India’s new 3-hour deepfake removal rule: Experts urge strict compliance
New Deepfake Rules in India: The amendments of IT Rules 2021 shorten deepfakes takedown timelines, introduce compliance obligations for platforms hosting synthetically generated information (SGI), three-months user warnings now mandatory.
Deepfake Law in India: The amendments address the rise of deepfakes and AI-generated content, the amendments introduce a detailed definition of 'synthetically generated information' (SGI). (Image generated using AI) With inputs from Sumit Kumar Singh
Deepfake Law in India: After a major regulatory overhaul aiming at tackling deepfakes, harmful online content and improving platform accountability, Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 were notified by the Centre on February 10, legal experts welcome the move but call for efficient implementation.
The 2026 amendment aims to amend the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, set to come into effect from February 20, 2026.
Amendments
- The amendments shorten content takedown timelines, introduce detailed compliance obligations for platforms hosting synthetically generated information (SGI), three-months user warnings now mandatory.
- Under the amended Rule 3(1)(c), intermediaries (social media platforms like Facebook, Instagram, YouTube, X and other websites) will now be required to inform users every three months, instead of once a year, about the consequences of violating the platform’s terms of service, privacy policy or user agreement.
- Users must be clearly informed that access or usage rights may be withdrawn or disabled for non-compliance.
- They may face penalties under applicable laws for creating, generating or modifying unlawful content.
- Certain offences require mandatory reporting under laws such as the Protection of Children from Sexual Offences (POCSO) Act, 2012 and the Bharatiya Nagarik Suraksha Sanhita (BNSS), 2023.
- The move is seen as an attempt to strengthen informed digital participation and reduce the circulation of unlawful material including deepfakes.
Takedown timelines slashed drastically
- One of the most striking changes is the sharp reduction in timelines for content removal including deepfakes and grievance redressal.
- The amendments mandate that court-ordered or law enforcement-directed takedowns must now be complied with within three hours, as against the earlier 36-hour window.
- Similarly, platforms must remove non-consensual nudity within two hours, down from 24 hours.
- Grievance redressal timelines have also been halved to seven days.
- Legal experts say this compressed timeframe will require platforms to establish round-the-clock rapid response teams and enhanced automated moderation systems.
- This replaces the earlier more restrictive structure and is expected to expedite law enforcement coordination.
The amendments mandate that court-ordered or law enforcement-directed takedowns of deepfakes must now be complied with within three hours, against the earlier 36-hour window.
New framework for ‘synthetically generated information’
- In a significant move addressing the rise of deepfakes and AI-generated content, the amendments introduce a detailed definition of ‘synthetically generated information‘ (SGI).
- SGI includes audio, visual or audio-visual content that is artificially or algorithmically created or modified in a manner that makes it appear real and indistinguishable from actual persons or events.
What is not SGI
- The Rules clarify that routine or good-faith editing, formatting, enhancement, technical correction, colour adjustment, noise reduction, transcription, or compression that does not materially alter, distort, or misrepresent the substance, context, or meaning will not qualify as SGI, provided the substance or meaning of the content is not materially altered.
- Similarly, routine or good-faith creation, preparation, formatting, presentation or design of documents, presentations, portable document format (PDF) files, educational or training materials, research outputs will be excluded.
Additional compliance burden on SGI platforms
- Intermediaries offering SGI generation or sharing services must now inform users that punishment may be attracted for directing or causing SGI to be created or shared unlawfully.
- Warn that violations could result in content removal including deepfakes, suspension or termination of user accounts, disclosure of identity to complainants, and mandatory reporting under POCSO or BNSS.
Mandatory proactive detection and labelling
- Platforms must implement “reasonable and appropriate technical measures,” including automated tools, to prevent the generation or sharing of unlawful SGI.
- Prohibited SGI categories include content that contains child sexual abuse material (CSAM), non-consensual nudity, or obscene or sexually explicit material.
- Creates false documents or electronic records.
- Relates to procurement of explosives, arms or ammunition.
- Falsely depicts a natural person or real-world event in a deceptive manner.
- Where SGI does not fall under prohibited categories, it must be prominently labelled.
- Labels must be clearly visible in visual displays.
- Prefixed prominently in audio content.
- Embedded with metadata or technical provenance markers, including a unique identifier of the computer resource used to generate the content.
- The rules explicitly prohibit suppression, modification or removal of such labels and metadata.
Stricter rules for significant social media intermediaries (SSMIs). - SSMIs face additional obligations including mandatory user declarations where content is SGI.
- Verification of the accuracy of such declarations using technical measures.
A regulatory push against deepfakes
- The amendments represent one of the most comprehensive regulatory responses to deepfakes, AI-generated misinformation and digital harms in India.
- By sharply reducing takedown timelines, mandating proactive detection, and enforcing metadata-based labelling, the government appears to be signalling zero tolerance for deepfake abuse and unlawful synthetic content.
- With the rules set to take effect from February 20, 2026, intermediaries now face less than ten days to recalibrate compliance mechanisms and technological safeguards.
- Industry stakeholders are expected to seek clarifications on implementation logistics, especially concerning the feasibility of the three-hour takedown mandate and permanent metadata requirements.
Experts speak
Advocate Yashaswini Basu, data and energy transition lawyer from Bangaluru said, “The much needed regulatory oversight over synthetically generated information through the new IT rules enables mandatory transparency through permanent metadata and prominent labeling, ensuring users can distinguish AI-generated content from reality. By slashing takedown timelines to just three hours, the rules enforce rapid accountability while requiring platforms to use proactive automated tools against non-consensual imagery,”
