Deepfakes and AI-Based Cyber Crimes as Cyber Crime

Deepfakes and AI-based cyber crimes have created a new challenge for cyber law. Artificial intelligence can now generate fake images, videos, voices, messages and identities that appear highly realistic. These technologies may be used for creativity and innovation, but their misuse can cause fraud, defamation, privacy violations, blackmail, misinformation and threats to public order.
Meaning of Deepfakes
Deepfakes are artificial or manipulated digital content created with the help of artificial intelligence. The term is commonly used for fake videos, images or audio clips where a person’s face, voice or body is altered to make it appear as if that person has said or done something which never happened.

Deepfake technology usually works through machine learning systems, especially generative artificial intelligence. These systems study large amounts of data such as photographs, videos, voice samples or facial expressions. After learning these patterns, they can generate realistic content that resembles a real person. This makes deepfakes different from ordinary edited photos or videos. A normal edited image may show visible signs of manipulation, but a deepfake may look natural and convincing.
Deepfakes may be harmless in some cases, such as entertainment, satire, film production, education and accessibility tools. However, when they are created or circulated without consent and with dishonest or harmful intention, they become a serious form of cyber crime.
Meaning of AI-Based Cyber Crimes
AI-based cyber crimes are offences where artificial intelligence is used to commit, support, hide or increase the impact of a cyber offence. In traditional cyber crimes, the offender may use computers, networks, malware or fake websites. In AI-based cyber crimes, the offender uses intelligent tools that can create content, automate attacks, imitate human behaviour, analyse victims and bypass security systems.
Such crimes may include AI-generated phishing emails, fake customer support chats, voice cloning scams, automated hacking, deepfake blackmail, fake social media profiles, AI-generated misinformation, identity theft and cyber fraud. The major concern is that AI can make cyber crimes faster, cheaper, more scalable and more convincing.
For example, a fraudster may use AI to write a perfect email in the style of a company’s senior officer. Another person may use voice cloning to call an employee and instruct the transfer of money. A deepfake video may be used to damage someone’s reputation or influence public opinion during elections. These examples show how AI can convert ordinary cyber offences into highly sophisticated digital crimes.
Deepfakes as Cyber Crime
Deepfakes become cyber crime when they involve unlawful access, impersonation, cheating, privacy violation, obscene content, extortion, defamation, harassment, misinformation or public harm. The criminality does not arise merely because AI is used. It arises because the technology is used with a harmful purpose or in a manner prohibited by law.
One of the most common uses of deepfakes is impersonation. A person’s face or voice may be copied to create fake content. This can lead to identity theft, cheating by personation, financial fraud and reputational damage. In cases involving women and children, deepfakes may also be used to create sexually explicit or obscene material. Such conduct can cause severe mental trauma and social harm.
Deepfakes may also be used for political manipulation. Fake speeches, fake videos of public officials or fabricated statements can mislead the public. In sensitive situations, such content may affect communal harmony, elections, markets or public trust in institutions. Therefore, deepfakes are not merely a private wrong. They may also become a threat to public order and national security.
Important Forms of Deepfake Cyber Crimes
Image-Based Deepfakes
Image-based deepfakes involve the manipulation of photographs or creation of artificial images. These may be used to create fake profiles, defamatory posts, obscene images or misleading evidence. Such images can spread quickly through social media and messaging platforms. Once circulated, the harm may continue even after deletion because copies may already exist on different platforms.
Video Deepfakes
Video deepfakes are more dangerous because moving images appear more believable. A fake video may show a person making a statement, engaging in an act or attending a place where the person was never present. Such videos may be used for political propaganda, corporate fraud, personal revenge, blackmail and media manipulation.
Audio Deepfakes and Voice Cloning
Audio deepfakes involve cloning a person’s voice. This form of cyber crime is growing because voice samples are easily available through interviews, reels, podcasts, phone recordings and social media videos. A cloned voice may be used to cheat family members, employees, bank officials or business partners. In financial fraud, this can be extremely dangerous because many people trust voice instructions from known persons.
Real-Time Deepfake Impersonation
Real-time deepfakes allow impersonation during live video calls or online meetings. This can be used in corporate scams, fake interviews, online KYC fraud, romance scams and identity verification fraud. The victim may believe that the person on screen is real because the interaction appears live and natural.
Deepfake Blackmail and Extortion
Deepfakes are often used for blackmail. A fake intimate image, video or audio clip may be sent to the victim with threats of public release. Even if the content is false, the fear of social stigma may force victims to pay money or follow unlawful demands. This form of crime is especially harmful because it combines cyber fraud, psychological abuse and reputational attack.
Major Forms of AI-Based Cyber Crimes
AI-Powered Phishing
Phishing means tricking a person into sharing sensitive information such as passwords, OTPs, bank details or login credentials. AI makes phishing more effective by creating personalised and error-free messages. Earlier, many phishing emails could be identified through poor grammar or suspicious language. AI tools can now create professional emails in the tone of banks, government departments, law firms, universities or employers.
AI can also study social media profiles and create messages that appear personal. This increases the chances of the victim trusting the message. Such phishing may lead to identity theft, financial loss, unauthorised access and data breaches.
AI-Generated Social Engineering
Social engineering is the act of manipulating a person into taking an unsafe action. AI can help criminals understand human behaviour, create emotional messages and imitate trusted people. For example, a fake message may appear to come from a senior officer, family member, client or government authority. The message may ask for money, confidential files or urgent action.
AI chatbots can also conduct conversations with victims. These bots can respond naturally, remove suspicion and continue the fraud for a long time. This makes investigation difficult because the offender may not be directly communicating at every stage.
Automated Hacking and Malware
AI can be used to identify weaknesses in computer systems. It may help criminals scan websites, guess passwords, test vulnerabilities and modify malware. AI-supported malware can change its behaviour to avoid detection. This creates difficulty for cyber security teams because traditional security tools may not recognise new attack patterns immediately.
AI-Based Identity Theft
Identity theft occurs when a person’s personal data is misused to pretend to be that person. AI can make identity theft more convincing by creating fake documents, synthetic images, forged signatures, cloned voices and realistic profile pictures. Such fake identities may be used for opening bank accounts, obtaining loans, committing online fraud or creating fake social media accounts.
AI-Generated Misinformation
AI can create large volumes of false or misleading content. This includes fake news articles, fake screenshots, false public notices, fabricated images and manipulated videos. When such content spreads through social media, it may mislead the public and damage trust in genuine information. In extreme cases, it may cause panic, communal tension or loss of confidence in institutions.
AI-Assisted Financial Fraud
Financial fraud may involve fake investment schemes, fake trading platforms, loan scams, fake customer care numbers and impersonation of bank officials. AI can generate professional websites, realistic advertisements, fake testimonials and convincing conversations. This makes fraud appear legitimate and increases the chances of people losing money.
Legal Framework in India
India does not have a single separate statute only for deepfakes. However, several laws can apply depending on the nature of the offence. The Information Technology Act, 2000, Bharatiya Nyaya Sanhita, 2023, Digital Personal Data Protection Act, 2023, IT Rules and other special laws may become relevant.
Information Technology Act, 2000
The Information Technology Act, 2000 is the primary cyber law in India. It gives legal recognition to electronic records and also deals with several cyber offences. In deepfake and AI-based cyber crimes, the following provisions may become important:
- Section 66C deals with identity theft. If a person dishonestly or fraudulently uses another person’s electronic signature, password or unique identification feature, this provision may apply. Deepfake impersonation and misuse of digital identity may fall within this area depending on facts.
- Section 66D deals with cheating by personation using a computer resource. This provision is important in cases where AI-generated voice, video or fake profile is used to deceive someone and cause wrongful gain or loss.
- Section 66E deals with violation of privacy. It may apply where private images of a person are captured, published or transmitted in violation of privacy.
- Sections 67 and 67A deal with publishing or transmitting obscene and sexually explicit material in electronic form. These provisions are highly relevant in cases involving deepfake pornography, morphed intimate images and non-consensual sexual content.
- Section 69A allows blocking of public access to certain information in specified circumstances. This may become relevant where harmful deepfake content threatens public order, sovereignty, security of the State or other protected interests.
Bharatiya Nyaya Sanhita, 2023
The Bharatiya Nyaya Sanhita, 2023 may apply to AI-based cyber crimes through offences such as cheating, forgery, criminal intimidation, defamation, extortion and offences affecting public peace. If a deepfake is used to cheat someone, damage reputation, threaten a person or create forged electronic records, provisions of the BNS may become relevant.
Forgery-related provisions are important because electronic records can be manipulated or fabricated. A fake video, forged document, altered digital certificate or AI-generated identity proof may be part of a larger offence involving cheating or reputation harm.
Digital Personal Data Protection Act, 2023
Deepfakes and AI crimes often depend on personal data. Images, voice samples, biometric patterns, names, phone numbers, email addresses and social media data may be collected and used to create fake content. The Digital Personal Data Protection Act, 2023 recognises the importance of protecting digital personal data. It becomes relevant where personal data is processed unlawfully or without proper consent.
Although the Act is mainly a data protection law and not a criminal statute for every cyber offence, it strengthens the privacy framework. It also highlights that personal data cannot be treated as freely available material for misuse.
IT Rules and Intermediary Duties
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 impose due diligence duties on intermediaries. These rules have become important because deepfakes usually spread through social media platforms, video-sharing platforms, messaging services and other intermediaries.
The 2026 amendment has specifically addressed synthetically generated information, including deepfakes and AI-generated content. It strengthens the responsibilities of intermediaries in relation to identification, labelling, removal and control of harmful synthetic content. This is important because regulation of deepfakes cannot depend only on punishing the original offender. Platforms that host and circulate such content also play an important role in reducing harm.
Challenges in Regulating Deepfakes and AI Crimes
Difficulty in Detection
Deepfakes are becoming more realistic. Many people may not be able to identify whether a video or audio clip is genuine. Even experts may require technical tools to detect manipulation. As technology improves, detection becomes more difficult.
Speed of Circulation
Digital content can spread across platforms within minutes. Even if the original post is removed, copies may continue to circulate. This creates a serious problem for victims because reputational damage may occur before legal action begins.
Cross-Border Nature of Cyber Crime
AI-based cyber crimes may involve offenders, servers, victims and platforms located in different countries. This creates jurisdictional challenges. Indian agencies may require cooperation from foreign platforms or authorities to trace offenders and preserve evidence.
Anonymity of Offenders
Cyber criminals may use fake accounts, VPNs, encrypted platforms, cryptocurrency and disposable email addresses. This makes identification difficult. AI tools can also generate fake identities, making investigation more complex.
Evidentiary Challenges
In legal proceedings, electronic evidence must be properly collected, preserved and proved. Deepfakes create a new evidentiary concern because digital content can no longer be accepted only on face value. Courts and investigators must examine authenticity, metadata, source, chain of custody and expert analysis.
Conclusion
Deepfakes and AI-based cyber crimes represent a serious shift in the nature of cyber crime. They attack identity, privacy, reputation, financial security and public trust.
Indian cyber law already contains provisions that can address many such offences, but effective enforcement requires technical expertise, platform cooperation and public awareness. As artificial intelligence grows, cyber law must also evolve to protect individuals, institutions and society from synthetic digital harms.
Attention all law students and lawyers!
Are you tired of missing out on internship, job opportunities and law notes?
Well, fear no more! With 2+ lakhs students already on board, you don't want to be left behind. Be a part of the biggest legal community around!
Join our WhatsApp Groups (Click Here) and Telegram Channel (Click Here) and get instant notifications.








