Verification Debt: What Cybercrime Looks Like When AI Can Fake Anything

Srikanth
By
Srikanth
Srikanth is the founder and editor-in-chief of TechStoriess.com — India's emerging platform for verified AI implementation intelligence from practitioners who are actually building at the frontier....

AI hasn’t just changed how crimes are committed. It’s changed what counts as proof. Every deepfake video, cloned voice, and doctored invoice raises a quieter, harder question underneath it: in a courtroom, whose version of reality wins? We put that question to Narendra Singh – lawyer, cyber-law researcher, and author of Regulating AI: Artificial Intelligence in India.

Singh’s vantage point is unusually split down the middle. 

On one side, he’s spent 12+ year as a marketer, the same digital surfaces where AI-driven fraud now lives. On the other, he’s Co-Founder of Bran LP, a firm built specifically around branding for legal professionals – meaning he’s not just studying how AI complicates cybercrime evidence, he’s advising the very lawyers whose own credibility online is now part of the case they’re arguing. 

That dual seat – growth marketer and cyber-law researcher, sitting inside the same person – is rare enough on its own. It becomes urgent right now because India’s courts, businesses, and legal professionals are all being asked to trust digital records at the exact moment AI has made those records easiest to fake.

1. Is AI making it easier or harder to prove cybercrime happened?

AI has created a double-edged situation. It helps investigators analyse huge volumes of digital evidence quickly, detect suspicious patterns, and reconstruct cyber incidents. At the same time, AI also makes it much easier to create fake screenshots, deepfake videos, cloned voices, edited emails, and manipulated documents.

Today, proving a cybercrime is less about a single screenshot and more about verifying the complete digital trail-metadata, server logs, device records, IP addresses, timestamps, blockchain or cloud records, and forensic analysis. AI has increased the importance of digital forensics rather than replacing it.

2. Is Indian cyber law keeping pace with AI-powered attacks?

India is moving in the right direction, but legislation is evolving slower than AI threats. The Information Technology Act, 2000 was drafted before the rise of generative AI, deepfakes, and AI-powered phishing.

Recent developments like the Digital Personal Data Protection Act, 2023 improve privacy protection, but India still needs dedicated AI governance covering deepfakes, AI accountability, transparency, and liability. The law is adapting, but technology is advancing much faster.

3. Where are businesses most exposed to AI-driven fraud?

Most people think payment fraud is the biggest risk, but the biggest exposure is actually business identity and customer trust.

AI is being used for:

  • Deepfake customer support calls and CEO impersonation.
  • Fake payment confirmations and invoice fraud.
  • AI-generated phishing emails targeting employees.
  • Fake product reviews and marketplace scams.
  • Customer data harvesting through AI-powered chatbots and malicious websites.
  • E-commerce businesses should secure customer communication channels as carefully as payment systems.

4. How do courts distinguish authentic digital evidence from AI-fabricated evidence?

Indian courts rely on digital forensic verification, not appearance alone. Authenticity is examined through metadata, hash values, server logs, device extraction, chain of custody, and expert forensic reports. Under Indian evidence law, electronic evidence must satisfy legal requirements before it is accepted.

As AI-generated content becomes more realistic, forensic examination and preservation of original digital records become increasingly important.

5. What is the first cybersecurity gap you check for businesses in the AI era?

The first thing I check is human vulnerability.

Most successful cyberattacks still begin with an employee clicking a phishing link, sharing an OTP, approving a fake payment request, or trusting an AI-generated voice or message. AI has made social engineering much more convincing.

Businesses should combine employee awareness, multi-factor authentication, access controls, and AI-aware cybersecurity policies rather than relying only on antivirus or firewalls.

Closing Thought

Artificial Intelligence is transforming cybersecurity and cybercrime at the same time by following the Checklist. The future of cyber law in India lies in balancing innovation with accountability, privacy, and trustworthy digital evidence. Businesses, investigators, and legal professionals must evolve together to address AI-driven threats responsibly.

Follow:
Srikanth is the founder and editor-in-chief of TechStoriess.com — India's emerging platform for verified AI implementation intelligence from practitioners who are actually building at the frontier. Based in Bengaluru, he has spent 5 years at the intersection of enterprise technology, emerging markets, and the human stories behind AI adoption across India and beyond.
Leave a Comment