INTRODUCTION
The human face used to belong only to the person wearing it; basically, your face used to belong to you by default. That has changed. Tools built by Meta AI, OpenAI, and a growing list of smaller Indian and global developers can now rebuild a person’s face, voice, and mannerisms from a handful of photographs or a short voice note. India doesn’t have a clean answer. What it has is a set of borrowed tools, personality rights carried over from common law torts, privacy protections read into the Constitution, and a handful of IT Act provisions never written with any of this in mind, being stretched a little further with each new court order. That is not sustainable. India needs an actual Digital Personality Rights law.
THE CONCEPT OF DIGITAL PERSONALITY RIGHTS
At its core, a personality right protects the commercial and dignitary interest a person has in their own name, face, voice, signature, and other things that make them recognisable. India never legislated this into existence. It grew, almost by accident, out of tort law and the privacy jurisprudence that followed the Supreme Court’s recognition of privacy under Article 21 in Justice K.S. Puttaswamy v Union of India.[1]
Generative AI has changed the scale of the problem entirely. The same doctrine built for advertising disputes is now being asked to handle deepfake videos, cloned voices, and fabricated sexual content, none of which resembles the situations it was designed around.
THE NEW THREATS: FROM AI IMAGE GENERATORS TO VOICE CLONING
Image generators and large AI models, including tools linked to Meta AI, OpenAI, and a long tail of lesser-known “nudifying” apps, can now produce a convincing photo, video, or audio clip of almost anyone. Voice cloning needs even less: a few seconds of someone speaking is enough to generate an entirely new script in their voice. None of this is hypothetical. During the 2024 Lok Sabha elections, a cloned voice of a sitting Union Minister was reportedly used to spread false claims about reservation policy, and synthetic voices of leaders who had already passed away turned up in campaign material.[2]
Nudifying websites are a separate, more disturbing category, using generative adversarial networks to strip or swap clothing in an ordinary photo. Almost none of this content is consensual, and the overwhelming majority of it is aimed at women.[3]
A defamatory statement merely claims something happened. This kind of content actually manufactures the “evidence,” and once it starts circulating, there is often no way to fully take it back.
BEYOND CELEBRITIES: THE ORDINARY VICTIM
In 2023, actor Rashmika Mandanna’s face was morphed onto another woman’s body and spread online, which led to arrests under the IT Act. But look at who actually ends up in court, and a different pattern shows up: non-celebrity petitioners, especially women, are a tiny fraction of the cases that reach a judge, despite being targeted the most.[4]
Helpline data backs this up; most women reporting deepfake abuse have no public profile at all. They aren’t actresses or politicians.[5]
A homemaker, a student, or someone early in their career whose photo gets pulled off Instagram and turned into explicit content simply lacks the same access to the fast, sweeping injunctions courts have granted film stars. And that’s partly because personality rights were built around protecting commercial goodwill, so someone with no “brand” to speak of doesn’t fit neatly into the framework, even though what they’re going through is arguably worse.
JUDICIAL RESPONSE IN INDIA
With no dedicated statute to fall back on, courts have improvised. The Delhi High Court’s order in Anil Kapoor v Simply Life India is generally treated as the first real, comprehensive recognition of AI-specific personality rights misuse in the country; it stopped the use of the actor’s name, voice, and likeness through AI tools, face-morphing, and GIFs for commercial gain, and directed the takedown of infringing websites.[6]
Similar orders have since followed for Amitabh Bachchan, Aishwarya Rai Bachchan, and filmmaker Karan Johar, extending this protection even where no clear commercial transaction was involved. Around the same time, the Ministry of Electronics and Information Technology amended the Intermediary Guidelines in 2025, requiring platforms to label AI-generated content and stick to tiered takedown windows, as tight as two hours for non-consensual nude deepfakes.[7]
GAPS IN THE EXISTING LEGAL FRAMEWORK
A few cracks stand out. India has no standalone law that treats personality rights or digital identity as their own legal category, so courts keep improvising with tort principles, Article 21[8], and IT Act provisions that were never built for AI. Copyright and trademark law don’t really help either, since a face or a voice isn’t a “work” under the Copyright Act, 1957, and it isn’t a registrable mark under the Trade Marks Act, 1999.[9]
Section 79[10] of the IT Act is also structurally weak: platforms lose safe-harbour protection only after “actual knowledge” of infringing content, favouring litigants who can afford urgent court orders, while an ordinary victim often has no idea where to complain. The criminal provisions aren’t much better suited; Sections 66C, 66D, 66E, 67, 67A, and 67B of the IT Act[11] were written for a pre-AI internet, and courts now have to stretch what counts as “capturing” an image to cover content that was never captured from anything real in the first place. And there is no dedicated body, the way there is for data protection, whose job is to receive and act on complaints about synthetic identity misuse.
WHAT A DIGITAL PERSONALITY RIGHTS ACT SHOULD CONTAIN?
A proper statute needs to do a few things at once. It has to define digital personality rights broadly enough to cover a person’s face, voice, gait, signature, and other identifying features, and it needs to apply to everyone, not just public figures with a commercial reputation to protect. It should treat this as both a dignity issue and a property issue, so an ordinary person can seek relief purely on the basis of harm to their privacy and dignity, without having to prove any commercial loss at all. Takedown timelines need to be written into the statute itself, not left to subordinate rules that can quietly get watered down later.
Consent also needs teeth: before any AI system is trained on or used to recreate someone’s likeness, that consent should be as specific and meaningful as the standard already set for personal data under the Digital Personal Data Protection Act, 2023.[12]
There should be a low-cost grievance mechanism that doesn’t require a person to hire a lawyer and approach a High Court just to get something taken down. And finally, the law needs to draw a real line between satire, parody, and consented use on one side, and malicious impersonation, fraud, and sexual exploitation on the other, with liability that actually scales with the harm.
CONCLUSION
Law has always run a step behind technology, but this particular gap is starting to feel dangerous. A face can be copied today with less effort than it once took to forge a signature, and the damage to someone’s reputation, safety, finances, or dignity can spread across the country before anyone has even filed a complaint. But a right that only works if you can afford to walk into a High Court on short notice isn’t really a right for the ordinary person whose photo has been turned into something she never agreed to. Another interim injunction won’t fix that. What India actually needs is a Digital Personality Rights Act built to protect the face, voice, and identity of every person, not just the ones already famous enough to have a lawyer on speed dial.
Author(s) Name: Shakshi (Campus Law Centre, University of Delhi)
References:
[1]Justice K S Puttaswamy (Retd) and Anr v Union of India and Ors (2017) 10 SCC 1
[2] Kadambari Manojkumar Sonawane, ‘Deepfakes and the Law: Addressing Legal Accountability for AI-Generated Misinformation’ (Record of Law, 7 December 2025) <https://recordoflaw.in/deepfakes-and-the-law-addressing-legal-accountability-for-ai-generated-misinformatio> accessed 12 July 2026
[3] Nandini Tyagi, ‘Why India’s Deepfake Pornography Infestation is a Concern’ (NUJS Intellectual Property & Technology Laws Society, 18 February 2025) <https://nujsiplaw.wordpress.com/2024/04/01/why-indias-deepfake-pornography-infestation-is-a-concern/> accessed 12 July 2026
[4] Ritwik Sharma, ‘Rethinking Judicial Approaches to Sexually-Explicit Deepfakes: The Case for Article 21-Based Relief Against Nudifying Websites’ (Law School Policy Review, 23 February 2026) <https://lawschoolpolicyreview.com/2026/02/23/rethinking-judicial-approaches-to-sexually-explicit-deepfakes-the-case-for-article-21-based-relief-against-nudifying-websites> accessed 12 July 2026
[5] ‘Bollywood Celebrity Deepfake Detection’ (AI or Not, 18 May 2026) <https://www.aiornot.com/blog/bollywood-celebrity-deepfake-detection> accessed 12 July 2026.
[6] ‘Delhi HC’s Protection To Anil Kapoor; A Landmark Order On Personality Rights’ (Naik Naik & Co, 17 October 2023) <https://naiknaik.com/2023/10/17/vtubers-live-streamers-using-copyrighted-materials-its-legal-implications/> accessed 12 July 2026
[7] Arnav Naik, ‘Deepfake Laws in India: The IT Rules 2026 Guide’ (Prime Legal Blog, 20 June 2026) <https://blog.primelegal.in/deepfake-laws-india-it-rules-2026/> accessed 12 July 2026
[8] Constitution of India, art 21
[9] Copyright Act 1957; Trade Marks Act 1999
[10] Information Technology Act 2000, s 79
[11] Ibid ss 66C, 66D, 66E, 67, 67A and 67B
[12] Digital Personal Data Protection Act 2023, s 6

