Executive Summary:
The Indian government is addressing the misuse of AI through a multi-pronged strategy, including legal provisions, technological measures, and the development of a comprehensive AI governance framework. The IndiaAI mission was launched in March 2024 to foster a robust AI ecosystem. Existing legal frameworks, such as the IT Act, 2000, and the Bharatiya Nyay Sanhita, 2023, are being leveraged to penalize AI-related offenses, with ongoing efforts to refine and expand these measures.
Key Points / Main Content:
AI Strategy and Initiatives:
* IndiaAI Mission: Launched in March 2024 to establish a robust and inclusive AI ecosystem.
* Safe Trusted AI: Aims to balance innovation with strong governance for responsible AI adoption. 8 projects selected and over 400 applications in the second round to address issues like machine unlearning, bias mitigation, and governance testing framework.
* IndiaAI Safety Institute: An expression of interest was published on May 9, 2025, for onboarding partner institutions.
* Advisory Group on AI: Constituted under the chairmanship of the Principal Scientific Advisor to the Prime Minister to define India-specific regulatory AI framework.
Legal Provisions:
* IT Act, 2000:
* Section 66C: Addresses identity theft, including misinformation and deepfakes.
* Section 66D: Criminalizes using computer resources for cheating by personation.
* Section 66E: Prescribes punishment for capturing and publishing images of private areas without consent.
* Sections 67A and 67B: Penalize publishing obscene material, including deepfake-generated content.
* Bharatiya Nyay Sanhita, 2023:
* Section 111: Punishes continuing unlawful activities, including economic offenses and cybercrimes by organized crime syndicates.
* Other sections address cybercrimes like cheating, public mischief, and defamation.
* Digital Personal Data Protection Act, 2023: Imposes obligations on Data Fiduciaries to safeguard digital personal data and ensures the rights and duties of Data Principals.
* IT Rules, 2021:
* Legal obligations on intermediaries to remove prohibited misinformation, false information, and deepfakes.
* Failure to comply results in consequential action or prosecution.
* Grievance redressal mechanism with 24-hour timelines for morphed or artificially generated images; aggrieved persons can approach Grievance Appellate Committee.
Additional Measures:
* Government Advisories: Issued to intermediaries/platforms for compliance on using AI foundational models.
* UIDAI: Actively addressing AI misuse risks, including deepfakes and algorithmic bias.
* CERT-In: Issues alerts and advisories on cyber threats, vulnerabilities, and countermeasures, including those related to AI.
* Cybercrime Reporting: Ministry of Home Affairs launched a dedicated portal (cybercrime.gov.in) and toll-free number (1930) for reporting cybercrimes.
Impact Analysis:
Government:
* Impact: Responsible for enforcing existing laws and regulations, developing new AI governance frameworks, and coordinating efforts across different agencies.
* Action Required: Finalize and implement a comprehensive AI governance and ethics framework and ensure effective enforcement of legal provisions.
Private Entities:
* Impact: Subject to legal obligations and potential penalties for AI misuse, including the creation and dissemination of deepfakes or biased algorithms.
* Action Required: Comply with IT Rules, 2021, and other relevant regulations; implement measures to prevent AI misuse and ensure responsible AI development and deployment.
Foreign Actors:
* Impact: May face legal action under Indian laws for AI-related offenses committed within or targeting India.
* Action Required: Refrain from activities that violate Indian laws and regulations related to AI misuse.
Intermediaries/Platforms (e.g., Social Media):
* Impact: Legal obligations to remove prohibited misinformation, false information, and deepfakes; liable for consequential action if they fail to comply.
* Action Required: Implement effective mechanisms for detecting and removing AI-generated misinformation, establish grievance redressal mechanisms, and comply with government advisories.
Data Fiduciaries:
* Impact: Obligations to safeguard digital personal data and ensure the rights of Data Principals under the Digital Personal Data Protection Act, 2023.
* Action Required: Implement appropriate data protection measures and comply with the provisions of the Digital Personal Data Protection Act, 2023.
Citizens:
* Impact: Protected by legal provisions against AI-related offenses, including identity theft, misinformation, and privacy violations.
* Action Required: Report cybercrimes through the dedicated portal (cybercrime.gov.in) or toll-free number (1930).
Key Entities Referenced
IndiaAI mission: A strategic initiative launched in March 2024 by the Government of India to establish a robust and inclusive AI ecosystem aligned with India's development goals.
IT Act, 2000: Indian Information Technology Act, 2000. Legal provisions under this act are used to address misinformation, deepfakes, cheating by personation or identity theft.
Bharatiya Nyay Sanhita, 2023: A legal code of India, specifically Section 111 which punishes cybercrimes, among other sections addressing cheating and defamation.
Digital Personal Data Protection Act, 2023: An Indian law that imposes obligations on Data Fiduciaries to safeguard digital personal data and ensures the rights and duties of Data Principals.
Information Technology Intermediary Guidelines and Digital Media Ethics Code Rules, 2021 (IT Rules, 2021): Indian regulations that cast legal obligations on intermediaries, including social media platforms, to remove prohibited misinformation and deepfakes.
Ministry of Home Affairs: The Indian government ministry that launched the cybercrime reporting portal cybercrime.gov.in and the toll-free number 1930.
Unique Identification Authority of India (UIDAI): An Indian government agency actively addressing the key risks associated with AI misuse, including deepfakes, algorithmic bias, cyber fraud, and misuse of automated authentication systems.
Indian Computer Emergency Response Team (CERT-In): An agency that issues alerts and advisories regarding the latest cyber threats/vulnerabilities, including malicious attacks using Artificial Intelligence and countermeasures.
GOVERNMENT OF INDIA
MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY
LOK SABHA
UNSTARRED QUESTION NO. 533
TO BE ANSWERED ON: 23.07.2025
MISUSE OF AI
533. SHRI KODIKUNNIL SURESH:
Will the Minister of ELECTRONICS AND INFORMATION TECHNOLOGY be pleased to state:
(a) whether the Government has identified key risks associated with AI misuse—such as
deepfakes, algorithmic bias, automated surveillance, or cyber fraud—and outline the legal
framework in place to address them and if so, the details thereof;
(b) whether the Government has proposed or enacted any specific legislations, amendments or
regulations to penalize AI-related offenses including misuse by both private entities and foreign
actors and if so, the details thereof;
(c) whether any agencies (such as CERT-In, UIDAI, or cybercrime units) have been empowered
or trained to detect and respond to AI-backed threats and if so, the details thereof;
(d) whether any prosecutions, penalties or legal actions have been initiated in the country to date
for AI-related wrongdoing and if so, the details thereof; and
(e) the timeline for finalization and implementation of any comprehensive AI governance or ethics
framework?
ANSWER
MINISTER OF STATE FOR ELECTRONICS AND INFORMATION TECHNOLOGY
(SHRI JITIN PRASADA)
(a) to (e): India’s AI strategy is based on the Hon’ble Prime Minister's vision to democratize
the use of technology. It aims to address India centric challenges, create economic and
employment opportunities for all Indians.
AI ecosystem in India at present:
India has a strong information technology ecosystem. It generates annual revenues of more than
250 billion dollars and provides employment to more than 6 million people.
Global rankings such as Stanford AI rankings place India among the top countries in AI skills,
capabilities, and policies to use AI. India is also the second-largest contributor to GitHub AI
projects, showcasing its vibrant developer community.
India’s AI strategy:
India’s AI strategy aims to position India as a global leader in artificial intelligence. Government
launched IndiaAI mission in March 2024. It is a strategic initiative to establish a robust and
inclusive AI ecosystem aligned with India's development goals.
Safe & Trusted AI
• To balance innovation with strong governance frameworks to ensure responsible AI adoption.• In the first round, 8 projects have been selected addressing issues like machine unlearning, bias
mitigation, privacy-preserving machine learning, explainability, auditing tools, and
governance testing framework.
• More than 400 applications have been received in the second round.
• An expression of interest was published on 09th May 2025 for onboarding partner institutions
for setting up the IndiaAI Safety Institute.
Legal provisions under IT Act, 2000:
• Sections 66C (Punishment for identity theft) deals with misinformation, deepfakes, cheating
by personation or identity theft.
• Section 66D of the IT Act criminalizes the use of computer resources for cheating by
personation.
• Section 66E prescribes the punishment for capturing and publishing or transmitting the image
of a private area of any person without his or her consent.
• Section 67A and 67B make publishing or transmitting obscene material for instance, which
could be generated by using deepfake technology a punishable offence.
Legal provisions under BharatiyaNyay Sanhita, 2023:
• Section 111 of the BNS punishes the commission of any continuing unlawful activity including
economic offence, cyber-crimes, by any person or a group of persons, either as a member of
an organised crime syndicate or on behalf of such syndicate.
• Several other sections under the BNS also deal with cyber-crimes like cheating or cheating by
personation such as sections 318 (Cheating), 319 (cheating by personation), 353 (public
mischief), 356 (defamation).
Digital Personal Data Protection Act, 2023
• It casts obligations on Data Fiduciaries to safeguard digital personal data, holding them
accountable, while also ensuring the rights and duties of Data Principals.
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules,
2021 (“IT Rules, 2021”)
• Central Government after extensive public consultations with relevant stakeholders has
notified the IT Rules, 2021.
• The IT Rules cast specific legal obligations on intermediaries, including social media
intermediaries and platforms expeditiously remove the prohibited misinformation, patently
false information and deepfakes.
• In case of failure of the intermediaries to observe the legal obligations, they are liable for
consequential action or prosecution as provided under the extant laws.
• Under the IT Rules 2021, there is a provisions grievance redressal mechanism by the
intermediaries which inter-alia provides 24 hours of timelines for any grievances relating to
morphed or artificially generated images affecting the victim. If not satisfied with the
grievance redressal, aggrieved persons can approach Grievance Appellate Committee.
• Ministry of Home Affairs has launched a dedicated portal to report cybercrimes
[cybercrime.gov.in] and has also started a toll-free number 1930.
Additional measures to counter deepfakes:• Government of India issues advisories from time to time to intermediaries/platforms for
ensuring compliance on using Artificial Intelligence foundational model(s) /Large Language
Model (LLM)/Generative AI (Artificial Intelligence), software(s) or algorithm(s).
• Unique Identification Authority of India (UIDAI) is also actively addressing the key risks
associated with AI misuse including deepfakes, algorithmic bias, cyber fraud, and misuse of
automated authentication systems.
• The Indian Computer Emergency Response Team (CERT-In) issues alerts and advisories
regarding latest cyber threats/vulnerabilities including malicious attacks using Artificial
Intelligence and countermeasures to protect computers, networks and data on an ongoing
basis.
Government has constituted an Advisory Group on AI for India-specific regulatory AI
framework under the chairmanship of Principal Scientific Advisor (PSA) to Prime Minister. It
has members from diverse stakeholders from academia, industry and government.
*******