CAGE


Written Samriddhi Kapadnis, a 4th year B.B.A. LL.B. student at Symbiosis Law School, Nagpur

INTRODUCTION 

Nowadays, digital evidence plays a crucial role in the investigation of sexual crimes in India. Call records, CCTV images, videos and online communications are often the clinching evidence which either confirms or refutes an allegation. As per the National Crime Records Bureau’s data, in 2023, a total of 86,420 cybercrime cases were reported, which is a 31.2 per cent increase from the year before, reflecting the widespread presence of technology in the commission and investigation of gender-based crime in India.

But as digital evidence becomes a key component of the criminal justice system, a new and more complex danger is quietly undermining trust in this type of evidence: synthetic media. Synthetic media involves generative methods like generative adversarial networks (GANs) and diffusion models, which can create realistic visual content, including images, video, and audio, that never actually happened, often without the typical digital signatures that lie beneath the surface and are the basis for forensic identification. This ability to create “proof” out of thin air throws out an old evidentiary law assumption that a photograph or recording is a true transcript of what actually occurred.

A growing number of actual incidents make the size of the problem evident. A video of actor Rashmika Mandanna was stitched onto another woman’s body with artificial intelligence in November 2023 and spread across social media, which was later traced by the Delhi Police and the creator arrested. About two months later, another set of sexual images, also AI-generated, of Taylor Swift surfaced on X, allegedly gaining about 50 million views prior to its deletion. The incidents highlight that misinformation and fake evidence are not merely privacy or reputation issues but are also a problem of the chain of evidence that is fundamental to criminal prosecutions, especially in sexual violence cases where images and videos are the sole evidence available.

The Indian Evidence Act, 1872, and the Bharatiya Sakshya Adhiniyam, 2023, prior to the recent legislation, presume the existence of a “certifiable original” electronic record, which is evident in Section 65B and Section 63, respectively. In synthetic media, a reliable metadata, a verifiable original and a clear provenance to certify do not exist. This paper interrogates the question of whether the evidentiary and institutional landscape that is evident in India can cope with this rupture, and what is needed to ensure the sanctity and veracity of evidence in sexual-assault prosecutions.

WHY SYNTHETIC MEDIA BREAKS TRADITIONAL DIGITAL EVIDENCE

Synthetic media are images, video, audio or text that are entirely or predominantly generated by artificial intelligence instead of directly captured by humans. The most impactful use of deepfakes is when AI creates or manipulates AV content that looks convincing enough to be interpreted as the person doing or saying it, when it did not actually happen. Modern deepfakes are generally created using Generative Adversarial Networks (GANs), where a generator and a discriminator network are trained against each other until the generator generates something that is convincing enough to trick the discriminator, or diffusion models.

There are several primitives used in traditional digital forensics to establish authenticity of a record: metadata, data about the file itself, including the timestamp, the model of the device it was created on, and, for images, EXIF fields such as GPS location; cryptographic hash functions, such as SHA-256 that serve as a unique fingerprint for the file,  meaning that any alteration to the file changes its hash; and provenance, a documented history of who created, edited and transferred the file, which underpins the requirements for chain-of-custody for admissibility. Some standards try to formalise this, like the Coalition for Content Provenance and Authenticity (C2PA) which places a signed record of the content’s creation and modification history into the content.

Synthetic media interferes with all of these primitives. The whole history of a GAN or diffusion-generated image is the generation process, there is no “original” capture event to which metadata or provenance can be tied to the file. Those detection tools that try to identify forgery by spatial or frequency artefacts are only probabilistic and cannot guarantee a result when evaluated on laboratory datasets, a 2024 study found that detectors trained to spot artefacts from one generation method failed to generalise to images created with different or unseen forgery methods, and a separate, peer-reviewed evaluation showed that accuracy dropped by about 30 per cent when the images were degraded or re-encoded, as content often is after compression.

This issue is exacerbated when content is shared. A 2025 investigation into how well metadata is preserved during transfers turned up that while direct transfers (USB, email, “as a document” etc.) do not alter EXIF data nor file hashes, these two things are stripped from files by WhatsApp, telegram and Instagram, among other platforms, during a compression process on those platforms. Most digital evidence that is sent to the Indian police is in the form forwarded to investigators, and when it does arrive, the very information that is required to prove or disprove its authenticity may be lost. The net effect is a kind of evidentiary uncertainty that is not “has this record been altered,” but “did the event it depicts occur at all. The Indian evidence-based and institutional answer to that question is explored in the next section.

INDIA’S LEGAL AND INSTITUTIONAL FRAMEWORK

The fundamental principle of the evidentiary law relating to electronic records in India has stayed the same from Section 65B of the Indian Evidence Act, 1872 to Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 that is, that the device has created a faithful reproduction of an original. This was made mandatory in Anvar PV v PK Basheer, and reaffirmed as a “condition precedent to the admissibility of evidence by way of electronic record” in Arjun Panditrao Khotkar v Kailash Kushanrao Gorantyal, which overruled a more lenient interim position taken in Shafhi Mohammad v State of Himachal Pradesh. In Tomaso Bruno v State of Uttar Pradesh, earlier the Supreme Court had emphasized that investigation should be in line with the changing times and the evidence was not something the prosecution could simply ignore, where CCTV footage was considered evidence. None of this jurisprudence considers evidence that has not been captured at all: the certification model assumes that a real device captured a real event, and that is what synthetic media is not.

The same is true of India’s cyber and criminal law. The Information Technology Act, 2000 penalises obscene or sexually explicit disclosures and invasion of bodily privacy (5) while Bharatiya Nyaya Sanhita, 2023 criminalises sexual harassment (75), voyeurism (77) and defamation (356) assumes an actual act and an actual person with whom it is happening. It has been noted earlier that there is no reported judgement in India that directly addresses synthetic sexual imagery, though there is a precedent like State of West Bengal v Animesh Boxi, a trial court conviction obtained in 2018 for the uploading of a victim’s own intimate photographs without his consent.

In the beginning of 2026, a significant shift happened in the regulatory environment. In the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, notified on 10th February 2026 and effective from 20th February 2026, MeitY added a specific definition of “synthetically generated information” (SGI) under which platforms must obtain user declarations about the AI-generated content, visibly label it as such, and remove content that is unlawful within 3 hours. This is India’s first specific regulatory response to deepfakes, but it is not about evidentiary law or criminal liability, it’s about what platforms need to do with deepfakes.

The collection of such information also implicates privacy in any investigation related to such content. K.S. Puttaswamy v Union of India declared informational privacy as a fundamental right to life under article 21, subject to legality, necessity and proportionality. The Digital Personal Data Protection Rules, 2025, which have recently been notified and are now to be enforced in phases up to November 2026, introduce statutory obligations of purpose limitation and data minimisation which will impact on the collection, storage and sharing of intimate synthetic evidence in the course of investigation – a live compliance question, rather than a settled one.

CASE STUDIES AND FORENSIC REALITIES

Incidents reported show how these gaps are manifested. A 19-year-old woman in Hyderabad’s Charminar area was blackmailed when someone on Instagram she blocked used AI tools to create a nude photo from her profile picture and threatened to share it, leading to a case being filed under the IT Act and the BNS. A 21-year-old MBA student from Bavdhan in Pune decided to reject a man, whose information she came across through an online game, and was targeted by him, who made 13 fake Instagram profiles in her name and sent her AI-generated nude pictures to her family and friends, and has now been tracked and arrested. In both cases, the offense is being prosecuted under the existing obscenity and harassment laws, as there is no specific statutory definition of the offense for AI-generated sexual imagery in India.

In contrast, New Jersey’s 2025 law provided a specific criminal and civil remedy for deceptive AI-generated media, which provides victims with a statutory right of action, but which is not currently available in India under the BNS or IT Act.

These cases are difficult to construct, even when reported, as described in the forensic literature. They are also highly susceptible to poor performance when the images are created by a different method or a method not seen by the detector, which is the likely scenario in Indian investigations, where evidence is received either as a forwarded image or a manipulated image, and the accuracy of the detector drops by about 30 per cent after compression and re-encoding. This loss is not accidental, but structural, as a 2025 study of metadata integrity found that platforms like WhatsApp, Telegram and Instagram remove EXIF information and change file hashes when transferring files, whereas direct transfers would keep all these data intact. Combined, the two Indian cases and the New Jersey example illustrate the same point made in Section III: existing law allows for testimony to criminalize the harm after it has been discovered, but does not provide a mechanism to establish the synthetic content as evidence.

COMPARATIVE AND REGULATORY UNDERSTANDINGS

Three comparators are useful to the gaps detailed in Sections III and IV. The United Kingdom crime was already covered by the Online Safety Act 2023, which made it an offence and a “priority offence” for platforms to share or threaten to share intimate images, including deepfakes – but a separate law, the Data (Use and Access) Act 2025, was necessary to criminalise the creation or even requesting of a non-consensual intimate image. That creation offence only takes effect from 6 February 2026, after public pressure for regulating AI image generation tools on X, and it does not even need to be shared, or even created successfully—the act of creating it is enough. In the framework of the European Union’s Directive (EU) 2024/1385, Article 5, obliges all member states to make the production and dissemination of “manipulated intimate material” a criminal offense, a definition that includes synthetic sexual imagery as a form of violence against women, not obscenity or defamation. It has to be transposed by the member states until 14 June 2027, which is ongoing. Two federal laws now exist in the United States: the DEFIANCE Act of 2024 which provides a federal civil remedy to anyone who is the subject of a sexually explicit “digital forgery,” and the TAKE IT DOWN Act signed into law on 19 May 2025, which makes it a federal crime to publish non-consensual intimate imagery, including “digital forgeries,” and imposes a 48-hour removal mandate on platforms.

All three have developed their own specific offence relating to the production of non-consensual sexual images, not one based on obscenity or defamation or on platform-intermediary provisions. The last instrument is IT Rules 2026, which governs platforms, labelling and a three-hour takedown period for “synthetically generated information” but doesn’t introduce a new standalone offense and doesn’t impact evidentiary law. The deep fake case in India will have to be filed under IT Act 66E/67/67A, or BNS Act 75/77/356 – which were designed to cover actual images of actual persons. None of the three comparators, however, has developed a ready-made template to address the evidence side of the problem, which is a complete lack of the ability to incorporate provenance into existing rules of evidence in India. As far as that is concerned, India would be constructing without a blueprint.

TOWARDS A REFORM FRAMEWORK

Thus, five coordinated changes are necessary to close the gap, which, in a way, are extensions of the mechanism recognised by India’s law, and not imports from somewhere else.

Provenance-based authentication. The current Section 63 certification only requires that a device was used in its “regular use” and that it made its output correctly. If authenticity is truly in question, courts should ask for a record of how a file came to be the way it is, which the Coalition for Content Provenance and Authenticity already mandates, such as a record of creation, edits and transfers so far, a signed copy of which can be verified apart from the hash itself. An equivalent requirement to platforms to preserve provenance metadata is already in the IT Rules 2026 for synthetically generated information; requiring them to preserve such metadata for evidentiary submissions would simply bring investigative practice into line with the requirements of the IT Rules 2026.

Standardised forensic protocols. The collection, hashing and reporting of digital evidence in India does not have any accredited standard that is similar to ISO/IEC 27037. To adopt it, and to condition admissibility of AI-detection findings on laboratory accreditation against it, would eliminate the current variability in individual laboratories’ practices and provide a level playing field.

Guidance on probabilistic evidence of detection by the courts. As Arjun Panditrao Khotkar did with certification for device-generated evidence, courts must be similarly guided in determining the case of AI-detection findings. Each method of detection is specific and accuracy deteriorates significantly when used against compressed or re-encoded content; it is important for judges to know what detection tools were used and have an idea of their training data, error rate and known limitations so that the output of a detection tool can be treated as one of several corroborating factors.

Expedited preservation. The UK has obligations to remove platforms and the IT Rules 2026 itself has a three hour takedown period, indicating that it is possible to have fast timelines. In India, there is no such preservation order which mandates that platforms preserve original files and metadata until an investigation is completed and, without it, the content would usually be re-encoded or deleted before an FIR was even filed.

Victim privacy safeguards. The proportionality requirement of Puttaswamy and the purpose-limitation requirement of the DPDP Rules should ensure concrete practice of evidence handling which is restricted, the display of evidence in the courtroom, and limiting the number of officials who are able to access intimate synthetic material for forensic examination.

None of these demands ask India to create a new system of evidence, each of them is already in existence and is being extended to a new kind of content that was not envisioned when it was developed.

CONCLUSION

Synthetic media does not just create better fakes, it upends the game, as the Indian evidentiary law assumes that a photograph, video or recording is at least evidence of what was recorded. The BSA’s certification scheme, the BNS’s offences on harassment and defamation and the obscenity provisions of the IT Act were all drafted in a world where the falsity of digital content was more a matter of tampering than origin. From the two Indian cases studied in this paper, it is evident that existing legislation can still be leveraged to prosecute an offender, but the process should be undertaken only after an injury has been inflicted and in the absence of any system in place to certify the disputed content itself. Each of the United Kingdom, the European Union, and the United States has answered by making the creation of non-consensual synthetic sexual imagery a stand-alone offence; even while the IT Rules 2026 start to address the platforms that host these images, they are far from comprehensive of the evidentiary side of the issue, and no other comparator jurisdiction provides any template that is ready for India. The five reforms proposed above are extensions of Indian law and not departures from it: a mechanism for provenance-based authentication, which can be based on the certification logic already in Section 63 of the DPDP Rules; forensic accreditation, which can be modelled on a mechanism that India has not yet adopted, but which has been shown to work in other jurisdictions; a requirement that evidence of detection undergo judicial scrutiny, which would be based on the reasoning that led to the certification requirement for ordinary electronic records; a time requirement for preservation, based on a mechanism that India’s own regulator has recently demonstrated is viable; and privacy protections already required by the Constitution and the DPDP Rules. What is lacking is not the law’s principle, but the will to apply those principles that India has already accepted to evidence that didn’t exist when they were written. For now at least, digital evidence will continue to play a more and more prominent role in sexual assault cases in India, and its role will continue to be uncertain.

Leave a Reply

Discover more from CAGE

Subscribe now to keep reading and get access to the full archive.

Continue reading