India IT rules India

Estonia Labels Deepfakes With a Symbol; India Labels Them With a Deadline

As the EU's Article 50 takes effect with a standardized AI icon, India's parallel deepfake rules lean on a 3-hour takedown clock instead.

Two Deepfake Regimes, One Deadline Window People of Internet Research · India Aug 2, 2026 EU Article 50 takes effect Deepfake and AI-interaction disclo… Dec 2, 2026 GenAI marking grace period ends Generative AI systems already on t… 3 hours India flagged-content takedown Platforms must remove flagged AI-g… ~5M users India SSMI user threshold Continuous on-screen labelling dut… peopleofinternet.com
Two Deepfake Regimes, One Deadline Win… People of Internet Research · India Aug 2, 2026 EU Article 50 takes effect Dec 2, 2026 GenAI marking grace period ends 3 hours India flagged-content … ~5M users India SSMI user threshold peopleofinternet.com

Key Takeaways

Two Deadlines, Two Theories of Transparency

On August 2, 2026, Article 50 of the EU AI Act became enforceable across all 27 member states, requiring that deepfakes be "clearly and distinguishably" disclosed and that people be told when they are talking to a chatbot. Estonia is now writing the domestic scaffolding around that duty — designating the Consumer Protection and Technical Regulatory Authority (TTJA) as the national enforcer, fixing penalty provisions, and adopting the standardized visual icon set the European Commission published under its voluntary Code of Practice on Transparency of AI-Generated Content, replacing the patchwork of platform-specific "AI-generated" badges that previously stood in for a legal requirement.

India took a parallel road to the same destination five months earlier, and it looks almost nothing like Estonia's. On February 10, 2026, the Ministry of Electronics and Information Technology notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, bringing "synthetically generated information" into the IT Rules framework effective February 20. Rather than a labelling duty owed by the AI system's provider, India built a liability trap for the distributor: platforms must remove flagged deepfake or AI-generated content within three hours, cannot allow removal or suppression of labels or metadata once applied, and — for significant social media intermediaries with more than roughly five million registered Indian users — must display persistent, continuous on-screen labels for the full duration of synthetic content, not a one-time watermark.

Same Goal, Opposite Lever

The EU's model regulates the speaker. A provider or deployer of a generative AI system has to mark its own output — machine-readably by default, visibly for deepfakes and unreviewed public-interest text — and national market-surveillance bodies like Estonia's TTJA police that duty directly, with fines that scale to global turnover for the AI Act's more serious violation tiers.

India's model regulates the pipe. Intermediaries keep their Section 79 safe harbor only if they meet the new due-diligence bar: detect synthetic content, force user declarations, label continuously, and pull flagged material inside a compressed clock. The obligation to disclose AI-generated content still exists, but it is enforced through the threat of losing legal immunity and facing civil or criminal exposure for third-party content — not through a regulator fining a chatbot maker directly.

The Case for India's Speed

There is a real argument for the sharper edge. Non-consensual deepfakes — face-swapped intimate imagery, cloned political speech dropped hours before a state election, fabricated bank-fraud voice calls — do their damage in the window before any regulator can act, and a platform-side takedown clock reaches content the moment it starts spreading, regardless of who made the underlying model or where they're incorporated. Given the scale of India's user base and the documented virality of prior deepfake incidents involving film actors and politicians, a mechanism aimed at distribution speed rather than upstream disclosure is not an unreasonable design choice, and MeitY's amendment does track a genuine harm.

Where the Design Breaks Down

But a three-hour clock triggered by a flag — without a judicial order, and without a mandatory counter-notice window before removal — inverts the burden that due process usually assigns to speech restrictions. The EU's approach exempts AI-generated public-interest text from labelling entirely once it passes genuine human editorial review with a named person taking responsibility, and it carves out artistic, satirical, and cinematographic works from the visible-label requirement, so long as the AI role is disclosed in a way that doesn't puncture the work itself. India's amendment draws its labelling carve-outs more narrowly — OTT platforms, advertisers, and news publishers escape the continuous on-screen label — but the broader three-hour removal duty and the loss-of-safe-harbor threat apply to a wider swath of synthetic content without an equivalent editorial-review or satire exemption built into the takedown clock itself. That asymmetry is where proportionality gets lost: the EU calibrates the transparency duty to the harm (deepfakes and unreviewed public-interest claims get the strict rule; journalism and art get breathing room), while India applies its most aggressive enforcement tool — the shortened clock — uniformly across flagged synthetic content.

What Should Travel

Estonia's contribution is worth borrowing regardless of jurisdiction: a single, recognizable icon set and a machine-readable baseline mean a deepfake labelled in Tallinn looks the same as one labelled in Lisbon, which is the kind of interoperability India's platform-by-platform labelling mandate doesn't produce — X's "Made with AI" badge, WhatsApp's forwarded-content tags, and whatever a smaller Indian app builds to satisfy MeitY's rules will keep looking different from each other. India doesn't need to copy the EU's enforcement architecture, which brings its own fragmentation problems since deepfakes don't respect borders any better than Cloudflare-blocked GitHub repositories do. But it should copy the EU's proportionality logic: match the enforcement lever to the harm, protect a defined space for satire, art, and edited journalism from the fastest clocks, and give a platform something closer to a chance to verify a flag before its safe harbor — and a user's speech — disappears in three hours.

Sources & Citations

  1. European Commission — Article 50 FAQ
  2. European Commission — Code of Practice on AI-Generated Content
  3. News on Air (Prasar Bharati) — 3-hour deepfake takedown rule
  4. S.S. Rana & Co. — IT Amendment Rules 2026 notified
  5. Euronews — EU deepfake labelling rules
  6. EU AI Act Explorer — Article 50 transparency rules