🚨 Need immediate assistance? We respond within 10 minutes. 💬 WhatsApp Now 📞 Call Now
Bylaw.in

Home/AI & Synthetic Media Law/IT Rules 2026 Compliance

Practice Area · India

IT Rules 2026 Compliance

The IT Amendment Rules, 2026 changed three things that matter operationally: what counts as synthetically generated information, how it must be labelled, and how fast a grievance has to be actioned once it is received. This page is written for the people who have to build that into a working system — not for content, but for process.

Who this applies to

The obligations under the amended Rules attach to intermediaries as defined under the IT Act — social media intermediaries, hosting providers, and significant social media intermediaries with the additional obligations that status carries. In practice this also reaches AI tool and model providers whose output is published or shared through a covered platform, and creator or marketing agencies operating tools that generate synthetic content on a platform's behalf. Where the obligation sits in a supply chain with several parties is a question of fact, not a single rule.

Labelling and provenance-metadata obligations

The 2026 amendment defines “synthetically generated information” in Indian law for the first time. Content falling within that definition must be labelled clearly and prominently, and carry provenance metadata that allows it to be traced back to its origin. Two consequences follow for anyone building or operating a platform or tool: labelling has to be applied at the point of generation or publication, not bolted on afterwards, and the label has to survive ordinary re-sharing and re-encoding if it is to do the job the Rules intend.

Designing a grievance mechanism against the tiered windows

A grievance mechanism has to route an incoming complaint to the correct clock before it can meet it. The three windows are not interchangeable.

2h Rule 3(2)(b)

Citizen complaint — NCII/morphed

Requires a triage step that can identify private, morphed, or non-consensual intimate content on intake and route it to this lane immediately, ahead of the general complaint queue.

3h Rule 3(1)(d)

Court or government notice

Includes notices routed through the Sahyog mechanism from agencies such as I4C. This is an inbound government channel your compliance workflow has to be able to receive and prioritise — it is not something your platform initiates.

36h Separate proviso

Defined category, longer window

Still requires a defined SLA and audit trail; the longer window is not a reason to deprioritise a category-appropriate complaint.

General grievances outside these tiers still carry a twenty-four-hour acknowledgment requirement and a seven-day disposal period, shortened from fifteen days. A workflow built only around the fastest lane will miss this obligation.

What puts Section 79 safe harbour at risk

Safe harbour under Section 79 of the IT Act is conditional, not automatic. On the current framework, the following materially increase exposure:

  • Missing the applicable takedown window once actual knowledge is established — whether through a citizen complaint under Rule 3(2)(b) or a court/government notice under Rule 3(1)(d).
  • Failing to label synthetically generated information, or shipping a label that does not survive normal distribution.
  • Not designating a grievance officer, or operating a grievance mechanism that cannot demonstrably meet the twenty-four-hour acknowledgment and seven-day disposal requirement.
  • Treating a Sahyog-routed government notice as equivalent to a lower-priority general complaint.
  • Absence of an audit trail showing when a complaint was received, classified, and actioned — which matters as much for defending a compliant response as for identifying a non-compliant one.

Where DPDP obligations intersect

Where a tool trains on or generates content from personal data — a photograph, a voice sample, or other identifying material — the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 are separately engaged. Substantive Data Fiduciary obligations, including notice, consent and breach reporting, commence 13 May 2027, with penalties reaching ₹250 crore. Compliance architecture built now for the IT Rules is generally cheaper to extend to DPDP than to retrofit later.

Practical compliance checklist

A working starting point for legal and product teams to build from — not a substitute for an audit of your specific systems.

  1. Designate and publish a grievance officer

    With a functioning, monitored intake channel, not just a named individual on a policy page.

  2. Build a content-classification workflow

    Able to route an incoming complaint to the correct tier — NCII/morphed, court or government notice, or general grievance — at intake, not after review.

  3. Implement labelling and provenance metadata at the point of generation

    Not as a post-publication add-on, and tested against ordinary re-sharing and re-encoding.

  4. Set SLAs matched to each tier

    Two hours, three hours, thirty-six hours and the general twenty-four-hour/seven-day track, each with its own escalation path.

  5. Build receiving capability for Sahyog-routed and other government notices

    These are inbound and time-sensitive; the workflow needs a defined owner and priority handling.

  6. Maintain an audit log

    Timestamped records of receipt, classification, and action taken, sufficient to demonstrate compliance if safe harbour is later challenged.

  7. Map the DPDP intersection

    Wherever personal data feeds training or generation, so notice and consent architecture can be planned against the 13 May 2027 commencement rather than built afterwards.

If your platform is facing a notice or enforcement action

A notice from a grievance officer's own users is a different matter from a notice issued by a government agency or a court order, and the two call for different responses. Where a platform has actually received a notice, a complaint, or an indication that safe harbour is being questioned, the position depends heavily on what the platform did before the notice arrived.

Safe harbour is a defence to be established, not an entitlement to assume

Section 79 protection is conditional on due diligence, and in a dispute the burden of showing that diligence was observed falls on the intermediary. This is where an audit trail — records of when a complaint was received, how it was classified, and what was done within the applicable window — stops being a compliance nicety and becomes the actual evidence a platform relies on.

Where a notice has been received under Section 79(3)(b), whether directly or routed through the Sahyog mechanism, the immediate questions are: what window applies to the notice as framed, whether the platform's classification of the underlying content was correct, and whether the response taken and its timing are documented. Where a platform disputes that it is the correct addressee for a notice — because it is not an intermediary in the relevant sense, or because the content falls outside what it hosts or transmits — that position needs to be established on the specific facts rather than asserted generally.

Where enforcement action follows a claimed loss of safe harbour, the platform's exposure is then assessed as if it were directly liable for the content in question, which is why the question of whether due diligence was actually observed becomes central rather than incidental. Where a regulator or a court is involved rather than an individual complainant, the procedural posture and the timeline both change, and early engagement generally produces a better outcome than a delayed one.

On representation

A platform facing a notice, a complaint, or a question over its safe harbour position is entitled to establish its own compliance record and to contest a finding that due diligence was not observed. Nothing on this page is a comment on the merits of any particular matter.

Law stated as at 11 August 2026

Frequently asked

Do we need to integrate with the Sahyog portal?

Sahyog is the inbound government and law-enforcement channel through which agencies such as I4C issue notices under Section 79(3)(b) of the IT Act. Intermediaries need the operational capacity to receive and act on these notices within the applicable window; it is not a channel your platform uses to report content outward.

What exactly has to be labelled?

Content that meets the Rules' definition of synthetically generated information must carry a clear, prominent label and traceable provenance metadata. Whether a specific output meets that definition depends on how it was produced and how it is presented, which is a fact-specific assessment.

What happens if we miss the two-hour or three-hour window?

Missing the applicable window once actual knowledge is established is a factor that can put Section 79 safe harbour at risk, in addition to any liability arising from the underlying content itself.

Does BNS Section 319 create direct liability for our platform?

Section 319 addresses cheating by personation as an offence committed by an individual; it is not, by itself, a basis for intermediary liability. Platform exposure is generally assessed separately under the IT Act and the Rules, based on how the platform responded once it had knowledge.

When do DPDP obligations start applying to training data?

The Data Protection Board was constituted on notification of the Rules. Consent manager registration opens in November 2026. Substantive Data Fiduciary obligations commence on 13 May 2027.

We have received a notice claiming we failed to act within the required window. What now?

The response depends on the platform's own record: when the notice was received, how it was classified, and what was done and when. Where that record supports the platform's position, it is the primary evidence relied on. Where it does not, the exposure is assessed on the underlying content as though safe harbour did not apply.

Can we dispute that we are the correct addressee for a notice?

Yes, where the position is genuinely arguable — for instance, that the service does not fall within intermediary classification for the relevant function, or that the content in question falls outside what the platform hosts or transmits. This needs to be established on the specific facts of the service rather than asserted as a general defence.

What happens if safe harbour is found not to apply?

The platform is then assessed as though it were directly liable for the user content in question, in whatever proceeding has been brought. This is the material exposure behind the compliance obligations, and it is why the due diligence record matters as much before a dispute arises as during one.

Should we respond to a regulator or court notice differently from a user complaint?

Yes. A notice from a government agency, a court, or one routed through Sahyog carries a different procedural posture and generally a different timeline from an individual user complaint, and early engagement is generally more effective than a delayed response.

Enquiries

If a matter is time-sensitive — content already circulating, a takedown window running, or a statutory deadline approaching — say so in the first line.

Please do not send confidential or privileged material in a first message. Describe the situation in general terms only. A secure channel can be arranged once the enquiry has been acknowledged.

See the privacy notice for how enquiry information is handled.

Or write directly to info@bylaw.in

Please Note

As per the rules of the Bar Council of India, an advocate is not permitted to advertise or solicit work. By continuing to use this website, you acknowledge that you are seeking information about Bylaw.in of your own accord, that no advocate-client relationship is created by your visit, and that the content here is for general information only and is not legal advice.

We also use privacy-first analytics (Google Consent Mode v2, per the DPDP Act 2023) to understand how this page is used. Continuing agrees to this — or continue without it below.