Subject: Current Affairs | Published: 24 November 2025
India's War on Deepfakes: Analyzing the New IT Rules (2025) and Global Regulatory Trends for UPSC
Recommended UPSC Book List
Access the curated list of standard books and resources used by top aspirants for all subjects.
The rapid democratization of Generative AI (GenAI) has marked a paradigm shift in digital content creation, but it has simultaneously armed malicious actors with sophisticated tools to generate deepfakes—hyper-realistic, synthetically manipulated audio and video media. This technology, powered by advanced deep learning models, poses a multifaceted and severe threat to individual privacy, social cohesion, financial stability, and the very integrity of democratic processes. As deepfake-related fraud incidents surge globally, with some reports indicating a growth of over 300% in sophisticated attacks in 2024 alone, the challenge of crafting effective regulation has become a paramount concern for policymakers worldwide, including in India. The nation stands at a critical juncture, navigating the complex task of fostering innovation while mitigating the profound risks of a “post-truth” digital ecosystem.
Fun Fact: The term “deepfake” was coined in late 2017 by a Reddit user of the same name who was experimenting with swapping celebrity faces into videos. The name itself is a portmanteau of “deep learning,” the underlying AI technology, and “fake,” highlighting the deceptive nature of the content.
The Technological Underpinnings: A Deeper Dive into Synthetic Media
Understanding the regulatory challenge requires a foundational knowledge of the technology itself. Deepfakes are not a monolithic entity; they are the product of several evolving machine learning techniques, each presenting unique challenges for detection and regulation.
-
Generative Adversarial Networks (GANs): For years, GANs were the workhorse of deepfake creation. A GAN consists of two dueling neural networks: a Generator and a Discriminator. The Generator creates synthetic images or video frames (e.g., a face), while the Discriminator, trained on real data, attempts to identify whether the content is authentic or fake. The two networks are locked in a zero-sum game; the Generator constantly improves its fakes to fool the Discriminator, and the Discriminator gets better at detecting them. This adversarial process continues until the generated content is so realistic that the Discriminator can no longer reliably tell it apart from genuine media. The primary limitation of GANs is their instability during training and their relative difficulty in generating high-resolution, coherent video without significant artifacts.
-
Variational Autoencoders (VAEs): VAEs are another generative model often used for face-swapping. They learn a compressed, low-dimensional representation (a latent space) of facial features from a large dataset of images. This latent space is a mathematical abstraction of facial characteristics. By encoding a target face and a source face into this space and then decoding the result, a VAE can plausibly map the source’s expressions and movements onto the target’s likeness. VAEs are generally more stable to train than GANs but can sometimes produce blurrier results.
-
Diffusion Models: The latest and most powerful evolution in generative AI, diffusion models are behind state-of-the-art tools like Midjourney, Stable Diffusion, and OpenAI’s Sora. These models work by starting with pure noise (a random static image) and gradually refining it, step-by-step, to match a textual description (a “prompt”) or an input image. They are trained by learning to reverse a process of systematically adding noise to real images. Because of their ability to generate highly coherent, contextually aware, and photorealistic images and videos from scratch, they represent a quantum leap in synthetic media generation. Their output is significantly harder to detect as fake compared to older methods.
-
Transformers and Large Language Models (LLMs): While known for powering text-based AI like ChatGPT, the transformer architecture is also being applied to vision tasks. Vision Transformers (ViTs) can process images as sequences of patches, enabling them to understand context and relationships within an image. When combined with diffusion models, they can generate video content that is not only visually realistic but also logically consistent over time. Furthermore, LLMs are the engine behind voice cloning, where just a few seconds of a person’s audio can be used to generate a synthetic voice that can say anything, perfectly mimicking the original speaker’s tone, pitch, and cadence.
This escalating technological sophistication creates a perpetual “cat-and-mouse game” for detection. As soon as a new detection method is developed (e.g., looking for subtle artifacts like unnatural blinking, inconsistent shadows, or digital noise), new generative models are trained to overcome it. This makes purely technological solutions, such as detection software, an incomplete and perpetually reactive answer to the problem.
The Spectrum of Threats: A Multi-Domain Crisis
The dangers posed by deepfakes are not abstract; they manifest across critical sectors of society and governance, creating a complex web of challenges that no single law can address.
- Political Destabilization and Electoral Interference: This is perhaps the most widely discussed threat. Malicious actors can create convincing deepfakes of political leaders making inflammatory statements, admitting to corruption, or announcing false policy changes. Deployed strategically before an election, such content can sway public opinion, suppress voter turnout, and erode trust in the democratic process. For instance, a fabricated video of a candidate withdrawing from a race, released hours before polling, could cause irreversible damage. The 2024 general elections in several countries, including India and the US, saw the first large-scale instances of AI-generated political disinformation, prompting urgent regulatory action.
- National Security and Geopolitical Conflict: State and non-state actors can use deepfakes as a tool of asymmetric warfare. A synthetic video showing a false military attack or a fabricated confession from a captured soldier could be used to justify an invasion, incite regional conflict, or create diplomatic crises. The difficulty in immediately verifying the authenticity of such media in the “fog of war” makes it a potent weapon for psychological operations (psyops).
- Economic Fraud and Corporate Espionage: The financial sector is a prime target. Voice-cloning deepfakes have already been used in high-profile CEO fraud cases, where an employee is tricked into transferring large sums of money by a synthetic audio call perfectly mimicking their superior’s voice. A reported case in early 2024 involved a finance worker in Hong Kong being duped into paying out $25 million after a video call with what he thought were his senior colleagues, but who were all deepfake recreations. Deepfakes can also be used to manipulate stock markets by creating false news about a company’s performance or to engage in corporate espionage by impersonating executives in virtual meetings.
- Individual Harm and Social Erosion: At the individual level, deepfakes are a tool for profound personal violation. This includes the creation of non-consensual pornographic material, a form of digital sexual abuse primarily targeting women and a grave violation of an individual’s dignity and privacy. They are also used for sophisticated blackmail, cyberbullying, and reputational destruction. On a broader societal level, the proliferation of deepfakes leads to what is known as reality apathy or the liar’s dividend—a scenario where people become so skeptical of all digital content that they refuse to believe authentic information, even when it is verified. This allows actual wrongdoers to dismiss real evidence (e.g., a genuine recording of them) as a “deepfake,” thereby escaping accountability. This erodes the very foundation of shared truth upon which society operates.
Analogy: A deepfake is like a form of advanced digital forgery. In the past, forging a signature or a document required skill and physical access. Today, forging a person’s entire digital likeness—their face, voice, and mannerisms—requires only data and computing power, making every individual with a digital footprint a potential target.
India’s Evolving Regulatory Arsenal: The 2024-2025 Push
Recognizing the imminent and escalating threat, India’s regulatory and legal framework has seen significant momentum in 2024 and 2025. The government’s approach has matured from relying on broad, existing laws to creating specific, targeted obligations for digital platforms and content creators.
The IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2025
The cornerstone of India’s new strategy is the amendment to the IT Rules, 2021. Following extensive consultations in late 2024 spurred by viral deepfakes involving public figures, the Ministry of Electronics and Information Technology (MeitY) finalized and notified the IT Amendment Rules, 2025 in the first quarter of the year. These rules introduce several stringent, first-of-their-kind obligations for social media intermediaries and AI platforms:
- Mandatory Labeling and Disclosure (Rule 3(1)(b)(ix)): The amendments explicitly define “synthetic media” and “deepfake.” They mandate that all social media intermediaries and AI content-generation platforms must use “all reasonable measures” to ensure that any AI-generated content that is not for artistic, satirical, or educational purposes is conspicuously labeled. The label must be clear, persistent, and easily understandable to the average user (e.g., “AI-Generated Content” or “Synthetically Altered Media”).
- Expedited Takedown for Harmful Deepfakes (Rule 4(1)(d)): While the original IT Rules mandated a 24-hour window for takedowns upon receiving a court or government order, the 2025 amendments introduce an “expedited takedown” provision specifically for harmful deepfakes. Content that impersonates another individual in a malicious manner, depicts nudity or sexual acts, or poses an immediate threat to public order must be taken down within 6 hours of being reported by a user or a trusted flagger. This drastically shortens the response time, aiming to limit the viral spread of malicious content.
The Digital Personal Data Protection Act (DPDP), 2023
Enacted in 2023 and with its provisions coming into full force through 2024, the DPDP Act has become the primary legal shield for individuals against non-consensual deepfakes. The creation of a deepfake inherently involves the processing of personal data (a person’s likeness, voice, and other biometric information). The DPDP Act provides several grounds for legal recourse:
- Violation of ‘Purpose Limitation’: Even if a person consented to their photo being used for one purpose (e.g., a social media profile), using it for an entirely different purpose (creating a deepfake) is a breach of the “purpose limitation” principle under the Act.
- Significant Penalties: The Act empowers the Data Protection Board of India to levy substantial penalties on data fiduciaries (which can include AI companies and social media platforms) for such breaches, with fines extending up to ₹250 crore. This creates a strong financial disincentive for non-compliance.
The Bhartiya Nyaya Sanhita (BNS), 2023
The new penal code, which replaced the Indian Penal Code, also provides avenues to prosecute the creators and distributors of malicious deepfakes. Relevant sections include those pertaining to forgery (Section 85), defamation (Section 356), public mischief (Section 107), and provisions related to insulting the modesty of a woman. The BNS’s updated language and recognition of electronic records make it more applicable to digital crimes than its predecessor.
Election Commission of India (ECI) Directives
Building on its advisory from the 2024 general elections, the ECI, in a landmark move in early 2025, established a permanent Digital Misinformation and AI Monitoring Cell. This body is tasked with proactively monitoring the digital space during election periods, working with social media platforms for rapid response to deepfake-based misinformation, and running public awareness campaigns. To ensure accountability, the ECI has mandated that all political parties must submit a declaration of all authorized AI vendors and tools they intend to use for campaign purposes. This creates a chain of accountability and discourages the use of anonymous or illicit generative services.
Captivating Statistic: According to a 2025 report by a leading cybersecurity firm, the average cost of a deepfake-related financial fraud incident for a large corporation has now surpassed $5 million, a 400% increase since 2023, highlighting the severe economic threat posed by this technology.
Mnemonic for Key Regulatory Pillars in India
To remember India’s multi-pronged approach to tackling deepfakes, one can use the mnemonic “BRAIN”:
- BNS (Bhartiya Nyaya Sanhita): For criminal prosecution of creators.
- Rules (IT Amendment Rules, 2025): For platform accountability and takedowns.
- Act (DPDP Act, 2023): For protecting personal data and consent.
- Information (Public Awareness Campaigns): For building societal resilience.
- Network (ECI’s Monitoring Cell): For safeguarding electoral integrity.
A Comparative Look: Global Regulatory Approaches
India’s actions are part of a global scramble to regulate AI and synthetic media. However, regulatory philosophies differ significantly across major jurisdictions, reflecting varying priorities related to innovation, civil liberties, and state control.
| Jurisdiction | Regulatory Philosophy & Key Legislation | Approach to Deepfakes | Strengths | Weaknesses |
|---|---|---|---|---|
| European Union | Comprehensive, Risk-Based, Human-Centric: The EU AI Act (finalized in late 2024) categorizes AI systems into risk tiers (unacceptable, high, limited, minimal). | Deepfakes are classified as ‘limited risk,’ requiring mandatory transparency. Users must be informed they are interacting with synthetic media. Stricter rules apply if used for high-risk purposes like influencing elections. | Comprehensive, legally binding framework; strong emphasis on fundamental rights; sets a potential global standard (the “Brussels Effect”). | Can be slow to adapt to new tech; complex compliance may stifle smaller innovators; potential for over-regulation. |
| United States | Sector-Specific, Pro-Innovation, Patchwork: No single federal law. Relies on executive orders (like the 2023 AI Executive Order), agency-specific rules (e.g., FTC), and state laws (e.g., California, Texas). The NIST AI Risk Management Framework provides voluntary guidance. | Addressed through state laws on non-consensual pornography and election interference. Federal initiatives focus on voluntary labeling standards and developing detection tech. | Promotes rapid innovation; flexible and adaptable to different sectors; strong private sector involvement. | Inconsistent legal landscape across states; lacks a unified federal standard; potential for regulatory gaps and weak enforcement. |
| China | State-Centric, Control-Oriented: Regulations from the Cyberspace Administration of China (CAC) focus on content control, algorithmic transparency, and national security. Key rules on “Deep Synthesis” (2023) and “Generative AI Services” (2023). | Mandatory, conspicuous labeling of all synthetically generated content. Requires user consent for using likeness and a real-name identity verification system for users of generative services. | Strong enforcement capability; rapid implementation; effective at curbing politically sensitive content. | Prioritizes state control over individual liberty; can be used for censorship and surveillance; stifles free expression and creativity. |
| India | Co-regulatory, Platform-Focused, Rights-Aware: A blend of specific rules (IT Rules), broad data protection principles (DPDP Act), and criminal law (BNS). Focuses on platform liability and due diligence. | Mandatory labeling, expedited takedowns for harmful content, and significant penalties for data misuse under the DPDP Act. Aims to balance innovation with user safety. | Agile and targeted amendments; leverages existing legal structures; strong penalties create a deterrent. | Heavily reliant on platform compliance; enforcement against foreign entities is challenging; potential for conflict with free speech rights. |
Critical Policy Appraisal
| Challenges / Criticisms | Opportunities / Successes / Way Forward |
|---|---|
| The Free Speech Dilemma: Strict takedown rules could lead to over-censorship, where platforms remove legitimate satire, parody, or artistic expression to avoid liability, chilling free speech under Article 19(1)(a). | Fostering Digital Trust: Clear regulations can build user confidence in the digital ecosystem, encouraging safer online interactions and commerce. |
| Enforcement and Attribution: Identifying the original creator of a viral deepfake is technically difficult and often impossible, especially when they use VPNs and operate from non-cooperative jurisdictions. | Global Leadership in AI Governance: By creating a balanced regulatory model, India can position itself as a leader in responsible AI governance, influencing global standards. |
| The ‘Liar’s Dividend’: Over-regulation and constant warnings about deepfakes might exacerbate public skepticism, making it easier for malicious actors to dismiss genuine evidence as fake. | Spurring Safety Tech Innovation: Regulatory pressure can drive investment in new technologies for watermarking, content provenance (like the C2PA standard), and more robust detection models. |
| Compliance Burden: The stringent due diligence and rapid takedown requirements place a significant operational and financial burden on smaller startups and platforms compared to Big Tech. | Empowering Citizens: A combination of legal recourse (via DPDP Act) and public awareness campaigns empowers individuals to protect their digital identity and seek justice. |
Analytical Lens: UPSC Focus (Mains & Prelims)
Conceptual Basis
The legal and constitutional foundation for regulating deepfakes in India is multi-layered. The primary legislative instruments are the Information Technology Act, 2000 (specifically the 2021 and 2025 Rules issued under Section 87) and the Digital Personal Data Protection Act, 2023. Constitutionally, the issue involves a critical balancing act between the Right to Freedom of Speech and Expression (Article 19(1)(a)) and the Right to Life and Personal Liberty (Article 21), which the Supreme Court has interpreted to include the right to privacy and dignity. The regulations are justified under the “reasonable restrictions” clause of Article 19(2), which allows for laws in the interest of public order, decency, morality, and preventing defamation.
UPSC Integration: Connecting the Dots
- GS Paper 2 (Polity & Governance): The topic is directly linked to e-governance, the role of statutory and regulatory bodies (MeitY, ECI, Data Protection Board), and the fundamental rights chapter. It explores the challenges of applying traditional legal frameworks to emerging technologies.
- GS Paper 3 (Science & Tech, Internal Security, Economy): It covers awareness in the fields of IT and computers (Generative AI), challenges to internal security through social media (disinformation, social unrest), and the economic impact of cybercrimes.
- GS Paper 4 (Ethics, Integrity, and Aptitude): The concept of the “liar’s dividend” and “reality apathy” raises profound ethical questions about truth, trust, and accountability in public life. It presents case studies on the ethical responsibilities of tech companies and the moral dilemmas faced by policymakers.
Long-Term Impact & Policy Relevance
The regulation of deepfakes is not a one-time fix but an ongoing policy challenge that will define the next decade of digital governance. The long-term impact will be seen in how well India can foster a domestic AI industry while preventing its tools from being weaponized. The policy’s success will depend on adaptive regulation, international cooperation for cross-border enforcement, and, most importantly, building societal resilience through digital literacy. This topic will remain highly relevant as AI becomes more integrated into daily life, making it a perennial subject for questions on governance and technology.
Prelims Practice Question (MCQ)
Question: With reference to India’s legal framework for regulating deepfakes, consider the following statements:
- The Digital Personal Data Protection Act, 2023, allows for penalties up to ₹250 crore for the non-consensual processing of personal data.
- The IT (Amendment) Rules, 2025, mandate a 24-hour timeline for the takedown of all types of deepfake content upon user reporting.
- The Bhartiya Nyaya Sanhita, 2023, has no specific provisions to deal with digital crimes like deepfakes.
Which of the statements given above is/are correct? (a) 1 only (b) 1 and 2 only (c) 2 and 3 only (d) 1, 2, and 3
Answer: (a) 1 only Explanation:
- Statement 1 is correct. The DPDP Act, 2023, specifies penalties for data breaches, which can go up to ₹250 crore, and creating a deepfake without consent is a form of non-consensual data processing.
- Statement 2 is incorrect. The IT (Amendment) Rules, 2025, introduced an expedited takedown timeline of 6 hours for specific categories of harmful deepfakes, not a uniform 24-hour rule for all deepfakes.
- Statement 3 is incorrect. The Bhartiya Nyaya Sanhita (BNS), 2023, contains several provisions related to forgery, defamation, and public mischief that can be applied to prosecute crimes involving deepfakes.
Mains Sample Question
Question (15 Marks): “The regulation of deepfakes in India presents a classic dilemma between safeguarding individual dignity and privacy under Article 21 and upholding the freedom of speech and expression guaranteed by Article 19.” Critically analyze India’s recent regulatory measures, including the IT (Amendment) Rules, 2025, in light of this constitutional balance.
Mind Map Outline (Revision Structure)
- Deepfakes: Technology, Threats, and Regulation
- Core Concept: What are Deepfakes?
- Definition: AI-generated synthetic media.
- Etymology: “Deep Learning” + “Fake”.
- Underlying Technology
- Generative Adversarial Networks (GANs)
- Generator vs. Discriminator model.
- Variational Autoencoders (VAEs)
- Latent space representation.
- Diffusion Models
- State-of-the-art, noise-to-image process.
- Transformers & LLMs
- Vision Transformers (ViTs) and Voice Cloning.
- Generative Adversarial Networks (GANs)
- Spectrum of Threats
- Political & Electoral:
- Disinformation, voter suppression.
- Erosion of democratic trust.
- National Security:
- Asymmetric warfare, psyops.
- Economic & Financial:
- CEO fraud, stock market manipulation.
- Individual & Societal:
- Non-consensual pornography, blackmail.
- The “Liar’s Dividend” and reality apathy.
- Political & Electoral:
- India’s Regulatory Framework (The “BRAIN” Mnemonic)
- B - BNS, 2023:
- Criminal liability (forgery, defamation).
- R - IT Rules (Amendment 2025):
- Platform due diligence.
- Mandatory labeling.
- 6-hour expedited takedown.
- A - DPDP Act, 2023:
- Consent as a cornerstone.
- Penalties up to ₹250 crore.
- Role of Data Protection Board.
- I - Information Campaigns:
- Building public awareness and digital literacy.
- N - Network (ECI’s Monitoring Cell):
- Ensuring electoral integrity.
- Mandatory declaration of AI vendors by parties.
- B - BNS, 2023:
- Global Regulatory Landscape (Comparative Analysis)
- EU: AI Act (Risk-based, comprehensive).
- USA: Patchwork (Sector-specific, pro-innovation).
- China: State-centric (Control-oriented, mandatory labeling).
- Policy Analysis & Critique
- Challenges:
- Free Speech vs. Regulation (Article 19 vs. 21).
- Enforcement and attribution issues.
- Compliance burden on startups.
- Opportunities:
- Building digital trust.
- Leadership in AI governance.
- Driving safety-tech innovation.
- Challenges:
- UPSC Focus
- Constitutional Basis: Articles 19 & 21.
- Syllabus Integration: GS-2 (Governance), GS-3 (S&T, Security), GS-4 (Ethics).
- Practice Questions: Prelims (MCQ) and Mains (Analytical).
- Core Concept: What are Deepfakes?