India unleashes AI crackdown as deepfake scams soar
The gist
India is cracking down on a tidal wave of AI-powered deepfake scams and cyber fraud, unleashing aggressive new regulations, tech, and public campaigns to restore digital trust.
What to know
- AI-driven financial scams cost India over ₹22,495 crore in 2025, with deepfake endorsements and 'digital arrest' tricks triggering 90,000+ complaints and nearly ₹3,000 crore in damages.
- The 2026 IT Rules force major social platforms to label, metadata-tag, and rapidly remove synthetic AI content within just 3 hours—or risk losing legal protection.
- India launched the AI-powered Digital Payment Intelligence Corporation (IDPIC) and ramped up law enforcement crackdowns, while massive awareness campaigns and Supreme Court orders push citizens and platforms to fight back.
AI Supercharges Global Scams
AI-powered deepfakes and voice cloning have fueled an unprecedented global surge in sophisticated financial fraud, making scams nearly impossible to spot and driving losses into the billions.
By 2025, AI-driven cyber financial fraud has surged into a formidable global menace, with the FBI reporting over 22,000 AI-related complaints in the U.S. alone, resulting in nearly $900 million in losses. Criminals are increasingly deploying sophisticated AI tools such as deepfakes, voice cloning, and AI-powered chatbots to craft highly convincing scams that mimic corporate executives or government officials, thereby duping victims into wiring money or divulging sensitive information. This evolution has not only amplified traditional fraud schemes like romance scams and business email compromise but also lowered the barriers for fraudsters to produce deceptive content at scale, making detection by human vigilance nearly futile.
The rapid proliferation of AI-enabled deepfake fraud is staggering, with document deepfakes projected to increase nearly 3,900% in 2026, transforming isolated fake videos into a broader infrastructure for identity impersonation and remote verification bypass. This surge is global, exemplified by Southern Africa’s jump from fewer than 200 deepfake attempts monthly in 2024 to over 3,000 by late 2025. Moreover, AI-enhanced crypto scams are proving especially lucrative, generating 4.5 times more revenue per operation than non-AI-linked schemes, underscoring AI’s pivotal role in escalating both the scale and complexity of financial fraud worldwide.
India faces a particularly acute threat from AI-driven cyber financial fraud, with government data revealing losses exceeding ₹22,495 crore in 2025 and estimates suggesting the true toll, including unreported cases, could reach ₹1.2 lakh crore. Nearly half of Indian adults have been personally defrauded by or know someone victimized through AI voice-cloning or deepfake scams, nearly double the global average. High-profile scams include deepfaked endorsements by business leaders and AI-generated 'digital arrest' frauds impersonating police or CBI officials, which alone have triggered over 90,000 complaints and losses approaching ₹3,000 crore, highlighting the urgent need for robust countermeasures.
Traditional verification methods are increasingly inadequate against the sophisticated deception enabled by AI, necessitating a multi-layered defense strategy combining multi-factor authentication, AI-powered fraud detection, and continuous public digital literacy efforts. Experts emphasize that technology alone cannot stem the tide; practical safeguards such as independently verifying any urgent or secretive financial request—especially those involving AI-generated voices or videos—are critical. As advised, 'never transfer money on the strength of a call, video call or message alone,' underscoring the vital role of human vigilance alongside advanced technological solutions in combating this escalating threat.
India’s 3-Hour Takedown Law
India’s 2026 IT Rules force social platforms to label and rapidly remove synthetic AI content, with legal penalties for noncompliance and Supreme Court pressure to criminalize deepfake-driven crimes.
India’s 2026 IT Rules mark a decisive step in regulating AI-generated synthetic content by introducing a formal legal definition of 'synthetically generated information' and drastically shortening compliance timelines for content takedown from 36 hours to just 3 hours. These rules impose stringent requirements on Significant Social Media Intermediaries like Facebook and Instagram to verify user declarations about synthetic content using automated tools, with failure risking loss of legal safe harbour protections under Section 79 of the IT Act. Additionally, the mandate for permanent labeling and metadata tagging of synthetic media enhances transparency and traceability, preventing intermediaries from removing or altering such labels, thereby tightening accountability across digital platforms.
The government’s enforcement of these frameworks is underscored by swift legal actions, such as the FIR registered against creators of deepfake misinformation targeting Prime Minister Modi and Minister Piyush Goyal, alongside rapid takedown of related social media content. This proactive stance reflects a broader strategy to curb the misuse of generative AI in spreading synthetic misinformation, urging the public to rely on official verification channels amid rising AI-driven disinformation campaigns.
Recognizing critical gaps in existing cybercrime laws, the Supreme Court has called on Parliament to criminalize AI-driven offenses like 'digital arrest' scams and deepfake fraud, which have collectively cost Indian citizens over $5.5 billion in six years. Highlighting sophisticated impersonation tactics—including fake uniforms and staged virtual court hearings such as the 2024 SP Oswal case involving a deepfake of the Chief Justice—the Court’s intervention stresses the urgency of enacting specific criminal statutes and mandates rapid takedown and labeling requirements to close these legal loopholes.
Complementing legislative reforms, the Supreme Court has directed a coordinated national response involving the Reserve Bank of India, state governments, and cybercrime agencies to combat AI-driven financial fraud. This includes framing a Standard Operating Procedure for identifying mule accounts, operationalizing grievance redressal and money restoration mechanisms via the National Cyber Crime Reporting Portal, implementing the e-Zero FIR system for immediate complaint registration, and exploring telecom restrictions to prevent scam communications. Public awareness campaigns and judicial sensitization efforts are also mandated to empower citizens and courts in recognizing and swiftly addressing digital arrest scams.
AI Fights AI in Payments
The new India Digital Payment Intelligence Corporation (IDPIC) and academic partnerships are deploying advanced AI to spot, score, and stop fraudulent transactions in real time across the financial sector.
By mid-2026, India had made a significant leap in its fight against AI-driven financial fraud through the launch of the India Digital Payment Intelligence Corporation (IDPIC), a centralized, not-for-profit AI-powered fraud intelligence hub. Established with RBI support and coordinating closely with cybersecurity bodies like CERT-In and CSIRT-Fin, IDPIC harnesses artificial intelligence, machine learning, and big data analytics to enable real-time detection, risk scoring, and prevention of suspicious transactions across banks, fintechs, and payment service providers, thereby bolstering consumer trust and the resilience of the digital payments ecosystem.
Complementing IDPIC’s efforts, the Indian government’s IndiaAI Mission approved 13 cutting-edge 'Responsible AI' projects targeting deepfake detection, with premier institutions such as IIT Jodhpur, IIT Madras, and IIT Kharagpur spearheading innovations to counter AI-enabled cyber fraud. This technological push is reinforced by amended IT Rules mandating that Significant Social Media Intermediaries with over 5 million users remove unlawful AI-generated content within three hours of government or court orders, alongside requirements for clear labeling and traceable metadata, collectively enhancing rapid AI-powered content moderation and accountability in the digital space.
Industry players like Quick Heal Technologies have also stepped up with AI-driven tools such as AntiFraud.AI, which provide an early-warning system by detecting suspicious calls, fraudulent links, and scam attempts before they escalate. These tools are crucial in combating sophisticated AI-enabled cyber extortion tactics that blend social engineering with technical exploits, including fake authority impersonations and doctored video calls, underscoring the vital role of AI-powered detection in preempting complex fraud narratives that prey on users’ trust and fear.
Recognizing the evolving threat landscape, the Indian government formed an inter-ministerial group (IMG) to craft a comprehensive cybersecurity strategy for the financial sector, focusing on emerging AI-enabled threats such as deepfake impersonation and sophisticated phishing. This strategic coordination ensures that technological innovations like IDPIC and AI detection projects are integrated within a broader policy framework to safeguard India’s financial infrastructure against increasingly complex cyberattacks.
Police Target Fraud Networks
Indian law enforcement is dismantling cybercrime syndicates by tracing mule accounts and leveraging AI-powered detection, while the RBI and Home Affairs are tightening fintech oversight and public reporting.
By mid-2026, Indian law enforcement agencies, exemplified by Rajasthan and Navi Mumbai police, intensified crackdowns on cybercrime syndicates exploiting mule bank accounts to facilitate large-scale financial fraud, arresting dozens and tracing crores of rupees across multiple accounts. These operations leveraged centralized platforms like the Indian Cyber Crime Coordination Centre and national registries to link suspicious accounts across state lines, reflecting a strategic integration of AI-driven detection tools within banking systems to enhance real-time fraud identification and enforce legal accountability among financial enablers.
The Reserve Bank of India (RBI) has bolstered fintech sector oversight through the 2024 Self-Regulatory Organisation (SRO) Framework, promoting ethical conduct and transparency, while mandating AI and machine learning-based fraud detection models via the National Payment Corporation of India (NPCI) to monitor UPI transactions. Complementing these efforts, the Ministry of Home Affairs launched the National Cybercrime Reporting Portal and helpline, facilitating public reporting and government coordination to combat cyber financial fraud, including illegal loan apps, thereby creating a multi-layered defense against evolving threats.
The launch of the Indian Digital Payment Intelligence Centre (IDPIC) in late July 2026 marked a watershed moment, establishing a centralized AI-powered platform that enables real-time fraud intelligence sharing among banks, fintechs, and payment service providers. Coordinated with cybersecurity bodies like CERT-In and CSIRT-Fin, IDPIC employs advanced AI, machine learning, and big data analytics to detect suspicious transactions and perform risk scoring, significantly enhancing the financial sector's proactive capabilities to dismantle fraud networks and bolster the resilience of India’s digital payments ecosystem.
Responding to the Supreme Court’s August 2026 directives, the RBI was tasked with formulating a Standard Operating Procedure to identify and act against mule accounts within four weeks, underscoring a judicial push for swift, coordinated action. This mandate catalyzed inter-agency collaboration among banks, telecom operators, and law enforcement to enhance real-time transaction tracking, freeze suspicious funds, and expedite victim money recovery through mechanisms like the Money Restoration Module. Additionally, states and Union Territories were directed to operationalize grievance redressal systems and adopt the e-Zero FIR mechanism, while an inter-departmental committee was established to deploy technological safeguards, collectively forging a faster, more integrated national response to AI-driven cyber financial fraud.
Awareness & Accountability Surge
Massive cybersecurity workshops, Supreme Court mandates, and legal action against social platforms are forcing both citizens and tech giants to step up against deepfake and digital arrest scams.
India has launched extensive public awareness campaigns that have engaged over 1.13 million participants through more than 6,650 cybersecurity workshops, significantly elevating public understanding of deepfake threats and digital scams. Complementing these efforts, the Supreme Court has mandated states to initiate awareness drives specifically targeting digital arrest scams, while also directing courts to streamline grievance redressal mechanisms, thereby reinforcing the critical role of user vigilance and multi-stakeholder accountability in combating AI-driven cyber financial fraud.
In a decisive move to bolster platform accountability, India has amended its Information Technology Rules to require Significant Social Media Intermediaries (SSMIs) with over 5 million users to remove unlawful AI-generated content within three hours of government or court orders. This regulatory tightening is paired with mandates for labeling, traceable metadata, and verification of AI-generated content, fostering transparency and responsibility among digital platforms amid rising misuse of generative AI.
Legal actions against Meta India, including FIRs filed by Hyderabad Cyber Crime Police over the circulation of deepfake videos targeting Prime Minister Narendra Modi, underscore the heightened expectations for social media platforms to proactively detect and authenticate AI-generated content. Experts like Dr. Deepak Kumar Sahu of FaceOff Technologies emphasize the necessity of advanced AI-powered detection tools and behavioral biometrics to establish digital trust, highlighting that safeguarding information integrity has become as crucial as protecting critical infrastructure in the AI era.
India’s multi-institutional approach to combating AI misinformation is exemplified by the IndiaAI Mission’s approval of 13 Responsible AI projects focusing on deepfake detection, involving premier institutes such as IIT Jodhpur, IIT Madras, and IIT Kharagpur. These technical safeguards, combined with public awareness and stringent platform regulations, reflect a comprehensive strategy to protect users, curb organized cybercrime, and maintain trust in the country’s rapidly expanding digital payment ecosystem.
