The Forgery Is Free
AI is collapsing the cost of manufacturing plausible music claims. The operating record was not built to defend itself.
Somewhere in your inbox this year there will be a claim. It will be well formatted. It will name a work you administer, cite a share percentage, reference a registration, and attach a schedule that looks exactly like every legitimate schedule you have ever received. It will be polite, specific, and confident. There will be nothing about it that looks wrong.
That used to mean something. It no longer does.
For the whole history of this industry, bad claims had one natural predator: effort. A false assertion about who wrote what, or who controls which share, required a human being willing to construct it, type it, and defend it. Fraud existed, but it was artisanal. It moved at the speed of one motivated liar. Every process this business runs on, every claims portal, every counter-claim window, every request for supporting documentation, was built on that assumption. The assumption is now dead.
Here is what killed it. In September 2024, federal prosecutors in New York charged a North Carolina musician named Michael Smith in what was described as the first criminal case involving artificially inflated music streaming. In March 2026, he pleaded guilty to conspiracy to commit wire fraud. According to the Department of Justice, Smith created hundreds of thousands of songs using artificial intelligence, distributed them across the major platforms, and used thousands of bot accounts to stream them billions of times, fraudulently obtaining more than eight million dollars in royalties. The prosecutor’s summary is worth keeping: although the songs and the listeners were fake, the money was real.
Read the case carefully and the important part is not the bots. It is that every artifact in the scheme, the songs, the accounts, the metadata, the denials, was cheap to fabricate and expensive to disprove. When the Mechanical Licensing Collective halted payments and confronted him in 2023, Smith and representatives acting on his behalf denied any manipulation. That intervention stopped one payment stream, but it came after the broader scheme had already been running for years. The asymmetry is the story, and it is becoming an ambient condition of digital distribution.
The volume numbers are public. Deezer, which publicly reports its AI-detection data, said in April 2026 that it receives roughly seventy-five thousand fully AI-generated tracks every day, about forty-four percent of everything uploaded, and that a large majority of the streams those tracks attract are flagged as fraudulent. Fifteen months earlier the figure was ten thousand a day. Sony Music told the IFPI’s Global Music Report event in March 2026 that it had requested takedowns of more than one hundred and thirty-five thousand AI deepfakes impersonating its artists, up from seventy-five thousand a year earlier, with roughly sixty thousand identified in the previous twelve months alone.
The Tyler, the Creator episode is the one I would put in front of anyone who still thinks this is a fringe problem. In July 2025, days before his album Don’t Tap the Glass arrived, an AI-generated track using the album’s title spread across TikTok as a supposed leak. The real album entered the Billboard 200 at number one. Futurism reported that an upload of the AI fake held the number two position in Spotify’s album search results for the album’s own name, and that the fake dominated the search results fans were actually using to find the record. The counterfeit did not outsell the original. It out-discovered it.
Platforms have responded. Spotify introduced impersonation policies and an AI spam filter, and in March 2026 began testing an optional system that lets participating artists approve or decline eligible releases before they appear under their names. Sit with what that last measure concedes: Spotify can no longer assume that music delivered under an artist’s name has anything to do with that artist.
All of that is detection, and all of it is necessary. None of it is sufficient for the layer that decides who owns what.
Detection answers two related questions: is this audio synthetic, or is this streaming activity fraudulent? It cannot answer the question that decides where money actually goes: is this claim true? A claim is not audio. A claim is an assertion about ownership, and assertions are adjudicated the way they were in 1995, by checking them against records. Which records? A spreadsheet on someone’s laptop. A PDF schedule from a deal that closed years ago. A society database that, as the first article in this series showed, routinely disagrees with the writer’s own files. An email thread. Institutional memory. Records that do not know who asserted each fact, or when, or what the fact was before someone changed it, and that cannot demonstrate any of it to a stranger.
Those records were survivable while lying was manual, and we already have the damage report from that era. When the Mechanical Licensing Collective was established, the accumulated pool of United States digital mechanical royalties that could not be matched to an owner between 2007 and 2020 came to roughly four hundred and twenty-seven million dollars. Not necessarily stolen, and not necessarily disputed. Simply not matched to registered works and rightsholders, because the records could not reliably connect the reported uses to the people entitled to them. New unmatched royalties accrue every month. That is what this industry’s ownership data produced under ordinary operating pressure at human scale.
One honest caveat, because this argument deserves it. There is no public dataset yet measuring machine-generated ownership claims at scale. What the evidence establishes is the collapse in the cost of manufacturing plausible content, plausible identities, and plausible activity. The warning is what follows when that same collapse reaches the paperwork: the schedules, assertions, and supporting narratives through which ownership disputes are already conducted. Nothing about that paperwork is harder to generate than a song.
So remove the human speed. The same tools producing seventy-five thousand plausible tracks a day can produce plausible claims, plausible schedules, plausible chain-of-title narratives, and plausible counter-documentation, at zero marginal cost, in perfect formatting, in any volume anyone wants. Every claims process in this industry was priced on the assumption that fabrication was expensive and verification was merely tedious. The first half of that assumption is already gone. Verification still costs an administrator days per claim, because the record it must be verified against was never built to prove anything to anyone.
This is where the polite version of this article says the industry’s data quality needs improvement. The accurate version says something sharper. The operating record is now an attack surface. A catalog whose ownership history lives in overwrite-in-place spreadsheets and inboxes is a catalog whose history can be plausibly contested by anyone with a laptop, because the defender holds no evidence of a higher grade than the attacker can manufacture. When both sides of a dispute hold well-formatted files, and neither side’s file can show when it was created, who asserted it, or what it said last year, the dispute is decided by leverage, patience, and legal budget. Machines have unlimited patience.
Here is the question worth sitting with, and it is not rhetorical. If a confident, well-formatted, entirely false claim about one of your works arrived tomorrow, what exactly would you check it against? Not what would you believe. What would you produce, to someone who has no reason to trust you, that they could confirm for themselves?
For most catalogs, honestly answered, the response is a file the claimant could have made just as easily.
I will end where the earlier pieces ended, with the observation rather than the pitch. The defense against free forgery is not detection alone. It is a record that makes dishonest disputes expensive: one that captures who asserted what and when, that keeps its earlier states rather than overwriting them, and whose published positions are signed in a way that a stranger, a buyer, a society, a counterparty, or a machine can check without trusting whoever keeps the record. Other industries built records like that decades ago. Music mostly did not, because until now the cost of not having them arrived slowly, priced into holdbacks and audits and unmatched pools rather than felt directly.
The flood does not arrive slowly. The catalogs that come through it with their histories intact will be the ones that can show, cheaply and to anyone, what they claimed and when they claimed it. The rest will discover that in an age when anyone can manufacture a confident claim, a record that cannot defend itself is just the first draft of someone else’s.
Sources
U.S. Department of Justice, Southern District of New York, guilty plea announcement, 19 March 2026: https://www.justice.gov/usao-sdny/pr/north-carolina-man-pleads-guilty-music-streaming-fraud-aided-artificial-intelligence-0
U.S. Department of Justice, Southern District of New York, original indictment, September 2024: https://www.justice.gov/usao-sdny/pr/north-carolina-musician-charged-music-streaming-fraud-aided-artificial-intelligence
Deezer, AI-generated tracks now represent 44% of all new uploaded music, April 2026: https://newsroom-deezer.com/2026/04/ai-generated-tracks-represent-44-of-new-uploaded-music/
Sony Music deepfake takedowns, reported from the IFPI Global Music Report event, March 2026: https://www.musicbusinessworldwide.com/sony-music-has-targeted-135000-deepfakes-of-its-artists-music-for-removal-from-streaming-platforms/
Futurism, on the AI upload and Spotify search placement, July 2025: https://futurism.com/tyler-creator-ai-deepfake
Billboard, Don’t Tap the Glass debuts at number one, July 2025: https://www.billboard.com/music/chart-beat/tyler-the-creator-dont-tap-the-glass-no-1-billboard-200-1236031360/
Spotify, “Spotify Strengthens AI Protections for Artists, Songwriters, and Producers,” September 2025: https://newsroom.spotify.com/2025-09-25/spotify-strengthens-ai-protections/
Spotify for Artists, “Introducing Artist Profile Protection,” March 2026: https://artists.spotify.com/blog/introducing-artist-profile-protection
The Mechanical Licensing Collective, on historical unmatched royalties: https://www.themlc.com/historical-unmatched-royalties
Arpit Bhatia is the founder of SplitGraf, which builds a provable operating record for music rights: a system where changes are journaled, published states are signed, and a counterparty can verify what a catalog claimed, and when, without having to trust whoever keeps the record. SplitGraf is opening a small number of pilots with publishing operators and administrators using real catalog data. Reach him at arpit@splitgraf.com.


