This article is for educational and legal awareness purposes only. It does not constitute legal advice or solicitation. Please consult a qualified advocate for advice on specific legal matters.
Overview
Artificial intelligence tools can now clone a person’s voice from a few seconds of audio and generate a realistic video of a person saying or doing something they never did. These capabilities are increasingly being used for fraud — a cloned voice used to impersonate a relative or an employer in an emergency call, a fabricated video used to extort money, or a morphed image used to defame or humiliate someone. This article explains the criminal provisions available under the Bharatiya Nyaya Sanhita, 2023 (BNS) and the Information Technology Act, 2000 (IT Act) for such conduct, notes the relevant government advisory on AI-generated content, and sets out how such incidents can be reported.
Common Patterns of Deepfake and AI-Generated Fraud
- Voice-cloning scams: A synthetically generated voice, made to sound like a family member or senior official, is used on a phone call to create urgency and induce a money transfer.
- Fabricated video for extortion: A morphed or AI-generated video, often depicting the victim in a compromising or fabricated situation, is used to demand money under threat of publication.
- Impersonation for reputational harm: A deepfake video or audio clip is circulated to make it appear that a person said or did something objectionable, damaging their reputation or standing.
- Identity misuse: A person’s photograph, voice, or likeness is used without consent to create a synthetic profile or persona for fraudulent purposes, such as fake endorsements or fraudulent KYC.
None of these require the perpetrator to be physically present or to forge a document in the traditional sense — the “forgery” and “cheating” occur through synthetic media. Indian criminal law addresses this through a combination of general provisions on cheating, forgery, defamation and extortion under the BNS, and technology-specific provisions under the IT Act.
Provisions Under the Bharatiya Nyaya Sanhita, 2023
Cheating and Cheating by Personation
Section 318 of the Bharatiya Nyaya Sanhita, 2023 defines cheating as deceiving a person and thereby fraudulently or dishonestly inducing that person to deliver property, or to do or omit to do something they would not otherwise have done, causing or likely to cause harm to that person in body, mind, reputation, or property. Where the deception induces delivery of property or a valuable security, the offence carries a punishment of imprisonment up to seven years and a fine. A voice-cloning call that induces a victim to transfer money falls squarely within this provision.
Section 319 deals specifically with cheating by personation — pretending to be another person, whether that person is real or imaginary, and thereby cheating the victim. This is the provision most directly applicable to deepfake and voice-clone impersonation used to induce a transaction, and it carries imprisonment of up to five years, or fine, or both.
Forgery
Section 336 defines forgery as making a false document or a false electronic record, with intent to cause damage or injury, to support a claim, to induce a person to part with property, to enter into a contract, or with intent that fraud may be committed. The provision expressly covers electronic records, so an AI-fabricated document, screenshot, or synthetic recording created to deceive can amount to forgery. Where the forged electronic record is intended to be used for cheating, the punishment extends up to seven years; where it is intended to harm a person’s reputation, the punishment extends up to three years.
Defamation
Section 356 retains the offence of criminal defamation, punishable with simple imprisonment up to two years, or fine, or both, and is a non-cognizable, bailable offence. A fabricated video or image circulated with intent to harm a person’s reputation, or with knowledge that it is likely to do so, can attract this provision in addition to civil remedies for defamation.
Extortion
Where a fabricated video or audio clip is used to threaten a person with publication unless money is paid, Section 308 on extortion may also apply. It penalises intentionally putting a person in fear of injury — which extends to injury to reputation — and thereby dishonestly inducing that person to hand over property. The provision illustrates this with a threat to publish defamatory material unless payment is made, which closely mirrors a common deepfake-extortion pattern. Depending on the nature of the threat, the punishment can extend up to seven years, and up to ten years where the threat is of death or grievous hurt.
Provisions Under the Information Technology Act, 2000
The BNS provisions are general in character; the Information Technology Act, 2000 supplies technology-specific offences that more precisely target digital impersonation and synthetic content.
Section 66C — Identity Theft
Section 66C penalises fraudulent or dishonest use of another person’s electronic signature, password, or any other unique identification feature. This provision is being applied to the misuse of a person’s biometric or identifying characteristics — including facial features and voice — to create a synthetic identity. The punishment is imprisonment up to three years and a fine up to ₹1 lakh.
Section 66D — Cheating by Personation Using a Computer Resource
Section 66D specifically penalises cheating by personation carried out by means of any communication device or computer resource. This is the technology-specific counterpart to BNS Section 319 and is directly relevant to voice-cloning and video-deepfake scams executed over a phone, messaging app, or video call. The punishment mirrors Section 66C: imprisonment up to three years and a fine up to ₹1 lakh.
Section 66E — Violation of Privacy
Section 66E penalises intentionally or knowingly capturing, publishing, or transmitting the image of a private area of a person without consent, in circumstances violating that person’s privacy, punishable with imprisonment up to three years or a fine up to ₹2 lakh, or both. This provision becomes relevant where a deepfake places a person’s likeness onto explicit or intimate imagery without consent.
Section 67 — Obscene Material in Electronic Form
Where fabricated or morphed content that is obscene is published or transmitted in electronic form, Section 67 applies, with imprisonment up to three years and a fine up to ₹5 lakh on a first conviction, rising to five years and ₹10 lakh on a subsequent conviction. This is frequently invoked alongside Section 66E where non-consensual synthetic intimate content is created and circulated.
Civil Remedy: Personality and Publicity Rights
Apart from criminal law, courts in India have begun recognising a civil remedy grounded in a person’s personality and publicity rights against unauthorised AI-generated use of their name, voice, or likeness. In Anil Kapoor v. Simply Life India & Ors. (Delhi High Court, order dated 20 September 2023), the Court granted an injunction restraining the unauthorised commercial use of the actor’s name, image, voice, and other attributes of his persona, including through AI tools and face-morphing technology. While that order concerned a public figure and commercial misuse, it illustrates that a civil suit for injunction and damages is a parallel route available in appropriate cases, in addition to a criminal complaint.
The MeitY Advisory on AI-Generated and Synthetic Content
The Ministry of Electronics and Information Technology (MeitY) has issued advisories to intermediaries and platforms under the IT Act and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. An advisory dated 15 March 2024 requires that where a platform’s software permits synthetic creation, generation, or modification of text, audio, visual, or audio-visual content that could be used as misinformation or a deepfake, such content should be labelled or embedded with permanent unique metadata or an identifier capable of tracing its origin and any subsequent modification. The advisory also reiterates that non-compliance can expose intermediaries, platforms, and users to prosecution under the IT Act and other applicable laws. Separately, amendments to the IT Rules have expanded due-diligence obligations for intermediaries specifically regarding synthetically generated information, including tighter takedown timelines for unlawful synthetic content.
How to Report Deepfake or AI-Generated Fraud
- National Cyber Crime Reporting Portal: Incidents can be reported online at cybercrime.gov.in, which allows filing of complaints relating to cyber fraud, identity theft, obscene or morphed content, and online financial fraud.
- Cyber Crime Helpline (1930): For financial fraud specifically, the 1930 helpline allows time-sensitive reporting aimed at freezing fraudulently transferred funds before they are withdrawn.
- Local Police / Cyber Cell: A complaint can also be lodged at the jurisdictional police station or the district cyber cell, leading to registration of a First Information Report under the Bharatiya Nagarik Suraksha Sanhita, 2023, read with the applicable BNS and IT Act provisions.
- Preserving Evidence: The original audio/video file, call logs, chat records, transaction details, and any URLs where the content was circulated should be preserved, as these form the basis of the digital evidence in the investigation.
Practical Points
- A synthetic voice or video is not, by itself, proof of anything — verify unusual or urgent requests for money through an independent channel, such as a direct call to a known number, before acting.
- Content that combines a real person’s likeness with fabricated or explicit material may attract multiple provisions simultaneously — cheating, forgery, defamation, or extortion under the BNS, together with identity theft, privacy violation, or obscenity under the IT Act — depending on the facts.
- Reporting promptly, particularly through the 1930 helpline for financial fraud, materially improves the chance of freezing or reversing a fraudulent transaction.
- A person facing deepfake-based extortion, defamation, or fraud may consider consulting a qualified advocate to assess which combination of criminal complaint and civil remedy is appropriate to the facts.
Takeaway
Indian law does not yet have a single, dedicated “deepfake statute,” but a fabricated voice or video used for fraud, extortion, or defamation is not left unaddressed. The general provisions on cheating, cheating by personation, forgery, extortion, and defamation under the Bharatiya Nyaya Sanhita, 2023 apply irrespective of whether the deception is achieved through a forged paper document or a synthetically generated one, while Sections 66C, 66D, 66E, and 67 of the Information Technology Act, 2000 supply technology-specific offences squarely aimed at digital identity theft, impersonation, privacy violation, and obscene synthetic content. Alongside these, the MeitY advisory framework places labelling and takedown obligations on platforms, and civil personality-rights remedies offer a further avenue in appropriate cases.
Useful Resources
- National Cyber Crime Reporting Portal
- MeitY Advisory dated 15 March 2024 — Due Diligence by Intermediaries/Platforms on AI-Generated Content
- Indian Kanoon — Section 66C, Information Technology Act, 2000
- Indian Kanoon — Anil Kapoor v. Simply Life India & Ors. (Delhi HC, 2023)
- Devgan.in — Bharatiya Nyaya Sanhita, 2023, Section 318 (Cheating)
Disclaimer: The information provided on this website is for general legal awareness and educational purposes only. It does not constitute legal advice, advertisement, or solicitation. No reader should act or refrain from acting based on this information without seeking professional legal counsel. Advocate Akhil Singh and this website are not liable for any actions taken based on the content provided herein.