India's IT Rules: labelling synthetically generated information

What the 2026 amendments require of platforms and users — labelling, provenance metadata, two-hour takedowns, and what is at stake.

What the rules require

India's amended IT Rules bring synthetically generated information — deepfakes, AI-generated images, cloned audio — inside the due-diligence framework that intermediaries must follow. Such content must be clearly and prominently labelled, platforms must preserve provenance metadata where feasible, and the most harmful synthetic content must come down within two hours of a valid notice. In force since 20 February 2026.

The amendments were notified by the Ministry of Electronics and Information Technology in February 2026 and modify the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Unlike the EU and California regimes, the duty falls primarily on platforms rather than on the model providers that generate the content.

Synthetically generated information

The rules introduce “synthetically generated information” — SGI — as a defined category covering content that is artificially created or altered, including deepfakes and AI-cloned audio.

Labelling is medium-specific, which is the detail most summaries miss:

MediumWhat is required
Visual SGIA visual label, clearly and prominently displayed
Audio SGIAn audio disclosure — a visual label alone does not serve
All SGI, where feasiblePermanent metadata or a unique identifier, sufficient to trace the computer resource that generated or altered the content

That third row is the one that behaves like the EU and California regimes: an embedded, durable identifier rather than a visible notice. The rules qualify it with where feasible, which is the same technical-feasibility hedge Article 50(2) uses.

Takedown windows

The amendments compress the removal timelines sharply — previously 36 hours for unlawful content.

ContentWindow
High-risk synthetic content — non-consensual intimate imagery, impersonation-based deepfakes2 hours from a valid notice
Other unlawful content3 hours, down from 36

A two-hour window is an operational constraint before it is a legal one. It presumes a platform can identify the content, confirm the notice and act inside a single shift — which in practice means automated detection rather than queued human review.

What non-compliance costs

The rules carry no fixed monetary penalty. The consequence is structural: safe harbour under Section 79 of the IT Act — the protection that shields an intermediary from liability for user content — is put at risk.

For a large platform that is a more serious exposure than a fine. Losing safe harbour does not produce one bill; it changes the platform's liability position for everything its users post.

The amendments also empower MeitY to issue binding directions to platforms without a prior public complaint, which shortens the distance between a problem and an order.

Dates

  1. MeitY notifies the amendments bringing synthetically generated information within the IT Rules. Source
  2. Amendments take effect. Labelling, provenance metadata and the compressed takedown windows apply.

How this differs from the EU and California

Three regimes, three different answers to the same question — worth holding apart, because a single compliance posture does not satisfy all three.

India IT RulesEU Article 50California SB 942
Duty falls onIntermediaries and posting usersProviders, and deployers separatelyCovered providers, and platforms from 2027
Visible labelRequired, medium-specificDeployer duty under 50(4), not 50(2)Offered as an option to users
Embedded markMetadata or unique identifier, where feasibleMachine-readable, no fields specifiedFour specified fields
ThresholdNone statedNone1,000,000 monthly users

How Verda maps to the rules

The dutyTierHow Verda meets it
Permanent metadata or unique identifier, where feasibleComplianceAn imperceptible watermark embedded in the signal, which survives the re-encoding that strips metadata
Traceable to the computer resource that generated the contentProvenanceThe mark resolves through a registry to the provider, system and version that produced it
Preserve provenance metadataComplianceSigned C2PA manifests written alongside the watermark, so a preserved manifest carries the richer record
Audio SGI needs an audio-appropriate approachComplianceAudio is marked in the waveform, not in a container, so it survives transcoding and re-recording
Not required by the rulesIdentityOptionally resolve to a verified organisation or creator — relevant to impersonation, not required

The labelling duty itself — the visible notice on a post — is a platform product decision, not something a watermark provides. Verda addresses the embedded half.

Common questions

When did the India AI labelling rules come into force?

20 February 2026, following notification by MeitY earlier that month. They amend the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

Who do the rules apply to?

Primarily to intermediaries — social media and similar platforms — and to the users who post synthetically generated content. This differs from the EU and Californian regimes, which place the marking duty on the provider of the generating system.

Is a watermark required?

The rules require a clear and prominent label, and, where feasible, permanent metadata or a unique identifier that traces the content to the computer resource that created it. A durable embedded mark is the practical way to meet the second part, because metadata alone does not survive re-upload.

What is the penalty?

There is no fixed fine. Non-compliance puts the intermediary's safe harbour under Section 79 of the IT Act at risk, which changes its liability position for user content generally.

How fast must harmful deepfakes be removed?

Two hours from a valid notice for high-risk synthetic content such as non-consensual intimate imagery and impersonation deepfakes; three hours for other unlawful content, reduced from the previous 36-hour window.

Have a question?

Reach out to us at bd@verda.ai