On October 6, Prime Minister Narendra Modi told board members of the GSMA, the global mobile-operator body, in Delhi that emerging technologies need "global standards and common rules." He also suggested exploring mechanisms that let users immediately identify the origin of deepfakes and AI-generated content, according to a Press Information Bureau release reported by MediaNama. The goal is sensible. The risk is in one ambiguous word: "origin."
The strongest case for the call
The argument for common rules is serious. Synthetic media crosses borders instantly, and a label that exists in one jurisdiction but is stripped in another protects nobody. Fragmented rules also raise compliance costs, and those costs fall hardest on smaller developers who cannot staff a legal team per market. Interoperable provenance would help users, platforms and honest creators alike. If the aim is a shared technical standard, India has earned a seat at the table.
What India has already done
India is not starting from zero. On February 10, 2026, MeitY notified the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, which came into force on February 20, per Business Today. The rules create a category of "synthetically generated information." Permitted synthetic content must be prominently labelled and carry permanent metadata or provenance markers, including unique identifiers, and platforms may not enable their removal, according to Hogan Lovells.
MediaNama's reading is that the metadata duty applies "to the extent technically feasible" and identifies the platform tool that created or altered the content. That is a meaningful design choice. The identifier points to a computer resource, not to a human being.
The same package also did other things, and the rest of it deserves more scrutiny than the labelling rule:
- Takedown of flagged unlawful content within three hours, down from 36.
- Grievance responses cut from 15 days to 7.
- Significant social media intermediaries, those with more than 5 million registered users in India, must obtain user declarations on whether content is synthetic and verify them.
- In-scope platforms must use automated tools to block prohibited synthetic content.
Where "origin" becomes dangerous
The PIB release does not say whether "origin" means the generating tool or the individual who created or posted the content. Those are very different policies.
Tool-level provenance is a defensible, proportionate measure. It tells a viewer that an image came from a particular generator, much like a watermark. It requires no collection of personal data about the person who typed the prompt. It also fits the open-internet principle that infrastructure should disclose what it did, not whom it served.
Creator-level provenance is another matter. A global mechanism that lets anyone "immediately identify" who made a piece of content would resemble the "first originator" traceability demands that WhatsApp challenged in 2021 over end-to-end encryption. For a satirist, a whistleblower or a dissident in any country, a universal origin tag is a deanonymisation tool. Exported as a global standard, it would hand every government the same capability, including those with far weaker rule-of-law protections than India's.
The limits of metadata
Provenance metadata also has a technical ceiling. Metadata can be stripped by screenshots, re-encoding or hostile tools, and the people who make malicious deepfakes are the least likely to comply. The result is an asymmetry: honest tools label, bad actors do not, and an unlabelled image starts to look authentic by default. A label regime that overpromises can lower public vigilance. Standards work should therefore pair provenance with detection research and media literacy, and should be honest that absence of a label proves nothing.
The three-hour takedown window raises its own concern. A rule that short leaves little room for a platform to assess a borderline satire or political parody before acting, and fast clocks tend to push intermediaries toward over-removal. That is a free-speech cost that a global template should not inherit uncritically.
The global comparison
The EU is on a similar path. Article 50 of the AI Act requires providers to mark outputs "in a machine-readable format" so they are "detectable as artificially generated," and deployers must disclose deepfakes. Those transparency obligations became applicable on August 2, 2026, according to the European Commission. The Commission has paired the law with a voluntary Code of Practice, icons for disclosure and guidelines on exceptions, and the Commission's AI Act framework page says the labelling duty targets deepfakes and public-interest text, not all content. That scoping is a useful model.
The contrast with India is instructive. The EU legislated through a statute with a co-developed voluntary code. India used an amendment to subordinate intermediary rules, with no standalone AI law. Neither approach is wrong, but a global standard drawn from them should borrow the EU's tight scoping and India's tool-level identifiers.
What a good standard looks like
India has a credible claim to lead this discussion, and it should use that position to set boundaries as well as ambitions.
- Define origin as the generating system, not the individual, and say so in writing.
- Keep it technical and voluntary at the standards layer, through interoperable open specifications, with binding duties left to national law.
- Scope narrowly to realistic deepfakes and synthetic media that could deceive, not every edited photo.
- Protect anonymity explicitly, including a bar on using provenance data for creator identification without judicial authorisation.
- Review the evidence on whether labels change behaviour before hardening them.
Modi's framing, "our digital future must expand opportunity while strengthening trust," is the right balance. Trust is built by systems that disclose themselves honestly, not by systems that make speakers identifiable by default. If the Delhi conversation turns into a tool-level provenance standard, it will be a real contribution. If it turns into a person-level traceability mandate, it will become a template for surveillance.