Who this guide is for: AI platform operators serving Indian users, content platform compliance teams, cloud service providers, social media companies, and legal counsel advising on Indian digital regulation.

In effect since February 20, 2026. MeitY's 2026 amendments to the IT (Intermediary Guidelines) Rules slash the compliance window for removing synthetic content from 36 hours to 3 hours. All intermediaries must label AI-generated content. The definition of "intermediary" is broad: social media, messaging apps, cloud services, search engines, and AI tools that host or transmit user content. Global platforms serving Indian users are in scope.

1. What the Rules Require

MeitY amended the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 with effect from February 20, 2026. The amendments introduce a dedicated framework for Synthetically Generated Information (SGI) and sharply tighten the obligations that intermediaries must meet to retain safe harbor protection under Section 79 of the IT Act.

Core Concept: Synthetically Generated Information (SGI)

SGI covers deepfakes, AI-generated or AI-altered images, video, voice cloning, and realistic algorithmically generated audio-visual content. The definition is intentionally broad. Any content where AI meaningfully contributed to its creation or modification may qualify as SGI.

Key Obligations

2. Who Is Affected

Entity Type In Scope? Key Obligation
Social media platformsYesLabel SGI, 3-hour takedown, user reporting mechanisms
Video and streaming platformsYesLabel SGI content, active content moderation
Messaging applicationsYesLabel SGI in forwarded and broadcast content
Cloud and hosting providersYesRespond to takedown orders within 3 hours
Search enginesYesDe-index flagged SGI content on order
AI tools (generative AI)YesLabel all outputs as AI-generated at point of delivery
Enterprise AI (internal use)ConditionalIn scope if outputs reach public-facing users or are distributed externally

3. Global Platform Exposure

India has over 900 million internet users. Any platform serving Indian users is in scope regardless of where the company is headquartered or incorporated. The territorial scope of the IT Act extends to intermediaries whose services are accessed from Indian territory.

Loss of safe harbor under Section 79 of the IT Act is the nuclear penalty. It means the platform becomes directly liable for all user-generated content it hosts or transmits. At scale, this liability is existential. Maintaining safe harbor requires demonstrable, timely compliance with every obligation in the rules.

Compliance is not a policy matter alone. It requires technical infrastructure: content classification systems, labeling pipelines, takedown workflows, and verifiable evidence of response times. Regulators and courts will ask for proof, not assurances.

Indian courts have demonstrated willingness to order intermediaries to act regardless of the defendant's physical jurisdiction. Cross-border enforcement via mutual legal assistance and asset-level action against Indian operations is an established pattern.

4. SWT3 Procedure Mapping

The following SWT3 procedures provide cryptographic evidence of compliance with India IT Rules 2026 obligations. Each anchor is immutable, timestamped, and independently verifiable.

AI-TRANS.1

Transparency Record

India context: The mandatory labeling requirement means platforms must prove they labeled AI-generated content. Not just that labeling was configured in policy, but that it was applied to specific content at specific times. Configuration evidence is not sufficient; execution evidence is required.

SWT3 witnesses: AI-TRANS.1 records transparency actions at the moment they occur: what content was labeled, when the label was applied, and what disclosure was provided to users. Each anchor is cryptographically tied to the inference that produced the content, creating verifiable evidence of labeling compliance that cannot be retroactively altered.

Assessor Tip

AI-TRANS.1 anchors prove labeling was active and applied. Compare anchor timestamps against content publication timestamps to verify labels were applied before or at the moment of publication, not after a complaint was received.

AI-WATERMARK.1

Content Provenance Marking

India context: The rules require content to be "clearly and prominently" labeled. AI-WATERMARK.1 records both visible labels and embedded metadata, including C2PA provenance manifests and invisible watermarks. When a takedown request arrives, the watermark record proves whether the content was marked as AI-generated at creation time, which is the relevant moment for compliance.

SWT3 witnesses: Records the watermark type applied (visible label, C2PA manifest, steganographic embedding), the content hash at the time of marking, and the timestamp of the marking event. Creates an immutable record of provenance marking that survives any subsequent content distribution or re-encoding.

Assessor Tip

AI-WATERMARK.1 anchors prove provenance marking was applied at creation time. This distinction matters: marking applied after a complaint does not satisfy the rules. Look for anchors with timestamps preceding or matching the content publication event.

AI-INF.1

Inference Provenance

India context: When an AI system generates content that later becomes the subject of a takedown order, the inference provenance record shows exactly when the content was generated, by which model, and under what parameters. This is operationally critical for the 3-hour response window. Locating the source of specific content manually within 3 hours is not feasible at platform scale.

SWT3 witnesses: Every inference produces a Witness Anchor containing the model ID, input and output hashes, generation timestamp, and requesting context. The output hash can be matched directly against content in the takedown order, enabling rapid identification of origin.

Assessor Tip

AI-INF.1 anchors enable rapid content identification via hash lookup. Match the content hash provided in a takedown order against inference records to identify the source within minutes. This is how a 3-hour deadline becomes achievable at scale.

AI-CONSENT.1

Consent and Disclosure

India context: The rules require user notification that they are interacting with AI-generated content. For generative AI platforms, this spans both input-side disclosure (the user understands they are using an AI system) and output-side disclosure (recipients understand the content they are viewing was AI-generated). Both disclosure moments require evidence.

SWT3 witnesses: AI-CONSENT.1 records consent and disclosure events: what was disclosed, to which user session, and at what timestamp. Creates verifiable evidence that users were informed about AI involvement at the point of generation and at the point of consumption.

Assessor Tip

AI-CONSENT.1 anchors prove disclosure was made. This is critical when a user claims they were not informed that content was AI-generated. The anchor provides a timestamped, immutable record of the disclosure event that can be produced in response to a regulatory inquiry or court proceeding.

AI-MARK.1

Content Classification

India context: The SGI definition is broad. Platforms must classify content as synthetically generated or not, and the classification must be accurate. Failing to label AI content violates the rules and risks safe harbor loss. Falsely labeling authentic human-created content as AI undermines user trust and creates separate legal exposure. Accurate classification at scale requires a documented, auditable pipeline.

SWT3 witnesses: AI-MARK.1 records the classification decision for each content item: what content was evaluated, what classification was assigned (synthetic, human, or mixed), and the confidence level of the decision. Creates an audit trail of the classification pipeline's outputs over time.

Assessor Tip

AI-MARK.1 anchors demonstrate the classification pipeline was active and producing consistent decisions. Review confidence level distributions in anchor records to identify potential misclassification patterns before a regulator does.

5. The 3-Hour Window

The shift from 36 hours to 3 hours is not a modest tightening. It is a fundamental change in the operational model required to maintain compliance. Manual content identification, manual provenance tracing, and manual response workflows are not compatible with a 3-hour clock.

Without Governance Records

With SWT3

SWT3 is the notary, not the enforcement mechanism. The platform's takedown infrastructure acts. SWT3 provides the cryptographic evidence record that proves the action was taken, when it was taken, and what content it addressed.

6. Framework Mapping

Framework Relevant Requirements SWT3 Evidence
India IT Rules 2026 Rule 3(1)(d) takedown window, SGI labeling obligation, safe harbor conditions AI-TRANS.1, AI-WATERMARK.1, AI-INF.1
EU AI Act Art. 50 Transparency obligations for AI systems, AI-generated content marking requirements AI-TRANS.1, AI-MARK.1
California SB 942 AI content detection tools requirement, visible and latent disclosure for AI-generated content AI-WATERMARK.1, AI-TRANS.1
DPDP Act (India) Personal data protection obligations, consent requirements for data processing AI-CONSENT.1, CJT jurisdiction fields

7. Quick Reference

Questions an examiner or regulator is likely to ask, and how SWT3 anchors answer them.

Examiner Question SWT3 Evidence
Was this content labeled as AI-generated before it was published? AI-TRANS.1 and AI-WATERMARK.1 timestamps vs. publication timestamp
When was the takedown order received and when did you act? AI-TRANS.1 anchor records the response action with timestamp
Which model generated this content and when? AI-INF.1 anchor: model ID, output hash, generation timestamp
Were users notified that this content was AI-generated? AI-CONSENT.1 anchor: disclosure event, user session, timestamp
How does your classification pipeline decide what counts as SGI? AI-MARK.1 anchor trail: classification decisions, confidence levels, pipeline version
Was the watermark or provenance tag present at creation, not added later? AI-WATERMARK.1 timestamp predates distribution; immutable, cannot be backdated

8. Quick Start

The jurisdiction CJT field tags every anchor with the applicable legal territory. Set it to "IN" for content subject to India IT Rules 2026. This field survives all clearing levels and is available for regulatory queries without requiring full anchor decryption.

from swt3_ai import Witness

witness = Witness(
    tenant_id="your-tenant-id",
    api_key="axm_live_...",
    jurisdiction="IN",         # India IT Rules 2026 scope
    legal_basis="legitimate_interest",
    purpose_class="content_moderation"
)

# Witness the inference that produced AI-generated content
anchor = witness.observe(
    procedure="AI-INF.1",
    model_id="your-model-id",
    input_hash=hash_of_prompt,
    output_hash=hash_of_content,
    metadata={"content_type": "video", "sgi_classification": "synthetic"}
)

# Record the labeling action
label_anchor = witness.observe(
    procedure="AI-TRANS.1",
    metadata={
        "inference_anchor": anchor.fingerprint,
        "label_applied": "AI-generated content",
        "label_visible": True,
        "rule": "India IT Rules 2026 Rule 3(1)(d)"
    }
)

witness.flush()    # Send anchors to the SWT3 ledger

For TypeScript, Rust, C#, Ruby, and Swift implementations, see the SDK documentation. All SDKs support the jurisdiction CJT field with identical behavior.

References