Indian Man Arrested for AI Deepfake Images of Ex-Girlfriend
Independently fact-checked against primary sources (last audited August 5, 2026). · 4 primary sources cited on this page. How we verify our legal content

Dibrugarh police in Assam, India arrested Pratim Bora in July 2025 for creating and selling sexually explicit deepfake images of a woman he had studied with at college. He faces six charges under the Bharatiya Nyaya Sanhita, the criminal code that replaced the Indian Penal Code in 2024.
Dibrugarh police in Assam arrested 30-year-old mechanical engineer Pratim Bora in July 2025 for using artificial intelligence tools to create sexually explicit images and videos of a woman he had known since college. The case became one of India's most widely reported examples of AI-enabled image-based abuse and renewed calls for a dedicated deepfake law.
Police investigating the case told the BBC that Bora earned roughly Rs 10 lakh, about US$12,000 at 2025 exchange rates, by selling access to the fabricated content through a Linktree page that drew around 3,000 subscriptions.
Why This Article Does Not Name the Woman Targeted
Recording Law does not name the woman in this case, and readers should treat coverage that does with caution.
The BBC, which reported on the case in detail, deliberately used a pseudonym for her, introducing her only as a homemaker in Dibrugarh "whom we'll call Sanchi" and noting she is not on social media. The Assam Tribune, the most substantial local outlet covering the arrest, and Gulf News, which followed the BBC's reporting, also withheld her name.
Much of the secondary coverage circulating online does name her and describes her as an Assam influencer. That framing gets the case backwards. The large following belonged to the fabricated account, not to her. Some of the same articles that call her a well-known influencer also state, a few paragraphs later, that the real woman had no prior public persona. Repeating a name and a false public-figure label attached to sexual deepfakes compounds the original harm, which is the reason this article uses her relationship to the accused instead.
The Arrest and Investigation
Dibrugarh police arrested Bora in Tinsukia, Assam in July 2025. The senior police officer leading the investigation told the BBC that officers arrested him on the evening of July 12. Gulf News, in a piece dated July 14, said only that the arrest happened on a Saturday night, while the Assam Tribune dated it July 13. He was produced in court in Dibrugarh and remanded to police custody.
The woman and Bora had been in a relationship during their college years. Reports agree that the relationship ended before the fake account appeared and describe revenge for the breakup as the alleged motive. When the relationship ended is not stated in the coverage this article relies on, and because she is a private individual, this article does not detail the relationship further.
The complaint that triggered the investigation came from the woman's side. The Assam Tribune reported that she lodged it herself, while the BBC reported that her brother filed a short written complaint on the night of July 11.
How the Scheme Worked
According to police accounts reported in Indian media, Bora ran the operation for roughly five years:

- Fake identity creation: Bora set up an Instagram account called "Babydoll Archi" in August 2020, using real photographs taken from the woman's own social media profiles
- AI content generation: Police said he used commercially available generative tools, reported as Midjourney, Desire AI, OpenArt AI, ChatGPT, and Dzine, to place her face onto synthetic bodies
- False narrative: The account presented her as a US-based adult performer, blending her images with those of a known adult film actress to manufacture the association
- Distribution: He used multiple fake email accounts and social profiles to spread the content while concealing his identity, and the account was later renamed
- Monetization: Subscriptions were sold through a Linktree page, reaching about 3,000 subscriptions
According to the BBC, the fake account grew to about 1.4 million followers, an audience that lent an appearance of legitimacy to content that was fabricated end to end.
Charges Under the Bharatiya Nyaya Sanhita
The Assam Tribune reported that the first information report cites six sections of the Bharatiya Nyaya Sanhita (BNS), which replaced the Indian Penal Code on July 1, 2024:
| BNS Section | Offense | Maximum Penalty |
|---|---|---|
| Section 74 | Assault or criminal force to outrage a woman's modesty | 1 to 5 years imprisonment + fine |
| Section 75 | Sexual harassment (showing pornography without consent) | Up to 3 years rigorous imprisonment, or fine, or both |
| Section 294 | Sale and distribution of obscene material | First conviction: up to 2 years + fine up to Rs 5,000 |
| Section 336(4) | Forgery intending to harm the reputation of any party | Up to 3 years imprisonment + fine |
| Section 351(2) | Criminal intimidation | Up to 2 years imprisonment, or fine, or both |
| Section 356(2) | Defamation | Up to 2 years simple imprisonment, or fine, or both, or community service |
Of the six charged sections, the widest exposure comes from Section 74, which carries a minimum of one year and a maximum of five. Section 336(3), forgery for the purpose of cheating, does carry up to seven years, but that subsection is not among the charges the Assam Tribune lists.
Reporting on the case also describes exposure under the Information Technology Act 2000 for obscenity, privacy violation, and identity manipulation. The specific IT Act section numbers filed against Bora are not confirmed in the coverage reviewed for this article, so the sections described in the next part should be read as the general law that applies to this conduct rather than as a list of the charges he personally faces.
India's Legal Framework for Deepfakes
India has no standalone statute aimed at deepfakes. Prosecutors instead combine general criminal provisions with IT Act sections and the intermediary rules, which is exactly the pattern this case follows.
The Information Technology Act
Section 66E of the IT Act criminalizes intentionally or knowingly capturing, publishing, or transmitting the image of a private area of a person without their consent, under circumstances violating their privacy. The statute defines private area narrowly, and whether an AI-generated image counts as the image of a person's private area is one of the unsettled questions in applying pre-deepfake law to synthetic content. The offense carries up to three years imprisonment, a fine up to Rs 2 lakh, or both.
Section 67 covers publishing or transmitting obscene material in electronic form. Section 67A covers sexually explicit material and carries heavier penalties: up to five years and a fine up to Rs 10 lakh on a first conviction, rising to up to seven years on a subsequent conviction.
IT Intermediary Guidelines Amendments
India's Ministry of Electronics and Information Technology (MeitY) has tightened the rules on AI-generated content in stages:
- November 2023: MeitY advised social media platforms to identify and act on deepfake content after a manipulated video of actress Rashmika Mandanna spread widely
- October 2025: MeitY published draft amendments to the IT Rules on labelling synthetically generated information, under a notice dated October 22, 2025 that invited public comments by November 6, 2025. The ministry's own notice describes these as draft amendments released for feedback, including a proposed minimum 10 percent visual or initial audio duration for labels, so they should not be read as law that was in force during 2025
- February 2026: The government announced an amendment to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 on February 10, 2026, compressing the takedown window for certain AI-generated content from 36 hours to three hours following a valid notice or order, and requiring labelling of synthetically generated content
The three-hour clock runs from a qualifying notice or order, not from the moment a victim first spots the content, so the practical speed of removal still depends on how fast a complaint is filed and processed.
Digital Personal Data Protection Act 2023
The DPDP Act requires consent for processing personal data, and its penalty ceiling reaches Rs 250 crore, roughly US$30 million. The Act does not mention deepfakes by name. Note that these are regulatory penalties, not compensation paid to an individual, so a person targeted by synthetic sexual imagery should not assume the Act gives them a personal payout.
Proposed Deepfake Legislation
Shiv Sena MP Shrikant Shinde introduced the Regulation of Deepfake Bill, 2024 in the Lok Sabha on December 5, 2025 as a private member's bill. It would require consent before creating a deepfake of a person, mandate digital watermarking for traceability, criminalize sexually explicit deepfakes along with those used for fraud or election interference, and establish a Deepfake Task Force.
Private members' bills rarely become law in India. The bill had not been enacted after its introduction, and this article does not track it beyond that point. Anyone relying on the current state of Indian law should check MeitY and Lok Sabha records for changes after February 2026.
Other Notable Deepfake Cases in India
Rashmika Mandanna Case (Delhi, 2023 to 2024)
In the case that pushed deepfakes onto India's political agenda, a viral video placed actress Rashmika Mandanna's face onto footage of a British-Indian influencer. Delhi Police's IFSO unit arrested 23-year-old Eemani Naveen, a B.Tech graduate from Guntur in Andhra Pradesh, on January 20, 2024. He was charged under Indian Penal Code Sections 465 and 469 for forgery and forgery harming reputation, plus IT Act Sections 66C and 66E.
Kasaragod, Kerala
In June 2024, police in Kasaragod, Kerala arrested three young men for using AI apps to generate nude images of women from their own village. Published victim counts vary widely across reports, from roughly 150 to more than 200, and this article could not confirm a figure against a primary police or court source, so no specific number is stated here.
Personality Rights Suits
Aishwarya Rai Bachchan obtained an interim injunction from the Delhi High Court by an order dated September 9, 2025, in a personality-rights suit seeking to restrain misuse of her name, image, and likeness, including through artificial intelligence. Several other Indian actors have reportedly obtained comparable orders, though this article does not name them because that reporting could not be confirmed in a source we would rely on.
What the Case Shows About Scale
Every tool named in the Bora investigation was commercially available and required no specialist skill. The barrier to producing convincing sexual imagery of a specific real person is now low enough that the limiting factor is intent, not capability.
The monetization layer matters just as much. A subscription link turned harassment into recurring income, and the fabricated account's 1.4 million followers gave the fiction enough social proof to keep selling. Regulation aimed only at platforms hosting the images misses the payment and link-in-bio layer that made the operation profitable.
Reporting a Deepfake in India
A person targeted by synthetic sexual imagery in India can file a complaint at a local police station, at the nearest cyber crime cell, or online through India's National Cyber Crime Reporting Portal, which accepts reports relating to women and children without requiring the complainant to identify themselves publicly.
Be realistic about the practical risks. Content spreads faster than takedown orders, mirrored copies routinely outlive the original post, and pursuing a case can mean handing devices and account records to investigators. Preserving links, screenshots, and account handles before reporting is generally more useful than reporting from memory after the account disappears.
This article provides general legal information about deepfake laws in India and is not legal advice. Indian rules in this area changed in February 2026 and further changes are likely. Consult a lawyer qualified in India for advice on a specific situation.
Frequently Asked Questions
Why does this article not name the woman targeted by the deepfakes?
Because the most authoritative reporting on the case does not name her. The BBC used a pseudonym for her and noted she is not on social media, and both the Assam Tribune and Gulf News withheld her name. Coverage that does name her also tends to describe her as an influencer, which is inaccurate. The large following belonged to the fabricated account, not to her.
What AI tools were reportedly used to create the deepfake images?
According to police accounts reported in Indian media, Bora used commercially available generative tools reported as Midjourney, Desire AI, OpenArt AI, ChatGPT, and Dzine to place the woman's face onto synthetic bodies. None of these required specialist technical knowledge, which is a large part of why the case drew national attention.
Is creating deepfake images a crime in India?
India has no standalone deepfake statute, but several existing laws apply. The IT Act 2000 covers capturing or sharing images of a person's private area without consent under Section 66E, obscene electronic material under Section 67, and sexually explicit material under Section 67A. The Bharatiya Nyaya Sanhita covers sexual harassment, forgery, criminal intimidation, defamation, and distribution of obscene material.
What charges does the accused face?
The Assam Tribune reported six Bharatiya Nyaya Sanhita sections in the FIR: 74, 75, 294, 336(4), 351(2), and 356(2). The heaviest is Section 74, assault or criminal force to outrage a woman's modesty, which carries one to five years; Section 336(4), forgery intending to harm reputation, carries up to three years. Reporting also describes IT Act exposure for obscenity and privacy violation, but the specific IT Act sections filed against him are not confirmed in the coverage reviewed here.
How much money did the accused reportedly make?
Police investigating the case told the BBC that he earned about Rs 10 lakh, which is roughly US$12,000 at 2025 exchange rates, from around 3,000 subscriptions sold through a Linktree page. Some coverage names a specific subscription platform, but that name could not be confirmed in reliable reporting, so this article describes the mechanism rather than naming the service.
What is India doing to regulate deepfakes?
The government has moved through the intermediary rules rather than a dedicated statute. MeitY advised platforms to act on deepfakes in November 2023, circulated draft labelling proposals for synthetically generated information in October 2025, and announced an amendment on February 10, 2026 cutting the takedown window for certain AI-generated content from 36 hours to three hours. A private member's bill on deepfakes was introduced in December 2025 but has not been enacted.
Can someone targeted by a deepfake sue in India?
Civil routes exist alongside the criminal complaint. Aishwarya Rai Bachchan obtained an interim injunction from the Delhi High Court in September 2025 on personality-rights grounds, in a suit seeking to restrain misuse of her name, image, and likeness, including through artificial intelligence. The DPDP Act 2023 also carries penalties up to Rs 250 crore for data breaches, though those are regulatory penalties rather than compensation paid to an individual complainant.
How can someone report deepfake content in India?
Complaints can be filed at a local police station, at the nearest cyber crime cell, or through the National Cyber Crime Reporting Portal at cybercrime.gov.in. Under the February 2026 IT Rules amendment, intermediaries face a three-hour window to act on certain AI-generated content, but that clock starts from a valid notice or order, not from the moment the content is first posted.
Updates
We removed the name and the 'influencer' description of the woman targeted in this case, because the most authoritative reporting deliberately protects her identity and shows she had no public profile before the fake account existed. We also corrected the maximum penalty stated for the forgery charge (up to three years under BNS Section 336(4), not seven, with Section 74 carrying the heaviest exposure among the charged sections), restored the precise scope of IT Act Section 66E, corrected the dollar conversion of the reported earnings, removed several details we could not confirm in reliable sources, and clarified that the October 2025 labelling rules were a draft rather than binding law.
Independently fact-checked against the cited primary sources
Removed the name and the influencer description of the woman targeted, after review found the most authoritative reporting deliberately anonymizes her and describes her as having no public profile. Corrected the currency conversion of Rs 10 lakh, removed unconfirmed relationship dates and an unconfirmed subscription platform name, separated the general IT Act explainer from the charges actually filed, reclassified the October 2025 MeitY labelling proposal as a draft rather than a notified rule, and removed unconfirmed victim counts in the Kerala case. A follow-up review against the enacted statutory text corrected the maximum penalty for the forgery charge under BNS Section 336(4) (up to three years, not seven, with Section 74 carrying the heaviest exposure among the charged sections at one to five years), corrected the descriptions of the forgery and criminal intimidation charges, restored the statutory scope of IT Act Section 66E (images of a person's private area), and removed an unconfirmed claim that the fake account had Instagram verification.
Article published covering the July 2025 arrest of Pratim Bora and India's legal framework for deepfake crimes.
Sources and References
- BBC News investigation into the Assam AI deepfake case (uses a pseudonym for the woman targeted)(bbc.com)
- Assam Tribune: Dibrugarh man arrested for circulating AI-generated obscene images of former partner (BNS sections in the FIR)(assamtribune.com)
- Gulf News: Assam engineer held over AI-generated content targeting a former classmate(gulfnews.com)
- Bharatiya Nyaya Sanhita 2023 (India Code)(indiacode.nic.in).gov
- Information Technology Act 2000 (India Code)(indiacode.nic.in).gov
- IT Rules 2026: deepfake regulation, three-hour takedowns and AI labelling obligations(mondaq.com)
- MeitY notice dated October 22, 2025 inviting public comments on draft IT Rules amendments on synthetically generated information(meity.gov.in).gov
- Bar and Bench: Delhi High Court grants interim injunction protecting Aishwarya Rai Bachchan's personality rights (order of September 9, 2025)(barandbench.com)
- Regulation of Deepfake Bill, 2024 introduced in the Lok Sabha (December 5, 2025)(thefederal.com)
- Digital Personal Data Protection Act 2023, consent for processing personal data(dpdpa.com)
- National Cyber Crime Reporting Portal (Government of India)(cybercrime.gov.in).gov