Deepfakes & AI Impersonation: Legal Recourse and Rights for Victims of Synthetically Altered Videos
Examining India’s Constitutional Safeguards, Criminal Remedies, and Emerging Legal Framework Against AI-Generated Digital Manipulation
Author: Krushna Bawa, Student at DES’s Shri Navalmal Firodia Law College, Pune
Abstract:
Artificial Intelligence (AI) refers to technology allowing computers and machines to mimic human capabilities of learning, understanding, problem-solving, decision-making, creativity and artificial intelligence (AI), which refers to technology allowing computers and machines to mimic human capabilities of learning, understanding, problem-solving, decision-making, creativity and autonomy. Artificial Intelligence (AI) has revolutionized digital architecture by providing novel tools which can generate very realistic images, sounds and videos.
Deepfakes are artificial media created by using AI technology to make a person appear as if they have done something they never did. In many current deepfakes, methods such as voice imitation, simulated video calling, and artificial intelligence-created media are used in order to imitate the way people communicate. With the development of generative AI technology and availability of these techniques, there has been a significant surge in their usage to deceive identities at an enterprise level. Deep fakes constitute a distinct kind of AI-generated images which aim at mimicking a real person in order to deceive. They are usually face swapping, replicating the appearance of a certain person, or creating a visual that gives the impression that something was done by a real person when this is not true. Other AI-generated images are artificially created through text prompts such as fantasy art or stock-like photography. They are artificial images that do not pretend to represent real life.
India has seen an increasing trend of manipulation of digital media in the form of fake endorsements by celebrities, voice clonings, fake speeches, and artificial intelligence-generated intimate images of individuals without their consent. Such abuses in the system underline the importance of a sound legal framework which safeguards the citizens against highly sophisticated cybercrimes. In the absence of a dedicated law dealing with deepfake technology, Indian judicial system depends on constitutional rights, criminal laws, and IT rules.
The Constitution of India guarantees the right to life and personal liberty under Article 21, which the Supreme Court judicially interprets to encompass the rights to privacy, dignity, and reputation. Besides, there is a set of statutes that deal with issues of identity theft, cyber frauds, digital evidence, obscenity on the Internet, and intermediary liability, and these statutes are: the Information Technology Act, 2000; the Bharatiya Nyaya Sanhita, 2023 (BNS); the Digital Personal Data Protection Act, 2023 (DPDP Act); and the Intermediary Guidelines, 2021.
Even with these safety measures in place, several regulatory problems arise. Modern laws that have been developed prior to the emergence of generative artificial intelligence do not contain clear definitions of deepfake or any punishment for creating deepfake videos. This leads to the problems faced by litigants including procedural delays, difficulties establishing the identity of offenders, jurisdictional disputes in dealing with issues arising in a different country and general problems in seeking urgent injunction against the publication of deepfake videos.
The following article will analyse the legal avenues available to victims of deepfake and AI impersonation under the constitution and legislation of India. The effectiveness of principles of privacy, criminal law, cyber laws, and intermediary liability principles in solving the problem will be examined. In conclusion, the work will analyse important judicial precedents in this sphere, reveal existing gaps in regulation and call for legislative solutions to these problems.
Background and Legal Framework:
The Rise of Deepfakes and AI Impersonation:
Artificial Intelligence has redefined the process of creation and consumption in the present-day digital medium. Leveraging advanced machine learning algorithms, AI is capable of generating realistic images, sounds, and videos of actual humans. While it offers many commercial applications, such a swift development in technology creates a challenge for current law due to an increase in the number of deepfakes and impersonation through algorithms. Deepfakes involve the use of technology to generate fake audio or video content that resembles the physical attributes, facial expression, voice, and gestures of a particular individual. AI impersonation involves the utilization of voice cloning, artificial avatars, and fake digital personas to dupe individuals and accept AI generated content as real content.
As opposed to traditional image and video editing techniques, deepfake technology enables the generation of convincing synthetic material that becomes harder and harder to spot even using special forensic software. This way, victims suffer great damages until manipulated material is detected and taken down from digital platforms. The emergence of numerous social media sites, instant messaging apps, and artificial intelligence software has resulted in the spread of manipulated content within just a few minutes, leading to permanent damages to someone’s reputation, privacy, and mental state. These developments have shown the need for an effective legal mechanism that would protect victims and allow for technological advancements in artificial intelligence.
Constitutional Protection under the Constitution of India:
While the Constitution of India does not specifically mention artificial intelligence and deepfake technologies, there are several Fundamental Rights which provide a sound constitutional basis to safeguard victims from the menace of AI impersonations.
Article 14 – Equality Before Law:
Article 14 grants equal protection of laws and equal treatment by laws. All victims of impersonations through artificial intelligence, regardless of gender, occupation, or social standing, have an equal right to be safeguarded by the law against any illegal use of artificial intelligence. Thus, it becomes incumbent on the part of the state, constitutionally, to apply existing laws equitably in matters of digital identity thefts, online harassments, cybercrimes, and manipulation of media content.
Article 19(1) (a) – Freedom of Speech and Expression:
Every citizen has been given the freedom of speech and expression under Article (19) (1) (a). The use of Artificial Intelligence has certainly helped increase creative expression through digital communication, artistry, and education. It is necessary to note that such freedom is only limited to cases where no deception or harm is caused using AI against other people’s rights. The usage of deep fakes for disseminating misinformation or causing any reputational harm falls out of the ambit of constitutionally protected expression.
Article 19(2) – Reasonable Restrictions
Under Article 19(2), the State is permitted to place appropriate restrictions on free speech to protect public order, morality, decency, defamation, incitement, and national security. It follows that any malicious deepfake will certainly be covered under this constitutional provision where it causes any communal disturbance, political misinformation, hate speech, or defamatory content. It means that Article 19 creates a fine balance between protecting innovation and individual rights against algorithmic harm.
Article 21 – Right to Life and Personal Liberty
Article 21 is the most significant constitutional provision governing digital privacy.
The Supreme Court has consistently interpreted the expression “life and personal liberty” to include the rights to privacy, dignity, autonomy, identity, reputation, and informational self-determination. Deepfakes directly interfere with these constitutional values by enabling unauthorised digital manipulation of an individual’s identity. A synthetically altered video portraying a person engaging in acts that never occurred not only invades personal privacy but may also permanently damage social relationships, professional opportunities, and mental health. Consequently, Article 21 serves as the constitutional foundation for protecting victims of AI-generated impersonation.
Information Technology Act,2000
The Information Technology Act, 2000 functions as India’s primary legislation governing cybercrimes and electronic communication.
Section 66C – Liability under Identity Theft:
Section 66C provides penalties in cases of identity theft that involve the dishonest or fraudulent use of any other person’s electronic signature, password, or identification mark. It means that where parties resort to AI-generated content to impersonate humans for any fraudulent purpose, Section 66C comes into play.
Section 66D – Cheating by Personation
Section 66D criminalizes cheating by personation through the use of computer systems. Cases where the use of deep fake videos or cloned voices leads to deception for the transfer of funds, submission of private data, or fraud are offenses punishable under this section.
Sections 67 and 67A – Electronic Obscenity
The sections outlaw the publication or transmission of obscene or sexually explicit electronic data. The two sections are of significant jurisprudential importance when criminals spread unsolicited sexually explicit content generated using artificial intelligence technology.
Section 72 – Breach of Confidentiality
This section punishes any breach of confidentiality of electronic information against laws or contracts.
Digital Personal Data Protection Act (DPDA), 2023
The Digital Personal Data Protection Act, 2023 provides India with the basic legislative structure that regulates the automated processing of digital personal data. This legislative structure is premised on stringent standards of consent, legal processing, purpose limitation, and accountability. As creators generate deepfakes through the collation of digital personal data such as biometric images, voice recordings, and video footage sourced from the internet, the processing of such personal data without consent amounts to a violation of the statute. Additionally, the statute requires Data Fiduciaries to put in place robust mechanisms for protecting such personal data.
Bharatiya Nyaya Sanhita, 2023
The Bharatiya Nyaya Sanhita, 2023 is an important update to India’s substantive law structure with regards to criminal laws, as it helps provide an essential statutory tool to punish any crime which involves technology. In cases where the offenders use malicious deepfakes for crimes such as cheating, criminal impersonation, forgery of identity, extortion and electronic obscenity, these statutory provisions could be used alongside other laws relating to cybercrimes. The establishment of the BNS clearly shows the intentions of the legislature to strengthen criminal liability.
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
The Information Technology Rules, 2021 mandate that social media intermediaries and digital platforms undertake stringent due diligence. They have to ensure an efficient grievance redress mechanism, undertake a quick takedown of any illegal content received through valid legal notices, and cooperate fully with the investigations of law enforcement agencies. For deepfakes, quick response from intermediaries is essential in minimizing damage and preventing the spread of such content. Hence, these Rules bolster the primary IT Act through statutory accountability.
MAIN ANALYSIS AND CASE STUDIES
The fast-paced progress of Artificial Intelligence has highlighted many loopholes in existing legal systems. While there is no specific law in India which caters to deepfakes, there are constitutional laws which protect victims through privacy, dignity, freedom of expression, reputation, and electronic evidence. Judicial decisions, along with the Information Technology Act, 2000, the Bharatiya Nyaya Sanhita, 2023, and the Digital Personal Data Protection Act, 2023, constitute the basis of handling AI impersonation.
Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017):
Facts
Constitutionality of the Aadhaar scheme was challenged in the Supreme Court of India. One of the major questions that arose was whether the Constitution recognises privacy as a fundamental right.
Judgment
The nine-judge Constitution Bench declared that Right to Privacy is a fundamental right under Article 21 of the Constitution. The Court held that privacy is indispensable for human dignity, personal autonomy, bodily integrity and informational self-determination. Each individual has a right to assert control over personal data and prevent its abuse.
Legal Principle
In the judgment, it was ruled that privacy does not only relate to physical space but also includes individual’s digital identity, personal data, images, voice and other aspects of informational privacy.
Relation to Deepfakes
Deepfakes use photographs, videos, audio files and other data collected from individuals via social media and other online platforms without their consent. By using personal data in such way, creator violates individual’s informational privacy and dignity. Thus, constitutional principles enunciated in the case of Puttaswamy provide the most relevant legal grounds for protection of victims of deepfakes. Courts can base on this case when interpreting laws in order to protect digital identity and personal autonomy.
Shreya Singhal v. Union of India, (2015)
Facts
The petitioner raised the constitutional validity of Section 66A of the Information Technology Act, 2000 which according to him was an unreasonable restriction on the fundamental right to freedom of speech and expression because it criminalized vague online communications.
Judgment
The Supreme Court held Section 66A to be unconstitutional as it violated the right to freedom of speech and expression guaranteed under Article 19(1)(a). On the other hand, the validity of the intermediary liability regime under Section 79 of the Information Technology Act was upheld taking into account the due diligence of digital intermediaries.
Legal Principle
According to the judgment, while freedom of speech and expression is a fundamental right, the regulation of online content will be constitutionally valid provided that it falls within reasonable restrictions enumerated under Article 19(2).
Relation to Deepfakes
Deepfake creators often use freedom of expression as a defence for creating deepfake videos. However, the case of Shreya Singhal makes it quite clear that constitutional protection is available only to lawful content which is not violating any other fundamental right. Deepfakes created through artificial intelligence which are meant for defamation, harassment, deceit, or inciting violence can thus be lawfully restricted.
Anvar P.V. v. P.K. Basheer, (2014)
Facts
The matter related to the admissibility of electronic records in court. The Court decided whether electronic records were admissible without satisfying the provisions of Section 65B of the Indian Evidence Act, 1872 (now incorporated in the Bharatiya Sakshya Adhiniyam, 2023).
Judgment
The Supreme Court ruled that electronic records can only be admitted when the statutory provisions on electronic certification are fulfilled. The Court stressed that it was necessary to authenticate the records before using them in judicial proceedings.
Legal Principle
It is crucial to verify digital evidence since electronic records can be manipulated, altered, or forged.
Relation to Deepfakes
Deepfake cases are highly dependent on digital evidence. The Court needs to identify which videos are authentic and which are generated by AI. The ruling made in Anvar P.V. allows for proper verification of manipulated electronic evidence.
Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020)
Facts
The Supreme Court reviewed the conditions necessary for considering electronic records in evidence and interpreted Section 65B of the Indian Evidence Act.
Judgment
While reiterating the necessity of electronic certification, the court also highlighted a few instances where such certification would become impracticable. Further, it highlighted the importance of authenticating digital evidence for providing a fair trial.
Legal Principle
Digital evidence cannot be admitted blindly. Rather, its source, integrity and reliability need to be established.
Relation to Deepfakes
Deepfakes becoming more common, courts will have to deal with claims about forged videos and audios. Through Arjun Panditrao, the principles have been laid down in terms of which digital evidence can be authenticated.
CRITICAL ANALYSIS AND EVALUATION:
Misuse of deepfakes and algorithmic impersonation increasingly highlights the limitations that exist in the legal framework of India. Though the Constitution of India, the IT Act, 2000, the Bharatiya Nyaya Sanhita, 2023, and the Digital Personal Data Protection Act, 2023 have measures to counter privacy invasion, cyber frauds, and identity theft, none have measures to deal with AI-generated synthetic media. This means that the victim has to compile multiple legal laws, which makes the process of seeking justice extremely difficult.
Another problem that adds on to this is that of rapid advancements in AI technology. The creation and distribution of the deepfake video take just a few minutes, and finding out who was responsible for it is not an easy task due to factors such as anonymity of users, end-to-end encrypted communication, and extra territorial jurisdiction issues. Even after removal from the platform, the damage caused by the video can be irreversible for the victim.
Additionally, even though judicial precedents such as Justice K.S. Puttaswamy (Retd.) v. Union of India have reinforced the right to privacy through Article 21, current legislative provisions do not account for the emergence of generative AI. This leaves significant ambiguity when applying conventional principles of law to modern offenses arising from the application of technology.
In order to address these vulnerabilities, India needs to introduce laws pertaining specifically to deepfakes. Introducing enhanced intermediary liability, expedited take down policies, robust digital forensics systems, and overall citizen awareness will efficiently safeguard citizens while promoting the development of responsible artificial intelligence.
CONCLUSION:
Artificial intelligence has brought about a major revolution in the digital world, making innovation possible in many different areas; however, the use of artificial intelligence technology, such as deepfake and AI impersonation, is becoming a growing concern. The use of deepfake and AI impersonation can cause a violation of privacy rights, harm one’s reputation, facilitate financial fraud, spread misinformation and disinformation, and make people distrustful of digital content.
There are many laws in place to protect the privacy rights of the citizens of India from being violated, including the Constitution of India, the Information Technology Act, 2000, the Bharatiya Nyaya Sanhita, 2023, the Bharatiya Sakshya Adhiniyam, 2023, the Digital Personal Data Protection Act, 2023, and the Information Technology Rules, 2021. In addition to the mentioned laws, there are several landmark judgments from the Supreme Court of India that provide additional safeguards for the privacy rights, dignity, and reputation and the admissibility of electronic evidence.
As AI technology continues to develop, it is necessary for India to embrace a forward-thinking approach to its laws. It is imperative for India to have a legal structure for dealing with issues of content generated by AI, accountability in digital spaces, digital forensics, and increased awareness in order to ensure protection of the victim while at the same time promoting responsible use of the technology. The protection of privacy and personal identity in the digital realm is both a legal requirement as well as a constitutional requirement for India.
REFERENCES
- Constitution of India, Articles 14, 19(1)(a), 19(2), and 21.
- Bharatiya Nyaya Sanhita, 2023.
- Bharatiya Sakshya Adhiniyam, 2023.
- Information Technology Act, 2000.
- Digital Personal Data Protection Act, 2023.
- Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
- Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
- Shreya Singhal v. Union of India, (2015) 5 SCC 1.
- Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473.
- Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1.
- Ministry of Electronics and Information Technology (MeitY), Government of India.
- Indian Computer Emergency Response Team (CERT-In), Cyber Security Advisories.
- Ministry of Home Affairs, National Cyber Crime Reporting Portal.
- Digital Personal Data Protection Act, 2023 – Official Government Publications.