#FactCheck - Video falsely links a man slapping a cleric to Iran protests
Amid reports that the death toll in Iran’s ongoing protests has risen to 2,571, a video has been widely circulated on social media showing a man slapping a person dressed in clerical attire after an argument. Users sharing the clip claim that public anger in Iran has escalated to the point where people are now physically attacking religious clerics. However, research by the Cyber Peace Foundation has found this claim to be misleading. The research established that the video is not recent and has no connection to the current protests in Iran. In fact, the clip dates back to 2021 and was entirely scripted.
Claim
On January 14, 2026, users on X (formerly Twitter) shared the viral video with captions suggesting that Iranian citizens are openly assaulting clerics amid the ongoing unrest. One such post stated that the situation in Iran had deteriorated so badly that people were now beating religious leaders.
The link, archived version, and screenshot of the post are available below:

Factcheck:
To verify the authenticity of the claim, the Cyber Peace Foundation extracted keyframes from the viral video and conducted a Google reverse image search. This led investigators to a report published on April 19, 2021, on the Persian-language website of Deutsche Welle (DW). The visuals matched the viral clip exactly, confirming that the footage is nearly five years old, not recent. Here is the link to the original video, along with a screenshot:

Further examination of reports by Fars News Agency revealed that Tehran police had conducted a detailed probe into the video at the time and declared it fake and pre-scripted. According to Tehran Police Chief Hossein Rahimi, the individual seen wearing religious attire was not a cleric. Here is the link to the original video, along with a screenshot: He was actually employed at a carpet cleaning shop in Tehran, while the man seen slapping him was his own son.
Police stated that the video was deliberately staged and circulated to provoke public sentiment and create unrest by falsely linking it to religious tensions. Both the father and son were arrested, and images of them in police custody were published in contemporaneous reports. Additional confirmation was found on the Independent Persian website, which had also reported on the incident on April 19, 2021, reiterating that the video was fabricated and unrelated to any protest movement. Here is the link to the original video, along with a screenshot:

Conclusion
The claim that the viral video shows an Iranian protester slapping a cleric during the current wave of protests is false. The video is from 2021, was scripted, and has no link to the ongoing demonstrations in Iran. It is being reshared with a misleading narrative to spread disinformation and inflame public sentiment.c
Related Blogs

Introduction
Global cybersecurity spending is expected to breach USD 210 billion in 2025, a ~10% increase from 2024 (Gartner). This is a result of an evolving and increasingly critical threat landscape enabled by factors such as the proliferation of IoT devices, the adoption of cloud networks, and the increasing size of the internet itself. Yet, breaches, misuse, and resistance persist. In 2025, global attack pressure rose ~21% Y-o-Y ( Q2 averages) (CheckPoint) and confirmed breaches climbed ~15%( Verizon DBIR). This means that rising investment in cybersecurity may not be yielding proportionate reductions in risk. But while mechanisms to strengthen technical defences and regulatory frameworks are constantly evolving, the social element of trust and how to embed it into cybersecurity systems remain largely overlooked.
Human Error and Digital Trust (Individual Trust)
Human error is consistently recognised as the weakest link in cybersecurity. While campaigns focusing on phishing prevention, urging password updates and using two-factor authentication (2FA) exist, relying solely on awareness measures to address human error in cyberspace is like putting a Band-Aid on a bullet wound. Rather, it needs to be examined through the lens of digital trust. As Chui (2022) notes, digital trust rests on security, dependability, integrity, and authenticity. These factors determine whether users comply with cybersecurity protocols. When people view rules as opaque, inconvenient, or imposed without accountability, they are more likely to cut corners, which creates vulnerabilities. Therefore, building digital trust means shifting from blaming people to design: embedding transparency, usability, and shared responsibility towards a culture of cybersecurity so that users are incentivised to make secure choices.
Organisational Trust and Insider Threats (Institutional Trust)
At the organisational level, compliance with cybersecurity protocols is significantly tied to whether employees trust employers/platforms to safeguard their data and treat them with integrity. Insider threats, stemming from both malicious and non-malicious actors, account for nearly 60% of all corporate breaches (Verizon DBIR 2024). A lack of trust in leadership may cause employees to feel disengaged or even act maliciously. Further, a 2022 study by Harvard Business Review finds that adhering to cybersecurity protocols adds to employee workload. When they are perceived as hindering productivity, employees are more likely to intentionally violate these protocols. The stress of working under surveillance systems that feel cumbersome or unreasonable, especially when working remotely, also reduces employee trust and, hence, compliance.
Trust, Inequality, and Vulnerability (Structural Trust)
Cyberspace encompasses a social system of its own since it involves patterned interactions and relationships between human beings. It also reproduces the social structures and resultant vulnerabilities of the physical world. As a result, different sections of society place varying levels of trust in digital systems. Women, rural, and marginalised groups often distrust existing digital security provisions more, and with reason. They are targeted disproportionately by cyber attackers, and yet are underprotected by systems, since these are designed prioritising urban/ male/ elite users. This leads to citizens adopting workarounds like password sharing for “safety” and disengaging from cyber safety discourse, as they find existing systems inaccessible or irrelevant to their realities. Cybersecurity governance that ignores these divides deepens exclusion and mistrust.
Laws and Compliances (Regulatory Trust)
Cybersecurity governance is operationalised in the form of laws, rules, and guidelines. However, these may often backfire due to inadequate design, reducing overall trust in governance mechanisms. For example, CERT-In’s mandate to report breaches within six hours of “noticing” it has been criticised as the steep timeframe being insufficient to generate an effective breach analysis report. Further, the multiplicity of regulatory frameworks in cross-border interactions can be costly and lead to compliance fatigue for organisations. Such factors can undermine organisational and user trust in the regulation’s ability to protect them from cyber attacks, fuelling a check-box-ticking culture for cybersecurity.
Conclusion
Cybersecurity is addressed primarily through code, firewall, and compliance today. But evidence suggests that technological and regulatory fixes, while essential, are insufficient to guarantee secure behaviour and resilient systems. Without trust in institutions, technologies, laws or each other, cybersecurity governance will remain a cat-and-mouse game. Building a trust-based architecture requires mechanisms to improve accountability, reliability, and transparency. It requires participatory designs of security systems and the recognition of unequal vulnerabilities. Thus, unless cybersecurity governance acknowledges that cyberspace is deeply social, investment may not be able to prevent the harms it seeks to curb.
References
- https://www.gartner.com/en/newsroom/press-releases/2025-07-29
- https://blog.checkpoint.com/research/global-cyber-attacks-surge-21-in-q2-2025
- https://www.verizon.com/business/resources/reports/2024-dbir-executive-summary.pdf
- https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf
- https://insights2techinfo.com/wp-content/uploads/2023/08/Building-Digital-Trust-Challenges-and-Strategies-in-Cybersecurity.pdf
- https://www.coe.int/en/web/cyberviolence/cyberviolence-against-women
- https://www.upguard.com/blog/indias-6-hour-data-breach-reporting-rule

Most laws regulate what people do. This one regulates what clock everyone is doing it by, and once you sit with that idea for a moment, it stops sounding like a bureaucratic footnote and starts sounding like something genuinely foundational.
On 27 August 2026, India's Department of Consumer Affairs notified the Legal Metrology (Indian Standard Time) Rules, 2026, making Indian Standard Time the single legally binding reference for every legal, administrative, commercial, and official purpose across the country. The Rules will come into force 180 days after their publication in the Official Gazette, giving government departments, businesses, and institutions a compliance runway to align their systems before the requirement actually bites.
Why time needed a law at all
It might seem strange that a country needs legislation to tell everyone what time it is. India has used IST, a single time zone five and a half hours ahead of Coordinated Universal Time, since 1947. But using a time zone informally and legally mandating it as the sole authoritative reference for every official and commercial transaction are two very different things, and the gap between them is exactly where this rule lives.
The government's own reasoning, laid out in its official statement, centres on a shift most people experience daily without ever thinking about its plumbing. Banking and digital payments, telecommunications networks, railways, power grids, and government record systems all depend on accurate, synchronised time stamps to function correctly. When different systems quietly draw their time from different sources, even by fractions of a second, the resulting inconsistencies can affect the coordination and recording of transactions in ways that are invisible until something goes wrong. A trade executed on a stock exchange, a UPI payment cleared between banks, a railway signal handoff between two junctions, and an emergency service dispatch all depend on every clock in the chain agreeing with every other clock, and until now, India had no single rule compelling that agreement.
The quieter, more interesting part of the rule
Buried inside the announcement is a detail that matters more than the headline. The Rules do not simply declare IST the law of the land; they also authorise the use of NavIC, India's own satellite navigation system, alongside other approved domestic timing sources, as legitimate means of disseminating that time. The government's stated rationale is candid about the current state of affairs: several critical Indian systems presently draw their time from foreign satellite based sources, and building domestic timing infrastructure through NavIC and legal metrology laboratories is intended to reduce that dependence going forward.
That single sentence carries real weight once you consider how global positioning and timing systems actually work. Most of the world's precise digital time synchronisation ultimately traces back to GPS, the American satellite constellation, whose signals also happen to be notoriously easy to disrupt. GPS and other satellite navigation signals arrive at receivers on Earth as extremely weak radio transmissions, weak enough that they can be jammed with cheap equipment or spoofed, meaning an attacker broadcasts a counterfeit signal that mimics a legitimate one closely enough to fool a receiver into accepting false position or timing data. Researchers and government reports going back years have flagged that a large share of critical infrastructure sectors, power grids, financial markets, telecommunications, and transport among them, carry meaningful dependence on GPS derived timing, and a 2017 UK government assessment specifically warned that systematic satellite signal jamming could cause serious disruption to a country's financial, electricity, and communications systems all at once. Cybersecurity researchers have separately demonstrated proof of concept attacks where a deliberately falsified timing signal, rather than a falsified position, was enough to destabilise systems that assumed their clock could always be trusted.
Seen against that backdrop, embedding NavIC as an approved domestic timing source inside a legal metrology framework is not merely a nationalistic footnote about self reliance. It is a genuine resilience decision. A country that can generate, verify, and distribute its own trusted time signal, independent of a foreign satellite constellation that it does not control and cannot secure on its own, has a meaningfully smaller attack surface for an entire category of infrastructure disruption that rarely makes headlines until it actually happens.
Who actually built this, and why that composition matters
The drafting process itself offers a useful clue about how seriously this was treated. Reports on the rule making process indicate the Rules were shaped by a high powered inter ministerial committee chaired by the Secretary of Consumer Affairs, with representation from the National Physical Laboratory and the Indian Space Research Organisation for the underlying science and satellites, IIT Kanpur for engineering expertise, the National Informatics Centre and CERT In for network infrastructure and its security, the Securities and Exchange Board of India for financial market implications, and the Railways, Telecom, and Financial Services departments for the systems that will actually have to run on this new standard day to day. That is not a committee assembled around a single ministry's convenience; it is a committee assembled around the actual shape of the problem, spanning physics, engineering, finance, and network security together. As part of the broader One Nation, One Time initiative, a White Rabbit Technology based IST Dissemination Demonstration Network was already commissioned at the Regional Reference Standard Laboratory in Bengaluru back in July 2026, suggesting the infrastructure groundwork was underway well before the legal framework caught up to it.
What the 180 day window actually means in practice
It is worth being precise about what compliance actually requires here. This is not a deadline demanding new hardware overnight; for most organisations, it means auditing which internal systems currently reference time from an unverified or foreign source and ensuring they align with certified IST going forward, alongside institutions preparing to receive that certified time through the domestic infrastructure the government is simultaneously building out. The six month runway exists precisely because this touches an unusually wide spread of sectors at once, and forcing an abrupt cutover would create more operational risk than the rule is designed to remove.
The bigger picture
A rule about what time it is legally does not sound like cybersecurity news, and on the surface, it is not. But underneath the administrative language sits a genuinely forward looking recognition: as more of daily life, banking, communication, transport, and governance runs on systems that must agree, down to the second, on a shared reference point, the integrity of that reference point becomes critical infrastructure in its own right. India choosing to build, verify, and legally anchor its own trusted time source, rather than continuing to quietly rely on a foreign satellite system it cannot secure independently, is less about symbolism and more about closing a vulnerability most people never knew existed until they were asked to think about it.
References
- OpenGov Asia, "India Issues Rules to Standardise National Time Reference Systems." https://opengovasia.com/india-issues-rules-to-standardise-national-time-reference-systems/?c=us
- Daily Excelsior, "Centre notifies rules mandating IST as common time reference; 180 day window for compliance." https://www.dailyexcelsior.com/centre-notifies-rules-mandating-ist-as-common-time-reference-180-day-window-for-compliance/
- Greater Kashmir, "Department of Consumer Affairs notifies Legal Metrology Rules, 2026." https://www.greaterkashmir.com/national/department-of-consumer-affairs-notifies-legal-metrology-rules-2026-12454447
- Insights on India, "Legal Metrology (Indian Standard Time) Rules, 2026." https://www.insightsonindia.com/2026/08/31/legal-metrology-indian-standard-time-rules-2026/
- Blitz India Media, "Indian Standard Time Rules 2026: NavIC, Legal Metrology." https://blitzindiamedia.com/news/indian-standard-time-rules-2026-navic-legal-metrology/
- Observer Voice, "India Establishes Legal Framework for Standard Time." https://observervoice.com/india-establishes-legal-framework-for-standard-time-225958/
- The Live Nagpur, "Govt notifies rules to make IST the common time reference." https://thelivenagpur.com/2026/08/31/govt-notifies-rules-to-make-ist-the-common-time-reference/
- Safran Navigation and Timing, "GNSS Security and Cybersecurity: What are the Parallels?" https://safran-navigation-timing.com/gnss-security-and-cybersecurity-what-are-the-parallels/
- Safran Navigation and Timing, "Securing Critical Infrastructures from Jamming and Spoofing Cyberattacks." https://safran-navigation-timing.com/securing-critical-infrastructures-from-jamming-and-spoofing-cyberattacks/
- Combain, "The Silent Threat In The Sky: GPS Jamming, GPS Spoofing." https://combain.com/gps-jamming-spoofing/

Introduction
Company law solved a version of this problem more than a century ago, and artificial intelligence regulation is now quietly borrowing the solution. When something goes wrong inside a company, the law generally cannot reach past the corporate entity to punish the people who ran it, because the company is treated as a legal person entirely separate from its shareholders and directors. Courts developed an exception for exactly the cases where that separation becomes a shield for wrongdoing, and lawyers now call it lifting, or piercing, the corporate veil. A growing body of legal scholarship argues that AI systems present a strikingly similar problem, and needs a strikingly similar fix. That emerging idea has come to be called lifting the AI veil.
Where the original doctrine comes from
The doctrine of lifting the corporate veil traces directly to the House of Lords decision in Salomon v. Salomon & Co. Ltd. in 1897. Aron Salomon, a leather and boot manufacturer, incorporated his existing business, sold it to the new company, and structured share ownership so that he and his family held nearly all the shares. When the company later failed, creditors argued Salomon should be held personally liable, since the company was effectively just him operating under a different name. The House of Lords disagreed, holding decisively that once validly incorporated, a company is a person in law entirely distinct from its subscribers, with its own rights and liabilities. That ruling established what remains company law's foundational principle: separate legal personality.
Separate personality is not, however, unconditional. Courts across common law jurisdictions, including India, carved out an exception for cases where the corporate form is used as a facade for fraud, to evade a statutory obligation, or to circumvent a legal duty that would otherwise apply to the individuals behind it. In such cases, a court will "lift the veil," looking past the company's separate legal identity to attribute liability directly to the directors or shareholders actually in control. India's Supreme Court, in Life Insurance Corporation of India v. Escorts Ltd., reaffirmed that this remains an exception applied only in narrow, exceptional circumstances, generally where a statute contemplates it, or fraud or improper conduct needs to be prevented. The doctrine has since found application well beyond fraud alone, including in tax matters, as seen in cases like State of U.P. v. Renusagar Power Co., where courts treated closely related corporate entities as one for the purpose of a specific statutory benefit.
Why AI creates the same structural problem
Scholarship examining AI liability has increasingly pointed to a near identical structural gap. As AI systems take on functions once reserved for human decision makers, board level analytics, automated lending decisions, algorithmic hiring, even proposed "robo-director" advisory roles, a familiar question resurfaces: who answers for the outcome when the AI system, rather than a named individual, produced the decision. A 2025 academic paper titled Lifting the AI Veil in Company Law argues explicitly that AI liability should be approached through an extension of existing doctrines, including directors' duty of care and precisely the piercing of the veil doctrine traditionally reserved for shareholders, rather than inventing an entirely new liability regime from scratch.
The concern driving this argument is not abstract. Commentary in outlets like MIT Technology Review has warned that granting AI systems anything resembling legal personhood risks handing companies a genuinely dangerous new shield, allowing a company to argue that a harmful outcome was the AI's autonomous decision, disconnected from any human actor's intent or negligence, much as a company might once have argued a harmful outcome was simply "the company's" doing and not any individual's. Critics of AI personhood proposals, writing in journals examining AI as legal persons, make the parallel explicit: while corporate veil piercing exists precisely to stop the corporate form being misused as a liability shield, the justification for extending similar legal personhood to AI is considerably weaker, since corporate personhood serves a clear economic purpose, enabling investment and risk pooling, that AI personhood does not obviously replicate.
How regulators have actually responded
The European Union's experience is instructive precisely because it shows the doctrine's underlying logic being adopted through legislation rather than judicial precedent. The European Commission originally proposed a dedicated AI Liability Directive in September 2022, intended to ease the burden of proof on claimants harmed by AI systems, including a rebuttable presumption of causality where a claimant could show an AI system breached EU AI Act obligations. That proposal was formally withdrawn in 2025, with the withdrawal notice published in the Official Journal on 6 October 2025, after member states failed to reach agreement. In its place, the revised EU Product Liability Directive now does much of the same underlying work through a different legal mechanism, explicitly treating AI software as a "product" for the purposes of manufacturer liability, meaning AI providers face strict liability for defective AI products without claimants needing to prove fault, applicable to AI products placed on the EU market from 9 December 2026 onward. Functionally, this achieves something close to piercing the AI veil by statute: instead of allowing a company to attribute harm to an autonomous algorithmic process and stop the inquiry there, liability is anchored back to the entity that built, trained, or deployed the system.
The Indian angle, and why it matters here
India has no AI specific liability statute at present, and no reported judicial decision has yet applied the corporate veil piercing doctrine by analogy to an AI system. But the underlying legal architecture is already familiar territory for Indian courts. India's jurisprudence on lifting the corporate veil, built through Escorts, Renusagar, and subsequent cases, already establishes the judicial comfort with looking past a formal legal structure to find the real, controlling actor when justice demands it. Indian courts have been consistently clear that this remains an exceptional remedy rather than a routine one, generally invoked where a statute contemplates it, where fraud or improper conduct needs to be prevented, or where a taxing or beneficial statute would otherwise be defeated by rigid adherence to corporate form. That same cautious, fact specific posture is likely to shape how any future Indian AI liability doctrine develops, applied sparingly rather than as a blanket rule.
As AI systems increasingly mediate lending decisions, insurance claims processing, and algorithmic hiring in Indian companies, the same reasoning that let Indian courts see through a corporate facade could plausibly extend to seeing through an "AI made the decision" defence, attributing responsibility to whichever human actor, developer, deployer, or governing board, exercised actual control over how that system was built and used. Given how central technology sector employment and AI deployment already are to India's economy, the absence of a clear domestic answer to this question is unlikely to remain untested for long.
The larger point
The doctrine of lifting the AI veil is less a wholly new legal invention and more a recognition that AI systems and corporations create the same essential problem: a formally separate entity that can, if left unchecked, absorb blame that properly belongs to the humans directing it. Company law solved this by refusing to let the corporate form become an alibi. AI law, whether through judicial doctrine, statute, or a hybrid of both as the EU's experience suggests, will likely need to reach the same conclusion, because the alternative is allowing genuine harm to disappear into a system nobody can be made to answer for.
References
- Bird & Bird, "Proposed EU AI liability rules withdrawn." https://www.twobirds.com/en/insights/2025/proposed-eu-ai-liability-rules-withdrawn
- LegalClarity, "AI Liability Directive: What It Was and Why It Was Withdrawn." https://legalclarity.org/ai-liability-directive-what-it-was-and-why-it-was-withdrawn/
- WCR Legal, "EU AI Liability Directive: Withdrawn, What Now Applies?" https://wcr.legal/eu-ai-liability-directive-withdrawn-pld/
- Verfassungsblog, "Anatomy of a Fall: On the Anticipated Withdrawal of the AI Liability Directive Proposal." https://verfassungsblog.de/anatomy-of-a-fall-aiact-aild-pld/
- MIT Technology Review, "Debates over AI consciousness are a trap." https://www.technologyreview.com/2026/08/20/1142571/ai-consciousness-debate-trap/
- ResearchGate, "Lifting the AI Veil in Company Law." https://www.researchgate.net/publication/393305638_Lifting_the_AI_veil_in_company_law
- Review of Law and Regulation, "Lifting the AI Veil in Company Law." https://rlr.iup.rs/wp-content/uploads/2025/07/04.pdf
- Bhatt & Joshi Associates, "Decoding the Jurisprudence on Lifting the Corporate Veil in Indian Court. https://bhattandjoshiassociates.com/decoding-the-jurisprudence-on-lifting-the-corporate-veil-in-indian-court/
- Mondaq, "Analysis Of Standard Of Proof For Lifting Of The Corporate Veil In Cases Of Fraud." https://www.mondaq.com/india/corporate-and-company-law/1259382/analysis-of-standard-of-proof-for-lifting-of-the-corporate-veil-in-cases-of-fraud
- Record Of Law, "Analysis of the theory of corporate veil lifting." https://recordoflaw.in/analysis-of-the-theory-of-corporate-veil-lifting/
- Suren Uppal Offices, "Lifting of Corporate Veil: Navigating Judicial Precedents." https://www.suolaw.com/lifting-of-corporate-veil-navigating-judicial-precedents/