What was notified, and who it actually binds
On 24 August 2026, LawStreet Journal published India Notifies 2026 IT Rules to Regulate AI and Deepfakes: Key Changes Explained, carrying the notification text. Hindustan Times had reported two days earlier, on 22 August, that MeitY was set to notify a portion of the IT Rules for stricter compliances, so the sequencing was public before the gazette copy circulated.
The amendments sit inside the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the same instrument that pulled OTT platforms and digital news publishers into a three-tier grievance structure five years ago. The new material addresses synthetically generated information: content produced or altered by a computer resource so that it appears authentic. The obligations attach to intermediaries, and the enforcement lever is Section 79 of the Information Technology Act, 2000, the safe harbour that protects a platform from liability for third-party content only while it observes due diligence.
On a narrow reading this is platform regulation with no bearing on a mid-size manufacturer running AI-generated product imagery. That reading does not survive contact with how the duty gets discharged. A platform cannot inspect every upload for synthetic origin, so it pushes the question upstream through declarations at upload, warranties in advertiser terms, and provenance metadata expected from the tool that made the asset. The obligation reaches every Indian company shipping AI-generated marketing creative, synthetic product photography, cloned-voice IVR, AI-scripted training video or a customer-facing avatar.
That is where the insurance question starts. A single unlabelled synthetic asset can produce a takedown demand, a defamation notice, an IP claim and a regulatory proceeding. Four different towers respond, and most Indian buyers have never asked which.
Three duties, three different claim shapes
Strip the notification to its operative mechanics and there are three duties. Each one fails in a different way, and each failure lands on a different policy.
- Labelling. Synthetically generated content must be identifiable as such to the person consuming it. The failure mode is an asset that goes out unlabelled, or labelled in a form the rules do not accept. The resulting harm is that a viewer treats fabricated material as real.
- Traceability. Provenance information must travel with the asset rather than living in a project folder. The failure mode is an asset whose origin cannot be reconstructed after the fact, which converts an arguable compliance position into an indefensible one.
- Takedown and grievance response. Once notified, content has to come down inside the timelines the 2021 Rules already set. The failure mode is a missed clock, and the consequence is exposure the intermediary would otherwise have been shielded from.
The three duties fail together in the ordinary case, because one absent process causes all three: nobody logged which tool generated the asset, so nobody could label it, and when the notice arrived nobody could find it.
Media liability answers first, on wordings written before synthetic content existed
The claimant in the ordinary case is a person or business harmed by what the asset said or showed. Defamation, false endorsement, passing off, copyright infringement in a generated image, breach of personality rights in a synthetic likeness: these are content torts, and content torts are what media liability covers. Indian media liability wordings, sold to OTT platforms, publishers, ad agencies and increasingly to in-house brand teams, are the natural first responder. The corpus post on media liability insurance in India sets out the base product.
Three cuts in the wording decide whether it responds to a synthetic-media claim.
The definition of covered material. Older wordings enumerate: editorial content, advertising, broadcast, published material. An AI-generated avatar in a WhatsApp support flow, or a cloned voice on an outbound call, may not read as any of those. Ask for a definition that turns on communication to a third party rather than on a list of media formats.
The deliberate-acts exclusion. Almost every media liability wording excludes intentional or knowing wrongdoing. Publishing an unlabelled synthetic asset is a deliberate act of publication, and an insurer looking for a way out will argue the failure to label was knowing. The distinction that matters is between deliberate publication and knowledge of falsity or infringement. Get the exclusion narrowed to the latter, in writing.
Regulatory defence costs. A MeitY proceeding or a takedown escalation is not a claim by a third party for damages, so it sits outside the base insuring clause on most wordings. Media liability policies commonly carry a regulatory investigation costs extension with a modest sublimit. Confirm the extension exists, confirm the sublimit is not INR 25 lakh against a INR 15 crore limit, and confirm the definition of regulator names Indian statutory authorities rather than only data-protection regulators.
Technology E&O and professional indemnity: when you generated it for somebody else
A large share of India's synthetic content is produced by someone other than the brand whose name appears on it. Advertising agencies, production houses, martech SaaS vendors, and GCCs running content operations for an overseas parent all sit in that position. For them the exposure is contractual before it is tortious, and the responding tower is technology errors and omissions or professional indemnity.
The claim arrives as an indemnity demand from the client, not a defamation suit from the public. The client received a takedown, or lost safe harbour, or got a consumer-court notice, and the master services agreement says the vendor warranted compliance with applicable law. Two provisions then decide the outcome.
The contractual liability exclusion carves out liability the insured assumed under contract that it would not have had at law. Compliance warranties in an MSA are exactly that. Where a client demands an express warranty that all delivered assets are labelled and traceable under the IT Rules, that warranty is uninsured on a standard PI wording unless the exclusion is amended to preserve cover for liability that would have attached anyway in negligence.
The related-claims clause decides whether a campaign is one claim or two hundred. A single unlabelled template used across a quarter of programmatic placements generates a large number of individual complaints from one root cause. Aggregation to a single claim protects the aggregate limit and costs one retention. Non-aggregation multiplies the retention by the number of notices. The gap map across cyber, PI and D&O towers works through the same aggregation problem for other AI failure modes.
A GCC delivering content services to its parent is usually contracting under an intra-group agreement drafted for transfer-pricing reasons, and those agreements frequently carry uncapped indemnities that no PI tower will follow.
Cyber is mostly the wrong tower, with two real exceptions
Buyers reach for cyber because the word AI is in the sentence. For a labelling failure, cyber almost certainly declines. The operative trigger in an Indian cyber wording is a security failure: unauthorised access, malware, denial of service, compromise of a computer system. A company publishing its own unlabelled synthetic advertisement suffered no security failure. It made a marketing decision.
Two situations flip that.
The first is impersonation running the other way. Where a third party fabricates a synthetic video or voice of your chief executive to defraud a customer, a vendor or your own finance team, the exposure is fraud and reputational harm rather than content liability. Cyber and crime wordings are where that lands, and the boundary between them is the subject of the corpus analysis on deepfake payment fraud, crime cover and cyber cover. Media liability will not respond, because your company did not publish anything.
The second is an account compromise. An attacker takes over a brand's social handle and posts synthetic content that defames a competitor. There is a genuine security failure, so cyber is engaged, but the third-party content liability that follows sits in the media liability extension of the cyber policy rather than in its breach-response section. Those extensions carry small sublimits, commonly a fraction of the cyber aggregate.
D&O answers the regulator, and the named-officer problem
Regulatory action under the IT Rules is directed at the intermediary as an entity, which is awkward for directors and officers liability, a product built around claims against individuals. Indian D&O programmes typically extend entity cover only to securities claims, so a proceeding against the company itself is often outside the tower entirely.
Individuals are still exposed, and the 2021 Rules created the exposure by name. Significant social media intermediaries must appoint a chief compliance officer, a nodal contact person and a resident grievance officer, each a named individual with statutory duties. Where the notified synthetic-media obligations extend that architecture, the people holding those posts carry personal exposure for the platform's due-diligence failures. Confirm that the D&O definition of insured person reaches statutory officers appointed under regulation, not only directors, KMP and employees acting in a managerial capacity. Many wordings do, through an outside-position or employee definition, but the answer should be read rather than assumed. See the product page on directors and officers liability for the base structure.
For the board of a company that is not an intermediary, the D&O exposure is second-order and slower. A synthetic-content failure producing a regulatory proceeding and a revenue hit becomes an allegation that the board approved AI deployment across marketing without a governance framework, a labelling policy or an audit trail. In a listed company that reaches D&O through a securities claim; in a subsidiary, through a parent-company action.
Two mechanical points. Fines and penalties are insurable only to the extent Indian law permits, which is narrower than the wording's own language suggests, so read the local-law rider rather than the extension. And investigation costs cover, which pays for representing an individual in a regulatory proceeding before any claim is made, is the extension that actually gets used in this scenario.
Vendor labels are not compliance: the Spotify divergence
On 18 August 2026, MediaNama set Spotify's AI persona labels against India's synthetic media rules. The comparison generalises well beyond music streaming, and the assumption it tests, that a platform's own label discharges an Indian obligation, is an expensive one for a risk manager to carry into a renewal.
Global platforms and generative tool vendors have each built their own disclosure scheme, designed for their own product surface and their own regulatory priority, usually the EU AI Act's transparency obligations or a voluntary provenance standard. Those schemes were not built to the form, prominence or metadata expectations of an Indian notification issued in August 2026. A label that satisfies a vendor's internal policy is evidence of good faith and nothing more.
The commercial consequence shows up in contracts. A martech vendor's terms may warrant that AI-generated outputs are labelled in accordance with the vendor's AI content policy. An Indian buyer relying on that warranty has bought compliance with a policy document, and the warranty will hold even as the buyer fails the rules. When the takedown arrives, the buyer's recovery against the vendor is limited to that narrow warranty, its liability cap and its jurisdiction clause, while the buyer's own liability to the claimant is uncapped.
Ask the vendor to warrant compliance with the applicable Indian rules as notified rather than compliance with its own labelling policy. A refusal is itself underwriting information, and your broker should put it in the submission rather than leave the insurer to find it at claim time. Keep a per-asset provenance record on your own side as well, because tool vendors change their metadata behaviour between releases without notice.
The renewal questionnaire: nine questions across four towers
Turn the analysis into renewal work. Ask in writing, and take answers as endorsements rather than as broker email. Silence in a wording is resolved by the adjuster, not by the buyer.
Media liability
- Does the definition of covered material reach AI-generated images, synthetic voice, avatars and machine-written copy, whatever the distribution channel?
- Does the deliberate-acts exclusion turn on knowledge of falsity or infringement rather than on the act of publication itself?
- What is the sublimit for regulatory defence costs, and does the definition of regulator include Indian statutory authorities acting under the IT Act?
Technology E&O and professional indemnity
- Is liability arising from a contractual warranty of compliance with the IT Rules preserved, at least to the extent the liability would have attached in negligence?
- How does the related-claims clause aggregate complaints arising from one template, one model version or one campaign?
Cyber
- Has an AI exclusion appeared in the renewal draft that was absent from the expiring wording, and what does it do to the media liability extension?
- What is the sublimit on that media extension, and does it respond to third-party content published from a compromised account?
Directors and officers
- Does the definition of insured person reach statutory officers appointed under regulation, including compliance, nodal and grievance officers?
- Does investigation costs cover respond to a regulatory proceeding before any claim is made against an individual?
Underwriters will ask their own questions in return, and the answers that improve terms are process answers: a written labelling standard, a named owner for synthetic-content review, an asset register recording which tool produced what, and a takedown runbook with tested timelines. A company that can produce those four documents prices differently from one that cannot.