AI, Deepfakes and Personality Rights: Protecting Digital Identity in India

In 2023, a convincing deepfake of a prominent Indian actor spread across the internet before any effective remedy could contain it.

Introduction

In 2023, a convincing deepfake of a prominent Indian actor spread across the internet before any effective remedy could contain it. The episode exposed a broader threat: artificial intelligence can now reproduce a person's face, voice and mannerisms at scale, while Indian law still offers fragmented protection for identity and dignity. Less visible victims face the same harm with fewer resources and far less public attention.

Powerful deepfake tools are now widely accessible and require little specialist knowledge. That accessibility has accelerated fraud, non-consensual sexual imagery and identity misuse, turning personality rights from a celebrity concern into an everyday problem.

The harm immediately affects their reputation, dignity, and mental health, and that too deeply. These AI videos have already affected victims before they reach court. In this gap between technological harm and legal remedy lies the central crisis that this paper addresses.

At the heart of these violations lies a right that law has struggled to name - the personality right. Personality rights, which recognise every person as a physical and spiritual moral being (Joubert, 1953, pp. 130-131) (Neethling et al, 2005, p. 24) and guarantee his enjoyment of his own sense of existence (von Bar, 2000, p. 61) They are today protected in various countries to a greater or lesser degree. It is not just a commercial right; it is rooted in the idea that every person has inherent dignity worth protecting, the foundation of all human rights that artificial intelligence now places under unprecedented threat.

The protection of human dignity is not a novel concern; it lies at the very core of international human rights law. Article 12 of the Universal Declaration of Human Rights and article 17 of the International Covenant on Civil and Political Rights Both provisions guarantee legal protection against arbitrary or unlawful intrusions into privacy, family life, home, communications, honour, and reputation. These two treaties or instruments were adopted in 1948 and 1966, respectively, so the question therefore arises whether these foundational frameworks remain adequate to protect digital personality in the AI era.

By early 2026, India will have approximately 958 million active internet users, according to IAMAI. (Internet and Mobile Association of India [IAMAI], 2025). The state of digital rights in India is very poor. India does not have a standalone legislation statute for personality rights; the courts are still relying on indirect routes like Justice K. S. Puttaswamy (Retd.) v. Union of India, IPR laws, and passing off doctrine, but none of these was designed to address AI-generated identity violations. Recent incidents of many celebrities' deepfake videos exposed this gap starkly, with courts issuing reactive interim orders in the absence of any legislative foundation.

India, therefore, represents a critical and urgent case study of how existing legal systems fail to protect digital personality.

It is not that no attention is being given to dignity or law, but is that enough? Studies either examine data privacy alone or restrict personality rights. No comprehensive analysis has yet addressed personality rights as a universal human rights concern, bridging international law frameworks, India's legislative vacuum, and the need for a cohesive global regulatory response. This paper attempts to fill precisely that gap.

Human Dignity, Digital Identity and Personality Rights in an Artificial Intelligence Age

AI-based personas, deep faking, and digital twins threaten the personal dignity of a person, interfere with human perception, and alter the digital identity of individuals in the virtual world. Such a growth would bring the personality rights close to the larger dignity-based framework of human rights, so that technological advancements do not undermine the rights to morality and laws that were historically granted to the human person.

Concept of Human Dignity in the Digital Age

Human dignity is the absolute core of modern human rights law and ethical paradigms that have imposed themselves on the emerging technologies. Basically, dignity refers to the natural and the equivalent value that all humans have, which is an absolute, non-denumerably infinite, intrinsic, and objective value of human real persons (Hanna & Kazim, 2021) that compels it to be imperative that people be treated as ends and not as a means of achieving economic, political and technological ends.

Taking the view of Kantian theory of human dignity, which says that human beings inherently possess human dignity, and also the reality of their free agency, which includes free will, autonomy, and responsibility as basic premises of digital ethics and AI ethics. (Kant, 1996)

Dignity is captured in major instruments of international human rights law, such as the Universal Declaration of Human Rights, which acknowledges the naturally existing dignity of every member of the human family as the pillar motivating liberty, fairness and harmony. The European and global AI ethics guidelines, as well as many other policy frameworks, implicitly consider dignity as the foundation of the rights of privacy, autonomy, and non-discrimination in the systems of algorithms.

However, Rights such as autonomy, due process, equality, dignity and transparency may remain formally recognised, yet the everyday operational rules that shape digital life are often defined through private ordering and opaque systems rather than through public, contestable procedures. (Alvarez-Pallete et al, 2026).

Dignity, Privacy and Datafication of the Person

Privacy protects the informational enclosures that human beings require to be in control of personal data and identity. These issues of commercialisation of dignity are sharp in the field of AI since algorithmic systems bridge the social association and decision-making. Automated profiling, predictive analytics and behavioural targeting threaten to make people statistical abstractions, thus forcing scholars to refer to datafication of the person. The innate moral value of the individual can be lost to computational efficiency when human identity is approached as a collection of data that can be predicted and best optimised.

Individuals' data must not simply be seen as an economic resource but must be regarded as an extension of the human personality, and it should be afforded protection based on dignity and human rights.

The rising adoption of artificial intelligence in daily life has radically altered the process of the construction and representation of personal identity. AI systems influence our choices, behaviours, relationships, and perceptions of self and others (Yadav,2025) In the online space, identity is no longer tied to physical characteristics or self-identification. Rather, it is the result of a convolution of traces of data, images, behavioural forecasts and algorithmic deductions of the way people are viewed and affected on the internet.

Digital Identity as Algorithmic Construction

Nevertheless, the digital identity may be defined as the combination of the data-based depiction in the forms in which a person is recognised, classified, and assessed in digital systems. Such representations can contain biometric data, social media data, browsing history, changes in personality generated by algorithms and predictive scores based upon creditworthiness, employability or consumer behaviour. Digital identity is a complex technical and legal-political category that requires a holistic approach (Gstrein & Kochenov, 2020).

Another concept which emerged significantly is personality rights, which means to defend the identity of the individual, including their name, image, likeness, voice, signature and reputation. All these rights were aimed at the protection of not only the economic but also the dignitary interests of people, in terms of avoiding the unauthorised exploitation or manipulation of the personal identity. In the 18th and 19th centuries, the basic protection for image rights in England was provided through contract law principles and breach of confidence. (Prince Albert v. Strange, 1848). The development of artificial intelligence, however, has massively increased the extent to which identity is manipulated.

Deepfakes, voice cloning, and generative avatars are some of the technologies that enable the development of highly realistic digital replicas of people without permission. In the 21st century, significant developments, largely driven by technological advancements, resulted in a substantial increase in the value of personalities' names and images compared to previous decades (Augustian & Shankar, 2025).

Laws of the past were mostly centred on physical and recognisable records like photographs or recorded tones. However, when compared to artificial intelligence, the artificial identities that AI systems are capable of creating are not exactly copies of a particular original source but are composite or fabricated and therefore can be considered identities alike. Therefore, legalism in which the concept of likeness or defamation is based only on the traditional definition of psychological similarity, relying on the dominant sketches in life, is finding it difficult to handle such new harms.

International Human Rights Framework and Personality Rights in the AI Era The concept of rights to personality is intended to safeguard how a person is represented to the world, giving them control over their public portrayal and preventing unwanted interference in their private life. Personality rights, traditionally viewed as an aspect of tort law or intellectual property, as it was seen in the case of Haelan Laboratories, Inc. v. Topps Chewing Gum, Inc. (1953), which established "right to publicity" as a transferable property interest, but the AI have the technological ability to reproduce and/or manipulate human identity without transferring.

The reference to the human rights principles of the UDHR and the ICCPR provides a plausible regulatory basis for the regulation of AI technologies. Right to personality should not be limited to celebrities but also extend to all persons whose personal information, identity and personality are being cloned or duplicated.

Human Dignity and Privacy under the UDHR

The accelerated evolution of artificial intelligence, especially deepfakes, biometric profiling, and synthetic voice corpora, is a major threat to personal identity and reputation in online spaces. Such technologies have the ability to reproduce or edit the image, voice or likeness of an individual without their permission, which may lead to disrespect of the dignity and reputation of a person. The international human rights law provides a powerful normative basis to deal with such harms.

The concept of dignity, privacy, honour and reputation that are the core principles discussed in the United Declaration of Human Rights (UDHR) and the International Covenant on Civil and Political Rights (ICCPR), slowly come to play in the realms of digital identity and AI governance. UDHR entrenches human dignity as the main premise of the international human rights framework.

Its Preamble, which states that "Whereas recognition of the inherent dignity and of the equal and inalienable rights of all members of the human family is the foundation of freedom, justice and peace in the world" (United Nations, 1948, preamble) and Article 1, which states that "All human beings are born free and equal in dignity and rights". These stipulations are an expression of the notion that each person has an intrinsic value that should be honoured everywhere, including the electronic space (United Nations, 1948, art. 1). Article 12 even goes on to secure the anti-arbitrary interference with the privacy of individuals and attacks on their honour as well as reputation (United Nations, 1948, art. 12).

These protections specifically extend to the field of synthetic media technologies like deepfakes and manipulated audio in the era of AI, where it is possible to create fake images and harm personal identity in the context of public discussion.

ICCPR, Informational Privacy and Digital Rights Evolution

These principles are strengthened and made into law under the ICCPR. Its Preamble repeats the fact that human rights are based on the inherent dignity of the human person, and Article 17 states about the protection of personal honour and reputation, and States are under an obligation to provide adequate legislation to that end (United Nations, 1966, art. 17). Provision must also be made for everyone effectively to be able to protect themselves against any unlawful attacks that do occur and to have an effective remedy against those responsible.

The way these provisions have been construed by the United Nations Human Rights Committee, especially in the General Comment No. 16, gives a clear understanding that privacy is not limited to the physical encroachment but also in informational privacy and security of personal information. This observation is very applicable in the digital world, wherein AI engines highly depend on gathering and processing personal data and biometric identities, behavioural patterns, to generate algorithmic images or simulated expressions. Digital rights are often associated with new rights.

In this case, they include the right to be forgotten, the right to the Internet, and the right to anonymity, and according to scholars, the conventional defence of dignity should be changed into the notion of digital dignity, as the right of individuals to control the way their identity is reproduced and represented on the Internet can be implemented.

Judicial And Legal Insights of Indians to Personality Rights.

The rights on personality have the strongest grounds in India with regards to the Articles 21 of the Constitution in the country that guarantees the right to life and personal liberty. The meaning of judicial vocation has expanded this provision and has incorporated to it the dignity, autonomy, and privacy. The historic case was- Justice K. S. Puttaswamy v. In Union of India, 2017 privacy has been recognized as a fundamental right and also right to be left alone Therefore, personal identity has constitutional protection, which was supported in R. Rajagopal v. state of Tamil Nadu,1994.

Personality rights protect attributes such as a person's name, image, voice and likeness. Unauthorised deepfakes, voice clones and AI impersonations threaten dignity and autonomy because they distort identity without consent.

This safeguard, however, largely disputes with Article 19(1) (a) which determines the freedom of speech and expression upon which the courts must then create a balance between the identity protection and the freedom of expression. In Jaikishan Kakubhai Saraf v. Peppy Store,2017, the court dismissed the relief on the basis that a meme only encourages but never harms the persona of the plaintiff. Such decisions illustrate that no set of dogma existed that was going to declare out legitimate use of expression and an exploitative use. Even though the reasonable restrictions in Article 19(2)[7] are permissible, the lack of a legal interpretation results in the situation where case-by-case resolutions occur.

This, is confusing especially in the virtual world where expression and exploitation often intersect. As a result, constitutional protection is inconsistent in both theory and practice, despite its seeming strength.

Case Law on Personality Rights in India Without a specific statute, the Indian courts have come to invent personality rights progressively based on the case law, especially in the commercial sense of celebrities. In D. M. Entertainment Pvt. Ltd. v. Baby Gift House, 2010, the court prohibited the infringement through the sale of the dolls, which looked like singer Daler Mehndi, by barring false endorsement and passing off, which the court understood as the abuse of personality rights. This was the introduction of the right of publicity to the Indian jurisprudence.

This was further enhanced in Titan Industries Ltd vs Ramkumar Jewellers, 2012, where the use of celebrity images without authorisation to do so was not allowed to be used in advertising. On the same note, in Shivaji Rao Gaikwad vs. Varsha Productions,2015, the Madras High Court protected the unique identity of a celebrity against commercial exploitation by acknowledging the existence of commercial value in identity.

The last cases indicate a more sophisticated and mixed technique of balancing privacy and intellectual property. In Arijit Singh v. Codible Ventures LLP,2023, and Abhishek Bachchan v. the Bollywood Tee Shop,2025, the court ordered injunctions on the unauthorised use of names, images and voices through digital means. However, in the latter, the court specifically attributed such abuse to infringement of dignity in Article 21, particularly in cases where technology represented the individual in false or humiliating situations.

But even the Indian jurisprudence is still disjointed. Courts oscillate between a privacy-based approach emphasising dignity and an intellectual property approach emphasising commercial exploitation. This two-sidedness leads to the ambiguity in the doctrine, especially whether protection is based on commercial value, misrepresentation, or identifiability as such. It also brings up questions of the fact that non-celebrities only have partial defences since their identities can be used against them without necessarily incurring economic loss, but at a high personal cost.

Legal Instruments and their limitations India is presently defending on an ad hoc basis of laws which include: the Copyright Act, 1957, the Trademarks Act, 1999, the Information Technology Act, 2000 and passing off, which ensures that legislation exists to undertake the prior. Although they offer partial protection, they are structurally ineffective, particularly regarding AI-based harms.

Copyright Act,1957 has few protections in the form of moral rights and performers rights. These only secure the application of certain performances and the integrity of such works, not identity traits of a person, like name, image, or voice, in a performance beyond a set performance. In addition, the Act does not solve the current problems of deepfakes, synthetic media and AI-generated impersonation, which causes the courts to interpret it broadly.

Only the situation when the personality attributes are commercialised as source identifiers is covered by the Trademarks Act, 1999. It must also show consumer confusion or fraudulence of endorsement, so non-commercial misuse like memes or parody is not permitted. This practice is commercial and restricts its utility in the protection of dignity and individual autonomy.

The Information Technology Act,2000 offers such a mechanism to mitigate against certain types of digital wrongs, but there are no explicit provisions against identity manipulation that relies on AI. Its structure is still procedural as opposed to rights-based, providing little protection substantively. Correspondingly, passing off under condition involves the demonstration of goodwill and misrepresentation, which is why it is not accessible to persons lacking an already formed commercial reputation.

The Indian system can be described as a fragmented system. In this condition, courts have gone ahead to offer protection by interpreting the law creatively. The rate at which AI technologies are trending reveals the shortcomings of this patchwork. Lack of specific statutory guidelines brings about disparity, time wastage and excessive dependence on court discretion.

The Personality Rights statute should thus be a comprehensive one that balances the constitutional values of fairness and independence with the corporations against which it is proposed, but which also seeks to address the new technological harms like deepfakes and voice cloning to provide the transparency, stability, and proper implementation in the changing digital landscape in India.

Regulatory Architecture and Way Forward

In the preceding section have demonstrated that AI driven threat to personality rights is alarming and cautious. and inadequately addressed by the existing legal framework. both in India and internationally. gradually through judicial responses and fragmented statutory provisions, are no longer sufficient to meet the current AI threat to digital rights. Right now, we are simply in need of not just legal reforms but a total wholesale regulatory framework, operating both domestically and globally on these legal matters where the rights of the individual should be placed at the centre and their dignity seen as primary.

International Regulatory Directions

While Indian courts have significantly recognised personality rights through constitutional and common law principles. There is an urgency of AI driven identity violations regulatory framework that is borderless and that transcends domestic jurisdictions entirely. Deepfake was created in one country, the scammer was from another country, and the victim was from a third country. That is why, meaningfully, this will not happen with a good regulatory framework in one country. There is an urgent need for a global regulatory framework.

existing international effects, while it is promising, it remains insufficient.

The EU AI Act prohibits specified biometric-categorisation practices that infer sensitive traits such as race or political opinion. Its carefully defined exceptions do not erase the broader principle: biometric systems that classify people by sensitive characteristics require strict legal limits and oversight.

Therefore, respect, protection and promotion of human dignity and rights as established by international law, including international human rights law, is essential throughout the life cycle of AI systems, (UNESCO, 2021) However, neither instrument creates a binding, universally enforceable right against AI-driven personality violations - leaving global protection critically incomplete.

urgently the international community needs a dedicated, legally binding instrument specifically addressing digital personality rights. There is need of development in competent standard like:

(i) obligatory authorization or informed consent by any AI system utilizing an individual of his image, voice or likeness.

(ii) borderless digital identity rights deletion right of action.

(iii) a cross-border enforcement system, which would have the technology companies directly responsible in the case of violations.

Duties of States and Platforms

The international regulatory framework direction gains meaningful force only when two parties, such as states and digital platforms, can prevent AI-driven personality violations. Without both, regulations will appear merely aspirational and not protective.

States bear an obligation under Article 2 of ICCPR that States Parties must refrain from violation of the rights recognised by the Covenant, and any restrictions on any of those rights must be permissible under the relevant provisions of the Covenant. Where such restrictions are made, States must demonstrate their necessity and only take such measures as are proportionate to the pursuance of legitimate aims to ensure continuous and effective protection of Covenant rights, (United Nations Human Rights Committee, 2004, para.

8) It demands legislation that moves beyond reactive judicial remedies to a proactive regulatory framework like criminal acquittal against non-consensual deepfake, mandating algorithms and transparency and establishing dedicated enforcement bodies that are capable of responding at the speed at which digital harm spread.

Section 79 of the Information Technology Act, 2000 (hereinafter referred to as the "IT Act"), provides a safe harbour to intermediaries, including social media platforms, ISPs, and hosting services for third-party content, provided they observe due diligence and act as neutral conduits, and the same has been observed by the Supreme Court of India in Shreya Singhal v. Union of India (2015). But it is structurally inadequate, where the platform profits from the very system enabling identity violation. The platform must bear a legal obligation like mandatory takedown of non-consensual deepfakes within a defined time frame, clear labelling of AI-generated material.

Furthermore, AI developers must conduct a mandatory personality rights impact assessment before deploying systems capable of identity manipulation.

Systemic Risk of Profiling and Datafication

The injury to dignity is structural as well as personal. Algorithmic profiles can classify and commercially exploit entire communities through identities they did not choose and cannot readily contest. When an AI system constructs a person for profit, it does more than process data: it appropriates identity and weakens individual autonomy.

India's DPDPA 2023 addresses data protection but applies a uniform standard to all personal data, leaving personality-linked attributes particularly vulnerable to AI-driven exploitation. It fails to recognise that permanent identity-linked data are inseparable from the individual, creating a critical gap where deepfakes and impersonation proliferate unchecked (Potluri & Shubhranshu, 2025), but it is failing to recognise the personality rights dimension of profiling. gap between data law and human rights law is precisely where personality rights violations now proliferate unchecked.

The essential thing that is needed is the accountability of AI in the form of algorithms that is obligatory and data minimisation, a ban on personality profiling without informed consent, and auditing of AI systems, which create behavioural identities on scale. The stealth movement of personality rights is called datafication, and it should be regulated actively as opposed to being responsively addressed through legislation.

Conclusion

Artificial intelligence has not only brought new technologies, but has also produced new forms of human rights violations, including tools to hide or destroy identity before any form of legal redress can be properly used. And because of lack of attention of the legislators, not only the abstract gaps of the law but also actual human rights dignity are being impacted.

The analysis reveals three connected vulnerabilities. Human dignity grounds personality rights in name, image, voice and likeness. International privacy guarantees require reinterpretation for automated identity manipulation. Indian courts have responded creatively from Puttaswamy onwards, but case-by-case protection cannot substitute for clear statutory rules.

cannot substitute for comprehensive legislation, particularly given the structural inadequacy of the alternative, which is used till now, the Copyright Act, Trademark Act and Information Technology Act against AI-generated identity violation. fourth it argued that concrete futures imposed on the state under ICCPR article 2 and on the platform beyond section 79's safe harbour protection are structurally necessary to match the scale of harms artificial intelligence now enables in the current situation.

The DPDPA 2023 has yet to adequately address identity fabrication through deepfakes, vocal approximations through voice cloning, and silent exploitation through algorithmic profiling. Physical identity protection by forsaking digital identity is a paradox to the human rights law which cannot be maintained. The state should enact legislation in advance, platforms should hold enforceable instruments with a binding consent and enforcing identity destruction and enforcing across borders.

AI can now fabricate identity faster than law can protect it. A coherent personality-rights framework is therefore no longer an academic luxury. It is necessary to preserve dignity, autonomy and trust in an environment where seeing and hearing can no longer guarantee authenticity.

Primary materials

Key primary materials: Digital Personal Data Protection Act, 2023 and subordinate legislation; Ministry of Electronics and Information Technology.

Technology and Digital RightsTechnology LawArtificial Intelligence