Manav.id
Platforms ยท 17 min read

Nobody listened, and the royalties were paid anyway

Deezer said in January 2026 that up to 85 percent of the streams on fully AI generated tracks were fraudulent, and stopped paying for them. That number is usually read as a story about AI music. It is not. It is a story about a payout system that has never once been able to tell whether a person was in the room.

Picture an independent artist opening a quarterly royalty statement. Not a famous one. A working musician with about forty thousand monthly listeners, which is a real career if you tour, and about eleven hundred euros a quarter if you do not. She has been at roughly that number for two years. This quarter the number is lower, and her plays are not.

She checks the obvious things. No playlist drop. No unusual skips. Her plays are actually up slightly. What has changed is the value of each one, by a fraction of a cent, which sounds like nothing until you multiply it by everything she has.

Somewhere on the same platform, in a genre she has never heard of, a catalogue of tracks that took an afternoon to generate is being played several hundred thousand times a day by software. Nobody is listening to any of it. The plays are real in the only sense the accounting system cares about, which is that they were counted. And because of how streaming royalties are divided, those counted plays are not taking money from the platform. They are taking it from her.

This is the part of streaming fraud that almost every article gets wrong. It is not framed correctly as a technology problem or an AI problem. It is a problem about what a payout event is allowed to assume, and the assumption underneath the entire industry is that a play implies a person.

Short answer: Deezer reported in January 2026 that up to 85 percent of streams on fully AI generated tracks were fraudulent, and demonetised them. Streaming fraud persists because platforms classify the track rather than proving the listener. Since royalties are paid from a shared pro rata pool, every fake play is money taken from real artists, not from the platform. The durable control is a human bound royalty event.

What did Deezer actually find, and what do the numbers mean?

In January 2026, Deezer announced that it was demonetising streams of fully AI generated music, and published the finding behind the decision: up to 85 percent of the streams on those tracks were fraudulent (Deezer newsroom, January 2026). The Financial Times and the music trade press covered it, and the figure travelled quickly, usually with the implication that AI music had swamped streaming.

The more interesting numbers are the ones that got less attention, and they point somewhere else entirely.

Deezer reported detecting more than 13 million fully AI generated tracks during 2025, and said that AI generated uploads had grown to a substantial share of all new uploads, running at tens of thousands of tracks per day by the middle of 2026 (Deezer newsroom). That is the number that sounds alarming. But Deezer also reported that fully AI generated tracks accounted for only a low single digit percentage of actual streams on the platform.

Hold those two facts next to each other, because their relationship is the whole story.

A small share of listening, a large share of fraud

AI generated tracks are a huge share of what gets uploaded and a tiny share of what gets played. Almost nobody is choosing to listen to them. And yet 85 percent of the plays they do receive are fraudulent.

That is not the profile of a competing genre. Nobody uploads seventy thousand tracks a day hoping to build an audience. That is the profile of a machine pointed at a payout formula. The music is not the product. The music is the minimum viable object required to open an account with the royalty pool, in the same way that a shell company is the minimum viable object required to open a bank account. The generation cost went to roughly zero, so the number of shells went to roughly infinity.

France's Centre National de la Musique studied stream fraud across platforms and found that between 1 and 3 percent of streams were fraudulent (CNM). On a global recorded music market measured in tens of billions of dollars annually (IFPI Global Music Report), a low single digit percentage of misdirected royalties is a very large number in absolute terms, and it is being subtracted from a population of artists whose median earnings are famously small.

Spotify has said publicly that it has removed spam tracks at very large scale, with reported figures in the tens of millions, and has changed its royalty rules to require a minimum number of streams before a track earns at all. Those are real responses to a real problem. They are also, as we will see, responses aimed at the wrong layer.

United States federal prosecutors have brought at least one case alleging large scale streaming manipulation using artificially generated tracks and automated listening, with reported proceeds in the millions of dollars. Those are allegations, and the figures come from contemporaneous reporting rather than a concluded judgment, so treat them as an indication of scale rather than a settled fact.

Why does a fake stream cost other artists money?

This is the mechanism that makes streaming fraud different from almost every other kind of platform abuse, and it deserves to be explained slowly, because once you see it you cannot unsee it.

The pool, not the advertiser

Start with a comparison. In advertising fraud, a bot loads a page, an ad is served, and an advertiser pays for an impression that no human saw. The money moves from the advertiser to the publisher and the intermediaries. The advertiser is out of pocket. It is theft, it is enormous, and it is somebody's specific budget line. We have written about that case separately in the piece on verified human conversions.

Streaming does not work that way. In the dominant model, called pro rata, the platform takes all the subscription and advertising revenue for a market in a period, sets aside its own share, and divides the remaining pot among rights holders in proportion to their share of total plays. The pot is fixed first. The division happens second.

Here is the analogy that makes it land. Imagine a restaurant where at the end of the night the tips are pooled and divided by the number of tables each server handled. Now imagine someone walks in, sits at forty empty tables, and leaves. They have not brought in a cent of extra tip money. The pool is exactly the size it was. But the divisor just got bigger, so every real server takes home less. The person who sat at the empty tables did not steal from the restaurant. They stole from the waiters.

That is a fraudulent stream. It is a table nobody sat at, counted in the divisor.

The arithmetic, done properly

Work a simplified example. Say a market generates a royalty pool of ten million euros in a month, and legitimate listening produces ten billion streams. The per stream rate is one tenth of a cent, and our artist with one million streams earns one thousand euros.

Now add three hundred million fraudulent streams, three percent of the legitimate total, which is inside the range the CNM study describes. The pool is still ten million euros, because no additional subscriber signed up and no additional advertisement was sold. The divisor is now 10.3 billion. The per stream rate falls by about 2.9 percent. Our artist still had one million real plays from real people and now earns about 971 euros.

She lost twenty nine euros to people she will never know about, on a platform that will never send her a notification about it, in a transaction with no visible victim. Multiply that across a career and across every artist in the pool, and you have a continuous, invisible transfer from the many people making music that humans choose to listen to, toward a small number of operators running scripts.

Two things follow from this that are worth stating plainly. First, the platform's own incentive to fix this is weaker than you would hope, because the platform's costs are largely fixed and the fraud is being paid out of the artists' share, not the platform's. That is not a claim of bad faith, and the platforms that have acted are acting against a weak incentive, which is to their credit. It is simply the structure. Second, it means the constituency with the strongest interest in a fix, working musicians, has the least power to demand one.

Why is classifying the music the wrong layer?

Deezer's response is genuinely notable, and it is worth being precise about why. Deezer did not tune a threshold. It made a categorical decision to stop paying for a class of content, and it published its detection methodology and made the technology available to the rest of the industry. That is a serious, transparent move by a company that did not have to make it.

It is still detection, and detection has a shape that this series keeps running into, most recently in the piece on reviews and in the piece on survey panels. The shape is this: you are trying to classify an artifact produced by an adversary who can iterate faster than you can retrain, and who only needs to succeed at the margin.

The re-upload problem

When a track is flagged and demonetised, the operator does not stop. The catalogue is regenerated with different parameters, uploaded under a different artist name, through a different distributor, and the machine starts again. The cost of the reset is measured in compute minutes. The cost of the detection cycle is measured in engineering quarters.

This is the same asymmetry that makes content moderation hard everywhere, but it is worse here, because in moderation the adversary usually wants a specific piece of content to survive. Here the adversary is indifferent to every individual track. They are not attached to the music. They will happily throw away the entire catalogue and generate another one, because the catalogue was never the point.

Eighty five percent is not a hundred

If 85 percent of the streams on a category are fraudulent and you demonetise the category, you have done something real. You have also, arithmetically, established that the remaining 15 percent were plays that the classifier considered legitimate and that are now unpaid, and that any fraud which does not present as fully AI generated content continues to be paid.

That second part matters more than the first. Nothing about the fraud mechanism requires the underlying track to be AI generated. An operator can license cheap production music, or commission it, or use public domain recordings, and run exactly the same automated listening against it. The moment content classification becomes the enforcement mechanism, the rational adversary response is to stop tripping the content classifier. You have not removed the incentive. You have added a specification to it.

False positives land on real people

And there is a cost on the other side that the industry is not talking about enough. A classifier that decides which music is AI generated will be wrong sometimes, and every false positive is a working musician who used a generative tool for a drum track or a vocal double, and who now finds their catalogue demonetised by an automated decision with an opaque appeals process.

The line between assisted and generated is genuinely blurry, it is getting blurrier, and it is an aesthetic and contractual argument rather than a technical one. Building the payment system's fraud control on top of an unresolved argument about what counts as real music is not a stable foundation. It guarantees a permanent stream of disputes in which the platform is asked to adjudicate authorship, which is a job nobody wants and nobody can do well.

What would a human bound royalty event look like?

Here is the reframing. The industry is fighting about the track. The money is being taken at the listener. Those are different layers, and only one of them is defensible.

A fraudulent stream has exactly one universal property, and it is not that the music was synthetic, or that the account was new, or that the IP address was in a data centre, all of which are contingent and evadable. The universal property is that no person was there. That is the thing that is true of every fraudulent stream and false of every legitimate one, which makes it the only sound basis for a control.

So the question becomes: can a royalty bearing event carry evidence that a human was behind it?

The shape of the artifact

A human bound royalty event is a play whose accounting record includes a proof that the account belongs to a unique person, produced on that person's own device, and verifiable later by someone who does not have to trust the platform.

Concretely, the account holder proves once, at enrollment, that they are a person and a distinct one, using an on device check where the biometric never leaves the phone and only a one way key is retained. There is no image, no template, no document, and nothing for the platform to lose in a breach. Then, on a schedule rather than per play, the session carries a fresh presence attestation. The royalty report can then separate streams attributable to proven unique humans from streams that are not.

The record looks roughly like this:

{
  "event": "royalty_period_attestation",
  "period":     "2026-Q3",
  "platform":   "example-streaming",
  "account_key": "9f2c...c41a",   // one-way key, not an identity
  "unique_human": true,           // proven once at enrollment
  "attestations": 42,             // presence proofs during the period
  "streams_attributed": 3184,
  "issued_at":  "2026-10-01T00:00:00Z",
  "signature":  "ed25519:MEUCIQD..."
}

Note what is absent. There is no name, no email, no device fingerprint, no listening history, and no location. A collecting society or a label auditing this record learns exactly one thing: how many of the streams they were paid on came from accounts that had proven a unique person was behind them. They learn nothing about any individual listener, which is both the privacy property and the reason a platform could plausibly agree to publish it.

The verification is a signature check against a published key, with no callback to anyone:

from manav import verify_receipt

report = load_royalty_attestation("2026-Q3")
ok = verify_receipt(report, published_key)

if ok:
    human_share = report["streams_attributed"] / total_streams_claimed
    print(f"Verified-human share of paid streams: {human_share:.1%}")

That last number is the interesting one, and it does not exist anywhere today. No label, no society, no regulator and no artist can currently state what fraction of the streams they were paid on came from people. That is a remarkable gap in an industry that settles billions of dollars a year on exactly that quantity.

Would this interrupt playback? No, and that objection deserves a real answer

The immediate and entirely correct objection from anyone who has worked on a consumer product is that you cannot interrupt music to ask someone to prove they are a person. Playback interruption is the single most damaging thing you can do to a listening experience, and any design that requires it is dead on arrival.

So the design does not do that. Three things make it workable.

First, the proof is at the account, not the play. A person proves once at enrollment, and that proof is durable. Nothing happens per track.

Second, presence attestation happens at natural boundaries that already exist in the product: app launch after a long gap, a new device, a payment event, or a periodic re-attestation on the order of weeks. These are moments where the user is already interacting, so the marginal friction is a single biometric tap of the kind they already perform to unlock the phone.

Third, and most importantly, this is a payout control, not an access control. Nothing needs to be blocked. A stream from an unattested account still plays, still counts for the artist's public numbers, still feeds recommendations. It is simply reported separately in the royalty accounting. The enforcement decision, whether unattested streams earn at a lower rate or not at all, is a commercial and contractual question for rights holders to negotiate, not a technical one for the platform to impose.

That distinction is what makes the design politically survivable. It does not require the platform to lock anyone out, and it does not require anyone to agree on what AI music is.

InterventionWhat it targetsWho bears the costAdversary response
AI content classifierThe trackArtists using generative tools, via false positivesStop using generative tools; use cheap human made music
Stream pattern anomaly detectionThe playback patternHeavy listeners flagged as anomalousResidential proxies, humanised playback timing
Minimum stream threshold before payoutThe long tailGenuinely small artists, who earn nothingConcentrate fraud on fewer tracks to clear the threshold
Category demonetisationA content classLegitimate artists in that classMove outside the class
Distributor penalties and clawbacksThe upload channelDistributors and honest clientsRotate distributors, use more of them
Human bound royalty eventThe listenerListeners, one tap at enrollmentRecruit or rent real humans, at real cost per account

Read the last column down. Every row except the final one has an adversary response that costs almost nothing. The final row has an adversary response that reintroduces a per person cost, which is the entire point. It does not make fraud impossible. It makes it expensive in the one currency the operator cannot generate: distinct human beings.

Honest limits

This is a design sketch, not a shipped product, and the gap between those two things is where most identity proposals die. Here is what it does not do.

It does not stop someone paying real people. An operator who recruits ten thousand real humans to install an app and let it run has defeated this control, and that business already exists in adjacent markets. What changes is the unit economics: they now need to acquire, pay and retain humans, which turns an infinitely scalable script into a business with headcount and a marginal cost per unit of fraud.

Cross platform uniqueness is not shipped. Proving that one person holds one account on a single platform is achievable today. Proving that the same person is not separately enrolled across five platforms without any of those platforms learning who they are requires nullifier constructions that Manav has not shipped. Anyone claiming otherwise is describing a roadmap.

It does not settle the AI music question. Deliberately. A human bound royalty event pays for tracks that people chose to play, whoever or whatever made them. Whether AI generated music should be licensed, labelled, or paid differently is a legitimate argument about copyright and disclosure, and it should be had on its own terms rather than smuggled in through the fraud control. Some readers will consider that a weakness of the proposal. It is intended as a feature: fraud controls that depend on winning an unrelated cultural argument tend not to survive the argument.

It requires adoption by parties who did not ask for it. A platform has to implement it, and rights holders have to demand the reporting. The realistic entry point is not a platform volunteering. It is a collecting society or a large rights holder asking, in a contract renewal, for the verified human share of the streams they are being paid on. That is a question a lawyer can ask without any technology at all, and it is the question that would create the demand.

It does not fix the pro rata model. The pool structure is what converts fraud into a transfer between artists. User centric royalty models, where each subscriber's fee is divided among the artists that subscriber actually played, would change the mechanism substantially and are worth arguing for on their own merits. A listener proof composes well with that model and is not a substitute for it.

What to do this week

For rights holders, societies, distributors and artists, in rough order of effort:

  1. Ask the question in writing. At your next platform reporting cycle, ask what fraction of the streams you were paid on came from accounts with any form of human verification. The answer, including the shape of the non answer, is informative.
  2. Separate two line items in your own reporting. Streams removed for content classification, and streams removed for listener behaviour. Most royalty statements conflate them, and they are different failures with different trajectories.
  3. Run the dilution arithmetic for your own catalogue. Take your streams, the reported per stream rate, and a fraud assumption of 1 to 3 percent from the CNM range. The euro figure is usually more motivating than the percentage, and it is the number to bring to a negotiation.
  4. Audit your distributor's upload controls. Ask how many tracks per day a single account can upload, what identity is required to open one, and what happens to the other tracks in a catalogue when one is flagged.
  5. Push for listener level reporting in contract renewals. Not access to listener identities, which you should not want and should not have. A signed, aggregate, verifiable statement of the human share.
  6. If you build platform infrastructure, instrument the account, not the stream. Log the enrollment event and its assurance level as a first class field in the royalty pipeline, even before any verification exists. You cannot report on a field you never captured.
  7. Do not accept a detection score as an answer. A percentage produced by the party being audited, using a method it will not publish, is a marketing artifact. Ask what would be verifiable by a third party without trusting the platform.

If you want to see what an offline verifiable receipt looks like in practice, the humans first demo shows the enrollment and the proof, and the developer documentation covers the widget modes and the verification API.

The general lesson

Every system that pays out per event eventually gets a machine pointed at it. Advertising learned this, and responded with measurement. Reviews learned it, and responded with classifiers. Surveys learned it, and responded with attention checks. Streaming learned it, and responded by classifying the music.

In every case the response was to examine the artifact more carefully, and in every case the adversary simply produced a better artifact, because producing artifacts is the one thing that got radically cheaper. The property that did not get cheaper is being a specific person. Systems that pay per event will eventually have to price that in, and the ones that do it deliberately will do it better than the ones that wait.

For streaming the stakes are unusually clean, because the victims are identifiable and sympathetic and the mechanism is arithmetic. The money is not coming from a platform's marketing budget. It is coming from the divisor, and the divisor is full of people who make music.

Frequently asked questions

How much streaming fraud is there? Deezer reported in January 2026 that up to 85 percent of streams on fully AI generated tracks were fraudulent, and demonetised them. Across all platforms and all content, France's Centre National de la Musique found that between 1 and 3 percent of streams were fraudulent. The two figures measure different things: one is a fraud rate within a narrow category, the other is a share of total listening.

Why do bots stream AI generated music? Because streaming royalties are divided from a fixed pool in proportion to play counts, so any counted play claims a share of the pool. Generating tracks costs almost nothing, so an operator can create an unlimited supply of objects that are eligible to receive royalties, then use automated listening to claim a share. The music is not the product. It is the entry ticket.

Does streaming fraud take money from the platform or from artists? From artists. In the pro rata model the revenue pool is fixed before it is divided, so a fraudulent stream does not create a new payment, it enlarges the divisor. Every real artist's per stream rate falls slightly. This is the opposite of advertising fraud, where the advertiser absorbs the loss.

Can a platform prove a stream came from a human? Not today, in any way a third party can check. A platform can assert it. The design proposed here would let an account prove once that a unique person is behind it, using an on device check that stores only a one way key, and would let a rights holder verify the resulting aggregate report offline against a published key rather than trusting the platform's word.

What is a verified listener? An account that has proven a unique human is behind it, without the platform holding any biometric template, document or identity. It is a property of the account, established once and re attested periodically, and it is used to separate royalty bearing streams in reporting rather than to block anyone from listening.

Would this stop AI generated music from earning royalties? No, and it is not designed to. If people genuinely choose to play a track, it earns, whoever or whatever made it. This control targets plays with no person behind them. Whether AI generated music should be labelled or licensed differently is a separate argument about copyright and disclosure, and it should be settled on its own terms.

Why not just improve the fraud detection? Because the adversary iterates faster than the classifier and can discard an entire catalogue at no cost. Detection also creates false positives that land on working musicians who used generative tools legitimately. Proving the listener targets the one property every fraudulent stream shares and no legitimate stream lacks: that no person was there.

Sources

  1. Deezer newsroom, announcement on the demonetisation of fully AI generated music and the finding that up to 85 percent of streams on those tracks were fraudulent, January 2026: newsroom-deezer.com
  2. Centre National de la Musique, study on stream fraud across platforms: cnm.fr
  3. IFPI Global Music Report, annual recorded music market figures: ifpi.org
  4. Financial Times coverage of Deezer's AI music fraud disclosures: ft.com
  5. Spotify Loud and Clear, royalty model and policy disclosures including minimum stream thresholds: loudandclear.byspotify.com
  6. United States Department of Justice, press release index for cases concerning streaming manipulation: justice.gov/news
A fraudulent stream is a table nobody sat at, counted in the divisor. The platform does not pay for it. The other artists do.