#FactCheck -AI-Generated Letter Falsely Claims Prime Minister Narendra Modi Has Resigned
Executive Summary
A letter circulating on social media falsely claims that Prime Minister Narendra Modi has resigned from his post. CyberPeace Research Wing's research found the claim to be false. Our research confirmed that the viral letter is fabricated and is being shared with a misleading claim. AI detection tools also indicate that the document is highly likely to have been generated using artificial intelligence.
Claim
An Instagram user shared the viral letter on July 29, 2026, claiming that Prime Minister Narendra Modi had resigned from office.
The post link, archived link, and screenshot are provided below:
https://www.facebook.com/photo/?fbid=2108984893363522&set=a.785246212404070
https://ghostarchive.org/archive/aHXTq

Fact Check
To verify the claim, we conducted a keyword search on Google. However, we found no credible media reports supporting the claim that Prime Minister Modi had resigned.
We then visited the official website of the Prime Minister's Office (PMO India). The website contained no announcement, press release, or official information confirming the purported resignation.
https://www.pmindia.gov.in/en/

As part of our research , we also reviewed the official X (formerly Twitter) account of PMO India. We found no post or statement related to the viral claim.

Finally, we analyzed the viral letter using the AI detection tool Sightengine AI. The analysis indicated that the document is 99% likely to be AI-generated.

To further verify the findings, we also scanned the letter using AI or Not. According to the tool's analysis, the document is 64% likely to be AI-generated.

Conclusion
The claim that Prime Minister Narendra Modi has resigned is false. No credible media organization or official government source has reported such a development. Furthermore, AI detection tools strongly suggest that the viral resignation letter was generated using artificial intelligence and is being circulated with a false claim.
Related Blogs

Introduction
The Digital Personal Data Protection (DPDP) Act 2023 of India is a significant transition for privacy legislation in this age of digital data. A key element of this new law is a requirement for organisations to have appropriate, user-friendly consent mechanisms in place for their customers so that collection, use or removal of an individual's personal data occurs in a clear and compliant manner. As a means of putting this requirement into practice, the Ministry of Electronics and Information Technology (MeitY) issued a comprehensive Business Requirements Document (BRD) in June 2025 to guide organizations, as well as Consent Managers, on how to create a Consent Management System (CMS). This document establishes the technical and functional framework by which organizations and individuals (Data Principals) will exercise control over the way their data is gathered, used and removed.
Understanding the BRD and Its Purpose
BRD represents an optional guide created as part of the "Code for Consent" programme run by MeitY in India. The purpose of the BRD is to provide guidance to startups, digital platforms and other enterprises on how to create a technology system that supports management of user consent per the requirements of the DPDP Act. Although the contents of the BRD do not carry any legal weight, it lays out a clear path for organisations to create their own consent mechanisms using best practices that align with the principles of transparency, accountability and purpose limitation in the DPDP Act.
The goal is threefold:
- Enable complete consent lifecycle management from collection to withdrawal.
- Empower individuals to manage their consents actively and transparently.
- Support data fiduciaries and processors with an interoperable system that ensures compliance.
Key Components of the Consent Management System
The BRD proposes the development of a modular Consent Management System (CMS) that provides users with secure APIs and user-friendly interfaces. This system will allow for a variety of features and modules, including:
- Consent Lifecycle Management – consent should be specific, informed and tied to an explicit purpose. The CMS will manage the collection, validation, renewal, updates and withdrawal of consent. Each transaction of consent will create a tamper-proof “consent artifact,” which will include the timestamp of creation as well as an ID identifying the purpose for which it was given.
- User Dashboard – A user will be able to view and modify the status of their active, expired or withdrawn consent and revoke access at any time via the multilingual user-friendly interface. This would make the system accessible to people from different regions and cultures.
- Notification Engine – The CMS will automatically notify users, fiduciaries and processors of any action taken with respect to consent, in order to ensure real-time updates and accountability.
- Grievance Redress Mechanism – The CMS will include a complaints mechanism that allows users to submit complaints related to the misuse of consent or the denial of their rights. This will enable tracking of the complaint resolution status, and will allow for escalation if necessary.
- Audit and Logging – As part of the CMS's internal controls for compliance and regulatory purposes, the CMS must maintain an immutable record of every instance of consent for auditing and regulatory review. The records must be encrypted, time-stamped, and linked permanently to a user and purpose ID.
- Cookie Consent Management – A separate module will enable users to manage cookie consent for websites separately from any other consents.
Roles and Responsibilities
The BRD identifies the various stakeholders involved and their associated responsibilities.
- Data Principals (Users): The user has full authority to give, withhold, amend, or revoke their consent for the use of their personal data, at any time.
- Data Fiduciaries (Companies): Companies (the fiduciaries) must collect the data principals' consents for each particular reason and must only begin processing a data subject's personal data after validating that consent through the CMS. Companies must also provide the data principals with any information or notifications needed, as well as how to resolve their complaints.
- Data Processors: Data Processors must strictly adhere to the consent stated in the CMS, and Data Processors may only process personal data on behalf of the Data Fiduciary.
- Consent Managers: The Consent Managers are independent entities that are registered with the Data Protection Board. They are responsible for administering the CMS, allowing users to manage their consent across different platforms.
This layered structure ensures transparency and shared responsibility for the consent ecosystem.
Technical Specifications and Security
The following principles of the DPDP Act must be followed to remain compliant with the DPDP Act.
- End-to-End Encryption: All exchanges of data with users must be encrypted using a minimum of TSL 1.3 and also encrypting within that standard.
- API-First Approach: API’s will be utilized to validate, withdraw and update consent in a secured manner using external sources.
- Interoperability/Accessibility: The CMS needs to allow for users to utilize several different languages (e.g. Hindi, Tamil, etc.) and be appropriate for use with various types of mobile devices and different abilities.
- Data Retention Policy: The CMS should also include automatic deletion of consent data (when the consent has expired or has been withdrawn) in order to maintain compliance with data retention limits.
Legal Relevance and Timelines
While the BRD itself is not enforceable, it is directly aligned with the upcoming enforcement of the DPDP Act, 2023. The Act was passed in August 2023 but is expected to come into effect in stages, once officially notified by the central government. Draft implementation rules, including those defining the role of Consent Managers, were released for public consultation in early 2025.
For businesses, the BRD serves as an early compliance tool—offering both a conceptual roadmap and technical framework to prepare before the law is enforced. Legal experts have described it as a critical resource for aligning data governance systems with emerging regulatory expectations.
Implications for Businesses
Organizations that collect and process user data will be required to overhaul their consent workflows:
- No blanket consents: Every data processing activity must have explicit, separate consent.
- Granular audit logs: Companies must maintain tamper-proof logs for every consent action.
- Integration readiness: Enterprises need to integrate their platforms with third-party or in-house CMS platforms via the specified APIs.
- Grievance redress and user support: Systems must be in place to handle complaints and withdrawal requests in a timely, verifiable manner.
Failing to comply once the DPDP Act is in force may expose companies to penalties, reputational damage, and potential regulatory action.
Conclusion
The BRD on Consent Management of India is a forward-looking initiative laying a technological framework that is an essential component of the DPDP Act concerning user consent; Although not yet a legal document, it provides an extent of going into all the necessary discipline for companies to prepare. As data protection grows in importance, developing consent mechanisms based on security, transparency, and the needs of the user is no longer just a regulatory requirement, but rather a requirement for the development of trust. This is the time for businesses to establish or implement CMS solutions that support this objective to be better equipped for the future of data governance in India.
References
- https://d38ibwa0xdgwxx.cloudfront.net/whatsnew-docs/8d5409f5-d26c-4697-b10e-5f6fb2d583ef.pdf
- https://ssrana.in/articles/ministry-releases-business-requirement-document-for-consent-management-under-the-dpdp-act-2023/
- https://dpo-india.com/Blogs/consent-dpdpa/
- https://corporate.cyrilamarchandblogs.com/2025/06/the-ghost-in-the-machine-the-recent-business-requirement-document-on-consent/
- https://www.mondaq.com/india/privacy-protection/1660964/analysis-of-the-business-requirement-document-for-consent-management-system

Executive Summary:
A video showing a convoy of soldiers travelling on motorcycles is being widely shared on social media with the claim that the personnel were heading towards Delhi’s Jantar Mantar to support the ongoing protest led by the Cockroach Janata Party (CJP). CyberPeace Research Wing’s research found the claim to be false. The viral video is not related to the CJP protest at Jantar Mantar. The footage predates the ongoing demonstration and is being circulated with a misleading claim.
Claim:
A social media user shared the viral video claiming that soldiers were travelling towards Delhi’s Jantar Mantar to support the youth participating in the CJP protest over issues related to the country’s education system. The post claimed that the soldiers were joining the protest to raise their voice on issues concerning the nation, youth, and their future.
https://x.com/RoflGandhee/status/2079986496556204066?s=20

A reverse image search using Google Lens led the Desk to a video uploaded on a YouTube channel named Commando Journey. Upon comparison, the Desk found that the YouTube video contained the same visuals as the viral video under research. Further verification of the video details revealed that the footage predates the ongoing Cockroach Janata Party (CJP) protest at Jantar Mantar. The protest, which began in June 2026, has been demanding the resignation of Union Education Minister Dharmendra Pradhan over alleged irregularities in examinations. The video was uploaded on the YouTube channel in February 2026, several months before the CJP protest began, confirming that it has been falsely linked to the recent demonstration.
https://www.youtube.com/shorts/cMvai580gdo

As part of the next phase of the research, the Desk reviewed several other videos uploaded on the same YouTube channel. During the analysis, the Desk identified multiple videos featuring visuals matching those seen in the viral clip. However, these videos were also uploaded before the CJP protest in Delhi, with one of the videos dating back to October 2025.
https://www.youtube.com/shorts/7eDc9TqOpzM

Conclusion
While the Desk could not independently verify the exact origin and context of the video, the research established that the footage predates the CJP protest and has been falsely linked to the demonstration. Based on the findings, the Desk concluded that the video shared on social media does not show soldiers travelling to Delhi’s Jantar Mantar to support the Cockroach Janata Party (CJP) protest. The footage is unrelated to the ongoing protest and has been circulated with a misleading claim.

Introduction
Digital evidence has become part of almost every modern investigation. A photograph can place a person at a location, an audio recording can capture a conversation, and a video can appear to show an event as it happened. For years, the main forensic concern was whether such material had been altered. The rapid growth of generative artificial intelligence has added a harder question: even when a file is preserved exactly as received, can investigators still trust what it appears to show?
Deepfakes have made this question practical rather than theoretical. Synthetic or manipulated audio, video and images can imitate real people and real events with increasing realism. CERT-In describes deepfakes as a high-risk threat because they can support disinformation, fraud, social engineering and reputational harm.[1] NIST research likewise treats AI-generated media as a digital-forensics challenge that requires systematic evaluation of detection technologies.[2]

The result is an evidence problem. The answer is not to stop trusting digital evidence, but to become more disciplined about establishing its origin, integrity, context and authenticity.
The evidence problem begins before the laboratory
When a suspicious video reaches an investigator through WhatsApp, Telegram, email or social media, the file may already have passed through several transformations. It may have been compressed, re-encoded, cropped, renamed or stripped of metadata. A screenshot may preserve what is visible but lose the original file structure. A forwarded audio clip may contain no reliable information about where it was first recorded.
For that reason, forensic examination should begin with acquisition and provenance, not with a quick “deepfake detector” result. Investigators should ask: Who supplied the file? Where was it obtained? Is there an original version? What device or account produced it? What happened to the file before it reached the investigator?
Cryptographic hashing remains important because it can demonstrate that an acquired working copy has not changed during examination. But a valid hash does not prove that the underlying event was genuine. A perfectly preserved fake is still a fake.
What a professional examination should look for
A reliable assessment combines several forms of evidence rather than relying on one technical indicator.
Source and acquisition. The original artefact should be preserved whenever possible. Investigators should record the acquisition method, date and time, source account or device, and any known transformations before collection. A documented chain of custody is essential when material may later support a legal, disciplinary or regulatory decision.
Metadata and file structure. Metadata may provide useful clues about creation, encoding, editing software and timestamps. File structure, compression behaviour and related technical characteristics can also reveal inconsistencies. However, these indicators are supporting evidence, not proof on their own, because metadata can be removed or rewritten during normal processing.
Content-level examination. Forensic analysis can include frame-by-frame video review, audio waveform and spectral examination, and inspection for inconsistencies in lighting, reflections, facial movement, lip synchronisation or background elements. Such signs may help guide an investigation, but they are not a permanent checklist. Generative systems continue to improve.
Independent corroboration. This is often the strongest step. If a recording allegedly shows that a person was in a particular place at a particular time, investigators can compare it with CCTV, access-control records, device artefacts, communications, location information, eyewitness accounts or other independent records. The goal is to determine whether the wider evidence supports the event represented by the media.
A real-world lesson: the Pikesville case
The 2024 Pikesville High School incident in Maryland provides a practical example of why authenticity cannot be assumed from appearance alone. An audio recording circulated online that was presented as the principal making racist and antisemitic comments. On January 17, 2024, Baltimore County Public Schools said it could not yet confirm the recording’s veracity and opened an investigation.[3]
Several months later, the school district reported that investigators, with assistance from the FBI and other experts, had verified that the audio had been created using artificial intelligence.[4] Police subsequently arrested the school’s former athletic director in connection with the fabricated recording.[5]

The forensic lesson is larger than the incident itself. The recording had social consequences before its authenticity was established. In a fast-moving online environment, the first version of an event can travel much further than the later correction. Deepfake investigations therefore have to consider not only whether media is authentic, but also how quickly unverified material can influence decisions.
From deepfake detection to content provenance
Detection tools will remain useful, but they should be treated as part of an examination rather than an automatic verdict. NIST’s Guardians of Forensic Evidence work reflects the need to evaluate how analytic systems perform against changing forms of AI-generated media and how well they generalise beyond controlled conditions.[2]
Another important direction is content provenance. The Coalition for Content Provenance and Authenticity (C2PA) has developed a technical framework for recording verifiable information about how digital content was created and changed. Content Credentials can bind provenance information to an asset using cryptographic techniques, allowing later users to inspect a recorded content history when that information is available.[6]

Provenance does not mean that every claim associated with a file is automatically true. It adds context: who created it, what actions were taken and how the asset changed. In a deepfake environment, that context can be as important as the content itself.
Why this matters in India
The issue is especially relevant to India’s fast-growing digital environment. CERT-In’s 2024 advisory identifies misinformation, fraud and reputational damage among the risks associated with synthetic media.[1] In August 2026, the Government of India stated that the regulatory framework addresses AI-generated deepfakes and noted amendments to the IT Rules in February 2026 concerning harms arising from synthetically generated information, including requirements related to labelling and traceable metadata for permissible AI-generated content.[7]
For organisations, deepfake response should therefore not be treated only as a media or public-relations issue. It can become an incident-response and forensic issue. A suspicious executive voice note, a manipulated employee video or a fabricated screen recording may require preservation, technical examination and independent corroboration before any action is taken.
Conclusion
Deepfakes do not make digital evidence useless. Deepfakes make handling of evidence more dangerous. The professional response is not to believe everything or to doubt everything. The professional response is to build a process around evidence: preserve the original where possible document how evidence was acquired, calculate and record hashes, examine metadata and technical characteristics use detection tools while understanding their limitations compare media with independent evidence and examine provenance information where it is available.
Importantly investigators and decision-makers should separate three questions: Is the file intact? Is the content authentic? Does the content actually prove the event being alleged? Deepfakes can pass the test while failing the other two.
In the age of AI evidence will increasingly be judged not only by how convincing it looks but, by how well its origin, integrity, context and history can be demonstrated. That is the standard that can help preserve trust when seeing and hearing're no longer enough.
References
1. CERT-In, “Deepfakes - Threats and Countermeasures,” Advisory CIAD-2024-0060, 27 November 2024. View source
2. NIST, “Guardians of Forensic Evidence: Evaluating Analytic Systems Against AI-Generated Deepfakes,” 27 January 2025. View source
3. Baltimore County Public Schools, “January 17, 2024, Community Update: Message from Superintendent Dr. Myriam Rogers Regarding Pikesville High School.” View source
4. Baltimore County Public Schools, “April 24, 2024 Staff and Community Update: Message from Superintendent Dr. Myriam Rogers Regarding Pikesville High School Investigation.” View source
5. The Baltimore Banner / WYPR, “Ex-athletic director framed principal with AI-generated voice, police say,” 25 April 2024. View source
6. Coalition for Content Provenance and Authenticity (C2PA), “Content Credentials: C2PA Technical Specification,” Version 2.1. View source
7. Government of India, Ministry of Electronics & Information Technology, “Government Strengthens Regulatory Framework to Address AI-Generated Deepfakes,” 6 August 2026. View source