A Problem Too Big to Ignore
India's digital economy is booming, but so is digital crime. From fraudulent UPI requests and e-commerce scams to sophisticated impersonation schemes using AI-generated deepfakes, the scale of the problem has become a national concern. Recent amendments
to India's IT Rules, which came into force in February 2026, explicitly target the misuse of “Synthetically Generated Information” (SGI) due to the rising threat of misinformation and financial fraud. The government has cited the weaponization of these technologies to damage reputations, manipulate public opinion, and commit financial fraud as a key driver for the new regulations. This surge in cybercrime has put immense pressure on authorities to move beyond simply chasing criminals and instead dismantle the ecosystem that allows them to thrive.
Shifting From Reactive to Proactive
The government's new stance represents a fundamental shift in regulatory thinking. For years, the onus was on users to be vigilant and on law enforcement to react after a crime was committed. Now, the responsibility is being placed squarely on the shoulders of the intermediaries—the tech platforms where these frauds originate and spread. Under amendments to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, platforms are being asked to do more than just take down fraudulent content after it is reported. They are now expected to deploy technical and operational controls to proactively prevent unlawful content, including deepfakes and other fraudulent material, from being hosted or shared in the first place. This marks a move towards a co-regulatory model where platforms become the first line of defence.
What 'Preventive Duties' Mean in Practice
These new preventive duties are not just abstract principles; they come with concrete technical and operational expectations. For telecom operators, new rules mandate the use of AI and big data analytics to detect and prevent fraud. For social media and other platforms, the IT Rules amendments require several key actions. They must implement prominent labelling for all AI-generated content and embed permanent metadata to trace its origin. Timelines for taking down malicious content have been drastically shortened, from 36 hours down to just three hours for government orders and even faster for sensitive material like non-consensual intimate imagery. Platforms are also required to educate users quarterly about these rules and what constitutes unlawful content. This creates a framework of accountability designed to make it much harder for fraudsters to operate anonymously.
The Ripple Effect Across Industries
The impact of these regulations is being felt across the entire digital ecosystem. Telecom companies face stricter rules for issuing SIM cards and are barred from transferring user data outside India under new authorisations. E-commerce platforms are under pressure to implement stronger verification processes for sellers to curb fraudulent listings. Fintech companies and banks are continuously updating security protocols, with the RBI also refining its compensation rules for victims of digital fraud. Significant social media intermediaries must now obtain user declarations about synthetic content and deploy their own verification measures. The underlying message is clear: any platform that can be used as a vehicle for fraud will be expected to build and maintain its own guardrails.
Balancing Security and Innovation
While the goal of a safer internet is universally welcomed, the tech industry has raised valid concerns about the implementation of these new duties. There are significant costs and technical challenges associated with deploying advanced AI for fraud detection and building immutable metadata systems. Startups, in particular, may struggle to meet the same compliance standards as larger corporations. Industry bodies have cautioned against a one-size-fits-all approach, arguing it could stifle innovation and increase friction for genuine users. There's also the complex issue of data privacy; while the Digital Personal Data Protection (DPDP) Act of 2023 provides a framework, new duties like disclosing the identity of rule violators to complainants create a new dynamic between accountability and user anonymity.













