India digital gender-based violence

Janhvi Kapoor Deepfake Case Shows India's Two-Hour Takedown Rule Cannot Substitute for a Criminal Offence

The Chuttamalle deepfake tests whether India's 2026 IT Rules, built around fast takedowns, can protect victims when no law targets the people who make the content.

India's Deepfake Takedown Rules at a Glance People of Internet Research · India 2 hours NCII takedown deadline Rule 3(2)(b) deadline for sexual a… 3 hours Court-flagged content deadline Down from 36 hours under Rule 3(1)… 5,000+ Webpages removed, Delhi HC Order of August 11, 2026 on Janhvi… peopleofinternet.com
India's Deepfake Takedown Rules at a G… People of Internet Research · India 2 hours NCII takedown deadline 3 hours Court-flagged content deadline 5,000+ Webpages removed, Delhi HC peopleofinternet.com

Key Takeaways

On October 4, 2026, actress Janhvi Kapoor condemned a sexually explicit AI video built from footage of the 'Chuttamalle' song from Devara, calling it 'bordering on sexual assault'. Co-star Jr NTR said on October 3 that he would pursue legal action, and other actors amplified the call. As of October 5, no FIR or arrest had been confirmed.

The case is a useful stress test. India has built its response to synthetic sexual abuse around platform takedown speed. The harder question is whether that is enough when the person who made the video faces no clear offence of their own.

The strongest case for the new rules

The case for aggressive takedown deadlines is serious and should be stated fairly. Non-consensual intimate imagery does most of its damage in the first hours, when it is copied, mirrored and re-uploaded. A remedy that arrives after 36 hours, or after a court hearing, arrives after the harm is largely done. Faster removal is the one intervention that directly limits spread.

That is the logic of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, notified by MeitY on February 10 as G.S.R. 120(E) and in force since February 20. According to S.S. Rana's summary, Rule 3(2)(b) requires removal within two hours for content showing nudity or a sexual act, impersonation, morphed images or deepfake sexual content. Court-ordered or officer-flagged content under Rule 3(1)(d) must come down within three hours, down from 36.

The rules also introduce 'synthetically generated information'. MediaNama's reporting notes that permitted synthetic content must be prominently labelled, with metadata embedded where technically feasible. Large social media intermediaries must ask users to declare synthetic content and verify those declarations. The government's PIB release explicitly lists non-consensual intimate imagery among the harms covered.

What the Kapoor case exposes

The takedown regime acts on a complaint. It does not identify, charge or deter the person who produced the file. Within a few days of the Chuttamalle video circulating, the visible responses were public condemnation and an announced intention to litigate. No criminal process was confirmed. India has no standalone offence for creating a deepfake. Prosecutors must stretch older provisions, such as the obscenity sections of the IT Act or the Bharatiya Nyaya Sanhita, over content that is wholly fabricated. Nothing in the 2026 rules changes that.

There is also a record that points to the limits of the court route. On August 11, 2026, the Delhi High Court ordered removal of more than 5,000 webpages carrying AI-generated pornographic and impersonating content targeting Kapoor. According to the OECD AI Incidents summary, the court declined a blanket ban on fan pages. That was the right call, but the episode shows how a victim with resources and counsel needs a High Court order to clear thousands of links. Most women targeted by deepfakes have neither. The same summary also shows that the same actress was targeted again within two months.

The free-speech cost of speed

There is a real tension here, and a pro-speech publication should name it. The Internet Freedom Foundation argues that the timelines leave no room for human review and push platforms toward automated over-removal. It also warns that the broad definition of unlawful synthetic content could capture satire and political commentary involving public figures, and that the rules allow disclosure of user identity to authorities without a prior judicial order.

Those objections apply with different force to different parts of the rules. A two-hour deadline for sexually explicit, non-consensual material is narrow and low-risk for speech: there is no legitimate expressive interest in a fabricated sex video of a real person. A three-hour deadline triggered by a 'reasoned intimation' from an officer, covering the full range of unlawful content, is a different matter. It invites over-removal of lawful speech, and nothing in the case here justifies it.

A more proportionate design

The evidence from this case supports three changes, none of which requires expanding platform liability.

The point is not that the February rules were mistaken. Rapid removal of intimate imagery is justified and proportionate. The mistake would be to treat it as the whole answer. A takedown cleans up one copy on one platform. Deterrence needs a law that reaches the person who made the video, and India does not yet have one.

What to watch

If an FIR is registered, the sections invoked will show how prosecutors handle fabricated content under existing law. If none is, the Chuttamalle case will become one more example of fast takedowns sitting alongside slow accountability.

Sources & Citations

  1. Hogan Lovells: India's IT Amendment Rules 2026 – AI labelling and 3-hour takedown
  2. IANS: Government strengthens framework to curb AI-generated deepfakes
  3. MediaNama: MeitY amendments on synthetic media
  4. Internet Freedom Foundation: IT Rules 2026 analysis
  5. S.S. Rana: Government Notifies IT Amendment Rules 2026
  6. OECD AI Incidents: Delhi High Court order on Janhvi Kapoor deepfakes