AI Policy Wiki
Dashboard

India IT Rules Amendment 2026 (Synthetically Generated Information)

high confidence · updated 2026-08-09

MeitY's February 2026 amendments to India's Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, which define synthetically generated information, mandate labelling and embedded provenance metadata, and cut the takedown window for unlawful content from 36 hours to three.

The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 are a set of amendments to India's 2021 intermediary rules, notified by the Ministry of Electronics and Information Technology (MeitY) on 10 February 2026 and brought into force on 20 February 2026 (Source: vaishlaw.com). The amendments introduce a statutory definition of "synthetically generated information" (SGI), bringing deepfakes and other AI-generated audio-visual material within the due-diligence framework that conditions an intermediary's safe harbour under Section 79 of the Information Technology Act, 2000. They also impose labelling and embedded-provenance obligations on lawful synthetic content and compress the deadline for acting on government and court takedown orders from 36 hours to three (Source: hoganlovells.com).

Status and legislative history

MeitY issued the amendments by gazette notification G.S.R. 120(E), dated 10 February 2026, with a ten-day gap before the 20 February 2026 commencement date (Source: hoganlovells.com). MeitY publishes a consolidated text of the 2021 Rules "updated as on 10.02.2026" incorporating the amendments, whose footnote apparatus attributes each amended provision to G.S.R. 120(E) (India's IT Rules, 2021 — MeitY consolidated text as amended to 10 February 2026 (G.S.R. 120(E))). That consolidated text states the notification date but no commencement date; the 20 February 2026 date rests on practitioner analyses rather than on the ministry's own compilation.

The amendments were made under the rule-making power of the Information Technology Act, 2000 rather than by primary legislation, which places them in the same instrument class as the 2021 Rules they modify. Minister of State for Electronics and Information Technology Jitin Prasada set out the amendments' scope and timelines in a written reply in the Lok Sabha on 5 August 2026 (Source: m.economictimes.com).

Scope and definitions

The amendments define synthetically generated information as audio, visual, or audio-visual information that is artificially or algorithmically created, generated, modified, or altered using a computer resource in a manner that appears real and authentic, portraying individuals or events as indistinguishable from actual persons or real-world occurrences (rule 2(1)(wa)) (India's IT Rules, 2021 — MeitY consolidated text as amended to 10 February 2026 (G.S.R. 120(E))). A companion definition of "audio, visual or audio-visual information" was inserted at rule 2(1)(ca), and a new rule 2(1A) provides that references to "information" used to commit an unlawful act — including under rules 3(1)(b), 3(1)(d), 4(2) and 4(4) — are to be read as including synthetically generated information, which is the clause that carries SGI into the pre-existing prohibited-content and traceability machinery without rewriting each provision (India's IT Rules, 2021 — MeitY consolidated text as amended to 10 February 2026 (G.S.R. 120(E))).

The definition carries carve-outs intended to exclude routine digital practice: good-faith editing or technical correction such as formatting, colour adjustment, noise reduction or compression; the creation of documents, presentations, educational materials, drafts or templates that do not result in false records; and the use of a computer solely to improve accessibility, clarity, translation or discoverability without altering substantive content (Source: hoganlovells.com).

Key provisions

Prohibited synthetic content

A new sub-rule on due diligence in relation to synthetically generated information requires an intermediary offering a computer resource that enables the creation, generation, modification, alteration, publication, transmission, sharing or dissemination of SGI to deploy "reasonable and appropriate technical measures, including automated tools or other suitable mechanisms" to prevent users from producing SGI that violates any law in force. The rule names the Information Technology Act, the Bharatiya Nyaya Sanhita, 2023 (45 of 2023), the Protection of Children from Sexual Offences Act, 2012 (32 of 2012), and the Explosive Substances Act, 1908 (6 of 1908), and enumerates four categories: content containing child sexual exploitative and abuse material or non-consensual intimate imagery, or that is obscene, pornographic, paedophilic, invasive of another person's privacy including bodily privacy, vulgar, indecent or sexually explicit; content resulting in the creation or alteration of any false document or false electronic record; content relating to the preparation, development or procurement of explosive material, arms or ammunition; and content that falsely depicts or portrays a natural person or real-world event by misrepresenting, in a manner likely to deceive, that person's identity, voice, conduct, action or statement, or that event as having occurred (India's IT Rules, 2021 — MeitY consolidated text as amended to 10 February 2026 (G.S.R. 120(E))).

Labelling and embedded provenance

Synthetic content not caught by the prohibited categories must be prominently labelled. The rule specifies visual prominence — a label "easily noticeable and adequately perceivable" in the visual display — or, for audio content, a prominently prefixed audio disclosure, sufficient to identify immediately that the information is synthetically generated. Separately, such information must be embedded with permanent metadata or other appropriate technical provenance mechanisms, "to the extent technically feasible", including a unique identifier identifying the computer resource of the intermediary used to create, generate, modify or alter it, and the intermediary must not enable the modification, suppression or removal of that label, metadata or identifier (India's IT Rules, 2021 — MeitY consolidated text as amended to 10 February 2026 (G.S.R. 120(E))). One requirement is addressed to a human viewer and the other to a machine reader, an approach that parallels the provenance mechanisms described at Data Provenance, C2PA, and Watermarking and AI Content Provenance.

Takedown and grievance timelines

Intermediaries must act on a government or court order, including a takedown order, within three hours of receipt, replacing the 36-hour window under the 2021 Rules (Source: hoganlovells.com). Grievance timelines were also compressed. The consolidated text records four substitutions made by the 2026 notification: removal on actual knowledge under rule 3(1)(d) from thirty-six hours to three; resolution of an ordinary complaint under rule 3(2)(a)(i) from fifteen days to seven; removal requests falling under rule 3(1)(b) from seventy-two hours to thirty-six; and content depicting nudity, a sexual act or impersonation, including artificially morphed images, under rule 3(2)(b) from twenty-four hours to two (India's IT Rules, 2021 — MeitY consolidated text as amended to 10 February 2026 (G.S.R. 120(E)); Source: m.economictimes.com). Under rule 3(1)(d) as amended, actual knowledge arises only by a court order or by a reasoned intimation in writing from an officer authorised in writing for that purpose.

Pre-publication declaration and verification by significant social media intermediaries

A new rule 4(1A) requires a significant social media intermediary that enables the display, upload or publication of information to act before publication: it must require users to declare whether the information is synthetically generated; deploy "appropriate technical measures, including automated tools or other suitable mechanisms, to verify the accuracy of such declaration, having regard to the nature, format, and source of such information"; and, where the declaration or the verification confirms that the information is synthetic, ensure it is clearly and prominently displayed with a label or notice to that effect. A proviso deems the intermediary to have failed its due diligence where it becomes aware, or it is otherwise established, that it "knowingly permitted, promoted, or failed to act upon" such information in contravention of the rules, and an accompanying Explanation extends the responsibility to "taking reasonable and proportionate technical measures to verify the correctness of user declarations" (India's IT Rules, 2021 — MeitY consolidated text as amended to 10 February 2026 (G.S.R. 120(E))). The verification duty is the provision that distinguishes India's approach from a pure self-declaration regime: the platform is obliged to check the user's answer rather than record it.

Proactive detection by significant social media intermediaries

A significant social media intermediary must deploy appropriate technical measures, including automated tools, to proactively identify information depicting rape or child sexual abuse, whether explicit or implicit, and information exactly identical in content to material previously removed under the rules, and must display a notice to any user attempting to access such information. Three provisos qualify the obligation: the measures must be proportionate having regard to free speech and expression and to user privacy; the intermediary must implement mechanisms for human oversight including periodic review of any automated tools deployed; and that review must evaluate the tools for accuracy and fairness, propensity for bias and discrimination, and impact on privacy and security. The obligation itself was strengthened by the 2026 amendments from "endeavour to deploy technology-based measures" to "deploy appropriate technical measures", a change from best-efforts to duty (India's IT Rules, 2021 — MeitY consolidated text as amended to 10 February 2026 (G.S.R. 120(E))).

Obligations by actor

The 2021 Rules distinguish ordinary intermediaries from significant social media intermediaries, a tier defined by a registered-user threshold of 50 lakh (five million) users in India. Platforms over that threshold carry additional obligations, including publishing periodic compliance reports, appointing grievance and compliance officers resident in India, and assisting law enforcement in tracing the first originator of information (Source: m.economictimes.com). The 2026 amendments layer the SGI obligations on top of that structure, with the creation-side duties attaching to any intermediary offering a generative computer resource and the proactive-detection duties attaching to the significant tier.

Enforcement

The rules operate through conditional safe harbour rather than direct penalties. Section 79 of the Information Technology Act, 2000 exempts intermediaries from liability for third-party content provided they observe the prescribed due diligence; failure to comply with the amended rules risks loss of that exemption. A new rule 2(1B) works in the other direction, providing that removal of or disabling access to information in compliance with the Rules, including by deploying automated tools, does not itself amount to a violation of the section 79(2)(a) or (b) conditions (India's IT Rules, 2021 — MeitY consolidated text as amended to 10 February 2026 (G.S.R. 120(E))) (Source: m.economictimes.com). This is the same enforcement architecture the 2021 Rules used, applied to a wider set of duties.

Reactions

Practitioner commentary has focused on the operational compression. Hogan Lovells characterised the ten-day gap between notification and commencement as "a narrow ten-day compliance window" for in-scope platforms and described the amendments as placing synthetic media at the centre of intermediary compliance (Source: hoganlovells.com). Vaish Associates described the pre-amendment rules as focused on removing illegal content after complaints rather than preventing harmful content beforehand, and characterised the amendment as a shift from reactive removal to proactive regulation, noting that a platform hosting user-generated video, audio or image content may in certain cases have 120 minutes to receive a complaint, verify content, make a legal determination, remove it, notify stakeholders and preserve records (Source: vaishlaw.com).

The 2021 Rules were themselves challenged in Indian courts on the grounds that certain provisions restricted freedom of speech or exceeded the authority granted under the parent Act (Source: vaishlaw.com). No comparable challenge to the 2026 amendments has been reported.

Comparison to other synthetic-media regimes

India's approach combines a labelling-and-provenance mandate with a prohibited-categories list and an accelerated takedown clock. The labelling and provenance obligations are closest in form to China's Deep Synthesis Provisions, which likewise pair conspicuous labelling with implicit identifiers, and to the transparency obligations in the EU AI Act. The prohibited-categories list overlaps in subject matter with the US TAKE IT DOWN Act on non-consensual intimate imagery and with the patchwork of state deepfake statutes, though India's instrument reaches a wider set of content types and, unlike those statutes, operates through intermediary due-diligence conditions rather than direct civil or criminal liability for the creator.

Open questions

  • Whether the phrase "to the extent technically feasible" in the provenance requirement is interpreted to permit intermediaries to omit embedded metadata for content types where standard provenance formats are not implemented is not addressed in the notified text.
  • Whether the three-hour compliance clock has been tested in enforcement practice since the 20 February 2026 commencement is not documented.

Relationships