India's Deepfake Industry Uses Open-Source AI, Telegram Bots for Non-Consensual Imagery
An investigation by DecodeInternet and Tattle exposed India's AI deepfake supply chain, detailing how AI tools are used to create non-consensual imagery and videos of women, distributed through platforms like Telegram and Instagram, and monetized via UPI payments. The report highlights failures in content moderation by major platforms, government oversight regarding deepfake complaints, and the prevalence of open-source Chinese AI models and US distribution platforms in this illicit industry. Cloudflare was identified as a dominant CDN provider for many deepfake websites, underscoring infrastructure's role in the problem.
Key Takeaways
- Government agencies in India, including I4C, NCRB, and MeitY, report no available data on deepfake-related complaints, routing all complaints to state police.
- A Bengaluru startup, Renown (operating ActualFans), reportedly took a 30% revenue share from deepfake subscriptions without identity verification.
- Telegram bots facilitate the creation of explicit deepfake video content, accepting payments via UPI, Apple Pay, Google Pay, Paytm, and PhonePe.
- AI deepfake app a1.art, run by Hong Kong-based Jishi Design with over 10 million Google Play downloads, was found to contain child sexual abuse material and remains available on app stores.
- 27 of 31 investigated AI nudification websites used Cloudflare as their CDN, indicating a significant infrastructure role in deepfake distribution.
Why It Matters
This investigation exposes a well-established, monetized AI deepfake ecosystem operating largely unchecked, highlighting significant failures in content moderation and regulatory oversight. The reliance on widely accessible tools and open-source models, combined with payment platforms, increases the scale and reach of non-consensual imagery. Industry stakeholders should monitor platform responses and legislative efforts to address the spread of AI-generated non-consensual content and its supporting infrastructure.
Additional Context
The investigation coincides with India’s newly implemented legal framework for synthetic media. Per the Ministry of Electronics and Information Technology (MeitY), the IT Amendment Rules 2026, which went into effect on February 20, 2026, formally introduced the category of 'Synthetically Generated Information' (SGI). These rules require intermediaries to implement proactive technical measures to identify and label synthetic content. Crucially, the regulations reduced the mandatory takedown window for non-consensual intimate imagery from 24 hours to just two hours, according to official Gazette notifications. Despite these laws, enforcement remains fragmented; recent reporting from Indian outlets like The Statesman in June 2026 indicates that police are still relying on older IT Act provisions to address viral deepfake cases involving public figures. Globally, the role of American hosting platforms has come under increased scrutiny. Per 404 Media (July 2025), over 5,000 models designed to recreate real individuals' likenesses were reuploaded to Hugging Face after being banned from CivitAI due to pressure from payment processors. This migration highlights the 'whack-a-mole' challenge in moderating high-bandwidth AI tools across different international jurisdictions. Additionally, the 2026 Cloudflare Threat Report noted a fundamental shift toward 'industrialized' cyber threats, where the use of AI has lowered the entry barrier for high-impact operations. While Cloudflare announced in July 2025 that it would block AI crawlers by default to protect IP, the widespread use of its CDN by 'nudification' sites underscores the difficulty in vetting individual site traffic within vast infrastructure networks.
Read full article at medianama.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source