“VIRTUAL KIDNAPPING” & AI VOICE MODULATION: AN EVOLUTIONARY ELEMENT OF CYBER CRIME

INTRODUCTION

Based on a 2023 report by the Times of India, a 59 y/o woman in Hyderabad had fallen victim to a scam call made to her late at night using an AI morphed voice imitating her nephew, stating a distressing situation and urgent need for money. Only did she later realize the truth after she had already transferred an amount of about 1.5 lakh into the scammer’s account.[1]

Both Criminal and Cyber laws of India are yet to be developed to have an accurate jurisprudence to effectively address a cybercrime of such magnitude. Even though Chapter XI of the IT Act of 2000[2] and Section 319 of the BNS[3] collectively talk about Identity theft, cheating and other computer related digital offences, these acts still mention the said offences as only being committed by actual humans to defraud other people. AI voice cloning has broken that idea in a completely new dimension. The voice sounds accurate enough to fool people and is fake enough to create a legal vacuum as no real person ever said the words. The following analysis examines how the legal framework written to address traditionally recognised offences is being stretched to adjudicate the gaps created by digital evolution along with certain provisions being present.

THE MECHANICS OF THIS SCAM

In this specific type of fraud, the AI tool usually needs a few seconds of audio make an exact replica of someone’s voice by simply cloning it[4]. A post on a social media platform such as Twitter (now X), Instagram or any other app including a voice clip of even a few seconds can provide enough material for an AI voice synthesising tool to generate an almost perfectly realistic sounding version of an individual’s voice. And when the scam call is made to the potential victim, the AI-generated voice overtakes the task of overwhelming the victim and tricking them into falling for the bait of ‘urgency’ and ‘secrecy’.

The CERT-In (India Computer Emergency Response Team) advisory (CERT- In Advisory CIAD- 2024- 0050)[5] on deepfake threats released in 2024 refers to this kind of AI-generated fake voice scam as one of the fastest growing Financial Cyber Crime, in the nation. CERT-In had also warned in the same advisory about such fake audios and videos being used often to trick people from generally vulnerable sections of society; senior citizens and less literate people per se[6].

Although Section 63 of the BSA (Bharatiya Sakshya Adhiniyam, 2023) (replacing the Indian Evidence Act)[7] which does introduce a provision for the admissibility of digital audio; due to the quickness of the scams and the inability to record or save such audio makes it ever more impractical for said audios and recordings or even the actual device used, to modify/generate audios to ever be produced as evidence or to be saved as proof.

THE LEGAL VACUUM OF AI VOICE MODULATION

Section 137 of the Bharatiya Nyaya Sanhita (BNS) requires an actual taking or enticing away of a person as it is based upon the principle of ‘corpus delicti ’, which only has jurisprudence over the physical kidnapping of a person and not digital[8]. With voice clone scams, no one gets kidnapped physically but rather is restrained digitally on verbal commands by the scammer. The “victim” allegedly kidnapped here only exists in the caller’s script on a virtual basis. A parallel to this provision is also Section 66D of the IT Act 2000[9], wherein the said section explicitly mentions the personification being done by a person and not AI, which even further blurs the lie of the responsible culprit. Nonetheless, the jurisprudence of Statutory provisions is limited here too.

 Section 319 of the BNS, which is cheating by personation, does not fit any more naturally here[10]. Personation is defined here as a crime wherein an individual impersonates someone else with intent to deceive, whereas in the current case, the relevance of the topic of AI Voice generation is in issue and not an actual person pretending to be someone else. Compared on an empirical level, both the provisions have limited jurisprudence while Section 66D of the IT Act acts as a better fitted shoe to the foot as it talks about cheating by personation by the means of a communication deice or a computer, which is the architecture of this fraud. When the call is accompanied by explicit threats such as: “pay now, or this individual gets hurt”. Section 308 BNS on extortion and Section 351 BNS on criminal intimidation may also apply, since both provisions turn on introducing fear to compel a person to act against their own interest[11].

But this doesn’t solve the real problem. The legal concept of “personation” was created for a world of forged letters, impersonated phone calls, and false identities taken by an actual human being on the other end of the queue based on the reality of the times when the Statutes were made. It has not been amended as per the requirements of today’s artificial media, or AI generated digital records, yet. Imagine, for instance, a voice that is not owned by anyone, but produced by an algorithm rather than performed by an impersonator. Until that question is tested, prosecutors can only use the language they’ve had for decades, which the drafters never imagined. On the contrary to mention the Definition given for Electronic Records in Section 2(t) of the IT Act of 2000 does include and acknowledges the existence of generated data, yet the interpretation continues to rely on the traditional intend of the drafters of the statute.

MEASURES TO PREVENT THE ISSUE

(1) Intermediary due diligence and safe harbour revocation under Rule 3 of the IT Rules, 2021 for AI cloning platforms:

Rule 3(1)(b)(v) of the IT Rules, 2021 requires intermediaries to ensure that users do not deceive or mislead recipients about a message’s origin, which directly applies to Al-cloned calls made to appear as if they originate from a known relative.[12] Rule 3(2)(b) further requires removal within twenty-four hours of complaints involving electronic impersonation.[13] Together, these provisions bring Al voice-cloning platforms within the due-diligence framework. Failure to comply may result in loss of safe-harbour protection under Section 79 of the IT Act, 2000.[14]

(2) Classification of voiceprints as protected biometric data under the DPDP Act, 2023 to curb voice scraping:

The Digital Personal Data Protection (DPDP) Act, 2023 does not create a separate category of “sensitive personal data”, unlike the Sensitive Personal Data or Information (SPDI) Rules 2011, which classified biometrics as sensitive. [15]A voice print is therefore treated as ordinary “personal data” under section 20(t) and is subject to the general consent framework.[16] Treating voiceprints as a protected biometric category would require a statutory amendment, not an interpretation of existing text.

(3) Mandatory TRAI/TCCCPR caller-id validation to block spoofed VoIP calls at the telecom level:

The operative mechanism is the Department of Telecommunications International Incoming Spoofed Call Prevention System, launched on 22 October 2024, which blocked nearly 90% of international spoofed calls displaying Indian numbers within 24 hours of deployment[17]. The use of spoofed calling service is independently punishable under Section 25 (c) of the Indian Telegraph Act, 1885.[18]

CONCLUSION

The success of the virtual frauds is not due to any gap in the vocabulary of the law but due to the actual topical gaps left, which the makers of the said statutes and acts (BNS/IT Act) could not have speculated considering the developments in the digital world of that time. There are laws in India against extortion, impersonation and criminal intimidation and they are quite capable of recording what happened. The failure is one of pace, because AI technology is moving fast, therefore the law is often one step behind. The personation clause of Section 319, the extortion clause of Section 308 and the BNS section 351 dealing with “Criminal Intimidation” were all written for a world of human impersonators, forged documents and face-to-face deception, but today the law is left to grapple with fraud created entirely using AI-generated voices.

This analysis does not ask for new legislation to be made from scratch rather, it needs faster and more practical amendments to keep up with the pace of the evolving technology. Clarity from the Judiciary is necessary to draw the extent of the jurisprudence of the definition of “Personation”. The perplexity created due to the difference in the interpretation of Statutory Provisions and definitions leads nowhere in terms of a definite law, which is what needs to be clarified.

Author(s) Name: Farhan Javed Pattekari (Rizvi Law College)

References:

[1] Woman from Hyderabad loses 1.5 lakh rupees in an AI scam <https://indiaai.gov.in/news/a-woman-from-hyderabad-loses-1-4-lakh-rupees-in-an-ai-sca> accessed 26 July 2026.

[2] IT Act 2000, chapter XI <https://www.indiacode.nic.in/bitstream/123456789/13116/1/it_act_2000_updated.pdf>

Accessed 26 July 2026

[3] BNS section 319 <https://www.mha.gov.in/sites/default/files/250883_english_01042024.pdf> Accessed 26 July 2026

[4] How little audio does it take to AI clone voice <https://www.duckduckgoose.ai/blog/how-ai-voice-cloning-works#how-little-audio-it-really-takes> Accessed 27 July 2026

[5] CERT-In Advisory CIAD- 2024 – 0050 <https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES02&VLCODE=CIAD-2024-0060> Accessed 26 July 2026

[6]  Indian Computer Emergency Response Team, Deep fakes: Threats and Countermeasures (Advisory No CIAD-2024-0060, Ministry of Electronics and Information Technology, Government of India, 27 November 2024) <https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES02&VLCODE=CIAD-2024-0060> Accessed 27 July 2026

[7] BSA (Bharatiya Sakshya Adhiniyam, 2023) section 63 <https://www.mha.gov.in/sites/default/files/2024-04/250882_english_01042024_0.pdf> Accessed 26 July 2026

[8] Bharatiya Nyaya Sanhita 2023, s 137 <https://www.mha.gov.in/sites/default/files/250883_english_01042024.pdf> Accessed 26 July 2026

[9] Section 66D of the IT Act, 2000 <https://www.indiacode.nic.in/bitstream/123456789/13116/1/it_act_2000_updated.pdf> Accessed 26 July 2026

[10] Bharatiya Nyaya Sanhita 2023, s 319.

[11] Bharatiya Nyaya Sanhita 2023, ss 308, 351.

[12] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, r3(1) (b) (v).

[13] Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, r3 (2)(b).

[14] Information Technology Act 2000, s 79.

[15] Information Technology (Reasonable Security Practises and Procedures and Sensitive Personal Data or Information) Rules 2011, r3.

[16] Digital Personal Data Protection Act 2023, s2(t)

[17] Press Information Bureau, International Incoming Spoofed Calls Prevention System (Ministry of Communications, 2024) <https://www.pib.gov.in/PressReleasePage.aspx?PRID=2067113&reg=48&lang=2>

Accessed 26 August 2026.

[18] Indian Telegraph Act, 1885, s 25 (c).

Sign Up to Our Newsletter

Be the first to know the latest updates

Whoops, you're not connected to Mailchimp. You need to enter a valid Mailchimp API key.