top of page

Deepfake Takedown Timelines and AI Safety Institute Referenced

12 August 2026

I. Correcting the Record on the Institute


The most important analytical point in this update is a correction, not a description. Prasada's Lok Sabha reply referenced the IndiaAI Safety Institute, but that body was not created by this statement, nor by the November 2025 AI Governance Guidelines specifically. The Institute operates under the IndiaAI Mission's Safe and Trusted AI pillar, an initiative with its own institutional history predating the Guidelines. Coverage that frames the Institute as a fresh announcement misreads a reference for a launch. This distinction matters practically: clients evaluating the Institute's regulatory weight should understand it as an existing research and standards body being cited in support of a broader compliance narrative, not a newly empowered enforcement authority.


II. The Same Timelines, Recontextualised for AI


Substantively, this update restates the three hour and two hour takedown windows already fixed by the February 2026 IT Rules amendment, now framed specifically around AI generated content. The framing matters more than the substance. By presenting the existing takedown regime as an "AI governance" achievement, the government folds content moderation infrastructure built for ordinary unlawful content into its AI policy narrative, without any AI specific procedural safeguard, no algorithmic audit requirement, no provenance verification standard, actually attaching to the takedown obligation itself. The deepfake framing performs political work that the underlying rule does not substantively deliver.


III. A Layered Statutory Response Without a Dedicated Statute


Prasada's answer usefully clarifies that India is not building a standalone deepfake law but is instead layering the IT Act's identity theft and impersonation provisions with the Bharatiya Nyaya Sanhita's cheating by personation and forgery offences. This is a defensible drafting choice, since a standalone deepfake statute risks obsolescence as generation techniques evolve, but it leaves practitioners without a single reference point for deepfake liability. Advising a client on deepfake exposure now requires cross referencing at minimum the IT Rules due diligence framework, the BNS provisions on personation, and the civil remedies available under personality and publicity rights jurisprudence, none of which are harmonised by this announcement.


IV. The Institute's Actual Mandate Is Research, Not Enforcement


The IndiaAI Safety Institute's stated functions, safety research, standards development, systems testing, and risk evaluation, are advisory and technical in character. It has no notified role in individual takedown decisions and no statutory enforcement power comparable to the Data Protection Board or MeitY's own rule making authority. Clients should not treat Institute engagement or certification, where it exists, as conferring any safe harbour or compliance credit under the IT Rules. The two regimes, content takedown enforcement and AI safety research, currently run on separate, uncoordinated tracks.


V. Comparative Note


The naming convention itself invites comparison to the UK's AI Security Institute, formerly the AI Safety Institute, and similar bodies established after the 2023 Bletchley Park summit. Those institutions share India's research and standards mandate but operate within jurisdictions that have, or are actively building, dedicated AI legislation to which their technical output feeds directly. India's Institute currently has no comparable legislative vehicle waiting to receive its findings; the IT Rules amendment path has been the only concrete legal instrument produced so far, and it long predates most of the Institute's substantive research agenda. The infrastructure for translating AI safety research into binding obligations does not yet exist in India in the way it is beginning to in comparator jurisdictions. Recent reporting on India's parliamentary proceedings suggests this may be changing, with indications that the government is weighing a dedicated AI statute, but until such legislation is drafted and notified, the Institute's technical output remains persuasive rather than binding, a distinction clients should keep sharply in view when a vendor or counterparty cites Institute guidance as though it carried regulatory force.


VI. Practitioner Guidance


Clients building AI products for the Indian market should treat compliance obligations as currently flowing entirely from the IT Rules takedown framework and the layered IT Act and BNS criminal provisions, not from any Institute standard or certification. Firms should monitor whether the government moves toward a dedicated AI statute, reportedly under discussion per recent IAPP reporting, since that would be the point at which Institute output could acquire binding legal weight, but should not delay current compliance work on the assumption that such legislation is imminent. Communications and marketing materials describing a product as "IndiaAI Safety Institute compliant" or similarly certified should be reviewed carefully, since no such certification currently carries defined legal meaning, and overstating the regulatory significance of Institute engagement could itself create consumer protection exposure independent of the underlying AI content risk.


bottom of page