Deepfakes, AI and the Law: Protecting Privacy and Reputation in India’s Evolving Legal Framework

Abstract

Generative AI development is happening much faster than the ability to create and share digital content, resulting in deepfakes which will pose a considerable threat to personal privacy and reputation, and the validity of digital communications. The purpose of this article is to evaluate whether India’s current legal framework is sufficient to address the misuse of deepfakes generated by AI technology. This will be achieved through a doctrinal research methodology by looking at the constitutional guaranteed rights to informational privacy and dignity, the applicability of the Information Technology (IT) Act of 2000, the Digital Personal Data Protection Act of 2023, and the Information Technology Intermediary Guidelines and Digital Media Ethics Code Rules of 2021. The analysis will include an examination of how India regulates deepfakes in comparison to global trends including, but not limited to, the European Union Artificial Intelligence Act. Ultimately, although the current legal framework can be defined as fragmented regarding the available remedies, it is not comprehensive in its ability to legislate deepfakes. A suggestion will be made for a new technology-neutral and rights-based legal framework which will balance innovation with the right to privacy as we embrace the digital age.

Introduction

In the era of the twenty-first century, every sector that uses artificial Intelligence (AI) has undergone significant transformation, revolutionizing sectors such as healthcare, finance, governance and even the legal. One of its most notable innovations is the ability to produce highly realistic images, audio recordings and videos that are hard to distinguish from real ones and is becoming increasingly commonplace, this is known as deepfakes. Deepfakes, fueled by cutting-edge machine learning algorithms such as Neural Networks, Machine Translation, and Deep Learning, have ushered in a new era of digital creativity with a host of legal dilemmas.

Generative AI has created tools that have dramatically lowered the skill-set needed to produce realistic and believable digital material. Now, anyone can create a totally fake video in a few minutes, use a fake facial expression on photos or clone a voice from a recording using publicly available AI tools. India experienced the urgency to regulate deepfake content after falsified AI-generated video of Rashmika Mandanna was circulated in November 2023, attracting public attention and spurring the Ministry of Electronics and Information Technology (MeitY) to issue warnings to intermediaries about their responsibilities under the Information Technology Act, 2000 and Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021. The situation demonstrates that authorities will continue to use existing regulatory laws to remediate harm caused by new technologies (e.g., AI) until specific law(s) governing deepfake content are enacted.

The legal implications of deepfakes are particularly significant in India, The attacks have raised questions about the existing legal framework, with several incidents involving AI-generated content involving celebrities and journalists’ defamation of the private individuals. While the Constitution of India, Information Technology Act, 2000, Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 offer some legal tools to curb the use of synthetic media, they are not specifically formulated for synthetic media created using AI tools.

Understanding Deepfakes: Technology, Privacy, and Reputational Harm

“Deep fake” is a merging of the word ‘deep learning’ and ‘fake which refers to a synthetic media created or modified by artificial intelligence to look, sound or act like the real person.

Unlike standard photo or video editing, deepfakes use sophisticated networks included Generative Adversarial Networks (GANs) and diffusion models to create extremally easy-to-true photographs that are often indistinguishable from the actual.

Deepfake technology has a handful of valid uses, such as the film industry, language translation, language accessibility, and educational simulations, but it’s also a cause for concern in the legal field and in society. Deepfakes have become a recent and sophisticated weapon of choice for the creation and release and spread of non-consensual sexualized footage, impersonation of public officials, voice cloning financial scams, and concocted videos with the potential of swaying public opinion. This fraud not only damages the victims, but also erodes the trust in digital transactions, complicating the task of determining fact from fiction.

The legal implications of the deepfake is the most significant consequence as it relates to the freedom of privacy. The Supreme court asserted in Justice K.S. Puttaswamy (Retd) v. Union of India (2017) that privacy is part and parcel of the right to life (Article 21) and liberty (Article 319) guaranteed by the Constitution. The Court also stressed that privacy is not just a physical right, it is also an informational right, an autonomy right, a dignity right, and a control right over one’s identity. An unauthorized and inaccurate use of a person’s facial image, voice or other distinctive features or characteristics in creating a deep fake directly affects these constitutionally recognised interests, particularly if the deep fake is fabricated in ignorance or against their will.

Deepfakes also pose a serious risk to the reputation of a person, which has always been regarded as one of the fundamental components of the right to life guaranteed by Article 21 by the Supreme Court. Falsified video or sound recordings of a person committing criminal, an unethical or socially undesirable wrong could go viral across digital channels before anyone questions their validity, inflicting harm that can be difficult or impossible to remedy to themselves, their children and families, and their careers.

In addition to potentially affecting individual rights, there are larger institutional concerns as well. As they have become more sophisticated, electronic evidence can become increasingly unreliable and can lead to the “liar’s dividend” – a situation in which true electronic evidence can be disregarded as a forgery, and a forgery can be accepted as genuine. These changes have profound implications for criminal investigations, court proceedings, the news media, and the governance of democracies, where trust in digital information is fundamental.

India’s Legal Framework: Evaluating Existing Protection Against Deepfakes

India does not have a specific law to regulate AI or AI-generated deepfakes. As a result, they have to depend on both constitutional and cyber laws, data protection laws, and intermediary obligations.

The Constitution of India has the backing for the problem tackling deepfakes through two Articles: Article 19 and Article 21.

Article 19(1) provides for the right to freedom of speech and expression, which is limited by reasonable restrictions in Article 19(2), in particular such restrictions as “defamation”, “decency”, “morality”, “public order”, and “incitement to an offence”. As such, the creation or circulation of harmful deepfakes is not entitled to constitutional protection if it violates the rights of others or poses a risk to the public interest.

Article 21 which was interpreted in Justice K.S. Puttaswamy (Retd) v Union of India, 2017, gives privacy, dignity and informational autonomy as fundamental rights. Synthetic media based on the use of a person’s image, voice or biometric feature without permission thus infringe on serious constitutional issues.

Information Technology Act, 2000.

(i) Section 66C is about criminalizing the use of another person’s electronic signature, their unique identifier, such as a password, or by acting as another person using their identity.

(ii) Section 66D is about using computer resources to cheat by personation. The provisions can be used if a deepfake is used to fake an individual for financial fraud, deception or illegal benefits.

(iii) Section 66E provides for offences in relation to images that cause substantial damage to someone’s privacy. Also, Section 66E covers offences relating to images made when there is deliberate capturing, showing or sending of images to the detriment of someone’s privacy.

(iv) Sections 67, 67A and 67B ban the publication or the transmission of obscene materials, sexually explicit materials and child sexual abuse material in electronic form to address the problem of AI generated such materials and content. All these provisions provide victims with legal avenues without targeting the technology. Together, they provide statutory remedies for the ordeal of deepfakes when it comes to its harmful effects.

Digital Personal Data Protection Act, 2023 

(i) As per Section 4 of the Act, personal data of a digital form may not be processed without compliance of the provisions of Act and only for a lawful purpose

(ii) Section 6, consent shall be free, affirmative, explicit, specific, informed and unambiguous. The racially inclusive nature of the term ‘person’ ensures that these provisions maintain an individual’s control over his or her personal data, because face images, voice recordings, or other identifiable personal information capable of being used to create a deepfake are often collected and processed without consent.

(iii) The Act nonetheless primarily focuses on the processing of personal data and is silent on the generation of synthetic media by AI, algorithmic manipulation and liability distribution among AI developers, deployers and users.

Deepfakes are also being tackled by digital intermediaries playing a significant part. According to Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, intermediaries have to take reasonable measures, create redressal systems for grievances regarding content distributed or hosted online, and follow legitimate orders regarding unlawful content on the Internet.

This “Catch-Up” approach frequently fails to keep up with the rapid dissemination of deepfakes on digital platforms, where the damage may be widespread. Combined, these constitutional and statutory provisions offer a patchwork of laws that offer a viable legal answer to deepfakes. But, they were drafted with considerations of regular cybercrimes and data processing. They notwithstanding, were drafted while taking into account the specific risks of generative AI. Lack of a clear legal definition, disclosure rules, platform responsibility and liability for Artificial Intelligence highlights the need for a more feasible and visionary legal framework.

Judicial Developments, Comparative Perspectives, and the Need for Reform

The Indian courts have always held the view that the expectations of privacy, dignity and reputation guaranteed by the Constitution are uninimpensed by technological progress and innovation. In Justice K.S. Puttaswamy (Retd). v. Union of India (2017), the Supreme Court had confirmed that privacy goes beyond physical privacy to personal and informational privacy and intervention of the government in this context is not permissible.

Likewise, in Subramanian Swamy v. Union of India (2016), the Court underlined that the concept of reputation of an individual was an integral part of the right to life in Article 21 of the Constitution, further emphasising the responsibility of the State to safeguard the citizens from the defamatory and malicious use of technology.

Balancing freedom of speech and regulation of the online space can also be found in the Supreme Court’s judgment in Shreya Singhal v. Union of India (2015). In striking down IT Act 2000 Section 66A (for violation of the Article 19(1)(a), the Court reconfirmed that online expression continues to be subject to reasonable restrictions under the Article 19(2).

Therefore, any new laws addressing deepfakes should strive to be specific and narrowly drawn to prevent overinclusion, while allowing for meaningful remedies to combat harmful uses of AI-generated content. Such a balance is crucial given the socially beneficial and harmful uses of deepfake technology.

The European Union AI Act and India

Comparative developments also show the journeyperson’s initial coverage of AI-specific regulation is global and is expanding. The EU Artificial Intelligence Act combines a risk-based approach with risk classification of AI systems, categorizing them by the extent of potential risks to people and society. The Act allows obligations of transparency for some AI-generated content, such as deep fake, in that requiring the disclosure that the content is man-made or manipulated, only in certain circumstances provided by the law. The ‘European’ approach is not about stifling innovation, however, but it is about imposing changable measures for accountability, consumer protection and public trust in a proportionate manner.

However no such legislation has been passed in India yet. While the Ministry of Electronics and Information Technology’s guidelines have directed digital platforms to tackle misinformation and harmful AI-generated content, these are guidelines that can be implemented by the Government, but don’t carry the force of law like the Parliament has done. Consequently, there remain legal dilemmas about the responsibilities of AI developers, deployers, online platforms and users. Issues with mandatory watermarking of AI-generated content and the responsibility of AI companies for algorithmic damage are still unresolved, as are standards for authenticating electronic evidence and cross-border enforcement.

This is because the pace at which generative AI has developed makes it urgent to take a proactive stand to the law, rather than past efforts to rely on specific parts of existing legislation.

Recommendations and the Way Forward

1. India should put forward the need for a dedicated regulatory framework for AI which specifically targets synthetic media created by AI. Such a Bill should appropriately define the term “deepfakes”, clarify and differentiate between non-malicious uses (artistic, educational, research and journalistic) and unlawful ones, and provide proportional civil and criminal penalties. A precise definition in the law itself would also eliminate legal ambiguity and allow for the clear and uniform application of the law.

2. Secondly, developers and deployers of generative AI systems are more accountable. Technical features like watermarking, provenance metadata and such content authentication features should be integrated into AI platforms to aid in the easier identification of AI-generated media. These steps will not stop these images being misused completely, but they will help make the images more traceable and limit their spread of dubious content.

3. Thirdly, these digital middlemen should introduce robust tools for detecting AI-generated content, provide quick handling of grievances, and ensure compliance with legitimate right to remove requests. Given how quickly deepfakes are becoming prevalent, it is crucial for online platforms to intervene in a timely manner to minimise the damage.

4. The same applies to the preparedness of the institutions. Specialist training needs to be delivered to Law Enforcement, Digital Forensic Labs, Prosecutors, and Judicial Members to ensure that they can identify, preserve, and examine AI evidence. Technical capacities of institutions enforcing the law will be important, but so will be an improved law that can be made to address the increasing complexity of synthetic media.

5. Under the Bharatiya Sakshya Adhiniyam, 2023, due to advancements in the capabilities of artificial intelligence to generate audio and video, courts may find that electronic records are less likely to be credible and therefore, the courts may need to rely on digital forensic techniques, metadata analysis, hash verification, and expert testimony as a way to differentiate between authentic electronic records and artificial intelligence-generated fabrications.

6. In addition, there must be continued efforts to educate the public about AI literacy and digital verification through public awareness initiatives to support the implementation of legislative reform.

Conclusion

In conclusion, it is crucial to strike a balance between safeguarding constitutional freedoms and fostering technological advancements when it comes to regulation of deepfakes. To conclude, deepfakes are among the most intricate legal issues resulting from the swift progress of generative AI. Their misuse is not only detrimental to individual privacy and reputation but is also a danger to democracy systems and the trust in internet communications in general. While there are some existing constitutional and statutory provisions, they fall short of offering a comprehensive framework for regulation of AI-powered synthetic media. Consistency with the rule of law and the protection of fundamental rights in the development of AI requires a coherent legislatory framework, upholding constitutional values, technological accountability and effective legal enforcement.

THIS ARTICLE IS WRITTEN BY ROSHAN GUPTA SH. SWAMI DAYAL BHATNAGAR LAW COLLEGE, CHAUDHARY CHARAN SINGH UNIVERSITY

REFERENCES :

Digital Personal Data Protection Act, 2023, Sections 4 and 6.

Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.

Shreya Singhal v. Union of India, (2015) 5 SCC 1.

Subramanian Swamy v. Union of India, (2016) 7 SCC 221.

People’s Union for Civil Liberties v. Union of India, (1997) 1 SCC 301.

The Constitution of India, Articles 19(1)(a), 19(2), and 21.

Information Technology Act, 2000, Sections 66C, 66D, 66E, 67, 67A, and 67B.

Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

Ministry of Electronics and Information Technology, Government of India, Information Technology Act, 2000 (official text).

Ministry of Electronics and Information Technology, Government of India, Acts and Policies.

Regulation (EU) 2024/1689 (Artificial Intelligence Act).

UNESCO, Recommendation on the Ethics of Artificial Intelligence (2021).

Organisation for Economic Co-operation and Development, OECD Principles on Artificial Intelligence (2019).

National Crime Records Bureau, Crime in India (latest available edition – Cyber Crime Chapter).

Henry Ajder et al., The State of Deepfakes: Landscape, Threats and Impact (Deeptrace Labs, 2019).

Hany Farid, “Digital Forensics in an Age of Deepfakes,” Journal of Applied Research in Memory and Cognition (2022).

Michael Veale & Frederik Zuiderveen Borgesius, “Demystifying the Draft EU Artificial Intelligence Act,” Computer Law Review International (2021).

Jonas Schuett, “Risk Management in the Artificial Intelligence Act” (2022).