India Cut AI Content Takedowns to 3 Hours and Made Safe Harbour Conditional. Nobody Has Audited What That Means.

Abhishek Dash10 min read
A glowing hourglass filling with social-media post cards under a 3:00:00 countdown, a cracked safe-harbour shield, takedown notices and a red government seal, with an AI chip asking what counts as AI content

In short

India's February 2026 IT Rules amendment cut AI-content takedown deadlines from 36 hours to 3 on a valid government or court order, cut nudity and impersonation complaints from 24 hours to 2, and made Section 79 safe harbour conditional on compliance, while narrowing takedown authority to Joint Secretary or DIG rank officers with monthly senior review. Mandatory labelling of AI-generated content with traceable metadata took effect from 20 February 2026, and an August 2026 draft proposed compressing general grievance resolution from 72 hours to 36.

Key takeaways

  • Takedowns on a valid government or court order dropped from 36 hours to 3 hours, and complaints involving nudity or impersonation dropped from 24 hours to 2 hours
  • Platforms lost Section 79 safe harbour protection for non-compliance, and takedown orders were confined to Joint Secretary or DIG rank officers with monthly senior review
  • Mandatory labelling of AI-generated content with traceable metadata took effect; the deepfake provisions were in force from 20 February 2026, with SSMI obligations applying to platforms with 50 lakh (5 million) or more registered users in India
  • The August 2026 draft cuts general grievance resolution from 72 hours to 36 and explicitly names deepfakes, AI-enabled impersonation, CSAM and non-consensual intimate imagery in scope
  • The July 2026 Piyush Goyal deepfake complaint (FIR 123/26 at Chanakyapuri) tested the machinery in the form the law was written for; whether takedowns occurred inside three hours is not publicly established

India did not adopt an AI law. It amended the IT Rules, the same rules that have governed platform liability since 2021, and in doing so changed three numbers that have not been properly analysed outside the legal commentary:

  • Takedown window: 36 hours down to 3 hours, on a valid government or court order
  • Sensitive-content complaints: 24 hours down to 2 hours
  • Safe harbour: Section 79 protection now conditional on compliance

This is that formula applied to a live regulatory change with almost no English-language technical coverage. And the honest treatment, up front: the amendment also narrowed takedown authority to officers at Joint Secretary or DIG rank with monthly senior review, which is a due-process control. The legitimate criticism is precise and different from "censorship," and that precision is the whole point of this post.

India has deliberately not adopted a standalone AI law. Per the September 2026 AI Governance Guidelines, the approach is: the IT Act, 2000 and the Digital Personal Data Protection Act, 2023 as the primary foundations; targeted amendments for new issues like content authentication, liability, and copyright; mandatory visible labelling of AI-generated content; and international cooperation on AI standards.

The vehicle is amendments to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, notified 22 October 2025, with deepfake-specific provisions in force from 20 February 2026.

What the February 10 2026 amendment changed

Notified 10 February 2026, addressing harms from synthetically generated information (SGI) including deepfakes and AI-generated content:

Change From To
Takedown on valid government/court order 36 hours 3 hours
Complaints: nudity or impersonation 24 hours 2 hours
Section 79 safe harbour Unconditional (subject to due diligence) Lost for non-compliant platforms
Who may issue a takedown order Broader set Officers at Joint Secretary or DIG rank only, with monthly senior review

Keep that fact base clean and let it carry the weight.

Additional obligations on Significant Social Media Intermediaries (SSMIs, platforms with 50 lakh or more registered users in India):

  • Deploy automated tools or suitable mechanisms to proactively identify information depicting "any act or simulation in any form depicting rape, child sexual abuse or conduct"
  • Make "reasonable efforts" to identify content identical to material previously removed
  • Inform users of the legal consequences of creating or sharing unlawful AI-generated content
  • Mandatory user disclosure that content is AI-generated, with platforms required to verify and display labels and attach traceable metadata

Definitions: "synthetically generated information" means audio, visual, or audio-visual content generated, modified, or altered through algorithmic, computational, or AI processes. The obligations reach both Indian and foreign platforms accessible in India.

The safeguard that cuts the other way

Takedown authority is now confined to Joint Secretary or DIG rank, with monthly senior review. Give that its full weight. It is the strongest argument that the regime was drafted defensively rather than as a censorship tool, and omitting it would make any analysis of this amendment a partisan framing exercise.

The legitimate criticism is different and more precise than "censorship": three hours is short enough that platform-level automated removal becomes the default outcome regardless of the merits of any particular order, and the safe harbour condition means compliance is incentivised even when removal is arguably wrong. Whether a rank restriction plus monthly review is a sufficient counterweight to a 3-hour automated pipeline is a real, open, and legitimately debatable question. Both sides of that question are defensible, and I will hold both here.

Pre-existing and continuing enforcement tools

The amendment did not land on a blank slate. IT Act s.353 penalizes false or misleading statements, rumours, or reports that can cause public mischief or fear. IT Act s.111 covers organised cybercrimes involving deepfake content. The IT Rules already require messaging-service SSMIs to help law enforcement trace originators of serious or sensitive content, and to use automated tools to detect and limit the spread of unlawful content.

The rolling advisories from PIB show the machinery was already running: 29 Dec 2025 on unlawful content, 9 Feb 2026 on religious matters, 16 Mar 2026 on abusive, defamatory, objectionable, derogatory and misleading synthetically generated information, an earlier deepfake advisory in Nov 2024, and a 6 Aug 2026 deepfakes advisory.

The August 6 2026 draft

Filed by MeitY, for public consultation: the 3-hour deadline (from 36) confirmed; general grievances compressed from 72 hours to 36; sensitive complaints (nudity, impersonation) down to 2 hours; mandatory labelling of AI-generated images, video, audio and other synthetic content with traceable metadata; harmful-content scope expanded to explicitly include deepfakes, AI-enabled impersonation, CSAM, and non-consensual intimate imagery; and SSMIs required to deploy technical measures to limit the spread of specified categories.

Explicitly still a draft, subject to stakeholder feedback, and may change. Date the claims accordingly.

The test case

25 July 2026, Piyush Goyal, Union Minister of Commerce and Industry, asserted that an AI-generated deepfake had maliciously altered his remarks to the media outside Parliament, portraying him as making threatening remarks against protesting students amid alleged NEET irregularities. Filed a police complaint; FIR No. 123/26 registered at Chanakyapuri police station. Warned of "strict legal action" against those creating, disseminating, or promoting it.

The PIB fact-check unit stated that Pakistani propaganda accounts were circulating the fabricated video. Government sources said many social media links carrying it had been taken down. Context: recently concluded student protests organised by the Cockroach Janata Party at Jantar Mantar, amid repeated official cautioning against unverified videos.

Goyal's framing, quoted in The Hindu: "irresponsible misuse of artificial intelligence to mislead the public cannot and will not be tolerated."

What is not established: whether takedowns happened inside three hours. That is not public, and I will not assert it. The machinery fired in the form the law was written for; the clock, the part that separates the designed behaviour from the real one, is unmeasured.

The CAIT case, and the symmetry argument

On 27 September 2026, the Confederation of All India Traders published a "FAKE NEWS ALERT" denying it had called a nationwide boycott of UPI transactions on 2 October (Gandhi Jayanti), calling viral claims "completely misleading and false" and urging reliance on official communications only.

Background, which explains the volume of viral claims: trader opposition to the government's decision to levy a 0.4% MDR on specified person-to-merchant UPI transactions above 2,000 rupees from 15 October. The dispute escalated into a partisan spat, with Telangana BJP chief Ram Chander Rao accusing Rahul Gandhi of spreading misinformation about UPI transaction charges.

Why this belongs here: it shows the deepfake and takedown machinery in India is not only a tool for state-versus-dissent speech. It is also the mechanism by which a fabricated claim about a traders' body announcing a national payment boycott got circulated widely enough to require a public denial. The same virality dynamics drive both. That symmetry is the honest core of this piece, and it is very hard to make the "censorship" framing survive contact with it.

The technical problem nobody has published

Here is the mechanical finding, and it is checkable, not partisan. The rule simultaneously requires platforms to build automated detection of unlawful synthetic content and penalises them for the automated removal of lawful content, because the two are the same system. Every false positive inside a 3-hour window is a Section 79 event.

That means one system does both mandated proactive detection and mandated rapid removal, and safe harbour now attaches to the accuracy of that system's output. A rule that removes deepfakes in three hours does nothing about a fabricated PDF or a WhatsApp forward, and India's actual high-velocity misinformation is frequently text and documents. The regulation addresses the new medium and leaves the old one untouched, and the CAIT case is the proof.

My test: the compliance harness

The strongest available first-party element here is measurable and does not require lobbying access, so I built it.

The compliance harness is a local pipeline implementing the amended IT Rules logic: synthetic-content classification, traceable metadata provenance, user labelling, the 2-hour and 3-hour SLA clocks, identical-content re-detection ("reasonable efforts to identify content identical to previously removed material"), and Section 79 conditionality. Run it against a synthetic corpus of lawful-but-AI-generated content and unlawful content, and measure the false-positive rate. That number, what fraction of lawful synthetic media gets removed in under three hours, is the whole cost of the regime, and it appears nowhere in the public record.

Provenance feasibility next. How much of the labelling requirement can actually be satisfied today? Check C2PA and Content Credentials maturity, C2PA conformance of common generators, and the cost of retrofitting. If the traceability requirement is not technically achievable at scale, the safe harbour becomes a de facto licence fee for compliance engineering, which is a defensible policy choice but should be argued openly rather than discovered by platforms.

Time-box the SLA: walk a real complaint through the 2-hour and 3-hour clocks end to end, including the monthly senior review step, and publish the elapsed wall-clock time. The law is short on paper; the operational latency including human review is what actually determines whether removal is automatic or considered.

The asymmetric failure cost: what does a platform lose for a late removal versus a wrongful early removal? The amendment does not make this explicit, and a post that surfaces the asymmetry is genuinely useful to the engineers who have to build it.

Second thread, the misinformation economy. Catalogue publicly documented viral false claims in India over a defined window (the CAIT "No UPI Day" case, the Piyush Goyal deepfake and its Pakistani-accounts origin claim, the E20 misinformation adjacent to my earlier E20 piece). For each: which channel, what format, how fast, and whether a takedown regime could have touched it. The finding holds: audio/video deepfakes are now removable in three hours, and the highest-velocity false claims in India are text and documents.

The adjacent trend, briefly

New York's Hochul signed the first statewide data center moratorium, citing water and grid load, a different jurisdiction restricting AI infrastructure rather than AI content. And S.4213, the Data Center Water and Energy Transparency Act of 2026, would require data center operators to report energy and water use to states, EPA, DOE and USDA, a disclosure regime for infrastructure rather than speech regulation. Same pressure, different valve, worth knowing about if you are tracking how jurisdictions are handling AI.

Where this could be wrong

The censorship framing does not survive contact with the text, and I want to say that directly. Takedowns require a valid government or court order, and the amendment simultaneously narrowed who may issue such an order to a named senior rank with monthly senior review. Refusing to engage with that half of the record is the fastest way to lose a technical audience.

Three hours may be reasonable for emergencies, for CSAM and NCII. The open question is whether the same clock applies to a government or court order about synthetic misinformation, where the alleged harm is reputational and political rather than immediate. The post should separate the categories, and note that the amendment does not separate them in the operative text.

Two precision fixes to hold onto, because accuracy is what makes this worth arguing about: safe harbour has always been conditional on due diligence under Section 79, so the change is that the condition now includes synthetic-content labelling and detection; and automated takedown is standard and does work, with its false-positive rate being the never-published number that matters.

What would update all of this: the finalized text of the August 6 draft; the current precise definition of "reasonable efforts" for identical-content re-detection, which is the clause most likely to be litigated; whether any takedown under the 3-hour rule has been publicly contested or a writ filed; current C2PA adoption in India; whether the CAIT denial included a circulation-volume number; and whether the 0.4% MDR threshold policy changed.

Close

India built a fast door for synthetic media and left the window open behind it. Both halves of that sentence are true, and the second one is the one that will be tested in the next election cycle.

On this page

Sources

  1. Press Information Bureau: Government Strengthens Framework to Counter AI MisinformationPress Information Bureau, Government of India, 2026
  2. The Hindu: Many social media links taken down, government sources on AI deepfake video of Piyush GoyalThe Hindu, 2026
  3. Business Today: CAIT factchecks No UPI Day claims for October 2Business Today, 2026
  4. S.4213, Data Center Water and Energy Transparency Act of 2026US Congress, 2026

Frequently asked questions

What exactly changed in the February 2026 IT Rules amendment?

Four things. Takedowns on a valid government or court order dropped from 36 hours to 3. Complaints involving nudity or impersonation dropped from 24 hours to 2 hours. Platforms lost Section 79 safe harbour protection for non-compliance. And takedown orders were confined to officers at Joint Secretary or DIG rank, with a monthly senior review. Mandatory labelling of AI-generated content with traceable metadata also took effect, with the deepfake provisions in force from 20 February 2026.

Is this censorship?

That framing does not survive contact with the text. Takedowns require a valid government or court order, and the amendment simultaneously narrowed who may issue such an order to a named senior rank with monthly senior review. That narrowing is a due-process control, not a loosening. The legitimate criticism is different and more precise: three hours is short enough that platform-level automated removal becomes the default outcome regardless of the merits of any particular order, and the safe harbour condition means compliance is incentivised even when removal is arguably wrong.

What did the draft August 2026 rules add?

General grievance resolution went from 72 hours to 36. Traceable provenance metadata was specified more concretely. AI-enabled impersonation and non-consensual intimate imagery were named explicitly in the harmful-content scope, alongside deepfakes and child sexual exploitation material. The draft was released for public consultation and may change.