ISSN : 2583-8725

Algorithmic Amplification And Intermediary Liability For Ai-Generated Deepfakes In India: Reassessing The Section 79 Safe Harbour

Suchitra and Prasoon Ranjan[1]

ABSTRACT

Section 79 of the Information Technology Act, 2000 (“IT Act”) exempts intermediaries from liability for third-party content on conditions of neutrality and due diligence. It was written for passive hosts. Today the largest platforms run recommender systems that decide what each user sees, and generative AI has made convincing deepfakes that is cheap to produce. A deepfake can reach millions of people before a victim, a court or a regulator can even respond.

This paper asks whether an intermediary that algorithmically amplifies an AI-generated deepfake keeps the section 79 safe harbour, and whether Indian law can regulate amplification without causing unconstitutional over-removal. Using a doctrinal and comparative method, it examines the statutory text, through the leading decisions, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (“2026 Amendment”). It tests the regime against Articles 14, 19(1)(a), 19(2) and 21 of the Constitution and compares the position in the United States, the European Union and the United Kingdom.

The paper argues that section 79 should be read, and where necessary amended, so that immunity attaches to hosting and not to algorithmic promotion once the platform has notice that the content is unlawful. The 2026 Amendment addresses labelling, provenance and takedown speed but does not address how content is ranked or recommended, and its reliance on delegated legislation leaves it open to challenge. The paper proposes a model for primary legislation that keeps immunity for hosting, withdraws it for amplification after credible notice, adds a systemic risk duty for large platforms and gives users whose content is removed procedural protection.

Keywords: intermediary liability; Section 79; safe harbour; algorithmic amplification; deepfakes; synthetically generated information; Shreya Singhal; IT Rules 2026

1. INTRODUCTION

The Internet has become an integral aspect of modern communication and commerce, facilitating the exchange of information, ideas, and goods on a global scale. However, this rapid growth has also created new legal problems. One of the most important is intermediary liability: when should a company that provides an online platform be legally responsible for content created or shared by its users? In India, Section 79 of the Information Technology Act, 2000 (“IT Act”) provides the basic framework. It gives intermediaries protection from liability for third-party content, but this protection is subject to certain conditions, including compliance with due-diligence requirements.

At the same time, advances in technology have also created new ways of misusing online platforms. Deepfakes is also the result of such development. Using artificial intelligence (“AI”), a person can create or manipulate audio, images or videos to make someone appear to say or do something that never happened. Such content can be used to deceive people, damage a person’s reputation, impersonate someone, commit fraud, create non-consensual intimate imagery (“NCII”), or manipulate public opinion.

The problem becomes more serious when a deepfake spreads online. The harm is not limited to the creation of the fake content but due to the social media and algorithmic tools, such content spreads rapidly and reaches a massive audience which increases the severity of such harm. A victim may not immediately know that a deepfake has been created. By the time it is reported, the content may already have been viewed, downloaded, copied and uploaded elsewhere. As a result, removing the original post may not completely remove the harm. Research on the spread of information online has also found that false information can travel farther and faster than truthful information.

This brings us to an important development in the way online platforms operate. Modern social-media platforms do not simply store or transmit content. They use ranking and recommendation systems to decide what content users are shown. For example, a platform may recommend a video to users who did not search for it or may repeatedly display content because its algorithm predicts that users will engage with it. In this way, a platform can increase the reach of content even though it did not create that content itself. This process is referred as algorithmic amplification.

For the purpose of this study, algorithmic amplification means an increase in the reach or visibility of content resulting from a platform’s own ranking, recommendation or distribution systems, rather than simply from the uploader sharing the content with others. These algorithms prioritise sensational, emotional, or controversial content, including deepfakes. The distinction is important because traditional intermediary law was largely developed around the idea of an intermediary as a relatively passive provider of online infrastructure. Algorithmic recommendation creates a more complicated situation: the platform may not create the deepfake, but its own systems may play a significant role in determining who sees it and how widely it spreads.

India has already begun responding to the growing problem of AI-generated and manipulated content. Indian courts have granted injunctions protecting the names, voices, images and likenesses of individuals from unauthorised exploitation, including through AI-based tools. At the regulatory level, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (“2026 Amendment”) introduced the concept of “synthetically generated information” and imposed additional obligations on intermediaries in relation to such content.[2]

However, an important question remains unanswered: what happens when an intermediary does not merely host a deepfake but actively amplifies it through its own algorithmic systems? Can they be held liable?

This question is particularly important under Section 79 of the IT Act. The protection provided by Section 79 is conditional and is connected to the intermediary’s role and compliance with due diligence. The traditional understanding of intermediary liability generally distinguishes between a platform that merely provides a space for third-party content and a platform that becomes more actively involved in the content or its distribution. In Shreya Singhal v Union of India, the Supreme Court also considered the circumstances in which an intermediary may be required to remove unlawful content. Similarly, cases such as Christian Louboutin SAS v Nakul Bajaj have examined circumstances in which the conduct of an intermediary may go beyond that of a purely passive platform.

The difficulty is that algorithmic amplification does not fit easily into this traditional distinction. A platform may not have created the deepfake, edited it or uploaded it. At the same time, its recommendation system may have increased the content’s visibility and allowed it to reach a much larger audience. This creates a gap between the traditional idea of a passive intermediary and the way modern platforms actually distribute information.

A platform whose own algorithm chose who would see a deepfake has a weak claim to neutrality, and that is the problem this paper takes up.

1.2 Research questions

The paper addresses four questions.

  • Does algorithmic amplification of a third-party deepfake take an intermediary outside Section 79?
  • How do Shreya Singhal and later decisions shape the knowledge standard when harm is caused by amplification?
  • Does the 2026 Amendment deal adequately with amplification?
  • What reforms would make the regime effective and constitutionally sound?

1.3 Hypothesis

Section 79 should be read, and where necessary amended, so that immunity attaches to hosting and not to an intermediary’s own algorithmic promotion once it has notice that the content is unlawful.

1.4 Methodology and scope

This research adopts a doctrinal and comparative legal research methodology to examine the relationship between algorithmic amplification of AI-generated deepfakes and intermediary liability under Section 79 of the Information Technology Act, 2000. The research is primarily based on the analysis of legal rules, judicial decisions, regulatory developments and academic literature rather than empirical investigation of the internal functioning of online platforms.

2. CONCEPTUAL FRAMEWORK

Before examining intermediary liability, it is necessary to understand three connected concepts: deepfakes, synthetically generated information and algorithmic amplification. They overlap but are not the same. The difference matters because the legal question does not end when a deepfake is created. It continues when  the content is uploaded and the platform’s systems increase its visibility.

2.1 Deepfakes and synthetically generated information

2.1.1 Deepfakes

A deepfake is digitally manipulated or artificially generated media in which artificial intelligence or machine-learning techniques are used to produce realistic audio, images or video of a person or event. Its defining feature is that it makes something look genuine that never happened. For example, a person’s face may be placed onto another person’s body, or their voice may be artificially reproduced to make it appear that they said something they never said.[3]

The technology is not unlawful in itself. It has legitimate uses in film, entertainment, education, satire, artistic expression and accessibility. The legal concern is the misuse of such technology.  A realistic synthetic video can falsely show a person committing an act, and a cloned voice can be used to impersonate someone in a financial scam. Deepfakes can therefore harm reputation, privacy, identity and personal security.[4]

2.1.2 Synthetically generated information

Synthetically generated information (“SGI”) is the broader category, and Indian intermediary law now recognises it expressly. The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 inserted Rule 2(1)(wa) into the IT Rules, 2021 which defines synthetically generated information (SGI). The rule defines SGI as audio, visual or audio-visual information that is created, generated, modified or altered by artificial or algorithmic means using a computer resource, so that it appears real, authentic or true, and that shows an individual or event in a way that is, or is likely to be seen as, indistinguishable from a natural person or real-world event.[5]

The definition has two elements. First, the content must have been artificially or algorithmically created or altered, and it must look realistic enough to pass as a real person or event. The law is therefore concerned with AI-generated or AI-altered content that can pass as genuine. A video made with an AI tool that shows a public figure making a statement they never made falls within SGI if it is realistic enough to be taken as genuine. So does a generated voice recording that convincingly sounds like a real person. The definition is confined to audio, visual and audio-visual information, so AI-generated text is not SGI as such.

Second, not every use of a computer to edit or improve content produces SGI. The Rules exclude routine or good-faith editing, formatting, technical correction, colour adjustment, noise reduction, transcription and compression, provided the change does not materially alter, distort or misrepresent the substance, context or meaning of the original. They also exclude certain document preparation, educational or research materials and accessibility-related improvements. Without these exclusions, improving a photograph, correcting a recording or translating content could be treated like deceptive synthetic media. The framework therefore separates ordinary digital editing from realistic synthetic content that can create a false impression of reality.

2.1.3 Relationship between Deepfakes and SGI

Deepfakes are one important category of synthetic content, and SGI is the broader legal category introduced by 2026 Amendment. The two terms are not synonymous. ‘Deepfake’ is a technological and social term, whereas ‘synthetically generated information’ is defined in the IT Rules 2026 Amendment. The progression runs from AI-generated or AI-altered content, to realistic synthetic content, to SGI, with the deepfake as a common example.

The distinction matters here because the 2026 Amendment brings SGI within the intermediary due-diligence framework. Rule 2(1A) provides that references to “information” in specified provisions on unlawful acts include SGI.[6] Regulation therefore reaches realistic AI-generated and AI-manipulated media as well as conventional user content. The further question is what legal significance the platform’s own role in distributing and amplifying that content should have.

2.2 Algorithmic amplification

2.2.1 How platforms distribute content

A platform such as a social-media service does not necessarily show every piece of uploaded content to every user. Instead, its systems may rank, recommend and select content based on factors such as a user’s previous activity, predicted interests, engagement patterns and other signals.

For example, a user may upload a video that initially reaches only their followers. If the platform’s recommendation system considers that video likely to attract attention, it may recommend the video to users who do not follow the uploader. The content can therefore reach an audience much larger than the uploader’s original audience.

This process is referred to in this research as algorithmic amplification.

In simple words, Algorithmic amplification occurs when a platform’s own ranking, recommendation or distribution system increases the visibility or reach of content beyond the audience that would otherwise encounter it through ordinary user-initiated sharing.

The platform need not have created the content. A deepfake may be made by one person and uploaded by another, and the platform’s algorithm then affects how widely it is seen.

2.2.2 Amplification and hosting

The distinction between hosting and amplification is central discussion to this paper. Suppose a user uploads a deepfake. At the most basic level, the platform supplies the infrastructure that keeps the content available. That matches the traditional picture of an intermediary, which is a service, through which information supplied by someone else is made available.

Now suppose the platform’s recommendation system identifies the same deepfake as likely to generate engagement and recommends it to a large number of further users. The platform still did not create the deepfake, but its system has shaped the scale of its distribution. The legal question shifts from who created the unlawful content to whether the intermediary’s own role in increasing its reach affects the intermediary’s legal position.

This does not mean every recommendation is active participation in unlawful content. Recommendation systems are an ordinary feature of modern platforms, and they distribute lawful and valuable content too. The point is to ask whether the degree of platform involvement should matter in deciding intermediary responsibility.

The European Union’s Digital Services Act also treats recommender systems as a source of risk. It requires very large online platforms and search engines to assess and mitigate systemic risks arising from the design and functioning of their services, including risks linked to the dissemination and amplification of certain harmful or misleading content.[7]

Under Indian law, Section 79 governs when an intermediary is protected from liability for third-party information. The question here is whether the platform’s own algorithmic role in increasing the reach of that information should bear on whether the protection is available or how far it extends.

2.3 Why amplification matters for deepfakes

The harm from a synthetic generated content grows with its speed, scale and audience. A video that falsely shows a person making a controversial statement does limited damage, if it stays in a small private group. If a platform repeatedly recommends it to thousands or millions of users, the consequences are very different and severe.

The problem has three stages: creation, uploading and distribution. At creation, a person uses AI to generate or manipulate content. At uploading, the content is placed on a platform. At distribution, users may share it and the platform’s own systems may rank or recommend it. Traditional intermediary-liability analysis concentrates on the relationship between the intermediary and the third-party content. Amplification adds a further factor, which is that the intermediary may influence the reach of content it did not create.

Synthetic media is persuasive. Chesney and Citron explain that advances in the technology create risks for privacy, reputation, fraud, political processes and other interests, because realistic fabricated media can make false representations look authentic.[8] Speed adds to the problem. Vosoughi, Roy and Aral studied about 126,000 news stories on Twitter and found that false news travelled farther, faster and more broadly than true news.[9] Their study did not examine AI-generated deepfakes or show that recommender algorithms amplify them, so its relevance is limited. It does show that false information can reach a large audience once it enters an online network. Deepfakes can make this worse because they present falsehood in a form that looks and sounds authentic, and users may be more ready to believe a video that appears to show a person speaking or acting. Realistic synthetic content, platform distribution systems and a large audience together raise the potential for harm.

That does not mean any platform that recommends a deepfake should lose its safe harbour automatically. Such a rule could overburden intermediaries and push them to remove lawful material merely because it might be synthetic or controversial. It could also affect legitimate uses of synthetic media, including satire, artistic expression, entertainment and research. The issue is one of degree, and four situations need to be told apart.

The first is a platform that merely hosts third-party content. In the second, the platform has notice that the content is unlawful and fails to respond appropriately. In the third, it continues to recommend synthetic content it knows to be harmful. In the fourth, its design or recommendation systems materially contribute to the wide dissemination of such content.

The central question follows. If a platform’s algorithm materially increases the reach of a deepfake, should that affect the availability or scope of the section 79 safe harbour? Amplification alone cannot answer it. A balanced analysis needs factors such as knowledge, control, the degree of amplification and the foreseeability of harm. Later parts of the paper examine these factors when asking whether Indian law should keep treating algorithmic distribution like passive hosting.

3. THE DEVELOPMENT OF SECTION 79

3.1 Origins and the 2008 amendment

The original section 79 protected “network service providers” from liability for offences under the Act if they proved lack of knowledge or due diligence. After a marketplace executive was arrested over obscene content listed by a user in Avnish Bajaj v State (NCT of Delhi), Parliament revised the provision.[10] The Information Technology (Amendment) Act, 2008 substituted the current section 79, which makes immunity conditional on the intermediary’s passive role, its due diligence, and the absence of actual knowledge or complicity.[11] This amendment replaced the blanket immunity with a system of ‘conditional safe harbour’.

3.2 Shreya Singhal v Union of India and the “Actual Knowledge” Standard

In Shreya Singhal the Supreme Court struck down Section 66A for vagueness and chilling effect. It also read down section 79(3)(b) and the Intermediary Guidelines Rules, 2011. The Court held that “actual knowledge” under section 79(3)(b) means receipt of a court order, or a notification from the appropriate government or its agency, directing removal, and that such directions must relate to the subjects listed in Article 19(2).[12] The Court was concerned that platforms facing private complaints would over-remove to protect their immunity, and that speech would suffer.

3.3 MySpace, Louboutin and Visakha

In MySpace Inc v Super Cassettes Industries Ltd the Delhi High Court’s Division Bench held that an intermediary’s knowledge must be specific, such as identified works and URLs, and that a general duty of pre-screening was impracticable. The decision depended on the platform’s passive and automated character.[13] In Christian Louboutin SAS v Nakul Bajaj the same court held that a platform that curates or promotes listings, or controls its sellers, plays an active role and cannot claim to be a passive conduit.[14] The landmark case of Google India Private Limited v. Vishakha Industries (2009)[15] explored the concept of intermediary liability in India before the 2009 amendments to the Information Technology Act. The case centred around a defamatory article posted on a Google Group. The aggrieved party (Vishakha Industries) notified Google (the intermediary) about the offensive content but claimed Google failed to take any action. Consequently, Vishakha Industries filed a complaint against Google and the content creators in January 2009.

Google, in their defence, sought exemption under Section 79 of the Information Technology Act and argued that control over the Google Groups platform resided with their parent company, Google LLC, making them the true intermediary. Additionally, they contended that the amended Section 79 (effective October 27, 2009) applied as the complaint was filed after that date.

The court, however, clarified that the pre-amendment version of Section 79 governed the case due to the filing date. This pre-amendment version offered intermediaries limited immunity, solely applicable to provisions enshrined within the Information Technology Act and its associated regulations. Defamation, the court observed, fell outside the purview of the Act, and hence, Google couldn’t claim immunity under the pre-existing Section 79.

In conclusion, the Supreme Court was unable to identify a relevant provision within the Information Technology Act that addressed defamation, and ruled that Google was not entitled to any protection from liability under the pre-amendment Section 79. This case significantly shaped the legal landscape surrounding intermediary liability in India.[16]

3.4 The 2021 Rules and Kunal Kamra

The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 set due-diligence requirements and created the SSMI category, which covers platforms with more than 5 million registered users and carries additional duties. Rule 7 provides that non-compliance costs the intermediary its section 79 protection.[17] Amendments in October 2022 and April 2023 added obligations, including a government “fact check unit” clause in Rule 3(1)(b)(v).[18] In Kunal Kamra v Union of India, the Bombay High Court struck that clause down in September 2024.[19] The decision shows that courts will review subordinate legislation that enlarges the meaning of “due diligence” beyond what the parent Act and the Constitution allow.

3.5 X Corp v Union of India

On 24 September 2025 a single judge of the Karnataka High Court dismissed X Corp’s petition against the government’s use of section 79(3)(b) and Rule 3(1)(d), and against the “Sahyog” portal through which authorised officers send takedown notices.[20] As reported, the Court held that section 79(3)(b) and section 69A can operate side by side and that the portal is a legitimate administrative tool. Critics say the decision validates a parallel takedown route that avoids the safeguards of section 69A and the Blocking Rules, 2009.[21] X Corp appealed in November 2025.[22] The outcome of the appeal is not considered here.

These decision matters for two reasons. First, a notice from a government officer sent through a portal is now enough to engage the conditional immunity, which gives the ‘notification by the appropriate government’. The decision also confirms that section 79 works as a lever on platform conduct, because immunity is the price of compliance. The 2026 Amendment uses the same lever.

4. AMPLIFICATION AND THE TEXT OF SECTION 79

4.1 Section 79(2)(b): selecting receivers and content

Section 79(2) sets out alternative conditions. Under clause (a), the intermediary’s function is limited to providing access to a communication system. Under clause (b), it does not initiate the transmission, select the receiver of the transmission, or select or modify the information in the transmission. Under clause (c), it observes due diligence and any guidelines the Central Government prescribes.[23]

Clause (b) sits uneasily with a personalised recommender system. A system that decides which users receive a given item, in ordinary language, selecting receivers. Ranking, clipping, auto-captioning and thumbnail selection can amount to selecting or modifying the information transmitted. The answer on the other side is that “the transmission” means a discrete communication from sender to recipient, and that a feed is a continuing display of hosted material. That argument has force for chronological or user-directed feeds. It has little force where an engagement-optimised model, and neither the uploader nor the viewer, determines who sees what.

4.2 Section 79(3)(a): aiding and inducing

Section 79(3)(a) removes immunity where the intermediary has conspired, abetted, aided or induced the unlawful act. Suppose a platform has credible notice that an item is a deepfake impersonating a person, or is non-consensual intimate imagery. If it keeps recommending the item, it is making a fresh distribution decision and is doing more than failing to remove. “Aiding” describes that conduct better than a failure to remove does.

4.3 The policy rationale and the counter-position

Safe harbour rests on the impracticability of reviewing every upload. The rationale is weakest for amplification. A platform that scores every item to decide how to rank it has evaluated that item, and it profits from the engagement that results. Reviewing content is infeasible at the point of hosting but much less so at the point of promotion.

The counter-position is that recommendation is an editorial function, protected as speech or treated as a neutral core service, and US decisions show how unsettled the question is. In Gonzalez v Google LLC, the Supreme Court declined to decide whether section 230 protects recommendations,[24] and in Twitter Inc v Taamneh it disposed of the claim on aiding-and-abetting grounds.[25] The Third Circuit in Anderson v TikTok Inc later reasoned that algorithmic curation can be the platform’s own expressive activity and so fall outside the protection of section 230 gives to third-party content.[26] The Second Circuit took a broader view of immunity in Force v Facebook Inc.[27] The Supreme Court’s treatment of curation as expression in Moody v NetChoice supports the view that curation belongs to the platform, although that case concerned First Amendment limits on state regulation and not liability.[28] Wu’s work on “machine speech” shows how contested the classification is.[29] Indian law has more room to move. It has no counterpart to the broad text of section 230 and no First Amendment doctrine, and section 79 is expressly conditional on neutrality.

4.4 Generative AI providers

Where a platform’s own generative tool produces the deepfake, the output is not third-party information. The provider selects or modifies the information, so section 79(2)(b) is not met, and in substance the provider is closer to an originator than an intermediary. The 2026 Amendment moves in this direction by placing duties on intermediaries that offer computer resources enabling the creation of SGI, but it does so by rule and does not settle how such providers should be characterised.[30]

4.5 Assessment

The text and structure of section 79 support reading the safe harbour as covering hosting and not amplification. Selecting receivers and content (section 79(2)(b)) and aiding or inducing (section 79(3)(a)) already build a neutrality requirement into the provision, and algorithmic promotion fits poorly with it. The question is open, and courts could reasonably decide it either way. That uncertainty is itself a reason for the legislature to clarify the point.

5. THE 2026 AMENDMENT

On 10 February 2026, the Ministry of Electronics and Information Technology (MeitY) notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, through Gazette Notification G.S.R. 120(E). The Amendment came into force on 20 February 2026 and introduced important changes to the existing IT Rules, 2021, particularly in relation to synthetically generated information (SGI), intermediary due diligence and the removal of unlawful online content.[31]

The major changes introduced by the Amendment are discussed below.

  • The Amendment formally recognises synthetically generated information (SGI). It introduces a specific definition of SGI under Rule 2(1)(wa). The definition covers audio, visual and audio-visual information that is artificially or algorithmically created, generated, modified or altered using a computer resource in a way that makes it appear real or authentic. This includes realistic deepfake videos, manipulated images and cloned voices. The Amendment also requires permissible SGI to carry appropriate labels and technical identifiers so that users can identify it as synthetic content.
  • The Amendment introduces additional responsibilities for intermediaries, particularly Significant Social Media Intermediaries (SSMIs). Under the new Rule 4(1A), SSMIs must obtain a declaration from users stating whether uploaded content is synthetically generated.[32] They must also use reasonable technical measures to verify the declaration before allowing the content to be published. Where the content is confirmed to be SGI, the platform must display a clear and prominent label identifying it as synthetically generated.
  • The Amendment reduces the time available to intermediaries to act on certain unlawful content. Under the amended Rule 3(1)(d), where an intermediary receives actual knowledge through a court order or a reasoned intimation from an authorised government officer or agency, it must remove or disable access to the specified unlawful information within three hours. This replaces the earlier period of 36 hours.[33]

A separate, shorter deadline applies to certain sensitive complaints. Under Rule 3(2)(b), intermediaries must remove or disable access to specified content involving nudity, sexual acts, morphed images or impersonation within two hours of receiving a complaint. This period was earlier 24 hours. The distinction between these two deadlines is important because they arise under different provisions and apply to different circumstances.[34]

  • The Amendment introduces a specific due-diligence framework for SGI under the new Rule 3(3). Intermediaries covered by this provision must take reasonable and appropriate technical measures to prevent unlawful synthetic content. For SGI that is not prohibited, the Rules require clear labelling and the use of permanent metadata or other technical mechanisms, to the extent technically feasible, to help identify the content as synthetic and trace its origin.

(5)  The Amendment is intended to operate within the powers granted to the Central Government under the Information Technology Act, 2000. The notification states that the Rules are made under Section 87(1), read with Sections 87(2)(z) and 87(2)(zg) of the Act. These provisions provide the rule-making authority for the regulatory framework.

(6)  Finally, the Amendment distinguishes deceptive synthetic content from ordinary digital editing and legitimate uses of technology. It excludes certain routine or good-faith activities, such as colour correction, noise reduction, compression and technical improvements, provided they do not materially alter or misrepresent the original content. It also excludes specified educational, research, document-preparation and accessibility-related uses, subject to the conditions in the definition. This distinction is significant because not every use of artificial intelligence or digital editing should automatically be treated as harmful synthetic content.

5.1 What the Amendment achieves

The Amendment gives SGI a legal identity of its own and moves part of the responsibility to the point where content is created and published. Its labelling and provenance obligations resemble the transparency duty for deepfakes in Article 50 of the EU AI Act.[35] The shorter windows for NCII address a real weakness of the earlier regime, in which a delay of 24 to 36 hours was out of step with how quickly the harm occurs.

Overall, the 2026 Amendment represents an important development in India’s regulation of AI-generated and manipulated media. It introduces a specific legal definition of SGI, requires labelling and technical verification, places additional obligations on certain intermediaries and reduces the time available to respond to specified unlawful content.

5.2 Gaps

The first gap is that the Amendment does not regulate amplification. On the published summaries it works on three matters: what must be labelled, what must be removed, and how fast. None of them concerns distribution. A labelled deepfake can still be boosted, and a deepfake that no order has yet reached can still be recommended. Nothing in the reported text requires an SSMI to assess how its ranking systems treat unverified synthetic media or to add friction to its spread.

The second gap is the legal basis. The Amendment conditions immunity on compliance through the due-diligence limb of section 79(2)(c) and Rule 7. Delegated legislation that widens the content of due diligence invites the kind of ultra vires challenge that succeeded in Kunal Kamra.[36] The Karnataka High Court’s decision in X Corp is more deferential to the executive, so the outcome of a challenge may depend on the forum and on how the case is framed.[37]

The third gap is that the timelines are demanding and uniform. Practitioners observe that a three-hour window is hard to meet without round-the-clock human and automated review, and that it risks erroneous takedowns and pressure on Article 19(1)(a).[38] Large platforms can build that capacity. Smaller intermediaries may over-remove or leave the market.

The fourth gap is the absence of a counter-notice mechanism. The reported text concentrates on platform obligations, and the uploader’s right to be heard appears thin and concerns proportionality.

6. CONSTITUTIONAL DIMENSIONS

6.1 The framework

Restrictions on speech must be imposed by law and fall within Article 19(2). They must also be reasonable, which Indian courts now test through proportionality. The test asks whether the measure pursues a legitimate aim, whether it is a suitable means, whether it is necessary because no less restrictive and equally effective alternative exists, and whether it strikes a proper balance between the right and the aim.[39] The Supreme Court applied the framework to restrictions on internet access in Anuradha Bhasin v Union of India.[40] Article 21 protects privacy, including dignity and control over one’s identity, as Puttaswamy recognised, and that supports affirmative measures against deepfake harm.[41] The Court has also required technical measures against abusive content, as in the Prajwala proceedings on sexual-violence material.[42]

6.2 Application

Protecting dignity, privacy, electoral integrity and the public from fraud is a legitimate aim, and labelling, provenance and targeted rapid removal of NCII are suitable means to it.

Uniform compressed timelines are most vulnerable on the necessity limb. A rule that gives a clearly non-consensual intimate deepfake and a contested political parody the same clock, with no hearing for the uploader, invites over-removal. The chilling effect on the uploader remains even if the content is later restored. A tiered regime would restrict less. The shortest timelines would apply only to narrow and readily identifiable categories, namely NCII, child sexual abuse material and clear impersonation fraud. Longer windows, reasoned decisions and counter-notice would apply to the rest.

Reducing reach restricts expression less than removal does. Demotion, friction and labelling leave the content available. A duty not to promote notified content, together with demotion pending review for unverified synthetic media in defined high-risk contexts, sits lower on the proportionality scale than an order to delete. This is the strongest constitutional argument for shifting regulatory weight from deletion toward distribution.

Article 19(2) requires restrictions to be imposed by law, and courts scrutinise delegated legislation for excess of power. Primary legislation is therefore the more durable course, and the proposed Digital India Act, long promised as the successor to the IT Act, is the natural vehicle.

Shreya Singhal upheld the section 69A blocking regime partly because of its procedural protections, which include reasoned orders, review and, where possible, a hearing.[43] Any amplification-based regime needs comparable safeguards: reasoned decisions, human review of contested cases, counter-notice, appeal, transparency reporting, and consequences for bad-faith notices.

7. COMPARATIVE PERSPECTIVES

7.1 United States

Section 230 of the Communications Decency Act gives broad immunity for third-party content, and its application to recommender systems is unsettled. Congress has legislated narrowly on deepfake NCII. The TAKE IT DOWN Act 2025 requires covered platforms to remove reported non-consensual intimate imagery, including AI-generated imagery, within 48 hours of a valid request.[44] Narrow, category-specific duties can therefore be added without dismantling general immunity.

7.2 European Union

The Digital Services Act keeps a conditional hosting exemption (Article 6), prohibits general monitoring obligations (Article 8) and requires notice-and-action mechanisms (Article 16).[45] It adds a separate layer for very large platforms, which must assess and mitigate systemic risks, including those arising from their recommender systems (Articles 34 and 35), and must offer at least one recommender option not based on profiling (Article 38). The AI Act separately imposes transparency duties for deepfakes (Article 50).[46] This model is structurally the closest to the one proposed in this paper, because it preserves hosting immunity while regulating how content is distributed. Systemic-risk regimes need independent oversight and public transparency, or they can become a channel for executive pressure.

7.3 United Kingdom

The Online Safety Act 2023 requires regulated services to assess and mitigate the risk of illegal content, and those assessments cover how algorithms and functionalities affect its spread.[47] A statutory regulator, Ofcom, enforces the duties, which avoids item-by-item litigation.

7.4 Reach of takedown orders

In Glawischnig-Piesczek v Facebook Ireland the CJEU held that a court may order removal of identical and equivalent content worldwide, subject to international law.[48] Deepfakes spread across mirrors and re-uploads, so effective relief needs tools such as hash-matching, which work proactively. That supports duties directed at system design.

7.5 Comparison and lessons for India

Table 1 summarises the four regimes.

Table 1. Liability for deepfakes and amplification in four jurisdictions

JurisdictionCore ruleLesson for India
United StatesThe TAKE IT DOWN Act 2025 requires removal of reported NCII, including deepfakes, within 48 hours.Narrow statutory duties can be added without ending general immunity.
European UnionHosting exemption (DSA art 6), notice-and-action (art 16) and no general monitoring duty (art 8).Hosting immunity and regulation of distribution can coexist, with independent oversight.
United KingdomOnline Safety Act 2023 duties on regulated services, enforced by Ofcom.A regulator can enforce design-level duties without item-by-item litigation.
IndiaConditional immunity under section 79, with the IT Rules 2021 as amended in 2026.A statutory amplification and systemic-risk layer is needed.

Three lessons follow. Hosting immunity and regulation of distribution can coexist, as the EU shows. Narrow, category-specific and time-bound duties work better than uniform ones, as the US experience suggests. Independent oversight matters, as the EU and UK regimes show. The last lesson carries particular weight in India, given the litigation over executive takedown tools such as the Sahyog portal.[49]

8. PROPOSED REFORM MODEL

The analysis supports a differentiated, knowledge-based framework enacted in primary legislation. It has eight elements:

  1. Immunity for passive hosting stays, and the Shreya Singhal actual-knowledge standard continues to govern liability for content that is merely hosted.
  2. Section 79 should state that immunity does not cover an intermediary’s own algorithmic recommendation, boosting or monetisation of specific content after credible and specific notice that it is unlawful. For SGI, notice could come from the depicted person or an authorised representative.
  3. On credible notice of an NCII, impersonation or fraud deepfake, the platform must suspend algorithmic amplification pending review, which must be completed within a short fixed period. Removal would not be required at this stage.
  4. SSMIs should carry a systemic risk duty. They would conduct periodic, independently audited assessments of how their ranking and recommendation systems treat synthetic media, adopt mitigation measures, and publish transparency reports.
  5. The 2026 labelling approach should stay. Interoperable provenance standards should be preferred, and knowingly false user declarations should be penalised.
  6. The shortest removal windows should apply to NCII and child sexual abuse material. Contested categories should have longer windows, with reasons, counter-notice and appeal.
  7. A provider whose tool generates the unlawful content should be treated as an originator of that output and denied intermediary immunity for it.
  8. A regulator independent of the executive should enforce the systemic duties and be subject to transparency obligations.

Therefore, immunity should be withheld from platforms that knowingly facilitate harm, which supports making protection depend on conduct.

9. CONCLUSION

Section 79 protects a platform that hosts third-party content on condition that it stays neutral. A recommender system that carries a deepfake to millions of users makes its own choices about selection and distribution, and the conditions in section 79(2)(b) and section 79(3)(a) are hard to reconcile with that. Indian courts can reach this conclusion from the text of section 79. Shreya Singhal remains a safeguard against private censorship, but it gives victims no timely remedy in the first hours, when the harm is greatest. X Corp shows that the knowledge standard is itself unsettled.

The 2026 Amendment improves provenance, labelling and the speed of removal. It does not regulate amplification and its reliance on delegated legislation and uniform compressed timelines leaves it exposed on legality and proportionality. The proposed reform model would help in keeping hosting immunity, remove protection from amplification after notice, add a systemic risk duty, and build procedural safeguards into primary legislation. It offers a workable reassessment of the section 79 safe harbour that takes account of both the dignity of deepfake victims and the speech interests that Shreya Singhal sought to protect.


[1] LL.B (Hons.) 3rd year & BA.LLB

Email : suchitra090903@gmail.com ; Nflrd.founder@gmail.com

[2] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules 2026, G.S.R. 120(E), notified 10 February 2026.

[3] Bobby Chesney & Danielle Keats Citron, Deep Fakes: A Looming Challenge for Privacy, Democracy, and National Security, 107 CALIFORNIA L. REV. 1753, 1756–58 (2019).

[4]Id. at 1758–76.

[5]Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, G.S.R. 120(E), GAZETTE OF INDIA, EXTRAORDINARY, pt. II sec. 3(i), r. 2(1)(wa) (Feb. 10, 2026).

[6]Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, G.S.R. 120(E), GAZETTE OF INDIA, EXTRAORDINARY, pt. II sec. 3(i), r. 2(1A) (Feb. 10, 2026).

[7]Regulation (EU) 2022/2065 (Digital Services Act), arts. 6, 8, 16, 34, 35, 38.

[8]Supra note 3.

[9]Soroush Vosoughi, Deb Roy & Sinan Aral, The Spread of True and False News Online, 359 SCIENCE 1146, 1146 (2018).

[10]Avnish Bajaj v. State (NCT of Delhi), (2005) 3 Comp LJ 364 (Del.).

[11]The Information Technology (Amendment) Act, No. 10 of 2009.

[12]Shreya Singhal v. Union of India, (2015) 5 SCC 1.

[13]MySpace Inc. v. Super Cassettes Indus. Ltd., 2016 SCC OnLine Del 6382 (DB); (2017) 236 DLT 478.

[14]Christian Louboutin SAS v. Nakul Bajaj, 2018 SCC OnLine Del 12215.

[15]Google India Pvt. Ltd. v. Visakha Industries, (2020) 4 SCC 162.

[16] Siddhant Samaiya, An Analysis of Intermediary Liability in India and the European Union, MANUPATRA ARTICLES (2024), https://articles.manupatra.com/article-details/an-analysis-of-intermediary-liability-in-india-and-the-european-union.

[17]Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, G.S.R. 139(E), GAZETTE OF INDIA, pt. II sec. 3(i) (Feb. 25, 2021), rr. 3, 4, 7.

[18]Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2022, G.S.R. 794(E), GAZETTE OF INDIA, pt. II sec. 3(i) (Oct. 28, 2022); Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2023, G.S.R. 275(E), GAZETTE OF INDIA, pt. II sec. 3(i) (Apr. 6, 2023).

[19]Kunal Kamra v. Union of India, W.P. (L) No. 9792 of 2024 (Bom. H.C. Sept. 20, 2024).

[20]X Corp. v. Union of India, W.P. No. 7405 of 2025 (Karnataka High Court Sept. 24, 2025).

[21]SFLC.IN, Analysis of X Corp. v. Union of India Judgment in Karnataka High Court, SFLC.IN (2025), https://sflc.in/xcorp-judgment-analysis/.

[22]Mustafa Plumber, X Corp. Moves Karnataka High Court in Appeal Against Ruling Upholding Centre’s Blocking Powers Through Sahyog Portal, LIVE LAW (2025), https://www.livelaw.in/high-court/karnataka-high-court/karnataka-high-court-hearing-x-corp-appeal-against-central-government-blocking-orders-310049.

[23]Information Technology Act, No. 21 of 2000, § 79(2)(a)-(c).

[24]Gonzalez v. Google LLC, 598 U.S. 617 (2023).

[25]Twitter, Inc. v. Taamneh, 598 U.S. 471 (2023).

[26]Anderson v. TikTok, Inc., 116 F.4th 180 (3d Cir. 2024).

[27]Force v. Facebook, Inc., 934 F.3d 53 (2d Cir. 2019).

[28]Moody v. NetChoice, LLC, 603 U.S. 707 (2024).

[29]Tim Wu, Machine Speech, 161 U. PA. L. REV. 1495 (2013).

[30]Khaitan & Co., MeitY Notifies the IT Amendment Rules 2026, Lexology (Feb. 17, 2026), https://www.lexology.com/library/detail.aspx?g=3e894ffc-4e0b-4487-a5e9-015d490d45d3.

[31] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, G.S.R. 120(E), Gazette of India, Extraordinary, pt. II, sec. 3(i), Feb. 10, 2026, r. 1(2).

[32] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, r. 4(1A), as amended by G.S.R. 120(E) (Feb. 10, 2026).

[33] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, r. 3(1)(d), as amended by G.S.R. 120(E) (Feb. 10, 2026).

[34] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, r. 3(2)(b), as amended by G.S.R. 120(E) (Feb. 10, 2026).

[35]Regulation (EU) 2024/1689, art. 50, 2024 O.J. (L 1689) 1.

[36]Kunal Kamra v. Union of India, Writ Petition (L) No. 9792 of 2023 (Bom. H.C. Sept. 26, 2024).

[37]X Corp. v. Union of India, W.P. No. 7405 of 2025 (GM-RES) (Karnataka H.C. Sept. 24, 2025).

[38]Ranjan Narula & Parth Bajaj, Regulating Synthetically Generated Information: India Amends IT Intermediary Rules, Managing Intell. Prop. (Mar. 11, 2026).

[39]Modern Dental College & Research Centre v. State of Madhya Pradesh, (2016) 7 SCC 353; K.S. Puttaswamy (Retd.) v. Union of India, (2019) 1 SCC 1 (India).

[40]Anuradha Bhasin v. Union of India, (2020) 3 SCC 637 (India).

[41]Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 (India).

[42]In Re: Prajwala, Suo Motu Writ Petition (Crim.) No. 3 of 2015, Order (Mar. 22, 2017) (India).

[43]Shreya Singhal v. Union of India, (2015) 5 SCC 1.

[44]TAKE IT DOWN Act, Pub. L. No. 119-12, (2025)

[45]Digital Services Act, Regulation (EU) 2022/2065, arts. 6, 8, 16, 34, 35, 38, 2022 O.J. (L 277) 1.

[46]Regulation (EU) 2024/1689 (Artificial Intelligence Act), arts. [relevant articles], 2024 O.J. (L 1689) 1.

[47]Online Safety Act 2023, c. 50, §§ 9–10 (U.K.).

[48]Case C-18/18, Glawischnig-Piesczek v. Facebook Ireland Ltd., ECLI:EU:C:2019:821.

[49]Chinmayi Arun, Facebook’s Faces, 135 Harv. L. Rev. F. 236 (2022).

Hot this week

“Gendered  Vulnerabilities in Cyberspace: Cybercrime Against Women and the Adequacy of Indian Law”

Prasoon Ranjan & Vishnukanti ABSTRACT Over the previous two decades, information...

Ai-Generated Evidence Under The Bharatiya Sakshya Adhiniyam, 2023: Rethinking Authenticity In The Age Of Deepfakes

Author- Mr. Anuj SethiResearch Scholar, Dr. Bhimrao Ambedkar University,...

CYBER LAW IN INDIA: LEGASLATIVE GAPS AND IMPERATIVE FOR COMPREHENSIVE REFORMS

Prasoon Ranjan IIMT COLLEGE OF LAW GREATER NOIDA Anuska...

Topic : Traditional Knowledge and Cultural Heritage:Legal Protectionand Ethical Consideration.

Dr. Lakshlata PrajapatiAssistant Professor, Faculty member of Law DepartmentMJPRU,BareillyEmail...

Environmental Rights and The Concept of Sustainable Development

       Dr. LakshLata PrajapatiAssistant Professorlatalaksh1979@gmail.com Abstract : The intersection of environmental rights...

Topics

“Gendered  Vulnerabilities in Cyberspace: Cybercrime Against Women and the Adequacy of Indian Law”

Prasoon Ranjan & Vishnukanti ABSTRACT Over the previous two decades, information...

CYBER LAW IN INDIA: LEGASLATIVE GAPS AND IMPERATIVE FOR COMPREHENSIVE REFORMS

Prasoon Ranjan IIMT COLLEGE OF LAW GREATER NOIDA Anuska...

Topic : Traditional Knowledge and Cultural Heritage:Legal Protectionand Ethical Consideration.

Dr. Lakshlata PrajapatiAssistant Professor, Faculty member of Law DepartmentMJPRU,BareillyEmail...

Environmental Rights and The Concept of Sustainable Development

       Dr. LakshLata PrajapatiAssistant Professorlatalaksh1979@gmail.com Abstract : The intersection of environmental rights...

From Hicklin’s page to the digital frame,

the test of shame has never stayed the same; what...
spot_img

Related Articles

Popular Categories

spot_imgspot_img