What India’s new deepfake law means for brands
India’s amended IT rules take effect February 20 2026. Platforms must label AI generated content. Unlawful deepfakes now face a three hour takedown window, down from 36 hours. Any synthetic image or clip needs a label covering at least ten percent of its surface. Brands need new contracts, disclosure rules and verification checks before an incident forces the issue.
Most companies are treating this as a legal filing exercise. That is a mistake. This is a communications problem wearing a legal costume. The brands that get it right will use it to build trust, not just avoid fines.
What exactly changed under India’s new IT rules for AI content
The amendment adds a new category called synthetically generated information, or SGI. Platforms and AI tools that create or host this content now carry direct labelling duties.
The Ministry of Electronics and Information Technology notified the changes on February 10 2026. That is according to legal analysis published by Mondaq on March 18 2026. The rules became operational ten days after notification.
Under the new Rule 3(3), any AI generated image, video or audio must carry a label. For visuals, the label must cover at least ten percent of the visible frame. For audio, it must run through the first ten percent of the clip, under the rules notified February 10 2026. Both must be prominent. Neither can sit buried in a description or a corner nobody notices.
The obligation does not stop at social media. It reaches AI-enabled services, publishers and any entity that distributes or hosts synthetic content. That is the reading in the India Briefing analysis of the rules. Platforms must also attach permanent metadata identifying content as synthetic. They must take reasonable technical steps to verify what users declare when they upload it.
For brands, the scope matters more than the label. An agency generating a product video with AI voiceover is now inside the rule. It does not matter whether the client asked about it. Nobody gets to claim they did not know.
Why does a three hour takedown window matter for crisis PR
Three hours is barely enough time to confirm a deepfake is real. It is nowhere near enough to plan a response. Teams that used to have a working day now have an afternoon.
Before this amendment, intermediaries had 36 hours to act on a lawful takedown order for unlawful content. That window is now three hours, per the same Mondaq analysis of the 2026 amendment. For a communications team, that changes the entire playbook.
A three hour clock means legal, comms and platform relations cannot work in sequence anymore. They need to work at the same time, on one call, with a pre-agreed decision tree. If your crisis process still routes everything through one signatory, that process is already too slow for this rule.
Brands also need standing relationships with platform trust and safety teams before a crisis, not during one. Cold outreach at hour two of a three hour window rarely works. Companies that have never filed a takedown request will learn the hard way. Account verification alone can eat half the clock.
The practical fix is boring but necessary. Build a one page escalation protocol. Name who confirms authenticity, who contacts the platform, and who drafts the public statement. All three should run in parallel, not in sequence.
What should brands change in vendor and agency contracts now
Every contract with a content vendor or ad agency needs a clause on AI disclosure and liability. Silence in the contract does not protect the brand once the content goes live.
Contracts should require vendors to disclose when AI tools generated or materially altered a video, image or voice track. They should confirm the required label was applied before publishing, not after a complaint. Contracts should also name who owns the metadata trail. Regulators and platforms will ask for it, and someone needs to produce it fast.
This is not paperwork for its own sake. Globally, 91 percent of PR professionals say they always edit AI generated output before it goes out. That figure comes from Muck Rack’s State of AI in PR 2026 report, published February 6 2026. That habit needs to become a contractual checkpoint, not a personal one. Individual diligence does not survive staff turnover.
Indemnity language also needs an update. If a vendor’s AI tool violates the labelling rule, the brand faces the fallout. The platform notice and the reputational cost land on the brand, not the vendor. Contracts should reflect that risk transfer honestly, rather than assume it will never come up.
Can a label actually rebuild trust, or is verification a separate job
A label tells someone that content was AI made. It does not tell them whether the claim inside that content is true. That gap is exactly where the real work sits.
Consider what happened in June 2026. A fact check published by Newsmeter on June 24 2026 exposed a deepfake circulating on Facebook. It used manipulated footage of prime minister Narendra Modi, finance minister Nirmala Sitharaman, Mukesh Ambani and Sudha Murty. The video promoted a fake investment scheme called Quantum AI, promising returns of up to 30 lakh rupees a month. It linked to a counterfeit Times of India page built to collect personal data.
No label would have stopped that video. The people running the scam were never going to comply with a labelling rule. That means the label protects honest publishers while doing almost nothing against the actors causing the most damage.
That is why labelling and verification are two different jobs. Communicators cannot outsource either one to a government rule. Globally, 77 percent of PR professionals say they struggle to tell accurate information from disinformation. That is from the ICCO World PR Report 2025-2026. It surveyed 244 professionals across 66 countries between September 2025 and March 2026. Verification and source checking are becoming a core communications skill, not a technical afterthought handled by someone else.
Brands that build real verification habits, not just compliance labels, are the ones that will still be trusted. That matters most the day a Quantum AI style scam uses their name instead of a scheme’s.
What is the PR industry getting wrong about AI governance today
Most agencies adopted AI faster than they built rules for using it. That gap between adoption and governance is where the next reputational failure will come from.
Muck Rack’s February 6 2026 report found that 76 percent of PR professionals now use generative AI. Only 51 percent of companies have a formal AI use case policy. The ICCO World PR Report 2025-2026 found something similar at agency level. 72 percent of agencies use AI tools without any agreed governance framework at all.
That is not a training problem. It is an accountability problem. Someone at every agency and every brand needs to own AI governance the way someone owns finance or legal sign-off. That person needs real authority to say no to a piece of content before it goes out. A memo nobody reads will not do the job.
The Indian rule gives that person a concrete deadline to work against. February 20 2026 already happened. The real question for most brands now is not whether they comply on paper. It is whether anyone could actually produce the metadata trail if a regulator or a journalist asked for it tomorrow.
Frequently asked questions
Are deepfakes illegal in India?
Deepfakes used to defraud, defame or impersonate someone can trigger liability under the IT Act and the amended IT Rules. Laws like the Copyright Act and the DPDP Act can also apply, depending on the harm.
What is synthetically generated information under the new IT rules?
Synthetically generated information, or SGI, is the term the amended rules use for AI generated or manipulated content. That includes audio, video, image and text, covering marketing, entertainment and fraudulent uses alike.
Do platforms have to label all AI content in India?
Platforms and AI-enabled services must label synthetic content prominently. The label must cover at least ten percent of a visual frame. For audio, it must run through the first ten percent of the clip, under the rules notified February 10 2026.
What happens if a platform misses the three hour takedown deadline?
The rules cut the window for acting on a lawful takedown order for unlawful synthetic content. It is now three hours, down from the earlier 36 hours. Platforms that miss it risk losing safe harbour protection for that content.
Does the labelling rule apply to marketing and advertising content?
Yes. The obligation covers any entity distributing or hosting synthetic content. That includes brand marketing, advertising and influencer content generated or materially altered using AI tools.

