TwinEthos homeRequest access

Law

India IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (synthetically generated information)

Ministry of Electronics and Information Technology (MeitY), Government of India · India (IN) · 3 provisions encoded · verified against the official source as of 2026-10-02.

Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.

Official text: egazette.gov.in, www.meity.gov.in.

Trust and provenance 3 official sources · last verified 3 Oct 2026 · not reviewed by a lawyer · 3 of 3 provisions audit-grade · release 2026.10.03.3

Where this instrument's data comes from, how current it is, and what has and has not been checked. Each provision below has its own panel.

Official sources
Lanes
Binding law — in force 3
Verification
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 3 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 3.
Audit standard
3 of 3 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
5 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
  • 2026.10.03.3 (3 Oct 2026): 3 provisions added

Each data release records which provisions changed; the full list is on Changes.

Binding law — in force

Large social platforms must collect a synthetic-content declaration, verify it and label synthetic content before publication (India IT Rules 2026)

IT Rules, 2021, rule 4(1A) (significant social media intermediaries: user declaration, technical verification and label before publication), inserted by G.S.R. 120(E) · official text · In force: applies since 20 Feb 2026 · India (IN)

Since 2026-02-20, a significant social media intermediary (a social media intermediary with more than fifty lakh, that is five million, registered users in India) that enables displaying, uploading or publishing information must, before display, upload or publication, require users to declare whether the information is synthetically generated, deploy appropriate technical measures, including automated tools, to verify the accuracy of the declaration having regard to the nature, format and source of the information, and, where the declaration or verification confirms it is synthetic, ensure it is clearly and prominently displayed with an appropriate label or notice (rule 4(1A) of the IT Rules, 2021, inserted by G.S.R. 120(E)). An intermediary that knowingly permits, promotes or fails to act on synthetic content in contravention is deemed to have failed its due diligence, and its responsibility extends to reasonable and proportionate technical measures to verify user declarations and to ensure no synthetic content is published without a declaration or label (proviso and Explanation). Detect an upload or publish handler with no synthetic-content declaration, verification or label step.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 20 Feb 2026
Official source
IT Rules, 2021, rule 4(1A) (significant social media intermediaries: user declaration, technical verification and label before publication), inserted by G.S.R. 120(E) · captured 2 Oct 2026 · anchor hash (SHA-256) 3e4c1c7e10c2… · 8 more anchors in the data release
Verification
Quoted text found word for word in the live official text by the weekly watcher (2 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

2 detectors (code pattern, data flow), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Declaration collected by a mobile client outside the repository
  • Verification run by a separate classification service
  • Applies only to significant social media intermediaries (over fifty lakh registered users in India); the declaration may be collected in a separate form component.

Who it applies to

  • Duty falls on: operator
  • Significant social media intermediaries (social media intermediaries primarily or solely enabling online interaction between users, rule 2(1)(w), above fifty lakh registered users in India) that let users display, upload or publish information, from 2026-02-20. What verification is 'appropriate' for each format, and whether the duty covers every upload or only audio-visual content, are for counsel (review flag). The Rules bind intermediaries offering their services to users in India; whether they reach an intermediary with no presence in India depends on the IT Act (ss. 1(2), 75), which is not captured (review flag).
  • Not covered:
    • Routine or good-faith editing, formatting, enhancement, technical correction, colour adjustment, noise reduction, transcription or compression that does not materially alter, distort or misrepresent the substance, context or meaning (rule 2(1)(wa) proviso (a))
    • Routine or good-faith creation, preparation, formatting, presentation or design of documents, presentations, PDF files, educational or training materials or research outputs, including illustrative, hypothetical, draft, template-based or conceptual content, that does not create a false document or false electronic record (proviso (b))
    • Use of computer resources solely to improve accessibility, clarity, quality, translation, description, searchability or discoverability without generating, altering or manipulating any material part of the information (proviso (c))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Read embedded C2PA provenance on upload, preserve it through media processing, and show users a Content Credentials indicator with a way to inspect the data.

In the upload or ingest handler, read embedded provenance (c2pa.Reader, c2pa-node, @contentauth/c2pa-web, or a c2patool report) and store the result with the media record: whether credentials are present, the generating system or capture device, and signature validity. Transcoding and thumbnail steps do not strip metadata (no -strip, exiftool -all=, -map_metadata -1, piexif.remove); the signed original is kept so its manifest stays inspectable. The post or media render component shows a badge stating whether provenance is available and what it says, with an inspect panel or link to the full provenance data.

Where it goes: 9 AI output handling, 1 application source code, 14 user-facing text.

What this provision adds:

  • Before an upload is displayed, ask the user to declare whether it is synthetically generated, check the declaration with technical means suited to the format and source, and label confirmed synthetic content clearly and prominently (rule 4(1A)(a)-(c)).

Example (FastAPI + c2pa-python), before:

@app.post('/upload')
async def upload(file: UploadFile):
    data = await file.read()
    s3.put_object(Bucket=PUBLIC_BUCKET, Key=file.filename, Body=data)

After:

@app.post('/upload')
async def upload(file: UploadFile):
    data = await file.read()
    try:
        reader = c2pa.Reader(file.content_type, io.BytesIO(data))
        provenance = json.loads(reader.json())
    except Exception:   # no manifest or unreadable
        provenance = None
    key = f'media/{uuid.uuid4()}'
    s3.put_object(Bucket=PUBLIC_BUCKET, Key=key, Body=data)   # original bytes, manifest intact
    db.media.insert(key=key, provenance=provenance, has_credentials=provenance is not None)

Control: Large online platform doesn't detect/display content provenance. The same guard addresses 3 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.

Rule id in-it-rules-sgi.ssmi-synthetic-declaration-verification-label · review status: primary source derived

Binding law — in force

Synthetic audio, images and video from a generation tool must carry a prominent label and permanent metadata with a unique identifier (India IT Rules 2026)

IT Rules, 2021, rule 3(3)(a)(ii) (prominent label or prefixed audio disclosure; permanent metadata and unique identifier), inserted by G.S.R. 120(E) · official text · In force: applies since 20 Feb 2026 · India (IN)

Since 2026-02-20, an intermediary that offers a computer resource which may enable, permit or facilitate the creation, generation, modification or alteration of synthetically generated information must ensure that every such information that is not unlawful (rule 3(3)(a)(i)) is prominently labelled so that the label is easily noticeable and adequately perceivable in the visual display, or, for audio, through a prominently prefixed audio disclosure, so that it can be immediately identified as synthetically generated; and that it is embedded with permanent metadata or other appropriate technical provenance mechanisms, to the extent technically feasible, including a unique identifier that identifies the intermediary's computer resource used to create, generate, modify or alter it (rule 3(3)(a)(ii) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, inserted by G.S.R. 120(E)). The intermediary must not enable the modification, suppression or removal of the label or the permanent metadata, including the unique identifier (rule 3(3)(b)). Synthetically generated information is audio, visual or audio-visual information artificially or algorithmically created, generated, modified or altered so that it appears real and depicts an individual or event as indistinguishable from a natural person or real-world event, excluding routine good-faith editing, document or presentation preparation, and accessibility or translation uses (rule 2(1)(wa)). Detect generated media with no visible label, no provenance metadata, or code that strips the label or metadata.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 20 Feb 2026
Official source
IT Rules, 2021, rule 3(3)(a)(ii) (prominent label or prefixed audio disclosure; permanent metadata and unique identifier), inserted by G.S.R. 120(E) · captured 2 Oct 2026 · anchor hash (SHA-256) 0e21cbe19051… · 7 more anchors in the data release
Verification
Quoted text found word for word in the live official text by the weekly watcher (2 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

2 detectors (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Labels added by the front end
  • A metadata write does not prove it names the intermediary's computer resource
  • Labels and metadata may be applied by a shared post-processing module; confirm the download, share and publish paths carry both. Routine editing and accessibility uses are not synthetically generated information (rule 2…

2 more known limits in the data release.

Who it applies to

  • Duty falls on: provider
  • Intermediaries that offer users in India a computer resource able to create, generate, modify or alter synthetically generated information, from 2026-02-20. Whether a generative AI service that produces content at its users' request is an 'intermediary' under IT Act s. 2(1)(w), what is 'technically feasible' for permanent metadata, and how prominent a label must be, are for counsel (review flag). The Rules bind intermediaries offering their services to users in India; whether they reach an intermediary with no presence in India depends on the IT Act (ss. 1(2), 75), which is not captured (review flag).
  • Not covered:
    • Routine or good-faith editing, formatting, enhancement, technical correction, colour adjustment, noise reduction, transcription or compression that does not materially alter, distort or misrepresent the substance, context or meaning (rule 2(1)(wa) proviso (a))
    • Routine or good-faith creation, preparation, formatting, presentation or design of documents, presentations, PDF files, educational or training materials or research outputs, including illustrative, hypothetical, draft, template-based or conceptual content, that does not create a false document or false electronic record (proviso (b))
    • Use of computer resources solely to improve accessibility, clarity, quality, translation, description, searchability or discoverability without generating, altering or manipulating any material part of the information (proviso (c))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Add both a visible AI-generated label and implicit metadata naming the provider and a content ID to synthetic content before the file is saved, returned, or exported.

A labeling step between the generator call and every save, return, or download path does two things: it adds an explicit label users can perceive (text drawn onto images or video frames, an audible notice in audio, a label beside generated text in the UI), and it writes implicit metadata into the file (a PNG text chunk, XMP block, or C2PA manifest) carrying the AI-generated attribute, the provider's name or code, and a unique content ID. Export and download routes go through the same step so files leave with both labels; a digital watermark can complement the metadata.

Where it goes: 9 AI output handling, 1 application source code.

What this provision adds:

  • Make the label easily noticeable in the visual display, or put a prominent audio disclosure before audio content, so it can be identified immediately as synthetically generated (rule 3(3)(a)(ii)).
  • Embed permanent metadata or another provenance mechanism, as far as technically feasible, with a unique identifier of the computer resource that made it, and never let users edit, hide or remove label or metadata (rule 3(3)(a)(ii), (b)).

Example (OpenAI Images + Pillow), before:

b64 = client.images.generate(model='gpt-image-1', prompt=prompt).data[0].b64_json
img = Image.open(io.BytesIO(base64.b64decode(b64)))
img.save(path)

After:

b64 = client.images.generate(model='gpt-image-1', prompt=prompt).data[0].b64_json
img = Image.open(io.BytesIO(base64.b64decode(b64))).convert('RGB')
font = ImageFont.truetype('NotoSansCJK-Regular.ttc', 24)
ImageDraw.Draw(img).text((12, img.height - 36), 'AI生成 / AI-generated', fill=(255, 255, 255), font=font)
meta = PngInfo()
# implicit label: AI-generated attribute, provider name or code, content reference (Art. 5);
# take the exact metadata field names from the national standard GB 45438-2025 (not encoded here)
meta.add_text('ai_generated_label', json.dumps({'ai_generated': True, 'provider': PROVIDER_CODE,
                                                'content_id': str(uuid.uuid4())}))
img.save(path, format='PNG', pnginfo=meta)

Control: GenAI content lacking explicit and implicit labels. The same guard addresses 4 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.

Rule id in-it-rules-sgi.synthetic-content-label-and-provenance · review status: primary source derived

Binding law — in force

Generation tools must deploy technical measures that stop users creating unlawful synthetic content (India IT Rules 2026)

IT Rules, 2021, rule 3(3)(a)(i) (due diligence in relation to synthetically generated information: no unlawful synthetic content), inserted by G.S.R. 120(E) · official text · In force: applies since 20 Feb 2026 · India (IN)

Since 2026-02-20, an intermediary that offers a computer resource which may enable, permit or facilitate the creation, generation, modification or alteration of synthetically generated information must deploy reasonable and appropriate technical measures, including automated tools or other suitable mechanisms, so that no user can create, generate, modify, alter, publish, transmit, share or disseminate synthetically generated information that violates any law in force, including content that contains child sexual exploitative and abuse material or non-consensual intimate imagery, or is obscene, pornographic, paedophilic, invasive of privacy including bodily privacy, vulgar, indecent or sexually explicit; that creates a false document or false electronic record; that relates to preparing, developing or procuring explosives, arms or ammunition; or that falsely depicts a natural person or real-world event by misrepresenting, in a way likely to deceive, the person's identity, voice, conduct, action or statement, or the event as having occurred (rule 3(3)(a)(i) of the IT Rules, 2021, inserted by G.S.R. 120(E)). This is a prevention duty at generation time, separate from the removal duties the Rules also set (not encoded). Detect a generation path with no input or output safety filter, or with the model's own safety checker switched off.

Trust and provenance not reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 20 Feb 2026
Official source
IT Rules, 2021, rule 3(3)(a)(i) (due diligence in relation to synthetically generated information: no unlawful synthetic content), inserted by G.S.R. 120(E) · captured 2 Oct 2026 · anchor hash (SHA-256) 28a192b3b93b… · 5 more anchors in the data release
Verification
Quoted text found word for word in the live official text by the weekly watcher (2 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors

1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.

Known limits:

  • Moderation configured in a cloud console or API gateway outside the repository
  • The filter may run in a gateway or a shared moderation module, and hosted models apply provider-side filters; confirm what screens prompts and outputs before reporting.

Who it applies to

  • Duty falls on: provider
  • Intermediaries that offer users in India a computer resource able to create or alter synthetically generated information, from 2026-02-20. What measures are 'reasonable and appropriate', and whether a generative AI service is an 'intermediary' (IT Act s. 2(1)(w)), are for counsel (review flag). The Rules bind intermediaries offering their services to users in India; whether they reach an intermediary with no presence in India depends on the IT Act (ss. 1(2), 75), which is not captured (review flag).
  • Not covered:
    • Routine or good-faith editing, formatting, enhancement, technical correction, colour adjustment, noise reduction, transcription or compression that does not materially alter, distort or misrepresent the substance, context or meaning (rule 2(1)(wa) proviso (a))
    • Routine or good-faith creation, preparation, formatting, presentation or design of documents, presentations, PDF files, educational or training materials or research outputs, including illustrative, hypothetical, draft, template-based or conceptual content, that does not create a false document or false electronic record (proviso (b))
    • Use of computer resources solely to improve accessibility, clarity, quality, translation, description, searchability or discoverability without generating, altering or manipulating any material part of the information (proviso (c))
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Screen user input and model output with a moderation or safety-classifier call that blocks, redacts, or escalates flagged content, and keep provider safety filters on.

In the request handler or model wrapper, user input is checked before the model call and generated output before it is returned or stored, using a moderation endpoint (OpenAI client.moderations.create), a safety classifier (Llama Guard, Azure AI Content Safety ContentSafetyClient.analyze_text), or a guardrail layer (Bedrock apply_guardrail or guardrailConfig, OpenAI Agents SDK input_guardrails and output_guardrails, NeMo Guardrails). A flagged result returns a safe fallback, redacts, or routes to review; the categories checked match what the product can foreseeably produce (self-harm, violence, sexual content involving minors, hate). Provider settings keep their blocking thresholds (no BLOCK_NONE or OFF in Gemini safety_settings) and image pipelines keep their safety checker (no safety_checker=None in diffusers). A filter error or timeout blocks the output rather than passing it.

Where it goes: 9 AI output handling, 1 application source code, 8 model configuration.

What this provision adds:

  • Screen prompts and outputs for child sexual abuse material, non-consensual intimate imagery, false documents, weapons and explosives, and deceptive depictions of real people or events before content is produced or shared (rule 3(3)(a)(i)).

Example (OpenAI Python SDK), before:

resp = client.chat.completions.create(model=MODEL, messages=history)
return resp.choices[0].message.content

After:

resp = client.chat.completions.create(model=MODEL, messages=history)
text = resp.choices[0].message.content
mod = client.moderations.create(model='omni-moderation-latest', input=text)
if mod.results[0].flagged:
    return SAFE_FALLBACK   # and record the flagged categories for review
return text

Control: Generated content reaches users with no input or output content filter. The same guard addresses 2 items with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id in-it-rules-sgi.unlawful-synthetic-content-blocked · review status: primary source derived

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.