MeitY’s Efforts in Combatting Deepfakes
Recognizing As the Ministry of Electronic and Information Technology (MeitY) continues to invite proposals from academicians, institutions, and industry experts to develop frameworks and tools for AI-related issues through the IndiaAI Mission, it has also funded two AI projects that will deal with matters related to deepfakes as per a status report submitted on 21st November 2024. The Delhi court also ordered the nomination of the members of a nine-member Committee constituted by the MeitY on 20th November 2024 (to address deepfake issues) and asked for a report within three months.
Funded AI projects :
The two projects funded by MeitY are:
- Fake Speech Detection Using Deep Learning Framework- The project was initiated in December 2021 and focuses on detecting fake speech by creating a web interface for detection software this also includes investing in creating a speech verification software platform that is specifically designed for testing fake speech detection systems. It is set to end in December 2024.
- Design and Development of Software for Detecting Deepfake Videos and Images- This project was funded by MeitY from January 2022 to March 2024. It also involved the Centre for Development of Advanced Computing (C-DAC), Kolkata and Hyderabad as they have developed a prototype tool capable of detecting deepfakes. Named FakeCheck, it is designed as a desktop application and a web portal aiming to detect deepfakes without the use of the internet. Reports suggest that it is currently undergoing the testing phase and awaiting feedback.
Apart from these projects, MeitY has released their expression of interest for proposals in four other areas which include:
- Tools that detect AI-generated content along with traceable markers,
- Tools that develop an ethical AI framework for AI systems to be transparent and respect human values,
- An AI risk management and assessment tool that analyses threats and precarious situations of AI-specific risks in public AI use cases and;
- Tools that can assess the resilience of AI in stressful situations such as cyberattacks, national disasters, operational failures, etc.
CyberPeace Outlook
Deepfakes pose significant challenges to critical sectors in India, such as healthcare and education, where manipulated content can lead to crimes like digital impersonation, misinformation, and fraud. The rapid advancement of AI, with developments (regarding regulation) that can’t keep pace, continues to fuel such threats. Recognising these risks, MeitY’s IndiaAI mission, promoting investments and encouraging educational institutions to undertake AI projects that strengthen the country's digital infrastructure comes in as a guiding light. A part of the mission focuses on developing indigenous solutions, including tools for assessment and regulation, to address AI-related threats effectively. While India is making strides in this direction, the global AI landscape is evolving rapidly, with many nations advancing regulations to mitigate AI-driven challenges. Consistent steps, including inviting proposals and funding projects provide the much-needed impetus for the mission to be realized.
References
- https://economictimes.indiatimes.com/tech/technology/meity-dot-at-work-on-projects-for-fair-ai-development/articleshow/115777713.cms?from=mdr
- https://www.hindustantimes.com/india-news/meity-seeks-tools-to-detect-deepfakes-label-ai-generated-content-101734410291642.html
- https://www.msn.com/en-in/news/India/meity-funds-two-ai-projects-to-detect-fake-media-forms-committee-on-deepfakes/ar-AA1vMAlJ
- https://indiaai.gov.in/
Related Blogs

For years, Malaysia governed artificial intelligence the way most countries did before they had to, with guidelines nobody could be fined for ignoring. The National Guidelines on AI Governance and Ethics, published by Malaysia's Ministry of Science, Technology and Innovation back in September 2024, told developers and deployers what "responsible AI" should look like. It just never made anyone legally responsible for anything.
Malaysia is now attempting to change that. On 10 July 2026, the National AI Office (NAIO), operating under the Ministry of Digital, released a Public Consultation Paper for what would become Malaysia's first horizontal AI statute: a single law covering AI across every sector, rather than a patchwork of guidelines, data protection rules, and whatever a particular regulator happens to think about algorithms this year. Written submissions closed on 31 July 2026, and the government has said it wants the Bill tabled and completed before the year is out. That is an aggressive timeline for a law this broad, and it tells you something about how urgently Putrajaya wants this on the books.
Why "horizontal" matters here
Most of the world's AI rules so far have been vertical. A banking regulator handles AI in banking, a health authority handles AI in diagnostics, and everything in between is grey space. Malaysia's own consultation paper is refreshingly candid about the problem this creates: it warns of "differing standards and approaches" building up across sectors, and notes that existing tools only really respond after something has already gone wrong.
The Bill tries to fix that by sitting above the sector specific rules rather than replacing them. It rests on three pillars.
- First, a Central AI Authority, which would still lean on existing regulators (think Bank Negara Malaysia for financial services or the Securities Commission for capital markets) through what the paper calls "Sectoral Leads."
- Second, a set of baseline principles written into law rather than left as suggestions: human dignity, transparency and explainability, accountability, safety and security, and data governance.
- Third, a structure that scales obligations to how dangerous a given AI system actually is, instead of regulating a spam filter and a hospital triage algorithm with the same rulebook.
The mechanics: three tiers, two roles, one authority
The risk framework itself splits into three tiers: Tier 1 for unacceptable risk, Tier 2 for high risk, and Tier 3 for low risk, with obligations scaling up as the potential for harm does. Obligations fall on two kinds of actors: Developers, who materially shape what a system can do, and Deployers, who actually run it in the real world. A single company can be both. This split deliberately echoes the controller and processor distinction from Malaysia's Personal Data Protection Act, though not perfectly, a point several legal commentators have already flagged as a source of future confusion, since a Deployer processing personal data will usually be a controller under the PDPA, while a Developer offering a hosted model might only be a processor.
The Central AI Authority itself is proposed to run three functions: an AI Safety function that maintains the risk framework and oversees testing and incident reporting; an Investigation and Enforcement function with power to demand fact finding and issue directions after incidents; and an AI Enablement function that produces guidance, templates, training, and runs the AI Sandbox, a controlled testing environment meant to let companies experiment before the full weight of compliance lands on them. For smaller businesses without in house compliance teams, that enablement mandate may end up mattering more day to day than the enforcement powers do.
Two more features round out the design. An incident reporting mechanism would require Developers and Deployers to flag not just failures but near misses and unexpected effects, with the public also able to lodge complaints directly. And the Bill's territorial reach is broad by design: it would apply to any AI system designed, developed, or used in Malaysia, regardless of where the underlying infrastructure sits, carving out exemptions only for personal use and national security matters.
How this stacks up against the EU AI Act
Malaysia's drafters have clearly been reading Brussels' homework, and it shows in the structure: a tiered risk model, a central authority, mandatory obligations tied to risk level. But the resemblance is more skeletal than skin deep once you look at the details.
The EU AI Act is a fully codified regulation running to hundreds of pages, with named prohibited practices spelled out in an annex, specific high risk categories listed by sector, and detailed conformity assessment procedures before a system ever reaches the market. Malaysia's Bill, at consultation stage, is still working from principles and a harm list rather than an exhaustive catalogue of prohibited or high risk use cases, closer in spirit to a framework law that leaves the granular detail to subsidiary guidelines and Sectoral Leads. That's partly a function of timeline: the EU spent roughly three years negotiating its Act before adoption, while Malaysia is trying to move from consultation paper to finished statute inside a single year.
Enforcement philosophy differs too. Brussels built the AI Act around compliance that happens before deployment: conformity assessments, technical documentation, and sign off procedures similar to product safety certification, particularly for high risk systems. Malaysia's design leans more on an enablement first posture, with sandboxes, guidance, and incident reporting sitting alongside enforcement powers rather than in front of them, at least as currently framed. Whether that survives contact with the final legislative text is an open question. The consultation drew real pushback from law firms wanting harsher penalty ranges and clearer thresholds, so the version tabled in Parliament may look tougher than the one made public in July.
There's also a jurisdictional difference worth flagging. The EU AI Act has genuine extraterritorial teeth backed by the largest single market in the developed world, which is why companies far outside Europe still comply with it. Malaysia's Bill claims similarly broad reach on paper, covering any system used in Malaysia regardless of where it's hosted, but the practical leverage to enforce that against a foreign Developer is a different question entirely, and one the Edwin Lee and Partners (Law firm based in malaysia) submission specifically raised as a gap needing an international cooperation mechanism.
India and AI Regulation
India has spent the past year deliberately walking in the evolving direction. Through MeitY's India AI Governance Guidelines, released in November 2025 ahead of the India AI Impact Summit, explicitly reject a standalone AI statute in favour of what officials have repeatedly called a "light touch" model: seven guiding principles, trust, people first, innovation, fairness, accountability, transparency, and safety, layered on top of existing law rather than a new one. The Digital Personal Data Protection Act, 2023 and the IT Act, 2000 with amendment rules, do most of the actual legal work, with sector regulators like the RBI and SEBI handling the specifics for their own industries.
The contrast with Malaysia is almost a case study in two governance philosophies. Where Malaysia is building a central authority with enforcement teeth from day one, India has so far preferred advisory bodies, an AI Governance Group and a proposed AI Safety Institute, that shape norms without imposing binding cross sectoral obligations.
Where Malaysia's Bill would be justiciable law with penalties attached, India's framework is closer to a philosophy statement with sandboxes and a national incident database bolted on. That is not a weaker approach so much as a different, and arguably shrewd, bet. India is the world's largest testing ground for AI adoption at scale, from welfare delivery to vernacular language tools, and a heavy compliance regime risks slowing exactly the kind of grassroots experimentation the government is trying to encourage. Betting on existing law and institutional judgment, at least for now, keeps that door open, and it has let India move fast without waiting for a perfect law first.
That said, India's position has been visibly shifting. In July 2026, MeitY Secretary S. Krishnan signalled the government is now exploring dedicated AI legislation after all, a notable departure from the "no early regulation" stance the ministry had held in 2023, and this is likely accelerated by growing concern over deepfakes and synthetic media, which already prompted binding traceability and labelling obligations under amended intermediary rules earlier this year.
The stakes for the next few months
None of this is finished. Malaysia's Bill is still a consultation paper, not enacted law, and the gap between what NAIO proposed in July and what Parliament eventually passes could be significant. Several submissions are already pushing for a wider harm list, sharper enforcement thresholds, and clearer rules for foreign Developers who never set foot in Kuala Lumpur. But the direction is set. Malaysia has decided AI governance can no longer run on goodwill and voluntary guidelines, and it now attempts to write enforceable AI law on a real deadline rather than settling for guidelines. However, the final Bill lives up to that ambition, or gets watered down in the process, is something only the next few months will show.
References
- Ministry of Digital. "Kementerian Digital Mulakan Libat Urus Cadangan Rang Undang Undang Tadbir Urus Kecerdasan Buatan (AI)." 10 July 2026. https://www.digital.gov.my/en-GB/siaran/Kementerian-Digital-Mulakan-Libat-Urus-Cadangan-Rang-Undang-Undang-Tadbir-Urus-Kecerdasan-Buatan-(AI)
- Digital Watch Observatory. "Malaysia launches consultations on AI Governance Bill." July 2026. https://dig.watch/updates/malaysia-ai-governance-bill-consultation
- Baker McKenzie, Wong and Partners. "Malaysia: Public Consultation on the AI Governance Bill." July 2026. https://www.bakermckenzie.com/en/insight/publications/2026/07/malaysia-public-consultation-on-the-ai-governance-bill
- Digital Policy Alert. "Testing requirements in AI Governance Bill" and related entries on the National AI Office consultation. https://digitalpolicyalert.org
- Rahmat Lim and Partners. "National AI Office issues public consultation paper on proposed Artificial Intelligence (AI) Governance Bill." https://www.rahmatlim.com/perspectives/articles/33264/mykh-national-ai-office-issues-public-consultation-paper-on-proposed-artificial-intelligence-ai-governance-bill
- Edwin Lee and Partners. "Malaysia's AI Governance Bill: Our Submission to the Consultation." https://lpplaw.my/ai-governance-malaysia/
- Kiizen. "Overview of the Proposed Malaysia's AI Governance Bill." https://www.kiizen.com.my/proposed-malaysias-ai-governance-bill/
- Zicelegal. "Consultation Alert: Public Consultation on Malaysia's AI Governance Bill." https://www.ziclegal.com/resources/consultation-alert-public-consultation-on-malaysias-ai-governance-bill
- Welcome.AI. "Malaysia's AI Governance Bill Expands Regulation and Accountability for Businesses." July 2026. https://www.welcome.ai/content/malaysias-ai-governance-bill-expands-regulation-and-accountability-for-businesses
- Regulations.ai. "Malaysia AI Regulation Overview." https://regulations.ai/regulations/RAI-MY-NA-SUMMARY-2026
- w.media. "Malaysia to enact AI law." https://w.media/malaysia-to-enact-ai-law/
- VisionIAS. "India's New AI Governance Guidelines Push Hands Off Approach." November 2025. https://visionias.in/blog/current-affairs/indias-new-ai-governance-guidelines-push-hands-off-approach
- EY India. "AI governance guidelines: A bet on innovation." https://www.ey.com/en_in/insights/ai/ai-governance-guidelines-a-bet-on-innovation
- TechnoSports. "Airegulation: Indian Government Finalizes AI Regulation." May 2026. https://technosports.co.in/airegulation-india-framework/
- The AI Track. "India AI Governance Guidelines Released for 2025 to 26." https://theaitrack.com/india-ai-governance-guidelines-2025/
- Lexology, contributed by a law firm. "India's AI Governance Model: MeitY's AI Guidelines and The Evolving Copyright Landscape." March 2026. https://www.lexology.com/library/detail.aspx?g=ffc0c58c-3727-4472-9914-5fa6a33ffffd
- Srishti IAS. "India's First AI Governance Framework 2026: Principles, Oversight, and Inclusive Growth Strategy." February 2026. https://srishtiias.com/india-first-ai-governance-framework-ahead-of-impact-summit-2026/
- Whalesbook. "India Plans Dedicated AI Law, Shifting From Light Touch Approach." July 2026. https://www.whalesbook.com/news/English/other/India-Plans-Dedicated-AI-Law-Shifting-From-Light-Touch-Approach/6a4811c9c7db2a6cf1650f24
- Saikrishna and Associates. "Decoding the India AI Governance Guidelines." November 2025. https://www.saikrishnaassociates.com/decoding-the-india-ai-governance-guidelines/
- News on Air. "MeitY Unveils India AI Governance Guidelines to Promote Safe and Responsible AI Adoption." 5 November 2025. https://www.newsonair.gov.in/meity-unveils-india-ai-governance-guidelines-to-promote-safe-and-responsible-ai-adoption
Contributors
- Maj. Vineet Kumar, Founder & Global President, CyberPeace
- Mr. Neeraj Soni, Senior Research Analyst, Policy & Advocacy, CyberPeace

Executive Summary:
A viral post on X (formerly twitter) shared with misleading captions about Gautam Adani being arrested in public for fraud, bribery and corruption. The charges accuse him, his nephew Sagar Adani and 6 others of his group allegedly defrauding American investors and orchestrating a bribery scheme to secure a multi-billion-dollar solar energy project awarded by the Indian government. Always verify claims before sharing posts/photos as this came out to be AI-generated.

Claim:
An image circulating of public arrest after a US court accused Gautam Adani and executives of bribery.
Fact Check:
There are multiple anomalies as we can see in the picture attached below, (highlighted in red circle) the police officer grabbing Adani’s arm has six fingers. Adani’s other hand is completely absent. The left eye of an officer (marked in blue) is inconsistent with the right. The faces of officers (marked in yellow and green circles) appear distorted, and another officer (shown in pink circle) appears to have a fully covered face. With all this evidence the picture is too distorted for an image to be clicked by a camera.


A thorough examination utilizing AI detection software concluded that the image was synthetically produced.
Conclusion:
A viral image circulating of the public arrest of Gautam Adani after a US court accused of bribery. After analysing the image, it is proved to be an AI-Generated image and there is no authentic information in any news articles. Such misinformation spreads fast and can confuse and harm public perception. Always verify the image by checking for visual inconsistency and using trusted sources to confirm authenticity.
- Claim: Gautam Adani arrested in public by law enforcement agencies
- Claimed On: Instagram and X (Formerly Known As Twitter)
- Fact Check: False and Misleading
.webp)
Introduction
In today's digital economy, data is not only a business asset but also the fuel for innovation, decision-making, and consumer trust. However, the digitisation of services has made personal or sensitive data a top target for cybercriminals. The stakes are high: a data breach can cost millions of fines, cause damage to reputation and devastate the confidence of consumers. Therefore, regulatory compliance and data protection have become a strategic imperative.
From the General Data Protection Regulation (GDPR) in the EU to the Digital Personal Data Protection (DPDP) Act of India, various sector-specific regulations like HIPAA for healthcare in the US, companies are now subject to a web of data protection and compliance laws. The challenge is to balance compliance efforts with strong security, a balance that demands both policy restraint and technical resilience. This blog examines pivotal pillars, shifting trends and actionable best practices for dominating data protection and compliance in 2025 and beyond.
Why Data Protection and Compliance Matter More Than Ever
Data protection isn't just about keeping fines at bay, it's about preserving the relationship with customers, partners and regulators. A 2024 IBM report says the average data-breach cost has now exceeded USD 4.5 million, with regulatory fines constituting a large portion of the cost. In addition to economics, breaches tend to result in intellectual property loss, customer loss and long-term brand attenuation. Compliance ensures organisations remain within certain legislative necessities for collecting, holding, transferring and setting of personal and sensitive information. Failure to conformity can lead to serious penalties: under GDPR, fines could be up to 4% of the company's annual turnover or €20 million, whichever is higher. In regulated sectors like banking and healthcare, compliance breaches can also lead to the suspension of licenses.
Important Regulatory Frameworks Informing 2025
- GDPR and Its Global Ripple Effect
GDPR was enacted in 2018 and continues to have a ripple effect on privacy legislation worldwide. Its tenets of lawfulness, transparency, data minimisation and purpose limitation have been replicated in many jurisdictions such as Brazil's LGPD and South Korea's PIPA.
- India's DPDP Act
The DPDP Act, 2023, gives high importance to consent-based processing of data, transparent notice rules and fiduciary responsibilities for data. With a penalty for default of up to INR 250 crore, it's amongst the most impactful laws for digital personal data protection.
- Sectoral Regulations
- HIPAA for healthcare information in the US.
- PCI DSS for payment card security.
- DORA (Digital Operational Resilience Act) in the EU for financial organisations.
- These industry-specific models generate overlapping compliance responsibilities, making cross-enterprise compliance programs vital.
Key Pillars of a Sound Data Protection & Compliance Program
- Data Governance and Classification
Having insight into what data you have to store, where it is stored and who can have access to it is the keystone of compliance. Organisations need to have data classification policies in place to group information based on sensitivity and impose more rigorous controls on sensitive data.
- Security Controls and Privacy by Design
Strong technical defences, encryption, multi-factor authentication, and intrusion detection are the initial defences. Privacy by design integrated in product development guarantees compliance is thought through from the initial stage, not added on afterwards.
- Consent and Transparency
Contemporary data legislation highlights informed consent. This entails simple, non-technical privacy notices, detailed opt-in choices, and straightforward withdrawal options. Transparency produces trust and lessens legal danger.
- Incident Response and Breach Notification
Most laws demand timely breach notifications, and GDPR insists on reporting within 72 hours. Having a documented incident response plan maintains legal deadlines and reduces harm.
- Employee Training and Awareness
Human mistake is the top source of data breaches. Ongoing training in prevention of phishing, password management, basic cyber hygiene and compliance requirements is crucial.
Upcoming Trends in 2025
- AI-Powered Compliance Monitoring
Organisations are embracing AI-powered solutions to systematically monitor data flows, identify policy breaches and auto-create compliance reports. The solutions assist in closing the loop between IT security teams and compliance officers.
- Cross-Border Data Transfer Mechanisms
With increasingly severe regulations, companies are spending more on secure cross-border data transfer frameworks like Standard Contractual Clauses (SCCs) and Binding Corporate Rules (BCRs).
- Privacy-Enhancing Technologies (PETs)
Methods such as homomorphic encryption and differential privacy are picking up steam, enabling organisations to sift through datasets without revealing sensitive personal data.
- ESG and Data Ethics
Data handling is increasingly becoming a part of Environmental, Social and Governance (ESG) reporting. Ethical utilisation of customer data, not just compliance, has become a reputational differentiator.
Challenges in Implementation
Despite having transparent frameworks, data protection plans encounter challenges like jurisdictions having competing needs, and global compliance is becoming expensive. The emerging technologies, such as generative AI, often bring privacy threats that haven’t been fully covered by legislation. Small and micro enterprises have neither the budget nor the skills to implement enterprise-level compliance programs. Qualifying these challenges often needs a risk-based strategy, allocations of resources to top areas of impact and automating the compliance chores wherever possible.
Best Practices for 2025 and Beyond
In 2025, regulatory compliance and data protection are no longer a precaution or a response to a breach but are strategic drivers of resilience and trust. As regulatory analysis rises, cyber threats evolve, and consumer expectations grow, administrations need to integrate compliance into the very fabric of their actions. By bringing governance and technology together, organisations can break free from a "checklist" mentality and instead adopt a proactive and risk-sensitive approach. Eventually, data protection is not just about not getting in trouble; it's about developing a kind that succeeds in the digital era.
References
- GDPR – Official EU Regulation Page: https://gdpr.eu
- India’s DPDP Act Overview – MeitY: https://www.meity.gov.in/data-protection-framework
- HIPAA – US Department of Health & Human Services: https://www.hhs.gov/hipaa
- PCI DSS Standards: https://www.pcisecuritystandards.org
- IBM Cost of a Data Breach Report 2024: https://www.ibm.com/reports/data-breach
- OECD – Privacy Guidelines: https://www.oecd.org/sti/privacy-guidelines