← Back to blog
NewsAbout 6 min read

Bombay High Court Draws the Line on AI Deepfakes: 18 Defendants, a John Doe Order, and a Three-Part Personality Rights Framework

Published Oct 7, 2026
Bombay High Court Draws the Line on AI Deepfakes: 18 Defendants, a John Doe Order, and a Three-Part Personality Rights Framework

On October 1, 2026, an interim injunction from the Bombay High Court gave “AI face-swapping” its first clear judicial coordinates on the South Asian subcontinent. In hearing a personality rights suit brought by actor Samantha Ruth Prabhu, Justice Madhav Jamdar ruled to prohibit any unauthorized creation, dissemination, or commercial use of AI deepfakes, manipulated images, and synthesized voice of her.

The weight of this injunction lies not in the amount of damages, but in the framework it builds: 18 defendants, a John Doe order, and a claim that splits “personality rights” into three independent rights.

Why the 18 Defendants Include Both Platforms and Regulators

The list of defendants in the suit is worth examining one by one. On the technology platform side, Meta (which operates Facebook and Instagram), Google, and Amazon are included; on the government side, the Ministry of Electronics and Information Technology (MeitY) and the Department of Telecommunications (DoT) are also listed as respondents.

Bringing regulators into a civil personality rights lawsuit is an uncommon move. The plaintiff’s lawyers explain it as a matter of enforcement: if the court only orders platforms to take content down, without cooperation from the telecommunications and information departments, the injunction is worthless on cross-border servers. Listing the competent authorities as parties means binding the enforcement chain into the judgment itself in advance.

The basis for holding platforms accountable lies in Rule 3 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. That rule requires intermediaries to exercise “due diligence” to prevent unauthorized publication and online harassment. The court’s citation of this rule in its ruling means platforms can no longer use “we are just a conduit” to escape liability.

The John Doe Order: Even Those You Can’t Catch Must Be Held Accountable

The John Doe order is a common-law device aimed at “unidentified defendants.” In this case, besides the 17 named entities, numerous anonymous accounts are generating and spreading content in the shadows. The injunction authorizes the plaintiff to retain the right to pursue these “Doe defendants” later.

The practical significance of this design is straightforward. Deepfake content is often generated by throwaway accounts, and the window for evidence collection is extremely short. By the time the court finishes proceedings against named defendants, the original accounts have long been deleted, but the content itself is still circulating between platforms. The John Doe order writes “unknown infringers” into the document in advance, so that when new wrongdoers are discovered later, there is no need to file a new case.

Personality Rights Are Split into Three: Privacy, Dignity, and Economic Value

The truly precedent-setting part is the court’s interpretation of the nature of the rights. The order cites Article 19(1)(a) and Article 21 of the Constitution, as well as Section 38B of the Copyright Act, and breaks the rights infringed upon the plaintiff into three layers:

The first layer is privacy and personal dignity. Article 21’s guarantee of the right to life and personal liberty, as interpreted by the court, includes the right to privacy and personal dignity. The key point in this passage is that the court explicitly states: digitally manipulated sexual content infringes privacy and dignity even if no one is selling it. The harm is not limited to commercial monetization.

Three glass vessels of different heights on a dark walnut desk, each half-filled with soft luminous mist

The second layer is the performer’s moral rights. Section 38B of the Copyright Act protects a performer’s moral rights in their performance, distinct from the economic rights in a work. This means that even if the use of a certain piece of footage has formally obtained some kind of authorization, moral rights can still be asserted independently.

The third layer is what is usually called personality rights and publicity rights. This layer is tied to commercial value, recognizing that a recognizable public image itself has protectable economic interests.

The three layers of rights stand side by side rather than replacing one another. This point will have the greatest impact on subsequent cases: plaintiffs no longer need to prove “how much money I lost” in order to obtain a remedy.

Why This Case Is Not an Isolated Example

The Samantha case is not the first time Indian courts have confronted AI identity abuse. In June 2026, the Bombay High Court heard a similar application from actor Preity Zinta, involving AI deepfake videos, manipulated images, and an AI chatbot persona. Earlier, actors such as Hrithik Roshan, Akshay Kumar, and Suniel Shetty had successively obtained restraining orders. In Abhishek Bachchan’s case, the Delhi High Court’s injunction explicitly listed “AI, generative AI, machine learning, deepfakes, face-swapping” one by one within its scope of restriction.

Viewed together, these cases show that India is taking a path of “case-by-case accumulation” rather than “separate legislation.” India currently has no dedicated personality rights law; its protection system is assembled from constitutional rights, intellectual property principles, and common-law remedies (such as passing off and misappropriation of goodwill). The novelty of the Samantha case is that it writes this assembled path systematically into the context of AI deepfakes for the first time.

The case will be heard again on December 10, when the court may address permanent relief and damages.

What It Means for People Making AI Content

If these judicial signals are translated into concrete constraints on the creative side, there are roughly three.

First, recognizable images of real people require explicit authorization. “Recognizable” here is not limited to faces; it also includes identifiable attributes such as name, voice, signature, and mannerisms. Creating an AI-generated character that “looks like a certain public figure” still carries risk under India’s judicial framework, even if labeled as fictional.

Second, the scope of authorization must clearly state the purpose. Section 38B separates moral rights, meaning that an authorization “permitted for use A” cannot automatically extend to use B. Using an actor’s likeness for advertising and for parody are two different things when it comes to the rights holder’s claims.

Third, platforms’ takedown obligations are hardening. Rule 3’s “due diligence” was written into the ruling, and intermediaries’ response time and burden of proof after receiving notice will both become points of contention going forward.

At the same time, the other side of the Atlantic is taking a different path. The SAG-AFTRA television and theatrical agreement, which took effect on July 1, 2026, writes “digital replicas” into contracts, explicitly stating that “scanless replicas” (images generated from filmed material rather than scans) are equally protected, and prohibits using digital replicas of minor performers to depict nudity or simulated sexual acts. America’s path is union contracts; India’s path is constitutional litigation: the direction is the same, the tools are different.

How far the Bombay High Court’s injunction ultimately goes will depend on the formal ruling in December. But it has already done one thing: it has moved the question “can AI use someone’s face?” out of discussions of technical feasibility and into an enforceable judicial process.

Related articles