Deepfake Pornography: Is Indian Law Prepared for Digital Identity Theft?

Abstract

The emergence of generative artificial intelligence has given rise to “deepfakes” — synthetic audio-visual content that convincingly superimposes one person’s likeness onto another’s body or voice. While deepfake technology has legitimate applications in entertainment and education, its most damaging misuse has been the creation of non-consensual pornographic content depicting real, identifiable individuals, predominantly women. This article examines whether India’s legal framework is adequately equipped to address deepfake pornography as a form of digital identity theft. It analyses the relevant provisions of the Information

Technology Act, 2000, the Bharatiya Nyaya Sanhita, 2023, the Digital Personal

Data Protection Act, 2023, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, including their 2025 amendments. The article further examines emerging judicial responses, including the Delhi High Court’s recognition of “personality rights” in Anil Kapoor v. Simply Life India and subsequent petitions by Aishwarya Rai Bachchan and other public figures, situating these developments against the constitutional foundation laid in Justice K.S. Puttaswamy v. Union of India. The article concludes that while India possesses a patchwork of applicable provisions, it lacks a dedicated, victim-centric statutory framework that treats deepfake pornography as a distinct offence of digital identity theft, and proposes specific legislative reforms.

Keywords: deepfake pornography, digital identity theft, personality rights,

Information Technology Act, Bharatiya Nyaya Sanhita, informational privacy

I. Introduction

In November 2023, a deepfake video depicting actress Rashmika Mandanna’s face superimposed onto another woman’s body circulated widely across Indian social media, drawing condemnation from the Union government and reigniting a long-overdue conversation about the legal status of synthetic, non-consensual sexual imagery in India.1 The incident was not isolated — it was symptomatic of a rapidly escalating phenomenon in which artificial intelligence tools, many freely available online, are being used to fabricate sexually explicit material depicting real individuals without their knowledge or consent.

Unlike traditional image-based sexual abuse, which involves the non-consensual sharing of genuine intimate images, deepfake pornography involves the wholesale fabrication of an intimate scenario that never occurred. The victim’s face — their digital identity — is appropriated and grafted onto pornographic content, creating a permanent, searchable, and shareable artefact that misrepresents their body, their choices, and their consent. This is, in a very real sense, a theft of identity: the unauthorised use of a person’s likeness to construct a false reality attributed to them.

This article asks a focused question: is Indian law, as it currently stands, prepared to recognise, prevent, and remedy this form of digital identity theft? To answer this, the article proceeds in five parts. Part II briefly explains the technology and the scale of misuse. Part III maps the existing statutory framework. Part IV analyses judicial responses to date. Part V identifies persisting gaps, and Part VI offers recommendations grounded in comparative practice.

II. Understanding Deepfake Technology and Its Misuse

Deepfakes are produced using deep learning techniques — most commonly generative adversarial networks (GANs) or diffusion models — that are trained on images, video, or audio of a target individual to generate synthetic media in which that person appears to say or do something they never did.2 The technology’s barrier to entry has fallen dramatically: applications that once required specialist technical knowledge are now accessible through consumer-grade mobile applications and websites, several of which are marketed explicitly for the creation of non-consensual sexual imagery.3

Empirical surveys cited in recent Indian legal scholarship indicate that the overwhelming majority of deepfake content circulating online is pornographic in nature and disproportionately targets women — film actors, social media influencers, journalists, and increasingly, private individuals including college students.4 The harm is not merely reputational. Victims report psychological trauma, professional consequences, harassment, and in some cases, extortion, where perpetrators threaten to circulate fabricated content unless payment is made.5

What distinguishes this harm from earlier forms of online abuse is the plausibility of the content. A deepfake does not merely allege something about a person — it appears to show it happening, exploiting the evidentiary weight that moving images have traditionally carried in human perception and, often, in legal proceedings.

III. The Existing Legal Framework in India

India does not, at present, have a standalone “deepfake law.” Instead, victims and prosecutors must rely on a combination of provisions originally drafted for other purposes — chiefly obscenity, privacy violation, and identity theft — supplemented by a 2025 regulatory amendment that, for the first time, defines “synthetically generated information.”

A. The Information Technology Act, 2000

Several provisions of the IT Act have been judicially and academically recognised as applicable to deepfake pornography.

Section 66C (Identity Theft): Punishes the fraudulent or dishonest use of another person’s “electronic signature, password or any other unique identification feature,” with imprisonment of up to three years and a fine of up to ₹1 lakh. While the provision was drafted with credential theft in mind, commentators argue that a person’s face and voice — captured and reused by AI to misrepresent their identity — constitute a “unique identification feature” within the spirit, if not the explicit letter, of the section.6

Section 66E (Violation of Privacy): Criminalises the capture, publication, or transmission of an image of a person’s “private area” without consent, in circumstances violating privacy, punishable with up to three years’ imprisonment and a fine of up to ₹2 lakh.7 Although the provision presumes an underlying genuine image was captured, several commentators contend it can extend to synthetic depictions that purport to show a person’s body, given the provision’s focus on the violation of the person’s reasonable expectation of privacy rather than the means of creation.

Sections 67 and 67A (Obscenity and Sexually Explicit Material): Section 67 punishes the publication or transmission of obscene material in electronic form with imprisonment of up to three years for a first conviction, while Section 67A specifically targets sexually explicit material, prescribing imprisonment of up to five years and a fine of up to ₹10 lakh.8 These provisions form the principal criminal charge in most reported deepfake pornography FIRs, though they were designed to address obscenity generally and do not require proof that the depicted person did not consent to being depicted — only that the material is obscene.

Section 69A: Empowers the Central Government to direct blocking of public access to information, including deepfake content, in the interest of sovereignty, security, public order, or to prevent incitement to a cognisable offence.9

B. The Bharatiya Nyaya Sanhita, 2023

The BNS, which replaced the Indian Penal Code, 1860, with effect from 1 July 2024, retains provisions analogous to the IPC’s offences of defamation, criminal intimidation, and outraging the modesty of a woman, which prosecutors continue to invoke alongside IT Act charges in deepfake pornography cases.10 However, the BNS does not introduce any provision specifically addressing AI-generated or synthetic content, representing a missed legislative opportunity at the very moment India was overhauling its core criminal code.

C. The Digital Personal Data Protection Act, 2023

The DPDP Act, India’s first comprehensive data protection statute, introduces consentbased processing obligations modelled loosely on the EU’s General Data Protection Regulation.11 However, as several scholars have observed, the Act is concerned primarily with the processing of personal data by data fiduciaries in commercial contexts, and does not squarely address the generation of synthetic biometric likenesses by individuals using publicly available images — a gap that leaves a significant category of deepfake creation outside its scope.12

D. The IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the 2025 Amendments

Under the 2021 Rules, intermediaries are required to act on complaints regarding nonconsensual sexual imagery within 24 hours and other unlawful content within 36 hours of notification, failing which they risk losing the “safe harbour” immunity from liability under Section 79 of the IT Act.13

On 22 October 2025, the Ministry of Electronics and Information Technology notified amendments to the 2021 Rules that, for the first time, define “synthetically generated information” and impose labelling obligations on platforms and creators of AI-generated content, requiring prominent, machine-readable identification of such content.14 These amendments — which came into force on 15 November 2025 — represent India’s first explicit regulatory acknowledgment of synthetic media as a distinct category, though they primarily impose transparency obligations rather than creating a new criminal offence specific to non-consensual deepfake pornography.

IV. Judicial Responses: Emerging Case Law

In the absence of dedicated legislation, Indian courts — particularly the Delhi High Court — have begun to develop a body of jurisprudence around “personality rights” that bears directly on the deepfake pornography problem, even where the underlying petitions concern commercial misuse rather than explicit content.

A. Anil Kapoor v. Simply Life India & Ors. (Delhi High Court, 2023)

In September 2023, the Delhi High Court granted an ex-parte, omnibus injunction in favour of actor Anil Kapoor against sixteen defendants who had used AI tools, face-morphing, and deepfake technology to misuse his name, image, voice, and well-known catchphrases for commercial gain.15 Justice Prathiba M. Singh held that the unauthorised use of a celebrity’s persona through AI tools constituted actionable torts of dilution and tarnishment, observing that the court “can’t turn a blind eye to such misuse.”16 The order directed domain registrars to take down infringing websites and restrained “the world at large” — including unknown future infringers — from similar misuse.

While Anil Kapoor did not involve pornographic content, its significance for deepfake pornography lies in its judicial recognition that AI-generated misappropriation of a person’s image, voice, and likeness — independent of any underlying copyrighted work — gives rise to an actionable legal injury. This reasoning provides a doctrinal foundation that could, in principle, extend to non-consensual sexual deepfakes, where the dignitary harm is considerably more severe.

B. Aishwarya Rai Bachchan v. [Defendants] (Delhi High Court, 2025, pending)

In late 2025, actor Aishwarya Rai Bachchan approached the Delhi High Court after AIgenerated content using her likeness was found circulating online, including content her counsel described as being used “to satisfy someone’s sexual desires.”17 The Court orally indicated its intention to grant an ad-interim injunction restraining further dissemination pending final hearing. This petition is significant as one of the first instances in which a deepfake pornography grievance involving a public figure has been explicitly placed before the Delhi High Court within the personality rights framework established in Anil Kapoor, with the matter scheduled for further hearing in January 2026.

C. The Constitutional Foundation: Justice K.S. Puttaswamy (Retd.) v. Union of India (Supreme Court, 2017)

Although decided years before the current wave of generative AI tools, the Supreme Court’s nine-judge bench decision in Puttaswamy remains the constitutional bedrock for any deepfake-related claim. The Court unanimously held that the right to privacy is a fundamental right protected under Articles 14, 19, and 21 of the Constitution, and — crucially for the deepfake context — that “informational privacy” is a distinct facet of this right, encompassing an individual’s entitlement to control the dissemination of information about themselves.18 The judgment further recognised that privacy harms may arise from non-State actors, not merely from government action — a holding of direct relevance to deepfake pornography, which is overwhelmingly perpetrated by private individuals using privately-operated platforms.19

Legal commentators have argued that Puttaswamy’s recognition of “informational selfdetermination” provides the conceptual vocabulary needed to characterise deepfake pornography as a violation of a person’s right to control their own digital identity — even where no specific statute uses that language.20

D. Reported FIRs and the Limits of Lower Court Practice

Beyond these high-profile petitions, Indian police have registered numerous First Information Reports concerning deepfake pornography targeting film actors, social media influencers, journalists, and private individuals, typically invoking Sections 66C, 66E, and 67/67A of the IT Act alongside provisions relating to defamation and outraging modesty under the BNS.21 However, legal commentators note that “comprehensive precedents are still developing” at the trial court level, and that the patchwork application of generalist provisions has produced inconsistent charging practices and, in many instances, slow or ineffective takedown of content despite the timelines prescribed under the 2021 Intermediary Rules.22

V. Gaps and Challenges

Drawing on the above analysis, at least four structural gaps emerge.

First, no statutory definition of “deepfake” or “non-consensual synthetic intimate imagery” existed prior to November 2025. Until the 2025 amendments, Indian law contained no definition of AI-generated content, forcing prosecutors to characterise deepfakes under provisions — obscenity, privacy violation, identity theft — none of which were drafted with synthetic media in mind. Even the 2025 amendments focus on labelling and transparency rather than creating a specific offence of non-consensual synthetic sexual depiction.

Second, the “identity theft” framing under Section 66C remains under-utilised. Despite the conceptual fit between deepfake pornography and identity theft — the unauthorised appropriation of a person’s face to construct a false narrative — Section 66C has rarely been the primary charge in reported deepfake pornography cases, which instead default to obscenity provisions under Sections 67/67A. This under-utilisation means the identity-based dimension of the harm — as opposed to its merely “obscene” character — is often legally invisible, even though it is, for many victims, the more significant violation.

Third, personality rights jurisprudence remains accessible primarily to celebrities. The injunctive relief secured in Anil Kapoor and sought by Aishwarya Rai Bachchan required engagement of senior counsel and the resources to litigate before the Delhi High Court. Private individuals — including the “women students and private individuals” referenced in recent surveys of FIR data — typically lack comparable access to swift civil remedies and must rely on local police stations and cybercrime cells, where capacity to investigate AI-generated content remains limited.23

Fourth, cross-border enforcement and platform accountability remain weak. Many deepfake generation tools and hosting platforms operate from outside India’s jurisdiction. While Section 69A empowers blocking of access within India, it does not address the underlying creation or cross-border hosting of such content, and the 36-hour takedown obligation under the Intermediary Rules has, in practice, been inconsistently enforced.24

VI. Comparative Perspectives and Recommendations

Other jurisdictions provide instructive models. In the United States, the federal TAKE IT DOWN Act, enacted in 2025, criminalises the non-consensual publication of explicit deepfakes and imposes a 48-hour removal obligation on platforms upon victim notification.25 The European Union’s AI Act mandates watermarking and disclosure of AI-generated content, while China’s Cyberspace Administration regulations of 2023 require labelling of synthetic media and prohibit unlawful deepfakes outright.26

Based on this comparative survey and the gaps identified above, this article proposes the following reforms for India.

First, the Bharatiya Nyaya Sanhita or the IT Act should be amended to create a specific offence of “non-consensual creation or distribution of synthetic intimate imagery,” distinct from general obscenity provisions, with sentencing that reflects the dignitary and identity-based nature of the harm rather than treating it merely as a pornography offence.

Second, Section 66C should be explicitly amended to clarify that a person’s facial image, voice, and biometric likeness constitute a “unique identification feature” for the purposes of identity theft, formally recognising deepfake pornography as a species of digital identity theft.

Third, the personality rights doctrine articulated in Anil Kapoor should be codified into statute, with a simplified, low-cost mechanism — potentially through dedicated cybercrime tribunals — enabling private individuals, not only celebrities, to obtain rapid injunctive relief and mandatory takedown orders.

Fourth, building on the November 2025 labelling requirements, platforms should be statutorily required to deploy proactive detection technology for known deepfake signatures, with safe harbour protection made conditional on demonstrable investment in such detection — following the trajectory already signalled by commentary on significant social media intermediaries’ obligations under Rule 7.27

VII. Conclusion

India’s legal system is not wholly unprepared for deepfake pornography — provisions exist that can be, and have been, invoked. Yet “not wholly unprepared” is a considerably weaker position than “adequately prepared.” The current framework is reactive, fragmented across statutes never designed for synthetic media, and accessible in practice primarily to those with the resources to litigate in the higher judiciary. The 2025 amendments to the Intermediary

Guidelines mark a genuine, if partial, step forward — but transparency and labelling obligations address the spread of deepfakes, not their creation, and do little to redress the identity-based violation at the heart of the harm.

The constitutional foundation laid in Puttaswamy — recognising informational privacy and self-determination as facets of the right to life and personal liberty — together with the personality rights jurisprudence emerging from Anil Kapoor and the pending Aishwarya Rai Bachchan petition, provides Indian courts with the conceptual tools to treat deepfake pornography as what it fundamentally is: a theft of digital identity. What remains absent is a legislature willing to translate that conceptual recognition into a clear, accessible, and adequately punitive statutory offence — one that does not require a victim to be a Bollywood star to obtain swift and meaningful relief.

Footnotes

  1. asia (2026) describes the viral circulation of a deepfake video of actress Rashmika

Mandanna in 2023 and the public concern that followed. See Law.asia (2026).

  1. See generally Chesney & Citron (2020) on the mechanics of generative adversarial networks and synthetic media production.
  2. See O’Flaherty (2024) on the proliferation of consumer-grade AI deepfake applications marketed for non-consensual sexual imagery.
  3. Legal Blur (2025) notes that FIRs registered between 2023 and 2025 predominantly involved “Bollywood and Tollywood actresses, women students and private individuals, and influencers and journalists.”
  4. See Öhman (2021) on the use of deepfakes for extortion and financial fraud.
  5. Information Technology Act, 2000, § 66C (India); see also Jus Corpus (2025) for the argument that facial and vocal likeness may constitute a “unique identification feature.”
  6. Information Technology Act, 2000, § 66E (India).
  7. Information Technology Act, 2000, §§ 67, 67A (India); see also Jus Corpus (2025).
  8. Information Technology Act, 2000, § 69A (India).
  9. Bharatiya Nyaya Sanhita, 2023, Act No. 45 of 2023 (India), in force from 1 July 2024.
  10. Digital Personal Data Protection Act, 2023, Act No. 22 of 2023 (India).
  11. See Record of Law (2025) for an analysis of the gap between the DPDP Act’s consent-based processing framework and AI-generated synthetic likenesses.
  12. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules,

2021, r 3(2)(b), r 7 (India); see also Chambers Expert Focus (2025/2026).

  1. Ministry of Electronics and Information Technology (2025); see also Khurana & Khurana

(2025) for a summary of the labelling obligations introduced by the 2025 amendments.

  1. Anil Kapoor v. Simply Life India & Ors., CS(COMM) 652/2023 (Delhi High Court, Sept. 20,

2023); see also Voicebot.ai (2023).

  1. Justice Prathiba M. Singh’s remarks are reported in Cryptonews (2023).
  2. See Gulf News (2025/2026) for details of the pending petition filed by Aishwarya Rai

Bachchan before the Delhi High Court.

  1. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 (Supreme Court of

India).

  1. See The Legal Journal on Technology (2026) for the argument that Puttaswamy’s recognition of informational self-determination extends to deepfake-based identity misuse.
  2. The Legal Journal on Technology (2026).
  3. See Legal Blur (2025).
  4. See LawArticle (2025) on the inconsistent application of IT Act provisions in trial court practice.
  5. See Legal Blur (2025).
  6. See Chambers Expert Focus (2025/2026) on intermediary obligations under Rule 7 of the IT

Rules, 2021.

  1. See Record of Law (2026) on the U.S. TAKE IT DOWN Act, 2025.
  2. See Record of Law (2026) on the EU AI Act, 2024, and the Cyberspace Administration of China’s Interim Measures for the Management of Generative Artificial Intelligence Services, 2023.
  3. See Chambers Expert Focus (2025/2026).

 

References

Anil Kapoor v. Simply Life India & Ors., CS(COMM) 652/2023 (Delhi High Court, Sept. 20,

2023).

Bharatiya Nyaya Sanhita, 2023, Act No. 45 of 2023 (India).

Chambers Expert Focus. (2025/2026). How India is challenging deepfakes. Chambers and

Partners. https://chambers.com/legal-trends/controlling-deepfakes-in-india

Chesney, R., & Citron, D. (2020). Disinformation machines: The threat of deepfake technology.

National Security Journal.

Cryptonews. (2023, September 22). ‘Not only me’: Actor Anil Kapoor wins AI deepfake court case. https://cryptonews.net/news/other/25996940/

Digital Personal Data Protection Act, 2023, Act No. 22 of 2023 (India).

Gulf News. (2025/2026). Aishwarya Rai Bachchan moves Delhi High Court over misuse of her image by AI. https://gulfnews.com/amp/story/entertainment/aishwarya-rai-bachchanmoves-delhi-high-court-over-misuse-of-her-image-by-ai-1.500262186

Information Technology Act, 2000, No. 21, Acts of Parliament, 2000 (India).

Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021

(India), as amended 2025.

Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 (Supreme Court of India).

Jus Corpus. (2025). Legal challenges of deepfake technology and AI-generated content in India.

https://www.juscorpus.com/legal-challenges-of-deepfake-technology-and-ai-generatedcontent-in-india/

Khurana & Khurana. (2025, December 16). Deepfake regulation India 2025: MeitY’s comprehensive IT Rules amendment. https://www.khuranaandkhurana.com/deepfakeregulation-india-2025-meity-s-comprehensive-it-rules-amendment

LawArticle. (2025, September 9). Deepfakes in India: A legal analysis of emerging challenges and regulatory framework. https://lawarticle.in/deepfakes-in-india-a-legal-analysis-ofemerging-challenges-and-regulatory-framework/

Law.asia. (2026, February 10). India tightens rules on deepfakes and AI-generated content.

https://law.asia/india-deepfake-regulations/

Legal Blur. (2025, December 8). Deepfakes regulation & digital identity in India.

https://legalblur.com/deepfakes-regulation-digital-identity-in-india/

Marico Ltd. v. Abhijeet Bhansali, Notice of Motion No. 96/2019 (Bombay High Court, Jan. 15,

2020) (India).

Ministry of Electronics and Information Technology. (2025, October 22). Explanatory note on amendments to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, concerning synthetically generated information. Government of India. https://www.meity.gov.in

O’Flaherty, K. (2024, February 8). Hackers are using AI deepfakes to bypass security—and it’s getting worse. Forbes.

Öhman, C. (2021). Deepfakes and financial fraud: The growing threat of AI-driven identity theft.

Journal of Cybersecurity Studies, 14, 57.

Record of Law. (2025, August 26). Regulating AI and the internet in India: Challenges of deepfakes and personality rights, comparative perspectives, and the road to reform. https://recordoflaw.in/regulating-ai-and-the-internet-in-india-challenges-of-deepfakesand-personality-rights-comparative-perspectives-and-the-road-to-reform/

Record of Law. (2026, February 11). AI and deepfake: Legal challenges.

https://recordoflaw.in/ai-and-deepfake-legal-challenges/

The Legal Journal on Technology. (2026, April 6). Deepfakes and dignity—Why Indian laws need reform against non-consensual AI-generated content beyond Section 67A.

https://www.thelegaljournalontechnology.com/post/deepfakes-and-dignity-why-indianlaws-need-reform-against-non-consensual-ai-generated-content-beyo

Voicebot.ai. (2023, September 25). Indian actor Anil Kapoor wins court order against unauthorized AI deepfakes. https://voicebot.ai/2023/09/25/indian-actor-anil-kapoor-winscourt-order-against-unauthorized-ai-deepfakes/

Deeksha Jadon
Author: Deeksha Jadon