#FactCheck - AI-Generated Image of Abhishek Bachchan and Aishwarya Rai Falsely Linked to Kedarnath Visit
A photo featuring Bollywood actor Abhishek Bachchan and actress Aishwarya Rai is being widely shared on social media. In the image, the Kedarnath Temple is clearly visible in the background. Users are claiming that the couple recently visited the Kedarnath shrine for darshan.
Cyber Peace Foundation’s research found the viral claim to be false. Our research revealed that the image of Abhishek Bachchan and Aishwarya Rai is not real, but AI-generated, and is being misleadingly shared as a genuine photograph.
Claim
On January 14, 2026, a user on X (formerly Twitter) shared the viral image with a caption suggesting that all rumours had ended and that the couple had restarted their life together. The post further claimed that both actors were seen smiling after a long time, implying that the image was taken during their visit to Kedarnath Temple.
The post has since been widely circulated on social media platforms

Fact Check:
To verify the claim, we first conducted a keyword search on Google related to Abhishek Bachchan, Aishwarya Rai, and a Kedarnath visit. However, we did not find any credible media reports confirming such a visit.
On closely examining the viral image, several visual inconsistencies raised suspicion about it being artificially generated. To confirm this, we scanned the image using the AI detection tool Sightengine. According to the tool’s analysis, the image was found to be 84 percent AI-generated.

Additionally, we scanned the same image using another AI detection tool, HIVE Moderation. The results showed an even stronger indication, classifying the image as 99 percent AI-generated.

Conclusion
Our research confirms that the viral image showing Abhishek Bachchan and Aishwarya Rai at Kedarnath Temple is not authentic. The picture is AI-generated and is being falsely shared on social media to mislead users.
Related Blogs

Executive Summary
A video showing a scuffle between a group of women and police personnel is being widely shared on social media with the claim that it shows Delhi Police assaulting women protesters at Jantar Mantar. CyberPeace Research Wing ’s research found the claim to be misleading. The viral video is not from Jantar Mantar in Delhi but from an unrelated incident in Dehradun, Uttarakhand. The old footage is being falsely circulated as a recent video from the ongoing protests.
Claim:
A Facebook user shared the viral video claiming that Delhi Police personnel were assaulting women and girls during the protest at Jantar Mantar.
The post link, archive link and screenshot are provided below.
https://www.facebook.com/reel/2864826433884333

Fact Check:
To verify the claim, we extracted keyframes from the viral video and conducted a reverse image search using Google Lens. This led us to the same video uploaded on the Instagram account iamvikasbaliyan on October 15, 2025.
https://www.instagram.com/reels/DP0H_SSE625/

According to the information shared with the post, the incident took place in Mohabbewala, Dehradun, Uttarakhand, after a truck crashed into a house, damaging the property. The homeowner allegedly demanded compensation and, when the issue remained unresolved, attempted to set the truck on fire. When police personnel intervened to stop her, a scuffle broke out between the woman and the police. The viral video captures this incident. In the next stage of the research, we found an ABP News report published on October 15, 2025, carrying the same visuals as the viral video. The report also identified the incident as having occurred in Mohabbewala, Dehradun.

Conclusion:
CyberPeace Research Wing ’s research found the viral claim to be misleading. The video does not show Delhi Police assaulting women protesters at Jantar Mantar. It is an old video from Dehradun, Uttarakhand, showing an unrelated incident that has been falsely linked to the ongoing protests in Delhi.

Introduction
India is operating on digital rails today. Even as UPI is set to hit over 130 billion transactions by 2025, it already makes up around 80% of retail payments flow by volume. That volume is really what it is all about: a single extra transaction is simply another attack surface, and fraud has correspondingly scaled up. FY 2024-25 alone saw an estimated 485 crore in losses to UPI-related fraud through 632,000 reported frauds. The response from the RBI has not been a single rulebook but a layered and dynamic regulatory infrastructure that currently spans banks, NBFCs, payment aggregators, card networks, and, by extension, the fintechs that connect into all of these components. Knowing why the infrastructure is shaped the way it is and what actual enforcement looks like is far more crucial than having a checklist in mind. This write-up moves beyond summarising the rules to outlining the thinking behind them, the latest trends shaping the segment and the reality of an implementation roadmap.
Why Has RBI Cybersecurity Compliance Become Non-Negotiable?
Three forces are converging on regulated entities at once:
1. The threat surface has outgrown legacy controls: Core banking systems were never designed for an ecosystem of APIs, third-party payment gateways, and unregulated fintech partners sitting on top of them. Every integration is a potential entry point, and attackers know it.
2. Financial stability is now a cyber question, not just a credit question: a prolonged outage at a large payment system operator doesn't just hurt one bank's balance sheet; it can freeze retail payments for hundreds of millions of people. RBI treats this as systemic risk, which is why its post-2020 directions lean so heavily on resilience (the ability to keep operating through an attack) rather than just prevention.
3. Enforcement has escalated: The RBI's May 2025 single order penalised five different banks, including levying a 97.80 lakh penalty on ICICI Bank with one part attributable to its late reporting of a cybersecurity incident and another to a lapse in account alert systems; this demonstrates this rise in intensity. Remember, under Sections 46 and 47A of the Banking Regulation Act 1949, the RBI has the power to levy penalties irrespective of the occurrence of an actual breach if an individual fails to comply with procedures like not properly assessing vendor access or reporting incidents late or failing to update crisis plans or timely reports. Now this is a significant development, an issue even in the absence of a full-scale 'hack'.
The Regulatory Architecture: What Actually Applies to Whom
Rather than one framework, regulated entities are governed by several overlapping directions depending on their category:
- Banks: The original RBI Cyber Security Framework requires board-approved cybersecurity policies, 24x7 Security Operations Centres, and defined incident reporting timelines.
- NBFCs: NBFCs were initially governed under the Master Direction on IT Framework for NBFC Sector, which escalates accordingly as per size of asset – the framework underwent substantial change in shape with the RBI notifying Cybersecurity, Technology Risk, Resilience and Assurance Framework directions, 2026 for NBFCs, which lays specific obligations based on tier level (NBFC-Base Layer, Middle Layer, Upper Layer & Top Layer entities) on issues like MIS reporting, fraud analytics & impact of incident reporting.
- PSOs: Non-bank Payment system Operators PSOs have been regulated under the Master Direction on Cyber Resilience and Digital Payment Security Controls, 2024 (July 2024). Card networks, payment aggregators, PPI issuers and other PSOs come under its umbrella, with staged compliance based on the volume/business size (large – NPCI, card networks and the largest PPI issuers will meet requirements on April 1, 2025; medium ones by April 1, 2026; and small ones by April 1, 2028).
- Other Bodies: IT Governance (on all regulated entities broadly) The Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices, 2023, became effective on April 1, 2024, and has set basic benchmarks for information technology (IT) strategy committees, IT risk management processes & IT assurance functions.
Overall trends' information across all these is clear: escalating tier requirements as per size and board-led controls are mandatory; a conscious acceptance that there will inevitably be data breaches in the future; and increasing emphasis on response and recovery.
Governance: Where RBI Compliance Actually Starts
A recurring theme across every RBI direction is that cybersecurity cannot be delegated entirely to the IT department. The Board of Directors is expected to own information security risk, with oversight typically delegated to a board subcommittee that meets at least quarterly. A board-approved information security policy, reviewed annually, must define the following:
- Roles and responsibilities across the Board, senior management, and the CISO
- Processes to identify, assess, monitor, and manage cyber risk
- Employee and stakeholder training and awareness programs
RBI's own 2022 thematic review of IT governance across 20 banks found unmanaged third-party vendor access, with vendors retaining privileged access to core systems long after a project ended at more than half the institutions reviewed. That kind of gap is a governance failure as much as a technical one: it happens because nobody owns the review cycle, not because the firewall is misconfigured.
Key Technical and Operational Controls
Once governance is in place, RBI's expectations translate into concrete control domains:
Infrastructure and access hardening: Network segmentation, endpoint protection, server hardening baselines, and multi-factor authentication for privileged access. Access reviews should be continuous or, at minimum, periodic, enforcing least privilege and separation of duties, not a one-time onboarding checkbox.
Vulnerability and patch management: Regular vulnerability scanning, risk-prioritised remediation, and a documented process for feeding vulnerability data into risk decisions, not just a scanner report sitting in an inbox.
Data security and localisation: Encryption at rest, in transit, and during processing; sound key management; data classification and masking; and adherence to the RBI's data localisation requirements for payment data.
Vendor and third-party risk: This has become one of the sharpest areas of regulatory focus. The 2024 PSO Master Directions explicitly require oversight of "unregulated entities" in the payment chain like payment gateways, third-party service providers, and vendors with due diligence, contractual security clauses, and ongoing monitoring baked in. For a bank or fintech, this means your compliance posture is only as strong as your weakest vendor's; the RBI increasingly holds the regulated entity accountable for its partners' failures, not just its own.
Security operations and incident response: 24x7 SOC capability, threat intelligence integration, and tested incident response plans via tabletop exercises and simulated attacks. A Cyber Crisis Management Plan (CCMP) drafted once and never rehearsed is, in practice, treated by RBI examiners as functionally absent.
Incident Reporting
This is where two separate regulatory clocks run in parallel, and conflating them is a common compliance mistake:
- RBI requirements: Regulated entities will normally have around 2-6 hours of detection to report most security incidents to the RBI with follow-up notifications as and when the nature of the incident unfolds.
- CERT-In's 6-hour rule: The CERT-In Directions dated April 2022 stipulate that every body corporate, which includes any bank, NBFC or payment aggregator, is obligated to report specified categories of cyber incidents to CERT-In within 6 hours of noticing them and not after fully confirming details at an additional 6 hours after noticing them. CERT-In directions also mandated that ICT system clocks are to be synced to NIC/NPL time servers, and system logs are to be maintained for a rolling 180 days within India.
- The Digital Personal Data Protection Act overlay: In the case of a data breach involving personal data, there will additionally be a 72-hour notification obligation from the data fiduciary to the Data Protection Board under the Digital Personal Data Protection Act, 2023, which runs in parallel to, and not in substitution of, the CERT-In time.
The practical consequences: If an SOP for incident response only maps one regime, then it would fail in an actual incident. We need a single intake process whereby multiple notification tracks are automatically triggered at the precise time an incident is detected, given that the inability to report "because we were still figuring it out" does not constitute an acceptable justification for a late notification under either regime.
Why Penetration Testing Sits at the Center of Compliance
RBI's VAPT (Vulnerability Assessment and Penetration Testing) mandate isn't a box-ticking annual scan. It's meant to validate, under real attack conditions, whether the governance and technical controls described above actually hold up. Automated scanning finds known vulnerabilities; penetration testing, ideally combining automated coverage with manual, business-context-aware testing, finds the logic flaws, chained exploits, and privilege escalation paths that scanners miss and that attackers actually use.
For most regulated entities, a realistic testing cadence looks like:
- Semi-annual vulnerability assessments across critical systems
- Annual (at minimum) penetration testing of applications, networks, and infrastructure supporting payment and customer-data systems
- Testing triggered by events before go-live, after major changes, and post-deployment.
- Documented remediation cycles and rescans, with reports mapped directly to the relevant compliance clauses for audit purposes
The Cost of Getting It Wrong
RBI's enforcement history grounds the financial impact of enforcement actions. In addition to the May 2025 fines levied on ICICI, Axis, IDBI, Bank of Baroda and Bank of Maharashtra, the RBI's published Enforcement Guidelines differentiate three levels of severity; procedural breaches such as delayed policy review or late incident notifications usually warrant 10 lakh to 1 crore fines plus formal reprimands and remediation orders with deadlines. Recurring governance breaches go farther than fines, resulting in restrictions on business activities and more stringent supervisory reporting, with egregious breaches leading to inclusion under the RBI's Prompt Corrective Action regime. Penalty orders are also publicly available, and the resulting toll on customer trust, partner trust, and investor confidence often dwarfs the fines.
A Practical Implementation Roadmap
For an organisation building or maturing its RBI compliance programme, a sensible sequence looks like this:
- Establish board-level ownership first: Form or formalise the Board IT/Risk sub-committee, appoint or empower a CISO with real authority, and get the information security policy formally approved, and this is the foundation every RBI examiner checks first.
- Mapping: A mid-sized NBFC, a large payment aggregator, and a scheduled commercial bank face different, overlapping obligations. Get this scoping wrong and you'll either over-engineer or leave gaps.
- Secure third-party access: Audit every vendor with system access, revoke stale privileges, and build vendor security clauses into contracts going forward, not retroactively.
- Build one incident response SOP: Run one compiled playbook that satisfies RBI, Cert-In and DPDP.
- Schedule and actually rehearse tabletop exercises: not just write a CCMP and file it away.
- Institutionalise VAPT as a continuous, risk-triggered programme rather than an annual compliance event, and ensure reports are structured to map directly onto RBI's compliance clauses for audit readiness.
- Track the regulatory calendar actively: 2024–2026 has brought new NBFC directions, PSO phase-ins, and ITG-RC&AP obligations in quick succession, and the pace shows no sign of slowing.
Conclusion
RBI's shift from perimeter-focused prevention to a risk-based, resilience-first model reflects a broader reality: in a digital payments ecosystem processing billions of transactions a month, breaches are not a hypothetical to plan around; they're an operational certainty to plan for. The frameworks discussed here, cyber resilience directions, IT governance mandates, CERT-In's reporting clock and the new NBFC cybersecurity directions aren't separate hurdles to clear individually. They're converging into a single expectation: that regulated entities can detect an incident quickly, contain it, recover fast, and prove with documentation, tested plans, and independent penetration test evidence that they were ready for it in the first place.
For banks, NBFCs, and fintechs operating in India today, that readiness is no longer just a regulatory requirement. It's the baseline cost of operating in the financial system at all.
References
Sources
- Astra Security — RBI Cybersecurity Compliance Checklist for Banks & NBFCs in 2026: https://www.getastra.com/blog/compliance/rbi-cybersecurity-compliance-checklist/
- TaxGuru — RBI Issues NBFC Cybersecurity and Technology Risk Directions, 2026: https://taxguru.in/rbi/rbi-issues-nbfc-cybersecurity-technology-risk-directions-2026-governance-framework.html
- Mondaq — Cyber Resilience and Digital Payment Security Governance (Master Directions, 2024): https://www.mondaq.com/india/fin-tech/1527836/cyber-resilience-and-digital-payment-security-governance-a-step-towards-secured-payments-systems
- TaxGuru — Master Directions on Cyber Resilience & Digital Payment Security Controls for Non-bank PSOs: https://taxguru.in/rbi/master-directions-cyber-resilience-digital-payment-security-controls-non-bank-payment-system-operators.html
- CyberNX — Ultimate Guide on RBI Master Directions for Cyber Resilience: https://www.cybernx.com/rbi-master-directions-guide/
- SIRI Law LLP — A Comprehensive Guide to India's CERT-In 6-Hour Cyber Incident Reporting Mandate: https://sirilawllp.com/a-comprehensive-guide-to-indias-cert-in-6-hour-cyber-incident-reporting-mandate/
- CreativeCyber — CERT-In 6-Hour Incident Reporting SOP for Indian Banks & NBFCs: https://creativecyber.in/resources/cert-in-6-hour-incident-reporting/
- BW Businessworld — RBI Slaps Penalties on ICICI, Axis and Three Others Over Compliance Failures (May 2025): https://www.businessworld.in/article/rbi-slaps-penalties-on-icici-axis-three-others-over-compliance-failures-555643
- FluxForce — RBI Cyber Framework: Banks' Requirements & Penalties: https://www.fluxforce.ai/regulations/rbi-cyber-security-framework-banks
- MYITMANAGER — RBI Cybersecurity Guidelines 2026: What Banks and NBFCs Must Do: https://myitmanager.in/rbi-cybersecurity-guidelines-2026-banks-nbfcs/

Introduction
Generative AI models are significant consumers of computational resources and energy required for training and running models. While AI is being hailed as a game-changer, however underneath the shiny exterior, cracks are present which significantly raises concerns for its environmental impact. The development, maintenance, and disposal of AI technology all come with a large carbon footprint. The energy consumption of AI models, particularly large-scale models or image generation systems, these models rely on data centers powered by electricity, often from non-renewable sources, which exacerbates environmental concerns and contributes to substantial carbon emissions.
As AI adoption grows, improving energy efficiency becomes essential. Optimising algorithms, reducing model complexity, and using more efficient hardware can lower the energy footprint of AI systems. Additionally, transitioning to renewable energy sources for data centers can help mitigate their environmental impact. There is a growing need for sustainable AI development, where environmental considerations are integral to model design and deployment.
A breakdown of how generative AI contributes to environmental risks and the pressing need for energy efficiency:
- Gen AI during the training phase has high power consumption, when vast amounts of computational power which is often utilising extensive GPU clusters for weeks or at times even months, consumes a substantial amount of electricity. Post this phase, the inference phase where the deployment of these models takes place for real-time inference, can be energy-extensive especially when we take into account the millions of users of Gen AI.
- The main source of energy used for training and deploying AI models often comes from non-renewable sources which then contribute to the carbon footprint. The data centers where the computations for Gen AI take place are a significant source of carbon emissions if they rely on the use of fossil fuels for their energy needs for the training and deployment of the models. According to a study by MIT, training an AI can produce emissions that are equivalent to around 300 round-trip flights between New York and San Francisco. According to a report by Goldman Sachs, Data Companies will use 8% of US power by 2030, compared to 3% in 2022 as their energy demand grows by 160%.
- The production and disposal of hardware (GPUs, servers) necessary for AI contribute to environmental degradation. Mining for raw materials and disposing of electronic waste (e-waste) are additional environmental concerns. E-waste contains hazardous chemicals, including lead, mercury, and cadmium, that can contaminate soil and water supplies and endanger both human health and the environment.
Efforts by the Industry to reduce the environmental risk posed by Gen AI
There are a few examples of how companies are making efforts to reduce their carbon footprint, reduce energy consumption and overall be more environmentally friendly in the long run. Some of the efforts are as under:
- Google's TPUs in particular the Google Tensor are designed specifically for machine learning tasks and offer a higher performance-per-watt ratio compared to traditional GPUs, leading to more efficient AI computations during the shorter periods requiring peak consumption.
- Researchers at Microsoft, for instance, have developed a so-called “1 bit” architecture that can make LLMs 10 times more energy efficient than the current leading system. This system simplifies the models’ calculations by reducing the values to 0 or 1, slashing power consumption but without sacrificing its performance.
- OpenAI has been working on optimizing the efficiency of its models and exploring ways to reduce the environmental impact of AI and using renewable energy as much as possible including the research into more efficient training methods and model architectures.
Policy Recommendations
We advocate for the sustainable product development process and press the need for Energy Efficiency in AI Models to counter the environmental impact that they have. These improvements would not only be better for the environment but also contribute to the greater and sustainable development of Gen AI. Some suggestions are as follows:
- AI needs to adopt a Climate justice framework which has been informed by a diverse context and perspectives while working in tandem with the UN’s (Sustainable Development Goals) SDGs.
- Working and developing more efficient algorithms that would require less computational power for both training and inference can reduce energy consumption. Designing more energy-efficient hardware, such as specialized AI accelerators and next-generation GPUs, can help mitigate the environmental impact.
- Transitioning to renewable energy sources (solar, wind, hydro) can significantly reduce the carbon footprint associated with AI. The World Economic Forum (WEF) projects that by 2050, the total amount of e-waste generated will have surpassed 120 million metric tonnes.
- Employing techniques like model compression, which reduces the size of AI models without sacrificing performance, can lead to less energy-intensive computations. Optimized models are faster and require less hardware, thus consuming less energy.
- Implementing scattered learning approaches, where models are trained across decentralized devices rather than centralized data centers, can lead to a better distribution of energy load evenly and reduce the overall environmental impact.
- Enhancing the energy efficiency of data centers through better cooling systems, improved energy management practices, and the use of AI for optimizing data center operations can contribute to reduced energy consumption.
Final Words
The UN Sustainable Development Goals (SDGs) are crucial for the AI industry just as other industries as they guide responsible innovation. Aligning AI development with the SDGs will ensure ethical practices, promoting sustainability, equity, and inclusivity. This alignment fosters global trust in AI technologies, encourages investment, and drives solutions to pressing global challenges, such as poverty, education, and climate change, ultimately creating a positive impact on society and the environment. The current state of AI is that it is essentially utilizing enormous power and producing a product not efficiently utilizing the power it gets. AI and its derivatives are stressing the environment in such a manner which if it continues will affect the clean water resources and other non-renewable power generation sources which contributed to the huge carbon footprint of the AI industry as a whole.
References
- https://cio.economictimes.indiatimes.com/news/artificial-intelligence/ais-hunger-for-power-can-be-tamed/111302991
- https://earth.org/the-green-dilemma-can-ai-fulfil-its-potential-without-harming-the-environment/
- https://www.technologyreview.com/2019/06/06/239031/training-a-single-ai-model-can-emit-as-much-carbon-as-five-cars-in-their-lifetimes/
- https://www.scientificamerican.com/article/ais-climate-impact-goes-beyond-its-emissions/
- https://insights.grcglobalgroup.com/the-environmental-impact-of-ai/