India explainer
India's Deepfake Rules: Three-Hour Takedowns and What They Also Reach
Deepfakes are a real harm and doing nothing was never an option. But a rule written to catch synthetic video is also a lever over what can be published and how fast it must come down — and levers built for one purpose rarely stay pointed at it.
Sometime in February 2026, India changed what a platform owes you when a machine makes a video of your face. The amended IT Rules — the intermediary guidelines that have governed online platforms here since 2021 — now carry a whole vocabulary for synthetic media: a definition of it, a duty to label it, a duty to ask users whether they made it with a machine, and deadlines for taking it down that are measured in hours rather than days. As reported, the Ministry of Electronics and Information Technology notified the amendment on 10 February 2026 and it took effect on 20 February, giving platforms about ten days to rebuild their moderation pipelines. I have been reading the commentary since, and I think both of the loud positions are wrong.
What the rules actually ask for
The centre of the amendment is a defined term: synthetically generated information. As reported, it covers audio, visual or audio-visual material that has been created or altered artificially or algorithmically so that it appears authentic — indistinguishable from a real person or a real event. Text-only output is outside it. So is routine editing, translation, accessibility work: the kinds of machine assistance that change how something is delivered rather than whether it happened.
That definition is narrower than the one people argue about online, and narrower than the draft that preceded it. It is aimed at the thing that actually breaks: the visual and auditory record. A generated paragraph is a claim you can weigh. A generated video of a person saying words they never said is something else — it arrives pre-believed, because we spent a century learning that footage is evidence.
From there, the obligations. Synthetic media that is otherwise lawful has to be labelled — as reported, visual content with a label that is prominent, easily noticeable and adequately perceivable, audio with a disclosure prefixed to it, and, where technically feasible, permanent metadata or an identifier that traces which system produced it. Significant social media intermediaries have to collect a declaration from the uploader about whether what they are posting is synthetic, and then — this is the part that matters — deploy technical measures to check whether the declaration is true. The earlier language asked platforms to endeavour to deploy such measures. The notified version drops the softener.
Then the clocks. As reported, content flagged as unlawful through a court order or an authorised government notice must come down within roughly three hours, cut from thirty-six. Non-consensual intimate imagery and impersonation of a person get a tighter window still — around two hours, down from twenty-four. Behind all of it sits safe harbour, the immunity that lets a platform host what its users say without owning every word of it. A platform that knowingly leaves unlawful synthetic content up risks losing that protection, which is the only enforcement lever in Indian intermediary law that platforms have ever genuinely feared.
The harms are not hypothetical, and I want to be honest about that
It has become a habit in digital rights writing to treat every new rule as an attack and every stated harm as a pretext. I do not want to write that essay, because the harms here are specific, documented, and fall on people who have no lobby.
Start with the largest category by volume, which is also the one least discussed in policy panels: non-consensual sexual imagery. The overwhelming majority of it targets women. It does not require a hack, a leak or a private photograph — a public profile picture is enough input. The damage is immediate and local: it reaches a family WhatsApp group, a workplace, a college, a marriage negotiation, long before any complaint is filed. And the old thirty-six-hour window was, for this harm, functionally no protection at all. Thirty-six hours is enough time for a clip to be saved, re-uploaded, and mirrored past the point where removing the original means anything. If you have ever tried to help someone through this — I have — the argument that the state should not act feels obscene.
Then voice cloning. A few seconds of audio is enough to produce a convincing call from a son in trouble, a bank officer, a superior asking for an urgent transfer. India ran ahead of most of the world in making digital payments instant and irreversible; we built the rails for money to move in seconds without building any comparable capacity for a victim to claw it back. Synthetic voice slots into that gap perfectly.
And then fabricated political content, at a scale no other democracy has to absorb. A general election here involves near a billion eligible voters across dozens of languages. Generation is now cheap enough that a fabricated clip of a candidate can be produced in every one of those languages, targeted regionally, and pushed into closed messaging groups where nothing can be fact-checked from outside. Waiting to see how bad it gets was never a neutral choice. It was a choice to let the first few cycles of damage happen to real people.
Doing nothing was never the safe option. But the shape of what we did do is going to outlive the problem it was built for.
Why a three-hour clock is itself a policy
Here is where I part from the government's framing. A takedown deadline is not just an administrative detail. The length of the clock determines what kind of decision the platform can make inside it, and therefore what kind of decision it will make.
Think about the arithmetic from a trust-and-safety desk in Bengaluru or Hyderabad at two in the morning. A notice arrives. The content is in Malayalam, or Bhojpuri, or Manipuri. Someone has to establish what it says, whether it is synthetic, whether it is unlawful, whether it is satire of a public figure — which is protected — or defamation dressed as satire, which is not. That is a judgement that a competent lawyer would want a day for. The rule gives three hours, across every language in a country with twenty-two scheduled ones, at a volume of thousands of notices.
No organisation resolves that by hiring enough experts. It resolves it by making the default action removal. Removing lawful content costs a platform an annoyed user and a grievance appeal. Leaving unlawful content up past the deadline costs it safe harbour, which is to say its entire legal position in the Indian market. The asymmetry is so steep that no honest compliance team would choose otherwise. Over-removal isn't a failure of the system under a three-hour clock; it is the rational output of it. And because the volume forces automation, the first pass will be made by classifiers — systems that are notoriously poor at exactly the categories that need protection most. Satire, parody, reportage that quotes the thing it is criticising, an activist republishing a manipulated clip in order to debunk it: to a model, all four look like the thing they are about.
I notice the same pattern that shows up everywhere in Indian tech policy: a genuine harm is identified, the response is calibrated for the worst actor, and the cost of that calibration lands on everyone else quietly, as friction rather than as law. It is the same structural move I traced in India's data protection Act, where an individual right was written alongside expansive state exemptions, and in facial recognition in India, where a tool procured for finding missing children ended up pointed at protest crowds with no statute in between.
Definitions travel
The labelling duty deserves a note, because its drafting history tells you something. The October 2025 draft, as reported, required a synthetic-content identifier covering at least ten percent of the visual surface area, or the first ten percent of an audio clip's duration. Industry objected that a fixed percentage is arbitrary across formats, and the notified version replaced it with a standard — prominent, easily noticeable, adequately perceivable.
That is better drafting and worse certainty. A numeric threshold is dumb but auditable; a qualitative standard is sensible but its meaning is settled later, by whoever is doing the enforcing. Every provision written as a standard rather than a number is a provision whose real content gets filled in after the public argument has ended and the press has moved on. That is not an accusation. It is just how rules work, and it is why the drafting stage is the only stage where citizens have leverage.
The deeper problem is that a definition written for one harm does not stay attached to that harm. The amendment defines synthetic media by a technical property — machine-generated, appears authentic — not by whether it injures anyone. Nearly everything in that set is harmless. A satirical dub of a politician is synthetic. A recreated historical figure in a documentary is synthetic. A voice-cloned narration that lets a person who has lost their speech keep publishing is synthetic. Once the category exists and carries obligations, the question of which subset gets enforced against is an administrative one, answered inside the executive, at whatever speed the clock allows.
A fast, broadly worded removal power is infrastructure. Whoever holds it next inherits it fully built, and never has to argue for it in public the way its authors did.
The part that worries me most is the next draft
On 30 March 2026, as reported, the ministry published a further draft — a second amendment — and invited comments by 14 April. As of this writing it has not been notified. Its contents are instructive, because they are not about deepfakes at all. Among the proposals: widening the remit of the inter-departmental committee from complaints to a broader class of matters, including those the ministry itself refers, and extending compliance obligations toward individuals who publish news and current affairs at scale. Press bodies — the Editors Guild, DIGIPUB, journalists' unions — and digital rights groups asked for it to be withdrawn. Amnesty called for the same.
Notice the sequence, because it is the whole argument. Phase one establishes a machinery on grounds nobody can reasonably oppose: women whose faces are stolen, parents defrauded by a cloned voice. Phase two, arriving weeks later while the institutional muscle is fresh, points the same machinery at news and current affairs. Nothing improper needs to happen for this to work. The urgency, the short clocks, the broad definitions, the automated first pass — all of it was justified honestly in phase one, and all of it is available in phase two without a fresh justification.
This is the mechanism I keep returning to in writing about how technology gets captured: capture rarely looks like a seizure. It looks like a capability built for a sympathetic purpose, retained after that purpose is served, and then redirected — each step small, each step defensible, the aggregate unrecognisable from where it started. It is also how data colonialism operates on the commercial side, where infrastructure built for convenience becomes infrastructure for extraction without a single moment anyone would call the turning point.
What I would actually want
I am not arguing for repeal. A country where a cloned video of an ordinary woman can circulate for a day and a half before anyone is obliged to act is not a country that has protected free expression; it has protected only the expression of whoever has the better lawyers. What I want is narrower and duller.
Keep the two-hour clock where it belongs — non-consensual intimate imagery and impersonation of a specific identifiable person, where the harm is unambiguous and the assessment is genuinely fast. Give the broad unlawful-content category a longer window and require the notice to state its reasons, as the Rule 3(1)(d) amendment of late 2025 already began to do by restricting who may issue such orders. Carve out satire, parody, criticism and journalism explicitly in the text rather than leaving them to a classifier's mercy. Publish the numbers: how many notices, from which authority, how many removals, how many restored on appeal. Sunset the emergency provisions so they have to be re-argued rather than simply retained. And keep the provenance work — labels and metadata — because that is the one intervention that adds information to the record instead of subtracting from it.
None of that is exotic. It is the ordinary architecture of a power that expects to be scrutinised. Its absence is the tell.
India was right that synthetic media was going to hurt people and that nobody was coming to fix it. I would rather live with rules that move too fast than with a vacuum that protects only the powerful. But we have built a fast, broad, lightly supervised removal power and handed it to whoever holds office next, and the next, and I have never once seen such a thing get narrower on its own. A tool built for one purpose rarely stays pointed at it.
Frequently asked questions
What do India's IT rules on deepfakes require?
Amendments to India's intermediary rules have focused on synthetic media: obliging platforms to label or disclose AI-generated content, to act on complaints about deepfakes within tight timeframes, and to deploy means of identifying such content. Specific obligations and deadlines have been revised more than once, so verify the current text before relying on any particular requirement.
Why is India regulating deepfakes?
Because the harms are concrete and already occurring: non-consensual sexual imagery overwhelmingly targeting women, financial fraud using cloned voices and faces, and fabricated political content in a country with enormous, fast-moving social platforms. The case for some regulation is strong; the argument is about its design.
What are the free-speech concerns?
Very short mandatory takedown windows push platforms to remove first and assess later, since over-removal is cheaper than risking liability. Combined with broad definitions, that can sweep in satire, parody, criticism and legitimate journalism. The concern is not that deepfakes should go unaddressed, but that a fast, broadly-worded takedown power is a tool a government can later point at inconvenient speech.