A Mumbai impersonation case has put generative AI, forged government credentials and venue security under fresh scrutiny. Police told a court that 24-year-old Rohan Parikh allegedly created a fake Prime Minister’s Office identity card and related documents using ChatGPT, then used the claimed PMO link at Jio World Plaza in Bandra Kurla Complex. The incident occurred on September 7, 2026, one day before Prime Minister Narendra Modi’s Global Fintech Fest engagement nearby. Mumbai Police later said the episode had no connection with the Prime Minister’s visit.
The episode shows why AI-assisted impersonation is not only a content problem; weak verification can turn convincing digital material into a physical security risk quickly.
Key Highlights
- Police alleged Rohan Parikh had created PMO-style documents with ChatGPT since 2025.
- His private guard, former Army man Dilip Kunde, was found carrying a licensed revolver.
- A Mumbai court sent both arrested men to 14 days’ judicial custody on September 11.
- Government data shows reported cheating by impersonation and fake profiles both rose during 2025.
What Happened At Jio World Plaza?
According to the latest India Today court report, Parikh and 49-year-old Kunde appeared before Additional Chief Judicial Magistrate D S Khedekar after police custody ended. Investigators said they recovered a laptop, hard drive and PMO-related documents from Parikh’s Khar residence. Phone data allegedly showed searches connected with drafting PMO correspondence.
| Date | Development |
| September 7, 2026 | Parikh allegedly displayed a PMO identity card after security stopped Kunde with a firearm. |
| September 11, 2026 | The court sent Parikh and Kunde to 14 days’ judicial custody. |
| September 17, 2026 | Police reply and bail hearing are scheduled. |
Earlier reporting on the security checks noted irregularities on the card, including a missing validity date and an issuer signature without the issuer’s designation. Kunde’s revolver was later found to be licensed.
The defence initially argued Parikh may have been deceived by communications suggesting a PMO-linked role. Police later told the court he had admitted fabricating the ID and documents with ChatGPT. Investigators are examining whether the material was used elsewhere.
How Could Generative AI Be Misused For Impersonation?
Generative AI can lower the effort needed to produce polished text, formal-looking letters, job descriptions, email wording and document layouts. That does not mean an AI chatbot automatically creates a valid government credential. A fake becomes dangerous when a person combines generated material with logos, copied signatures, screenshots, convincing language or false claims, then presents it to someone who does not independently verify it.
The Mumbai case illustrates that distinction. The alleged documents did not create official authority; the claimed authority depended on people accepting the presentation. Strong checks such as confirming an identity through an issuing department, scanning authorised credentials, checking validity fields and escalating unusual access requests can interrupt that chain.
The Wider Impersonation Trend
The concern is larger than one mall incident. A March 2026 Home Ministry reply in the Rajya Sabha recorded 23,252 complaints under “cheating by impersonation” on the National Cybercrime Reporting Portal in 2025, up from 19,991 in 2024. Fake or impersonating-profile complaints rose from 39,884 to 46,784 over the same period.
The National Cyber Crime Reporting Portal itself currently warns users about fake emails impersonating officials from I4C, the Intelligence Bureau and Delhi Police. That alert shows how attackers can borrow government names and institutional authority even without sophisticated deepfake video.
What Do Indian Law And The 2026 AI Rules Say?
Police registered the Jio World Plaza case under provisions of the Bharatiya Nyaya Sanhita, including allegations linked to impersonating a public servant and unlawful entry while armed, according to India Today’s initial case report. The final criminal liability will depend on evidence, charges and court findings, so allegations should not be treated as convictions.
India’s Information Technology Act separately covers identity theft under Section 66C and cheating by personation using computer resources under Section 66D. In August, the government reiterated its framework for AI-generated deepfakes, including synthetic text, audio and video.
The regulatory picture changed further in February 2026. A Press Information Bureau release says amended IT Rules require intermediaries to take reasonable technical measures against unlawful synthetically generated information, including misleading or impersonating content, while permissible AI-generated material must carry clear labelling and traceable metadata. These rules target misuse and platform responsibilities; they do not make ordinary AI-assisted writing illegal. For businesses and venues, that pushes document verification beyond visual inspection and towards source checks, audit logs and controlled access approval.
What Should Security Teams And Citizens Do About AI Impersonation?
The practical lesson is to verify the authority, not the appearance of a document. Security teams should confirm government credentials through official channels before granting exceptional access, particularly when a visitor invokes a sensitive office or arrives with armed security. Staff should also treat screenshots, forwarded PDFs and unofficial email addresses as prompts for extra checks rather than proof.
Citizens who encounter suspected impersonation can preserve screenshots, emails, phone numbers and payment records, then report suspicious identifiers through the National Cyber Crime Reporting Portal. For urgent financial cyber fraud, the national helpline is 1930.
FAQs
FAQ 1: Did police say ChatGPT created an authentic PMO identity card?
No. Police allege ChatGPT helped create forged material; official validity never came from the AI.
FAQ 2: Was the incident linked to Prime Minister Narendra Modi’s Mumbai visit?
Police said no connection had been established between the accused and the Prime Minister’s visit.
FAQ 3: Was the bodyguard’s firearm illegal?
Police said the revolver was licensed, while investigators examined how it was being commercially used.
FAQ 4: Can AI-generated impersonation be reported online in India?
Yes. Citizens can report cyber impersonation and identifiers through India’s National Cyber Crime Reporting Portal.
FAQ 5: What is the fastest defence against a convincing fake credential?
Independent verification with the issuing authority can expose forged credentials before access, payment, or trust follows.
Trending Now: AI, Payments, Security & Health Updates
- Will ChatGPT Ads Change AI Answers?
Check out who will see sponsored ads in India and whether they affect responses. - How Can You Create Studio Images?
Find out how to generate professional-looking studio images for free using ChatGPT. - How Does RBI’s New UPI System?
Uncover how UPI payments can now work without the usual “Yap and Pay” process. - How Will Delhi Handle BRICS Security?
Browse the major security arrangements as BRICS leaders arrive in the capital. - Could El Niño Raise India’s Disease Risks?
Reveal how hotter and drier conditions could increase dengue and other health risks.



