As of late, the architecture of India’s digital content governance has undergone an overhaul that seems to be legislatively irreversible. This shift from the nation’s post-liberalisation ethos of light-touch regulations to an interventionist one, that centres itself on absolute digital sovereignty. In 2026, we find ourselves captured within a strict liability regime which in my mind takes the form of a pincer.
The pincer operates through two mandates:
- Regulating artificial intelligence and
- Attempting to classify independent digital content creators as traditional broadcasters.
The convergence of these two flanks creates an insurmountable compliance ceiling that privileges heavily capitalised corporates while systematically stifling independent digital journalism and decentralised creator economies.
I argue that India’s Safe Harbour doctrine faces multifaceted suppression while algorithmic prior restraint emerges.
The foundational principle of India's internet economy has historically been intermediary liability protection: the Safe Harbour doctrine enshrined in Section 79(1) of the Information Technology Act, 2000 (IT Act). This provision immunised digital platforms from civil and criminal liability for third-party content, provided they acted as neutral conduits and observed government-prescribed "due diligence" norms under Section 79(2)(c).
The erosion of this shield accelerated with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. These rules significantly expanded the affirmative obligations of digital intermediaries, mandating the appointment of resident grievance officers, the implementation of automated content filtering mechanisms, and adherence to strict timelines for content takedowns. Crucially, the 2021 framework codified the catastrophic consequence of non-compliance through Rule 7, which explicitly stripped intermediaries of their Section 79(1) immunity if they failed to observe the rules, rendering them liable for punishment under prevailing criminal laws. This effectively created a regime of strict liability by executive fiat, bypassing the judicial determination of liability originally envisioned in the parent Act.
This mechanism directly subverted the strict constitutional standards established by the Supreme Court of India in Shreya Singhal v. Union of India (2015). In Shreya Singhal, the Court struck down Section 66A of the IT Act for constitutional vagueness, affirming that speech restrictions must fall strictly within the exhaustive parameters of Article 19(2) of the Constitution; a principle later reinforced in Kaushal Kishore v. Union of India. Shreya Singhal also read down the "actual knowledge" requirement, ruling that intermediaries only had to remove content upon receiving a specific court order or authorised government notification, preventing platforms from acting as private censors. Over the past two years, the state has actively circumvented this safeguard.
The Authenticity Flank: From Soft Law to the SGI Mandates
Initially, the state relied on executive advisories. In November and December 2023, the Ministry of Electronics and Information Technology (MeitY) issued advisories linking deepfakes to existing prohibitions on impersonation under Rule 3(1)(b)(v) of the IT Rules. On March 1, 2024, MeitY escalated this to aggressive pre-censorship, demanding platforms secure explicit prior approval before deploying under-trial AI models. This attempt to introduce a regressive model to global AI development drew immediate, severe criticism from the international tech industry and legal experts, who denounced it as an initiative that would completely stifle innovation and vastly exceed the ministry's statutory mandate under the IT Act. Following intense industry pushback, a superseding advisory on March 15, 2024, dropped the licensing requirement but doubled down on algorithmic labeling and metadata embedding.
This reliance on soft law operated as a trap. The government functionally prescribed new penal obligations through advisories, warning that non-compliance constituted a failure of due diligence, automatically triggering Rule 7. In the Lok Sabha, the state openly defended this approach wherein in response to a question by MP Naveen Jindal on March 25, 2026, Minister of State Jitin Prasada admitted that the government relied heavily on these Advisories and Standard Operating Procedures (SOPs) to address "grey areas." The state effectively maintained that its soft law was adequate, utilising it as a functional substitute for the long delayed Digital India Act, a comprehensive law intended to formally replace the 2000 IT Act but which remained stalled in what seems to be perpetual stakeholder consultation.
The legally precariousness advisories were later followed by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, notified on February 10, 2026.
The rules introduced Rule 2(1)(wa), defining "Synthetically Generated Information" (SGI) as artificially created, authentic-looking content. Despite carving out exemptions for good-faith editing, this framework places an impossible adjudicatory burden on platforms, guaranteeing automated over-censorship. More contentiously, Rule 3(3) mandates embedding all SGI with permanent, traceable metadata. Furthermore, Rule 4(1A) forces Significant Social Media Intermediaries (SSMIs) into an ex-ante surveillance model, requiring proactive, automated verification of SGI declarations before publication. To enforce absolute compliance, the rules slashed the "actual knowledge" takedown window under Rule 3(1)(d) from 36 hours to a mere 3 hours. This total elimination of meaningful human legal review effectively ensures that platforms will link government reporting portals directly to their automated takedown APIs.
The SGI metadata mandates intersect dangerously with fundamental privacy rights. This is mirrored in the ongoing constitutional battle of WhatsApp LLC v. Union of India, challenging Rule 4(2) of the IT Rules, 2021, which demands traceability of the "first originator" of information. Before a Supreme Court bench, it was argued that breaking encryption undermines user privacy. Should the Court rule that traceability violates the right to privacy established in K.S. Puttaswamy v. Union of India, the 2026 metadata apparatus will ultimately face a constitutional crisis.
These surveillance concerns have spilled into Parliament. In Lok Sabha (March 25, 2026), Leader of the Opposition Rahul Gandhi challenged the government on foreign surveillance risks and Chinese-origin CCTV vulnerabilities. MoS Jitin Prasada deflected, broadly citing the National Security Directive on Trusted Sources (2021), the Telecommunication Act, 2023, and the Digital Personal Data Protection (DPDP) Act, 2023 as evidence of adequate security, without addressing the state’s expanding tracking capabilities.
The Accountability Flank: The Ghost of the Broadcasting Bill
While MeitY captured the technological layer, the Ministry of Information and Broadcasting (MIB) targeted the content layer through the proposed Broadcasting Services (Regulation) Bill, 2024. Intended to replace the Cable Television Networks (Regulation) Act, 1995, the Bill sought to classify independent digital creators engaging in "systematic activity" as ‘Digital News Broadcasters.’
The classification hinged on two dangerously vague concepts: engaging in a "professional" capacity and conducting a "systematic activity." For instance, under this interpretation, a solo Chartered Accountant operating a monetised YouTube channel explaining tax law could be stripped of their status as a mere internet user and thrust into the regulatory posture of a massive corporate television network.
Under Clause 20, these creators would be bound by subjective Programme and Advertisement Codes. Clause 24 mandated the establishment of internal Content Evaluation Committees (CECs) to pre-certify all content; a system of prior restraint comparable to film certification upheld in K.A. Abbas v. Union of India, but entirely unconstitutional for the press.
Following accusations of exclusionary tactics highlighted by Rajya Sabha MP Saket Gokhale's questions regarding watermarked drafts shared only with corporate entities, unfortunately deflected by MoS Dr. L. Murugan, and massive public outcry, the government withdrew the Bill in August 2024. However, it simply pivoted to delegated legislation.
On March 30, 2026, MeitY published the draft Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Second Amendment Rules, 2026. Far from procedural clarifications, these amendments executed a sweeping bypass of the Broadcasting Bill's failure.
The most profound shift is the rewriting of the proviso to Rule 8(1). Previously, Part III of the IT Rules (the Digital Media Ethics Code) applied strictly to formal publishers. The draft expands this to "news and current affairs content... published... by users who are not publishers." In a single stroke, millions of independent commentators are thrust under the MIB’s subjective regulatory machinery.
Simultaneously, the draft proposes to formalize executive-led soft law through the insertion of Rule 3(4). This explicitly mandates that intermediaries must "comply with and give effect to any clarification, advisory, order... or guideline" issued by the Ministry, directly tying compliance to Section 79 due diligence. This allows the executive to dictate substantive penal obligations without parliamentary oversight.
The rules also radically weaponize the Inter-Departmental Committee (IDC). Altering Rule 14(2) and Rule 14(5), the draft strips the prerequisite of a formal user complaint, empowering the IDC to examine matters suo motu. Bypassing self-regulatory bodies entirely, the MIB can now directly refer independent creators to the IDC, initiating emergency blocking protocols under Rules 15 and 16 with zero due process.
Finally, the draft expands data surveillance by inserting without prejudice to requirements under other laws into the data retention clauses of Rule 3(1)(g) and Rule 3(1)(h). This loophole directly subverts the "Right to Erasure" established under Section 8(7) of the DPDP Act, 2023, enabling indefinite state data hoarding.
This executive aggrandisement inevitably collided with the judiciary, culminating in the highly consequential litigation of Kunal Kamra v. Union of India.
The dispute centered on the April 2023 IT Rule amendments, which created a centralized Fact Check Unit (FCU) empowered to label any information relating to the "business of the Central Government" as "fake, false, or misleading." If flagged, intermediaries had to remove the content or lose Safe Harbor. Comedian Kunal Kamra, alongside media guilds, challenged the rule as a violation of Articles 14, 19(1)(a), and 19(1)(g).
In September 2024, the Bombay High Court struck down the FCU as unconstitutional and arbitrary, noting its chilling effect. The Supreme Court refused to stay the order, citing its "paramount constitutional importance." However, the state immediately circumvented this ruling, despite possessing vast blocking powers under Section 69A of the IT Act. Through the March 30, 2026 draft IT Rules, the government empowered the IDC to act suo motu and made executive advisories binding under Rule 3(4). By doing so, the state effectively used delegated legislation to reconstruct the struck-down FCU as a decentralized, shadow censorship board.
Compliance Ceiling
The convergence of the Authenticity and Accountability flanks has fully realized a "Compliance Ceiling" that operates as a regressive tax, fundamentally distorting the digital free market. While hyper-scaled intermediaries can absorb these costs, the obligations are economically devastating for independent creators and mid-sized news outlets, who are forced to divert limited funds from journalism to legal compliance. Solo creators simply cannot afford the legal teams required to interpret vague advisories.
Facing the loss of Safe Harbor and potential criminal liability, platforms are economically forced into automated, defensive over-censorship. Rather than evaluating if an upload such as a satirical, AI-generated image constitutes protected political speech under Article 19(1)(a), algorithms will instantly flag and purge it as potentially unlawful SGI.
This aggressive regulation of the digital sphere stands in deeply ironic contrast to the state's posture toward traditional corporations. On March 27, 2026, MoS Jitin Prasada introduced the Jan Vishwas (Amendment of Provisions) Bill, 2026, explicitly aimed at "Ease of Doing Business" by decriminalizing 717 provisions across 79 Central Acts. Yet, hypocritically, the government relentlessly weaponized the IT Rules to increase strict liability and criminal threats for independent digital actors.
To protect their multi-billion dollar enterprises from strict liability, platforms will systematically silence creators without any formal legal process.
From 2024 to 2026, the Safe Harbor doctrine has been systematically dismantled from within, substituting judicial oversight with algorithmic pre-censorship, three-hour takedown windows, and unchecked executive power. To balance free expression with curbing targeted misinformation, policymakers must abandon this blunt approach for a Tiered Regulatory Framework. This model must clearly distinguish harmful algorithmic manipulation from creative expression, exempting micro-creators from onerous broadcaster-level compliance and CEC pre-certification. Crucially, the unconstitutional link between soft-law advisories and the loss of Safe Harbor (draft Rule 3(4)) must be permanently severed. Section 79 protection should only be voided by reasoned judicial orders, not executive whim. Without these vital recalibrations, the Indian digital public square risks becoming a highly sanitized, state-monitored broadcast network devoid of democratic dissent.