In October 2025, Aishwarya Rai Bachchan's counsel stood before the Delhi High Court and explained that his client's likeness was being used online, in his words, to satisfy someone's sexual desires. He called the situation unfortunate. It was a remarkable moment: one of the most recognised faces in the world, in court, asking a judge to stop strangers from generating pornography with her face.
She was not an outlier. She was early.
In the eighteen months since, the Delhi and Bombay High Courts have issued protection orders for Nagarjuna, Asha Bhosle, Baba Ramdev, Shilpa Shetty, Allu Arjun, Shashi Tharoor, Aman Gupta, Varun Dhawan, Preity Zinta, Shruti Haasan and Arjun Kapoor. Add the earlier cohort of Aishwarya Rai, Kajol, Salman Khan, Ajay Devgn, Abhishek Bachchan, Sonakshi Sinha, Vivek Oberoi and Gautam Gambhir, and something becomes obvious. This is no longer a series of isolated incidents. It is a queue.
Understanding what's actually happening to these people, and why their current defences are failing, matters for anyone whose face carries commercial value.
The four ways a face gets stolen
The threat is usually discussed as one undifferentiated blob called "deepfakes." In practice it splits into four distinct categories, each with a different victim, a different motive and a different remedy.
1. The scam endorsement
This is the largest category by financial damage, and it is not close. Analysis by Surfshark, drawing on the AI Incident Database and OECD data, found that deepfakes of celebrities and government officials endorsing fraudulent investments account for roughly $1.13 billion, about 52% of all reported deepfake fraud losses worldwide. Corporate executive impersonation, the next largest category, sits at around 25%.
The FBI's Internet Crime Complaint Center made a telling change to its 2025 annual report. For the first time in the bureau's 26 year history of publishing it, AI related fraud got its own descriptor. The count was 22,364 complaints and roughly $893 million in losses, of which investment fraud alone accounted for $632 million.
India is squarely in the blast radius. In one Bengaluru case, an 80 year old senior advocate lost over ₹40,000 after watching a manipulated video of the Union Finance Minister promoting stock market investments. Indian consumer-safety guidance now bluntly advises readers to assume every celebrity investment video is fake, and specifically notes that Ambani, Tata, Murthy and Kohli do not promote trading apps.
Sit with the implication. The endorsement value of India's biggest names is being used, at scale, to rob their own audiences. The star loses twice. Their commercial credibility is diluted, and the people harmed are their fans.
2. The sexual deepfake
By raw volume, non consensual intimate imagery dominates deepfake content globally, and it overwhelmingly targets women. It is the category that produces the most severe personal harm and the least commercial visibility, because victims rarely want to discuss it publicly.
Indian courts have begun naming it directly. In the Arjun Kapoor matter, the Delhi High Court order explicitly foregrounded AI generated sexually explicit content as the primary harm, reportedly the first time an Indian personality-rights judgment addressed it at that level of detail. Varun Dhawan's June 2026 order similarly covered AI generated pornographic material.
3. The fabricated statement
Here the harm is reputational and political. In May 2026, the Delhi High Court ordered the removal of deepfake content that falsely depicted Shashi Tharoor praising Pakistan. The technology does not need to show someone doing anything. It only needs to show them saying something.
Voice is the newer frontier. The Bombay High Court restrained the unauthorised replication of Asha Bhosle's voice through AI tools, following a similar action by Arijit Singh. For a singer, a cloned voice is not reputational damage in the abstract. It is the direct theft of the instrument they earn a living with.
4. The commercial appropriation
The quietest category, and the most straightforwardly larcenous. When the Delhi High Court protected Allu Arjun in April 2026, the order restrained defendants from exploiting his name, image, voice and gestures, right down to his "Thaggede Le" move from Pushpa, across AI content, deepfakes and unauthorised merchandise, with platforms directed to take down specified links within 72 hours.
Note what is being protected there. Not just a face, but a gesture. A catchphrase. The granular, hard won components of a persona built over decades.
What it is costing them
The legal wins are real. They are also expensive, slow and exhausting.
An interim injunction in a High Court is not a cheap instrument. Shruti Haasan's commercial suit sought ₹15 crore in damages for unauthorised use of her name, image, likeness and voice, a scale that tells you what the underlying asset is worth and what litigating over it involves.
But the deeper problem is structural. Every one of these cases is reactive. Someone, usually the star's team and often the star personally, has to notice the content, compile the URLs, brief a lawyer, and go to court. By the time an order lands, the scam has run, the video has been downloaded and reposted, and the damage is distributed across thousands of screens.
Courts have noticed the gap. Analysts commenting on the Bachchans' action against Google observed that it would not be surprising for a court to nudge YouTube toward writing something into its policies, or to create a faster queue for celebrity claimants. The fact that this is being discussed as a possible future improvement tells you what the present looks like.
There is also a limit the courts themselves are enforcing. When Raghav Chadha sought relief in May 2026, the Delhi High Court refused a blanket takedown, holding that criticism of his political decisions was protected speech while ordering the removal of specific obscene content. In the Arjun Kapoor matter the court drew the same line. Not all content featuring a public figure can be removed, only material that is defamatory, sexually explicit, or exploited for unauthorised commercial gain. Parody and criticism survive. That is the correct outcome, and it means blunt instruments will keep failing.
Why the existing playbook is broken
Put together, the current defence has four structural flaws.
It is reactive. Enforcement begins only after harm is visible. The content has already done its work.
It is manual. URLs are compiled by hand. Someone has to find them, and nobody can watch the whole internet by hand.
It is per incident. Each case is fought individually, even when the same infrastructure produces thousands of fakes.
It depends on the victim. Most platform reporting channels are built around first party complaints. A star's team can prepare everything, but the person themselves is frequently required to file. Ask any working actor how much of their month they can give to filling in web forms.
The regulatory environment has moved faster than the operational reality. India's amended IT Rules, notified in February 2026, introduced a Synthetically Generated Information framework and tightened takedown windows sharply, including a three hour clock for content flagged under court or government direction. But as legal analysts have pointed out, the SGI framework is a platform governance measure, not a personality rights remedy. It does not create a cause of action for identity misuse or a licensing regime. It tells platforms what to do once someone tells them. Somebody still has to do the telling.
What actually has to change
The gap in the market is not legal. India's courts have been notably progressive, building a substantial body of personality rights precedent without a dedicated statute. The gap is operational.
What is missing is the layer between the harm and the remedy. Continuous detection across the platforms where fakes actually live. Verification that the content is both synthetic and genuinely depicts the client. Evidence packaged to the standard a platform grievance officer or a High Court needs. Filing at volume without consuming the client's time. And re detection when the content inevitably reappears under a new account.
That is not a lawsuit. It is infrastructure.
The celebrities in that Delhi High Court queue did not fail to protect themselves. They did the only thing available, and they did it well enough to build precedent the whole industry now relies on. But a court order is a remedy of last resort, and no one should need one to stop a stranger from putting words in their mouth.
The next phase of this problem will not be solved in courtrooms. It will be solved by the systems that make sure most cases never need to get there.
Player Two builds likeness protection infrastructure for Indian talent: continuous detection, evidence grade reporting, and enforcement across the platforms where misuse actually happens.