- “A director” approves a confidential transaction through an apparent voice note;
- “A bank officer” requests verification through a fake audio/video interaction.
Businesses should therefore never treat voice or video familiarity as sufficient payment authority.
15. Corporate Control: How Businesses Should Prevent AI Impersonation Fraud
The strongest defence is procedural, not technological.
For high-value or unusual payments, businesses should require:
- dual approval;
- verification through a known callback number;
- confirmation inside an authenticated ERP or banking workflow;
- independent verification of changed beneficiary details;
- payment thresholds requiring additional approval;
- prohibition on approving payments solely through WhatsApp, voice note or video call;
- training on deepfake indicators;
- incident-response escalation to legal, finance and information security; and
- immediate contact with the bank and 1930 after suspected fraud.
16. Deepfake Investment Advertisements and False Endorsements
A common fraud pattern uses a manipulated video of a public figure, business leader or financial commentator to falsely endorse an investment, trading app, cryptocurrency opportunity or “guaranteed return” scheme.
The legal issues may include cheating, personation, platform due diligence, personality/publicity rights, trademark or passing-off issues, and financial-sector regulation depending on the product promoted.
A victim should preserve both the advertisement and the destination website or app. Often, the deepfake advertisement disappears quickly while the payment infrastructure remains active.
17. Deepfake Pornography and Non-Consensual Intimate Imagery
AI-generated intimate or sexual content requires urgent action. The applicable criminal provisions depend on the content, victim, manner of dissemination and whether a child is involved. The IT Rules also provide an expedited grievance mechanism for specified nudity, sexual, impersonation and morphed content.
The victim should:
- capture URLs and screenshots without repeatedly forwarding the content;
- record usernames, platform IDs and timestamps;
- submit the platform’s dedicated impersonation/intimate-content complaint;
- make a cybercrime/police complaint;
- seek preservation of uploader/subscriber data;
- consider urgent injunctive relief where circulation is extensive; and
- avoid public reposting of the impugned material merely to prove that it exists.
18. Civil Injunctions and Personality Rights
Criminal proceedings are not the only remedy. Indian courts have increasingly protected name, image, likeness, voice and other identifiable personality attributes against unauthorised AI exploitation.
In Aman Gupta v. John Doe/Ashok Kumar (Delhi High Court, 7 May 2026), interim relief restrained unauthorised AI use of the plaintiff’s name, image, video, likeness and voice and directed removal of identified material and disclosure of account information by platforms.
In Dr. Aniruddha Dhairyadhar Joshi v. John Does (Delhi High Court, 24 February 2026), the Court dealt with deepfake images, voice-cloned audio and fabricated AI material, directed removal of identified content and ordered disclosure of available basic subscriber information in relation to offending accounts.
These cases demonstrate that victims can seek remedies beyond damages: takedown, blocking, restraint on further AI exploitation and identification of anonymous uploaders may all become relevant depending on the facts.
19. But Courts Will Still Balance Free Speech
Deepfake disputes are not automatically decided in favour of anyone who dislikes a manipulated image. Satire, political criticism, parody and lawful creative expression raise constitutional free-speech considerations.
In Raghav Chadha v. Ashok Kumar/John Doe (Delhi High Court, 1 July 2026), the Court emphasised the need to balance reputation and dignity against free speech and declined to treat all impugned political content alike. It restrained only identified content that crossed the Court’s threshold on the facts before it.
Accordingly, a victim seeking an injunction should identify precisely why the content is deceptive, defamatory, commercially exploitative, intimate, fraudulent or otherwise unlawful. A request to suppress all criticism is legally very different from a request to remove a fabricated voice clone used to deceive the public.
20. Platform Complaint vs Court Order: Which Is Better?
They serve different purposes.
Platform complaint
- fast;
- low cost;
- can trigger the 2026 IT Rules timelines;
- useful for obvious impersonation and morphed content.
Court order
- useful where the platform disputes illegality;
- can restrain the creator directly;
- can support identification/disclosure orders;
- can cover mirrored or repeated content in appropriate cases;
- may enable formal “actual knowledge” takedown obligations.
In serious cases, both routes may run simultaneously.
21. What Evidence Should Be Preserved?
Deepfake cases are evidence-sensitive because posts can disappear and metadata can be altered.
Preserve at least:
- full URL of each post;
- username and profile link;
- platform post ID;
- date and time first seen;
- screenshots showing the account, caption and content;
- screen recording showing navigation to the post;
- original downloaded media file where lawfully available;
- file hash;
- email headers and message metadata;
- WhatsApp/Telegram/Signal identifiers;
- call logs and phone numbers;
- payment UTRs and bank statements;
- website domain and WHOIS information where available;
- advertisement IDs;
- platform grievance reference numbers;
- responses from the platform; and
- police/NCRP complaint numbers.
Where litigation is contemplated, maintain a clear chain of custody.
22. Is a Screenshot Enough?
A screenshot is useful but should not be the only evidence where better material exists. It may not show the full URL, metadata, account history, source file or surrounding context.
A stronger evidence package includes the screenshot plus URL, screen recording, downloaded file, hash value, device details and the relevant certificate for electronic evidence under the Bharatiya Sakshya Adhiniyam, 2023 where required.
23. Should You Use an Online Deepfake Detector?
AI-detection tools can be useful as an investigative lead, but their result should not be treated as conclusive forensic proof. Detection models can produce false positives and false negatives, particularly after compression, screen recording, re-encoding or repeated social-media uploads.
For important litigation or criminal investigation, preserve the media and obtain forensic analysis appropriate to the case.
24. How to File a Cybercrime Complaint for a Deepfake
A complaint should clearly explain:
- who is being impersonated;
- what content was created;
- where it was published or communicated;
- why it is false or unauthorised;
- whether money was demanded or transferred;
- whether threats were made;
- whether fabricated documents or electronic records were used;
- what usernames, phone numbers, email addresses, domains and bank accounts are involved;
- what immediate preservation or blocking action is needed; and
- which documents and electronic evidence are attached.
If money has already been transferred, use 1930 and the National Cyber Crime Reporting Portal immediately in addition to contacting the bank.
25. NCRP Complaint Does Not Automatically Replace an FIR
Reporting through 1930 or NCRP is critical for financial-cyber-fraud response, but a portal complaint is not automatically identical to registration of an FIR. If the facts disclose a cognizable offence, the police-registration process under Section 173 BNSS remains relevant.
If registration is refused, the complainant can use the statutory escalation route. See the detailed procedure in our Cybercrime Complaint vs FIR in India 2026.
26. How 1930 Helps in a Deepfake Financial Fraud
When a deepfake causes an immediate financial transfer, time is crucial. The purpose of the financial-cyber-fraud reporting system is to create rapid coordination between law-enforcement agencies, banks, payment intermediaries and other entities so that available funds can be identified and held before they move through additional accounts.
Do not wait to finish a detailed legal notice before reporting the transaction. Make the rapid report first, then supplement it with documentation.
27. What Should a Platform Takedown Notice Contain?
A useful notice should identify:
- the exact URL;
- the account/handle;
- the victim’s identity;
- the precise impersonated attribute—face, voice, image, name or video;
- the reason the content is synthetic or morphed;
- the unlawful purpose or resulting harm;
- whether Rule 3(2)(b) expedited action is invoked;
- whether the content is part of financial fraud or extortion;
- request for removal/disablement;
- request for preservation of subscriber and technical information; and
- police/NCRP reference, if already available.
28. Should the Victim Ask the Platform to Preserve Data?
Yes. Takedown and evidence preservation are separate objectives. A victim may want the content removed immediately while still requiring the platform to preserve:
- basic subscriber information;
- email address;
- phone number;
- IP logs;
- upload timestamps;
- device/session identifiers where lawfully available;
- payment or advertising account information; and
- content metadata.
Disclosure itself may require police process or a judicial order depending on the information and applicable law.
29. What If the Deepfake Is Hosted Outside India?
Cross-border hosting does not necessarily defeat Indian remedies where the harm, victim, transaction or publication has a sufficient Indian nexus. However, enforcement can become more complex where the uploader, hosting provider, domain registrar or platform entity is located abroad.
In such cases, preserve:
- domain registrar details;
- hosting provider information;
- platform entity;
- server or IP data where available;
- payment-processor information;
- advertising account details;
- transaction trail; and
- all Indian points of contact.
30. Employer and Board-Level Deepfake Incident Protocol
Companies should establish a written response protocol before an incident occurs.
- Freeze suspicious payments.
- Alert the bank and payment gateway.
- Call 1930 for financial loss.
- Preserve the synthetic audio/video and communication trail.
- Verify whether the apparent executive actually made the request.
- Disable compromised accounts.
- Notify information security, legal and senior management.
- File police/NCRP complaints.
- Send platform takedown/preservation requests.
- Consider employee/customer notification if the deepfake continues circulating.
- Review whether personal data or credentials were compromised.
- Document the event for insurance, audit and regulatory purposes.
31. Common Mistakes Victims Make
- Deleting the message before preserving it.
- Forwarding the deepfake widely and increasing circulation.
- Waiting several days before calling 1930 after financial loss.
- Filing a vague police complaint without URLs, usernames or transaction details.
- Assuming platform removal means subscriber evidence has been preserved.
- Relying exclusively on a screenshot.
- Assuming every AI-generated parody is criminal.
- Trying to privately negotiate with anonymous fraudsters.
- Paying a second “verification” or “release” amount.
- Ignoring possible compromise of email, social-media or bank credentials.
32. 2026 Legal Position: What Has Actually Changed?
The most important changes are these:
- Deepfakes now sit within a specific SGI framework under the amended IT Rules.
- Platforms face substantially shorter grievance and takedown timelines.
- Significant social-media platforms have stronger declaration and verification obligations for SGI.
- Permissible synthetic media should carry labels and provenance information.
- Courts are increasingly willing to grant targeted protection against voice cloning, AI impersonation and deepfake misuse.
- At the same time, courts continue to protect satire, criticism and lawful expression, particularly involving public figures.
Frequently Asked Questions
Is creating a deepfake illegal in India?
Not every synthetic image, video or audio clip is unlawful. Liability depends on content, purpose, representation and harm. Deceptive impersonation, fraud, non-consensual intimate imagery, forgery and extortion can attract serious legal consequences.
Can I force Instagram, Facebook, YouTube or X to remove a deepfake?
The IT Rules provide grievance mechanisms and specific expedited timelines for certain content. If the platform does not act or the issue is disputed, police or judicial remedies may also be available.
How fast must impersonation or morphed content be removed?
Under amended Rule 3(2)(b), specified complaints involving categories such as impersonation and morphed content carry a two-hour removal/disablement timeline. The precise facts must fit the Rule.
What if the content is removed but keeps reappearing?
Preserve each new URL. Depending on the case, a court may grant targeted relief concerning identified content, repeat links, fake accounts or disclosure of subscriber information.
Can a cloned voice amount to cheating?
Yes, where it is used to deceive a person into transferring money or taking an action they would not otherwise take. Sections 318/319 BNS and Section 66D IT Act may become relevant depending on the facts.
Can I file both a cybercrime complaint and a civil suit?
Yes. Criminal investigation, platform takedown and civil injunctive relief serve different purposes and may proceed simultaneously where legally maintainable.
Should I call 1930 for a deepfake?
Call 1930 immediately where the deepfake is connected to financial cyber fraud or money transfer. For non-financial deepfake abuse, use the NCRP/police and platform complaint mechanisms as appropriate.
Are AI labels compulsory in 2026?
The February 2026 amendments introduced labelling and provenance obligations for permissible SGI in the situations covered by the Rules, with enhanced obligations for significant social media intermediaries.
Can a public figure stop all AI memes and satire?
No. Courts must balance personality, dignity and reputation against freedom of speech. Targeted unlawful impersonation, fraud and false commercial endorsement are very different from legitimate satire or criticism.
Key Takeaways
Deepfake disputes in India now involve a combination of criminal law, cyber law, intermediary regulation, electronic evidence, platform procedure and civil injunctive remedies.
The practical sequence is usually:
Preserve evidence → stop any financial loss → call 1930 if money moved → file NCRP/police complaint → invoke the correct platform grievance rule → seek preservation of uploader data → consider civil injunction where necessary.
The most significant regulatory development is the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, which introduced the SGI framework and substantially tightened platform response obligations.
Authoritative Sources
- MeitY — IT Rules, 2021 as amended in 2026
- Information Technology Act, 2000 — India Code
- Bharatiya Nyaya Sanhita, 2023 — India Code
- National Cyber Crime Reporting Portal
- Aman Gupta v. John Doe/Ashok Kumar — Delhi High Court, 7 May 2026
- Dr. Aniruddha Dhairyadhar Joshi v. John Does — Delhi High Court, 24 February 2026
Disclaimer
This article is for general legal information and educational purposes only. It does not constitute legal advice, advertisement or solicitation. Deepfake and AI-impersonation disputes are fact-sensitive, and the applicable criminal provisions, platform obligations, jurisdiction and evidentiary requirements depend on the actual content, transaction, victim, intermediary and investigation.