A video of a Union Minister pocketing money lands in your family WhatsApp group. It looks right. The voice is his, the office is his, the lighting is ordinary enough to pass. Nothing on the screen tells you a machine built it, and by the time anyone official says so, your uncle has forwarded it twice.
Why It Matters
The rules were notified on 10 February 2026 and came into force ten days later. They do two things worth caring about. Synthetically generated information, meaning audio or video created or altered by a machine so it reads as authentic, now has to carry a label an ordinary person can actually see. And platforms have to embed permanent provenance markers into that content wherever it is technically feasible, then stop anyone from stripping them out. It is the same regulatory instinct that produced 83 security standards aimed at the handset in your pocket: fix it at the device or the platform, because chasing individual bad actors across the open internet has never scaled.
The draft wanted something blunter. A watermark covering ten percent of the frame, fixed, non-negotiable. That died before notification and was replaced by a principle: the label must be clear and prominent. Good. A hard percentage would have been unreadable on a phone and ridiculous on a television, and every design team in the country would have spent a year gaming the geometry instead of improving the disclosure. But turn it around and the change reads as an admission. Nobody could describe what a good label looks like, so the rule now describes a feeling and leaves the rest to whoever ships the app.
Then there is the clock, and the clock is where the framework quietly hands the work back to you. Platforms now face a hard deadline to pull flagged unlawful synthetic content once a lawful notice reaches them, cut sharply from the old window. Cross the significant intermediary threshold and a second duty lands: ask uploaders whether their material is machine-made, then verify that answer with technical measures instead of taking it on trust. On paper, aggressive. In practice, none of it moves until somebody notices, reports, and is believed. McAfee's State of the Scamiverse survey, published in February 2026, found Indians now spend 102 hours a year working out whether the messages hitting their phones are genuine. That is the real bill, and a shortened takedown window does nothing to it.
Takedown deadline
3 hours
Down from thirty six
Average scam loss
₹93,915
Per affected Indian respondent
Strict-tier threshold
50 lakh users
Registered accounts inside India
Cannot spot a fake
1 in 3
Indians surveyed, November 2025
The tier threshold is the number to watch, because it is a cliff rather than a slope. Cross it and you inherit the declaration-and-verification duty, which in engineering terms means building a classifier that guesses whether an upload is synthetic and then owning every case it gets wrong. Stay under it and you inherit almost nothing. Every mid-sized Indian app now has a live commercial reason to keep its registered account count comfortably short of the line, and no regulator has said a word about what happens when they do. TRAI has spent years watching this exact arithmetic play out in telecom without moving on it.
A three hour takedown clock means nothing to the person it was written for, because the clock only starts once she has already found the video, reported it, and been believed.
August gave the framework its first properly public test, and it is worth setting the written rule beside what actually happened in a courtroom.
| Category | Detail | Insight |
|---|---|---|
| Legal basis | An amendment to the existing intermediary guidelines, not a standalone AI statute | Existing framework extended, not rewritten |
| Scope | Audio, visual and audio-visual material altered to appear authentic | Text-only output sits outside the rule |
| Label test | Clear and prominent, with the draft's fixed frame percentage dropped | Flexibility bought at the cost of certainty |
| Provenance | Permanent markers embedded where feasible, with removal blocked by design | Traceability outlasts any visible badge |
| Exemptions | Routine editing, good-faith technical correction, accessibility work | Ordinary photo cleanup stays untouched |
| Verification | Uploader declares, platform checks the declaration with technical measures | Platforms now own the classification mistakes |
| Trigger | A lawful order or notice from a court or an authorised government agency | Nothing moves without an external complaint |
| August test | Bombay High Court, 5 August 2026, before Justice Arif Doctor | Meta and Google agreed after court intervention |
Read down that Trigger row again. The entire machine is reactive. Provenance markers, declaration duties, a stopwatch on removals, and every one of them waits for a complaint to arrive from outside. Which is why the story of the last six months is not the rule failing. It is the rule working exactly as drafted, on a schedule set by whoever has the time and standing to complain.
The same McAfee fieldwork, run across seven countries, puts the Indian exposure picture in one frame: most people have already been hit, and most of them know it.
Friction Points
Earlier this month the Bombay High Court heard Nitin Gadkari's application against Meta Platforms over face-swapped videos and fabricated quotes tying him to the E20 ethanol controversy. Justice Arif Doctor called the material absolutely vile and abusive and said it should have no place on a public platform accessible to everyone, including the young. Meta and Google agreed in court to remove the listed content and were directed to hand over basic subscriber information for the accounts behind it. The next hearing sits roughly four weeks out. Note what that sequence required: a sitting Union Minister, senior counsel, and a High Court listing, half a year after the deadline took effect. If that is the cost of entry, the rule is not built for the woman whose face was pasted into something at two in the morning.
Here is the part nobody in the drafting room seems to have answered, and I would put it as opinion rather than fact: a labelling regime binds the people who were already going to behave. The model that stamps provenance into its output and the platform that surfaces the badge are both following rules that a deliberate faker simply routes around, using an offshore tool, a screen recording, a re-encode. So the label ends up certifying the harmless half of the internet while the harmful half stays unmarked, and no one has told readers what they are supposed to conclude from a video that carries no label at all. Absence of a badge is not evidence of authenticity. It might just mean the rule was ignored.
And there is a cost on the other side that gets less attention than it deserves. Compressing removal into hours, with safe harbour hanging on compliance, pushes platforms toward automated over-removal, because deleting a borderline clip is cheaper than defending it. Satire, political commentary, parody accounts (and yes, that includes the stuff you actually wanted to see) all sit in the blast radius. The Internet Freedom Foundation has argued the shortened windows leave no room for meaningful human review, and on that narrow point the criticism looks right to me even if the underlying goal does not.
- An unlabelled video proves nothing either way. Treat missing provenance as unknown, not clean.
- The clock starts at the notice, not at the upload. Reporting fast matters more than knowing the law.
- Text is out of scope, so machine-written fake quotes and fake screenshots carry no labelling duty at all.
- Smaller apps sit below the strict tier and owe you far less, which is where a lot of this content will migrate.
- Provenance markers survive the label. If a clip matters, the metadata is the thing worth preserving before you forward it.
Three habits, none of which require you to read a gazette notification.
The rules are a real improvement over having nothing, and they are nowhere near what the marketing around them implied. India moved faster than most countries here, which counts for something, in the same way moving first on credit through UPI counted for something before the fine print landed. If you want a version of this that protects your household rather than a minister, the move is not legal. Go into the settings on every account your family uses, turn on whatever synthetic-media reporting the platform already offers, and use it the first time rather than the fifth, the same discipline that makes switching off Shorts on the living room television actually stick. The label is not going to save you. The report button might.