What Are the New Rules, Exactly?
India has significantly amended its Information Technology (IT) Rules, introducing some of the world's strictest regulations targeting AI-generated content, officially termed "synthetically generated information" (SGI). The most dramatic change is the takedown
timeline. Social media platforms must now remove unlawful content, including malicious deepfakes, within just three hours of receiving a valid order from the government or a court. This is a massive reduction from the previous 36-hour window. For especially sensitive complaints involving impersonation or non-consensual nudity, the deadline is even shorter—just two hours. Beyond takedowns, the rules mandate that all permissible AI-generated content must be clearly and permanently labeled. Platforms are also required to embed traceable metadata or unique identifiers to help track the content's origin. Failure to comply with these rules could result in companies losing their "safe harbor" protection, which shields them from liability for what users post.
Why Did India Act So Forcefully?
The government's aggressive stance didn't come out of a vacuum. India has been grappling with a surge of malicious deepfakes that have caused significant public and political alarm. High-profile cases involving manipulated videos of famous Indian actors and politicians went viral, sparking widespread outrage and calls for action. These incidents highlighted the potential for AI-generated content to be used for harassment, fraud, and spreading misinformation on a massive scale. The government has framed the new rules as a necessary step to ensure an "open, safe, trusted and accountable cyberspace" for its nearly one billion internet users. Officials have expressed a zero-tolerance policy for content that is provocative, controversial, or threatens national security, putting the onus squarely on platforms to police their networks more effectively.
The Impact on Instagram and Google
For U.S.-based tech giants like Meta (owner of Instagram and Facebook) and Google (owner of YouTube), these rules represent a monumental operational and financial challenge. The three-hour takedown window is particularly daunting, as it requires highly efficient, round-the-clock moderation teams and advanced automated systems that can act with near-immediacy. Digital rights groups have questioned whether such a tight deadline is operationally realistic at the scale these companies operate. Furthermore, the requirement for significant platforms to have users declare AI-generated content, and then use automated tools to verify those declarations, adds another layer of complexity and cost. The Indian government has already begun applying pressure, demanding that Meta revamp its algorithms and submit a detailed compliance roadmap to better detect and limit the spread of harmful content. The potential loss of safe harbor immunity is the biggest threat, as it would expose these companies to direct legal and criminal liability for user-generated content in a critical market.
A Global Precedent or a One-Off?
While other regions are also moving to regulate AI, India's approach is notable for its speed and enforceability. The rules, which went into effect in February 2026, established a working legal framework months ahead of the European Union's AI Act. The U.S. has taken a more targeted approach, primarily focusing on non-consensual intimate deepfakes. India's regulations are far broader, covering any SGI intended to mislead. This aggressive posture could create a ripple effect, inspiring other countries to adopt similar models. Tech companies often prefer to standardize their policies globally rather than create bespoke systems for each country. As a result, the stringent measures being tested in India could eventually influence content policies for users in the U.S. and elsewhere. How Meta, Google, and others adapt to India’s demands will be a closely watched test case for the future of global content moderation in the age of AI.














