When AI-generated deepfake videos of a head of government spread across a platform, who is legally responsible — the people who made the fakes, the platform that hosted them, or both? In July 2026, India answered that question in a way no other democracy has yet: police filed a criminal FIR naming the local head of a global tech company alongside the accounts that circulated the content. The case against Meta India head Arun Srinivas, registered by Hyderabad Cyber Crime Police, is the first time a senior executive of a major platform has been personally named in a criminal complaint over AI deepfakes hosted on their service. It is not a conviction — it is not even a formal charge. But it marks a shift in how governments are treating platform accountability for synthetic media, and anyone building or running an AI-powered product needs to understand what it signals.
Last verified: 2026-08-01 · First criminal FIR naming a platform country-head over AI deepfakes · India's IT Act Sections 66C/67 + Bharatiya Nyaya Sanhita invoked · IT Rules 2026 amendments tightened safe-harbour conditions · FIR is preliminary; no arrests yet
What Actually Happened With the Meta India FIR?
The Hyderabad Cyber Crime Police registered a First Information Report (FIR) against Meta India head Arun Srinivas and the operators of roughly 20 Facebook and Instagram accounts over the circulation of AI-morphed videos and images of Prime Minister Narendra Modi. The complaints were filed by businessman S. Aravind Reddy and Telangana BJP activist T. Saikiran Goud, who alleged the content was obscene, derogatory, and misleading. The manipulated media was reportedly circulated during protests linked to the NEET paper leak controversy.
Police invoked Section 66C (identity theft) and Section 67 (publishing obscene material electronically) of the Information Technology Act, 2000, alongside provisions of the Bharatiya Nyaya Sanhita (BNS), 2023 — India's replacement for the colonial-era Indian Penal Code. An FIR is not a finding of wrongdoing; it is the formal start of a police investigation. Police confirmed the probe is at a preliminary stage, with next steps dependent on the digital evidence gathered.
The case came days after Hyderabad Cyber Crime Police had separately summoned Meta representatives to explain the company's mechanisms for detecting and removing AI-generated scams and fraudulent advertisements. A Meta representative appeared before investigators and briefed them on content moderation and compliance measures. The FIR itself examines whether Meta's existing safeguards were sufficient to detect and limit the spread of the alleged deepfakes.
The development was first reported by India Today on July 31, 2026.
What Other FIRs Were Filed Around the Same Time?
The Meta India case is not isolated. It is part of a wave of criminal complaints targeting AI deepfakes of Indian political figures in late July 2026:
Piyush Goyal deepfake (July 25, 2026): Union Commerce Minister Piyush Goyal filed a police complaint after an AI-doctored video falsely put threatening words in his mouth about student protesters. Goyal stated on X that his remarks had been "maliciously doctored using AI to create and circulate a deepfake video." An FIR (No. 123/26) was registered at Chanakyapuri Police Station in Delhi at 4:35 AM on July 25, 2026. The PIB Fact Check unit confirmed the video was fabricated.
PIB fact-check of Pakistani propaganda: The Press Information Bureau's Fact Check unit found that Pakistani-backed propaganda accounts were among those amplifying the doctored Goyal clip. PIB stated the video was being circulated "with the alleged intent of misleading people and inciting unrest amid the ongoing student protests in Delhi." This is not the first time PIB has flagged Pakistani accounts for spreading AI deepfakes — similar debunking occurred for doctored videos of Defence Minister Rajnath Singh and Army Chief General Upendra Dwivedi.
Maharashtra Cyber Police FIR (July 31, 2026): Maharashtra Cyber registered a separate FIR against unidentified account operators over the same wave of AI-morphed content targeting PM Modi and Piyush Goyal. The complaint was filed by a BJP social media co-coordinator from Navi Mumbai who identified a Facebook account named "Maharashtra Dharm" posting the manipulated Goyal clip. This FIR invoked Sections 318(2), 336, 352, 353(1), 353(2), 356(1), and 356(2) of the BNS, along with Sections 66D and 67 of the IT Act.
What Indian Law Applies to AI Deepfakes?
India does not have a single, dedicated "deepfake law." Instead, AI-generated synthetic media is prosecuted through a combination of existing statutes — and the combination matters because it determines who can be held liable and for what.
The Information Technology Act, 2000
| Section | What it covers | Penalty |
|---|---|---|
| 66C | Identity theft — fraudulent use of another person's electronic signature, password, or unique identification | Up to 3 years imprisonment + fine up to ₹1 lakh |
| 66D | Cheating by personation using a computer resource (often used for deepfakes impersonating individuals) | Up to 3 years imprisonment + fine up to ₹1 lakh |
| 67 | Publishing or transmitting obscene material in electronic form | First conviction: up to 3 years + fine up to ₹5 lakh; subsequent: up to 5 years + fine up to ₹10 lakh |
Sections 66C and 67 are the ones invoked in the Meta India FIR. Section 66C applies because the deepfakes used a real person's likeness (PM Modi) without authorisation. Section 67 applies because the content was described as obscene and derogatory. The Maharashtra FIR additionally invoked Section 66D (personation/cheating), broadening the legal theory.
The Bharatiya Nyaya Sanhita (BNS), 2023
The BNS replaced the Indian Penal Code on July 1, 2024. The sections invoked across the FIRs — 318(2), 336, 353(1), 353(2), 356(1), 356(2) — cover defamation, public mischief, and statements conducive to public mischief. These are the criminal-law hooks that apply to the content creators and those who amplified it.
IT (Intermediary Guidelines) Amendment Rules, 2026
This is where platform liability gets real. On February 10, 2026, India's Ministry of Electronics and Information Technology (MeitY) notified amendments to the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. The amendments, which came into force on February 20, 2026, introduced a comprehensive framework for regulating "Synthetically Generated Information" (SGI) — covering deepfakes and AI-generated misinformation.
The key changes for platforms:
- Mandatory labelling: Intermediaries must ensure AI-generated content is labelled or marked with metadata that cannot be easily removed — pushing toward watermarking and content provenance tools.
- "Knowingly permitting" clause: If a Significant Social Media Intermediary (SSMI) knowingly permits, promotes, or fails to act upon unlawful SGI, it is treated as non-compliant with the IT Rules. This means it can lose safe-harbour protection under Section 79 of the IT Act — exposing the platform to direct civil and criminal liability for user content.
- Reduced takedown timelines: Platforms must remove or disable access to unlawful content within 3 hours of receiving a court order or government notice, down from the previous 36 hours.
- Proactive detection: SSMIs are expected to deploy automated detection tools to identify and classify AI-generated content — shifting from a reactive notice-and-takedown model to proactive monitoring.
The Meta India FIR is the first major test of whether the "knowingly permitting" clause and the loss of safe harbour can translate into criminal exposure for a platform's local leadership.
Can a Platform Executive Be Held Liable for User Content?
This is the question at the heart of the case — and the answer is genuinely unsettled.
The traditional position: Under Section 79 of the IT Act, intermediaries that exercise due diligence are shielded from liability for third-party content. The landmark 2015 Supreme Court decision in Shreya Singhal v. Union of India struck down the vague Section 66A of the IT Act and narrowed the conditions under which safe harbour can be lost. For most of the last decade, platforms have operated under the assumption that as long as they respond to takedown notices, they are protected.
What changed in 2026: The IT Rules amendments explicitly state that intermediaries failing to meet SGI-specific due diligence obligations — including proactive detection, labelling, and rapid takedown — will be treated as non-compliant and lose safe harbour. The rules pushed platforms from passive hosts into active moderators. What was once a reactive duty is now a proactive one.
The FIR against Meta's India head: Naming Arun Srinivas personally is an escalation. Previous cases in India — including the 2008 criminal defamation proceedings against Google for Google Groups content — targeted the company, not a named country head. The Shreya Singhal ruling and subsequent litigation have established that intermediary liability is determined case by case, and that the loss of safe harbour does not automatically equal guilt — it simply removes the shield. But the Meta India case tests whether naming a local executive in an FIR creates pressure for faster compliance even before the courts rule on the legal theory.
The key uncertainty: No platform has been definitively held liable for hosting unlawful content in India. Litigation in India is lengthy. As legal scholars have noted, the combination of India's slow judicial process and the legal resources of major platforms has historically rendered intermediary liability a weak regulatory tool. The 2026 amendment rules and the Meta FIR represent the government's attempt to change that — fast.
What This Means for You
If you build, operate, or market a platform that hosts user-generated content — especially in markets with evolving AI regulation — this case is your compliance warning.
For AI product builders:
- Content provenance and watermarking are no longer optional features. India's IT Rules 2026 require tamper-resistant labelling of AI-generated content on significant platforms. If your product generates synthetic media, you need detection and labelling infrastructure that survives downstream modification.
- The 3-hour takedown timeline is aggressive. If your moderation pipeline cannot identify and remove flagged SGI content within 3 hours of a government notice in India, you are non-compliant — and your safe harbour is at risk.
For businesses using AI tools:
- Creating or disseminating prohibited synthetic content can attract penalties under multiple Indian statutes simultaneously — the IT Act (66C, 66D, 67) and the BNS. The risk is criminal, not just civil.
- The PIB Fact Check unit is actively debunking deepfakes and tracing amplification networks, including foreign propaganda accounts. Content that gets flagged by PIB is more likely to trigger FIRs.
For global tech companies operating in India:
- The Meta case signals that India may hold local executives personally accountable — not just levy fines on corporate entities. If you are a country head, your personal legal exposure may now be tied to your platform's content moderation performance.
- The IT Rules 2026 amendment give regulators a concrete mechanism to argue that a platform "knowingly permitted" unlawful SGI by failing to deploy adequate detection — making inaction itself a compliance failure.
If you want to understand how India's broader AI strategy fits into this regulatory push, see our analysis of India's sovereign AI strategy and how Indian IT companies are betting on AI.
How Does This Compare to Global Platform Liability for AI Content?
India is not alone in grappling with platform accountability for AI deepfakes, but its approach is among the most aggressive in naming individuals.
| Jurisdiction | Approach | Key mechanism | Status (Aug 2026) |
|---|---|---|---|
| India | Criminal FIR against platform executive + content creators | IT Act 66C/67 + BNS + IT Rules 2026 (SGI amendments) | FIR filed; investigation at preliminary stage; no arrests |
| EU | Civil/administrative liability under Digital Services Act (DSA) | Risk assessments, content moderation transparency, notice-and-action | DSA in force since 2024; AI Act deepfake provisions phasing in |
| United States | Mixed — Section 230 shields platforms; state laws target deepfakes | Section 230 immunity; state-level deepfake laws (e.g., Texas, California) | No federal platform liability for deepfakes; state laws vary |
| United Kingdom | Online Safety Act | Duty of care for illegal content; Ofcom enforcement | Act passed 2023; deepfake provisions expanding |
The distinction matters: the EU, UK, and US frameworks primarily target the platform as a corporate entity through fines and regulatory enforcement. India's FIR goes further — it names a human executive in a criminal complaint. Whether that approach survives judicial scrutiny remains to be seen, but the signal effect is immediate: country heads now have a personal stake in their platform's AI content moderation.
Is This Political Pressure or Genuine Accountability?
Both. The honest answer is that the Meta India case sits at the intersection of a real legal question and intense political pressure.
The real question is legitimate: generative AI has made it trivial to create convincing deepfakes of public figures, and content moderation systems have not kept up. When AI-generated videos of a sitting prime minister circulate during political protests, the potential for real-world harm — riots, violence, electoral manipulation — is not theoretical. India's 2026 amendment rules are a serious attempt to force platforms to take synthetic content seriously.
The political pressure is also real. The FIRs were filed during a politically charged moment — student protests over the NEET paper leak, PM Modi's own Facebook post temporarily restricted by Meta, and the government summoning Meta executives to explain. The PIB Fact Check unit's framing of "Pakistani propaganda accounts" adds a national-security dimension that makes platform defence harder. And naming a specific executive — rather than filing against the company — has a pressure tactic quality that goes beyond what the law alone would require.
The risk regulators face: if prosecution moves faster than the evidence, the case could collapse in court, weakening the precedent. The risk platforms face: if they dismiss this as political theatre, they miss the structural shift — India's IT Rules 2026 have given the government concrete legal hooks to argue non-compliance, and other countries are watching.
For more on how India is approaching digital infrastructure security, see our guide on how India is defending critical infrastructure from cyberattacks.
FAQ
Q: Can a social media platform's executive go to jail for deepfakes posted by users? A: The Meta India FIR names the platform's India head in a criminal complaint, but an FIR is only the start of an investigation — it is not a charge or a conviction. Whether an executive can be held criminally liable depends on whether the platform is shown to have "knowingly permitted" the content to spread (which would strip safe harbour under the IT Rules 2026 amendments) and whether a court accepts that theory. No platform executive has been convicted of hosting user content in India to date.
Q: What is India's safe harbour provision for platforms? A: Section 79 of the Information Technology Act, 2000 grants intermediaries immunity from liability for third-party content, provided they exercise due diligence and comply with the IT Rules. The 2026 amendments specify that platforms which fail SGI-specific obligations (labelling, detection, 3-hour takedown) lose this safe harbour, potentially exposing them to direct liability.
Q: What is the penalty for creating AI deepfakes in India? A: Under the IT Act, Section 66C (identity theft) carries up to 3 years imprisonment and a fine up to ₹1 lakh. Section 67 (obscene electronic content) carries up to 3 years and ₹5 lakh for a first conviction. Additional charges under the Bharatiya Nyaya Sanhita can stack on top. Users creating or disseminating prohibited synthetic content may attract penalties across multiple statutes simultaneously.
Q: How fast must a platform remove deepfakes under India's 2026 rules? A: The IT (Intermediary Guidelines) Amendment Rules, 2026 require intermediaries to remove or disable access to unlawful content within 3 hours of receiving a court order or authorised government notice — a significant reduction from the previous 36-hour window. This applies to all intermediaries, not just large platforms.
Q: Has any other country filed criminal charges against a platform executive over AI content? A: As of August 2026, India's FIR against Meta's India head appears to be the first instance globally where a local executive of a major tech platform has been personally named in a criminal complaint over AI deepfakes. The EU (DSA), UK (Online Safety Act), and US (Section 230) primarily target platforms as corporate entities through fines and regulatory enforcement, not individual executives.
Q: What did the PIB Fact Check unit find about the deepfake videos? A: The Press Information Bureau's Fact Check unit confirmed that the AI-doctored video of Union Minister Piyush Goyal was fabricated and was being amplified by Pakistani-backed propaganda accounts with the intent of misleading viewers and inciting unrest. PIB has previously debunked similar AI deepfakes targeting Defence Minister Rajnath Singh and Army Chief General Upendra Dwivedi.

Discussion
0 comments