AI Sexual Deepfakes: Platform Accountability and Consent in the Generative-AI Era
Why in News?
The Hindu and NPR reported that an amended proposed class action in the United States now has five pseudonymous plaintiffs, all identified as Jane Does, alleging that generative-AI tools were used to create sexually explicit synthetic images from photographs taken when they were minors. The amended complaint names xAI and Stability AI as defendants.
The case is pending, and its allegations are not judicial findings. It still raises a durable governance question: when a service can both generate and disseminate abusive synthetic content, should responsibility stop with the user, or also extend to model safeguards, platform design, reporting, evidence preservation and rapid victim redress?
- The amended complaint was filed in the Northern District of California and added two plaintiffs to the three teenagers who had sued earlier.
- The plaintiffs allege that ordinary family or school photographs were converted into child sexual abuse material through AI systems without their knowledge or consent.
- One new plaintiff alleges that a photograph taken when she was about 11 years old was used to produce roughly 7,000 abusive images and videos; this number is an allegation in the complaint, not a court-verified finding.
- The suit seeks monetary relief and stronger technical guardrails; it also alleges negligence, defective design and failures connected with reporting suspected abuse.
- The Indian relevance lies in the distinction between a passive host and a platform whose own generative model, editing interface or publishing workflow materially helps create the disputed output.
The development matters in the context of:
- Sexual deepfakes turn identity and bodily privacy into editable inputs even when no genuine intimate photograph ever existed.
- The harm is persistent: deletion from one service does not remove downloaded copies, mirrors, private groups or model-derived variants.
- Women and children face disproportionate targeting, linking the issue to gender justice, child protection and equal participation in digital public spaces.
- India’s response now combines the IT Act, 2000, the amended IT Rules, 2021, sectoral criminal laws, constitutional privacy and the phased DPDP Act, 2023.

UPSC Relevance
Prelims Relevance
- A deepfake is synthetic or altered audio-visual content that realistically depicts a person saying or doing something that did not occur.
- The 2026 IT Rules use the wider term synthetically generated information, or SGI, for realistic algorithmically created or altered audio, visual or audio-visual information.
- Routine good-faith editing, compression, accessibility work and translation that do not materially misrepresent content are excluded from the SGI definition.
- Rule 3(3) requires covered intermediaries to deploy reasonable technical measures against unlawful SGI, including non-consensual intimate imagery and content invasive of bodily privacy.
- Under Rule 3(2)(b), a complaint about nudity, a sexual act, impersonation or an artificially morphed image must trigger reasonable and practicable removal measures within two hours.
- Section 79 of the IT Act offers conditional safe harbour for third-party information; due diligence and the intermediary’s role in initiating, selecting or modifying information matter.
- Section 66E penalises intentional or knowing capture, publication or transmission of an image of a person’s private area without consent in privacy-violating circumstances.
- The substantive consent, lawful-processing and data-principal provisions of the DPDP Act follow an 18-month commencement schedule from 13 November 2025 and were not yet operative on 16 July 2026.
Mains Relevance
GS Paper 2
- Governance: conditional safe harbour, statutory due diligence, transparent grievance systems and accountability for cross-border digital services.
- Social justice: gendered technology-facilitated abuse, child protection, dignity, accessible remedies and the chilling effect on women’s online participation.
GS Paper 3
- Science and technology: generative-model risk, provenance, watermarking, content credentials, age-sensitive safeguards and safety testing before deployment.
- Cyber security: rapid spread, evidence preservation, attribution, coordinated incident response and the limits of detection-only approaches.
Essay
- Innovation without consent can convert human identity into an extractive digital resource.
- The freedom to create synthetic media must be reconciled with dignity, autonomy and equal citizenship.
- Trust in AI depends less on model novelty than on who bears the cost when predictable safeguards fail.
Background and Context
What Makes Sexual Deepfakes a Distinct Harm
A sexual deepfake is not harmless fiction merely because the depicted event never occurred.
- It uses an identifiable person’s face, voice or likeness to fabricate nudity or sexual conduct, creating a false association that audiences may treat as authentic.
- Consent to take or share an ordinary photograph is not consent to sexual alteration, model training, publication or onward circulation.
- The injury combines privacy loss, reputational damage, sexual humiliation, harassment and loss of control over one’s social identity.
- Labelling can help users identify lawful synthetic media, but a label cannot legitimise non-consensual intimate imagery that should not have been generated at all.

Constitutional Foundation: Privacy, Dignity and Autonomy
India’s constitutional framework treats privacy as part of liberty and human dignity, not simply secrecy.
- In Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), a nine-judge Supreme Court bench recognised privacy as a fundamental right protected by Article 21 and other freedoms in Part III.
- The judgment connects privacy with bodily integrity, decisional autonomy, control over personal information and the freedom to shape one’s identity.
- Article 19(1)(a) protects expression, but Article 19(2) permits lawful restrictions linked to decency, morality and defamation; creativity is not a blanket licence for sexual impersonation.
- Fundamental rights primarily discipline the State, yet they guide legislation, proportionality review and judicial development of remedies involving private digital power.
The IT Act: Offences, Safe Harbour and Gaps
The Information Technology Act offers several routes, but no single legacy provision was designed around modern generative models.
- Section 66E addresses non-consensual images of a private area; applying its capture-based wording to a wholly synthetic body may require careful factual and judicial interpretation.
- Sections 67 and 67A address obscene and sexually explicit electronic material, while Section 67B directly addresses sexually explicit material involving children, including digital creation and related conduct.
- Section 79 makes safe harbour conditional on a limited intermediary role, statutory due diligence and timely action after legally recognised knowledge of unlawful material.
- When the service’s own model creates, modifies or publicly posts the output, the claim that it merely hosted third-party information becomes a fact-sensitive legal question.
India's 2026 SGI Due-Diligence Framework
The February 2026 amendments to the IT Rules move platform duties upstream from takedown alone to prevention, provenance and verification.
- Rule 3(3) covers intermediaries enabling the creation, alteration, publication or dissemination of SGI and requires reasonable technical measures to stop unlawful categories.
- The prohibited list expressly includes child sexual exploitative and abuse material, non-consensual intimate imagery, sexually explicit content and material invasive of bodily privacy.
- Permissible SGI must carry a prominent, continuing label and, where technically feasible, permanent metadata or provenance with a unique identifier; platforms must not enable its removal.
- A significant social media intermediary must seek an uploader’s SGI declaration, technically verify it before publication and label confirmed SGI; knowingly permitting or ignoring unlawful SGI can amount to failed due diligence.
Consent and the Phased DPDP Framework
Data protection adds a consent-and-purpose lens, but it should not be overstated as an immediate or complete deepfake remedy.
- An identifiable face photograph and a synthetic image linked to a person can constitute digital personal data because they concern an identifiable individual.
- The DPDP Act, 2023 is built around lawful processing, notice, purpose and consent that is free, specific, informed, unconditional and unambiguous, subject to statutory legitimate uses.
- The Gazette notification of 13 November 2025 phased commencement: institutional provisions began first, while the core processing, consent, fiduciary-duty and data-principal provisions were scheduled after 18 months.
- The Act excludes personal data made publicly available by the Data Principal from its application, and erasure cannot retrieve every downloaded copy; a dedicated NCII remedy remains important.
A Layered Test for Platform Accountability
Responsibility should track control, knowledge, foreseeability and the platform’s contribution to the harmful output.
- At the model layer, examine training-data governance, red-team testing, prompt and image filters, child-safety controls and resistance to repeated bypass attempts.
- At the product layer, examine whether features reward virality, offer sexualised modes, enable one-click editing of real people or publish generated outputs by default.
- At the hosting layer, assess complaint access, the two-hour victim route, hashing and re-upload controls, preservation of evidence and cooperation with lawful investigations.
- At the remedy layer, require accessible appeals, confidentiality, trauma-informed handling and protection against retaliatory doxxing or regeneration of more abusive images.
Way Forward
Build Consent and Safety into Generation
- Block sexual alteration of an identifiable person unless a trustworthy, revocable consent signal is verified; never permit such generation involving a child.
- Use adversarial testing, rate limits and repeat-offender controls, with heightened review for tools that accept face photographs as inputs.
- Measure safety by prevented harms and complaint outcomes, not only by aggregate model accuracy.
Create a Victim-Centred Response
- Offer a simple, multilingual and confidential two-hour complaint channel that accepts reports from victims or authorised representatives.
- Remove matched copies and foreseeable re-uploads while preserving a secure evidentiary record for lawful investigation.
- Provide status updates, escalation to the Grievance Appellate Committee and links to cybercrime and child-protection authorities.
Make Provenance Interoperable
- Adopt durable content credentials, cryptographic provenance and identifiers that survive ordinary compression and cross-platform sharing.
- Treat detection scores as probabilistic signals, not conclusive proof; human review and contestable decisions remain necessary.
- Publish audited transparency data on generation blocks, victim complaints, response times and repeat uploads without exposing victims.
Close Legal and Institutional Gaps
- Clarify a technology-neutral offence and civil remedy for creating or sharing non-consensual intimate imagery, including synthetic material.
- Separate liability for the perpetrator from duties of the model provider and host, with proportionate standards based on control and foreseeable risk.
- Strengthen cross-border cooperation, police capacity, forensic preservation and privacy-protective court procedures for pseudonymous victims.
Conclusion
AI sexual deepfakes show why consent must govern uses of identity, not just collection of a photograph. The deepest harm is the forced attachment of fabricated sexual conduct to a real person’s body, name and social life.
India’s 2026 SGI rules create a stronger operational baseline through prevention, rapid removal, labels and platform verification. Effective accountability still needs precise offences, fair safe-harbour boundaries, evidence-preserving enforcement and remedies designed around dignity rather than mere content deletion.
UPSC Practice Questions
Prelims MCQ 1
With reference to India’s framework for synthetically generated information, consider the following statements:
- The amended IT Rules define SGI with reference to realistic audio, visual or audio-visual information created or altered using a computer resource.
- A complaint concerning nudity, sexual conduct, impersonation or an artificially morphed image must be acted upon within two hours under Rule 3(2)(b).
- Every form of synthetically generated information is prohibited from publication in India.
How many of the above statements are correct?
(a) Only one (b) Only two (c) All three (d) None
Answer: (b) Only two
Explanation:
Statements 1 and 2 are correct. Permissible SGI is not banned; it is subject to prominent labelling and provenance duties. Unlawful categories, including non-consensual intimate imagery and child sexual exploitative material, must be prevented.
Prelims MCQ 2
Which one of the following best describes Section 79 safe harbour under the Information Technology Act, 2000?
(a) Absolute immunity for every output created or hosted by a digital service (b) Conditional protection for third-party information when the intermediary has a limited role and observes due diligence (c) A constitutional right of social media companies to disregard removal orders (d) A rule applicable only to government-owned digital platforms
Answer: (b) Conditional protection for third-party information when the intermediary has a limited role and observes due diligence
Explanation:
Section 79 is conditional. The intermediary’s functional role, compliance with due diligence and response to legally recognised knowledge matter; active creation or modification by a platform can complicate the third-party-information claim.
UPSC Mains Questions
- Non-consensual sexual deepfakes are simultaneously a privacy violation, a gender-justice concern and a platform-governance failure. Examine how India’s constitutional principles, Information Technology Act and 2026 SGI rules can be combined into a victim-centred accountability framework. (250 words)
- Conditional safe harbour was designed for intermediaries handling third-party information. Discuss the challenges of applying this principle when a platform’s own generative model creates, modifies and disseminates harmful synthetic content. Suggest a control-and-risk-based test for liability. (250 words)
- Technical labels can disclose that media is synthetic, but they cannot supply consent or cure abusive generation. Evaluate the relative roles of prevention-by-design, provenance, rapid takedown, criminal law and data protection in addressing AI-enabled intimate-image abuse. (250 words)
Sources: MeitY, Information Technology Rules updated in 2026 and The Hindu Explained, NPR and Associated Press.
Frequently Asked Questions
What is a sexual deepfake?
A sexual deepfake is realistic synthetic or altered media that falsely depicts an identifiable person nude or engaged in sexual conduct. It may use the person’s face, voice or ordinary photograph. The depicted event need not have occurred for the fabrication to violate dignity, privacy and consent.
Does photo consent permit synthetic sexualisation?
No. Consent is purpose-specific. Agreeing to be photographed, posting an ordinary picture or sharing it with someone does not itself authorise sexual alteration, AI generation or public distribution. Indian privacy doctrine protects autonomy and bodily integrity, while applicable statutes may create separate criminal and platform duties.
What do India’s 2026 IT Rules require?
Covered intermediaries must use reasonable technical measures against unlawful SGI, including non-consensual intimate imagery and child sexual exploitative material. Permissible SGI needs prominent labelling and provenance. Victim complaints about nudity, sexual acts, impersonation or artificially morphed images require reasonable removal measures within two hours.
Does Section 79 automatically protect AI platforms?
No. Section 79 protects qualifying intermediaries for third-party information only when statutory conditions and due diligence are met. If a platform’s model creates or materially modifies the disputed output, or the service ignores duties after lawful knowledge, the availability of safe harbour becomes fact-sensitive rather than automatic.
Can the DPDP Act address deepfake abuse?
It can add a personal-data, purpose and consent lens when identifiable photographs or outputs are processed. But core DPDP processing duties were still awaiting phased commencement in July 2026, publicly available data may fall outside scope, and erasure cannot recover every copied file. It is not a complete NCII remedy.
What should a victim do first?
Preserve URLs, timestamps and non-graphic proof without repeatedly downloading or forwarding abusive files. Use the platform’s victim grievance channel, report the material through India’s cybercrime mechanisms, and contact police or child-protection authorities where a minor is involved. Seek trusted legal and psychosocial support while limiting further exposure.