India's IT Rules: labelling synthetically generated information
What the 2026 amendments require of platforms and users — labelling, provenance metadata, two-hour takedowns, and what is at stake.
What the rules require
India's amended IT Rules bring synthetically generated information — deepfakes, AI-generated images, cloned audio — inside the due-diligence framework that intermediaries must follow. Such content must be clearly and prominently labelled, platforms must preserve provenance metadata where feasible, and the most harmful synthetic content must come down within two hours of a valid notice. In force since 20 February 2026.
The amendments were notified by the Ministry of Electronics and Information Technology in February 2026 and modify the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Unlike the EU and California regimes, the duty falls primarily on platforms rather than on the model providers that generate the content.
Synthetically generated information
The rules introduce “synthetically generated information” — SGI — as a defined category covering content that is artificially created or altered, including deepfakes and AI-cloned audio.
Labelling is medium-specific, which is the detail most summaries miss:
| Medium | What is required |
|---|---|
| Visual SGI | A visual label, clearly and prominently displayed |
| Audio SGI | An audio disclosure — a visual label alone does not serve |
| All SGI, where feasible | Permanent metadata or a unique identifier, sufficient to trace the computer resource that generated or altered the content |
That third row is the one that behaves like the EU and California regimes: an embedded, durable identifier rather than a visible notice. The rules qualify it with where feasible, which is the same technical-feasibility hedge Article 50(2) uses.
Takedown windows
The amendments compress the removal timelines sharply — previously 36 hours for unlawful content.
| Content | Window |
|---|---|
| High-risk synthetic content — non-consensual intimate imagery, impersonation-based deepfakes | 2 hours from a valid notice |
| Other unlawful content | 3 hours, down from 36 |
A two-hour window is an operational constraint before it is a legal one. It presumes a platform can identify the content, confirm the notice and act inside a single shift — which in practice means automated detection rather than queued human review.
What non-compliance costs
The rules carry no fixed monetary penalty. The consequence is structural: safe harbour under Section 79 of the IT Act — the protection that shields an intermediary from liability for user content — is put at risk.
For a large platform that is a more serious exposure than a fine. Losing safe harbour does not produce one bill; it changes the platform's liability position for everything its users post.
The amendments also empower MeitY to issue binding directions to platforms without a prior public complaint, which shortens the distance between a problem and an order.
Dates
- MeitY notifies the amendments bringing synthetically generated information within the IT Rules. Source
- Amendments take effect. Labelling, provenance metadata and the compressed takedown windows apply.
How this differs from the EU and California
Three regimes, three different answers to the same question — worth holding apart, because a single compliance posture does not satisfy all three.
| India IT Rules | EU Article 50 | California SB 942 | |
|---|---|---|---|
| Duty falls on | Intermediaries and posting users | Providers, and deployers separately | Covered providers, and platforms from 2027 |
| Visible label | Required, medium-specific | Deployer duty under 50(4), not 50(2) | Offered as an option to users |
| Embedded mark | Metadata or unique identifier, where feasible | Machine-readable, no fields specified | Four specified fields |
| Threshold | None stated | None | 1,000,000 monthly users |
How Verda maps to the rules
| The duty | Tier | How Verda meets it |
|---|---|---|
| Permanent metadata or unique identifier, where feasible | Compliance | An imperceptible watermark embedded in the signal, which survives the re-encoding that strips metadata |
| Traceable to the computer resource that generated the content | Provenance | The mark resolves through a registry to the provider, system and version that produced it |
| Preserve provenance metadata | Compliance | Signed C2PA manifests written alongside the watermark, so a preserved manifest carries the richer record |
| Audio SGI needs an audio-appropriate approach | Compliance | Audio is marked in the waveform, not in a container, so it survives transcoding and re-recording |
| Not required by the rules | Identity | Optionally resolve to a verified organisation or creator — relevant to impersonation, not required |
The labelling duty itself — the visible notice on a post — is a platform product decision, not something a watermark provides. Verda addresses the embedded half.
Common questions
When did the India AI labelling rules come into force?
20 February 2026, following notification by MeitY earlier that month. They amend the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
Who do the rules apply to?
Primarily to intermediaries — social media and similar platforms — and to the users who post synthetically generated content. This differs from the EU and Californian regimes, which place the marking duty on the provider of the generating system.
Is a watermark required?
The rules require a clear and prominent label, and, where feasible, permanent metadata or a unique identifier that traces the content to the computer resource that created it. A durable embedded mark is the practical way to meet the second part, because metadata alone does not survive re-upload.
What is the penalty?
There is no fixed fine. Non-compliance puts the intermediary's safe harbour under Section 79 of the IT Act at risk, which changes its liability position for user content generally.
How fast must harmful deepfakes be removed?
Two hours from a valid notice for high-risk synthetic content such as non-consensual intimate imagery and impersonation deepfakes; three hours for other unlawful content, reduced from the previous 36-hour window.
Have a question?
Reach out to us at bd@verda.ai