The Music Industry's New AI Fraud Gate Opens Without DistroKid
TL;DR
On September 14 IFPI, the recording industry's global trade body, launched the Streaming Integrity Initiative (SII): five baseline anti-fraud practices for music distributors, the companies that deliver tracks to streaming services. Signatories commit to Know Your Customer identity checks, vetting uploads for AI-generated content and likeness abuse, banning repeat offenders "across all platforms," and sharing fraud signals so a banned uploader cannot simply move to another service. Twenty-seven organisations are on the launch list, including all three major labels and 20 distribution companies. DistroKid, TuneCore, SoundOn and UnitedMasters are not. The published text contains no audits or penalties for signatories, so for now this is a checkpoint with a guest list, not a law.
What IFPI actually launched
The announcement casts distributors as "a gateway to the digital music ecosystem" with a "unique ability to prevent fraudulent content from reaching streaming platforms." That is the whole bet. A streaming service can spot bot plays after the fact. A distributor sees the uploader and the audio before a single stream exists.
The full text on IFPI's End Streaming Fraud campaign site lists five practices:
- Verify: "Before distributing content, verify the identity and legitimacy of the customer through robust KYC and fraud checks."
- Vet: lyrics and metadata checks, audio content recognition, and a dedicated clause to "implement measures to identify AI-generated content and vet for potential associated issues, including streaming fraud," plus protections for an artist's voice, name, image and likeness.
- Act: detect streaming anomalies, investigate, and "after repeated violations, ban the customer across all platforms," with an immediate ban still possible "in appropriate circumstances."
- Share: pass "high-confidence indicators of fraudulent and infringing activity" through data-protection-compliant industry arrangements "to help prevent offenders from re-entering the ecosystem through other services."
- Measure: track whether the measures work and update them as fraud methods change.
Read the Vet clause carefully. It does not ban AI music. It tells distributors to identify it and check whether it is part of a fraud or impersonation problem. The penalties are reserved for fraud and infringement, not for the fact that a model made the track.
Why the AI clause is not decoration
Deezer has published the clearest running count of what generative audio did to the upload queue. In July it said it now receives about 90,000 fully AI-generated tracks every day, and that AI music passed 50% of all new uploads in June 2026. In January 2025 the figure was about 10,000 a day, or 10% of deliveries, according to Music Ally's tally of Deezer's earlier releases.
The more telling number is what happens after upload. Deezer says fully AI-generated music accounts for only 1 to 3% of total streams, yet "up to 85% of the streams generated by fully AI-generated tracks were in fact fraudulent in 2025." Across its entire catalogue, fraud was 8% of streams.
That is the business model the SII is aimed at. Nobody needs a hit. You need a pile of cheap tracks, enough fake accounts to play them, and a distributor that does not ask questions. Streaming royalties are paid from a pool split by share of plays, so every fake play takes money from artists with real listeners.
A pro-rata pool works like one pizza sliced by a show of hands. A bot farm raises millions of hands, and every genuine artist's slice gets thinner whether or not a human ever heard the tracks being "played." Generative audio made it nearly free to invent enough names to raise hands for.
The US already has the template case. In March, a North Carolina man named Michael Smith pleaded guilty to conspiracy to commit wire fraud after using AI to generate hundreds of thousands of songs and bots to stream them billions of times between 2017 and 2024. He agreed to forfeit $8,091,843.64, according to the US Attorney's Office for the Southern District of New York. Help Net Security describes the toolkit as fake user accounts, bulk email registrations and scripted playback on cloud infrastructure. Identity checks and shared ban signals are aimed squarely at the first two.
Who signed, and who didn't
The launch list has 27 names: Sony Music Group, Universal Music Group and Warner Music Group; the independent-sector bodies Merlin, IMPALA and WIN; HYBE; and 20 distribution companies and platforms, including CD Baby, Ditto Music, FUGA, Symphonic and The Orchard.
Music Ally flagged the obvious gaps: DistroKid, Believe and its TuneCore, TikTok's SoundOn and UnitedMasters are not on it. Their history does not make them anti-fraud holdouts. In June 2023 CD Baby, TuneCore and Believe, DistroKid, UnitedMasters, Symphonic, EMPIRE and Vydia co-founded the Music Fights Fraud Alliance with Spotify and Amazon Music, operated through the nonprofit National Cyber-Forensics and Training Alliance.
No reason for the absences appeared in the launch coverage, and IFPI calls the current names "the first distributors to publicly support" the initiative while inviting others to join. One overlap is worth noting. Suno's v6 announcement last week named Warner Music Group, BMG and Believe as industry partners. Warner is on the SII list. Believe is not, at least not yet.
What changes if you make music with AI
- Expect identity checks. If your distributor signed, "robust KYC" before distribution is now a public commitment. Anonymous accounts pushing high volumes are exactly the pattern it targets.
- Expect detection, not prohibition. The Vet clause says identify AI content and check it for fraud and likeness problems. A fully generated track is not banned by the SII text. A cloned voice of a real artist falls squarely under the voice, name, image and likeness clause.
- Bans are designed to travel. The Share clause exists so an offender removed from one service cannot come back "through other services." Treat a strike at one signatory as a possible strike at all of them.
- This is the third gate of the summer. IFPI and partners announced voluntary "AI-Generated" and "AI-Assisted" track labels on July 10, then chart-eligibility principles on July 30 that require AI recordings to use a properly authorised, lawful AI service and raise no stream-manipulation concerns. The SII moves the same logic to the upload step.
- Detection tooling just got a written demand. Signatories commit to "adopt and contribute to the latest audio, artist and artwork recognition technologies." If you build audio fingerprinting or AI-audio classifiers, that sentence is a customer list.
The caveats
This is a voluntary commitment. Neither the IFPI release nor the practices page describes audits, compliance reporting or consequences for a signatory that does not follow through. Two supporters also suggested much of this is already standard practice: WIN's CEO said the practices "align with those that many distributors in our network are already implementing," and Merlin said they "align closely with what Merlin already requires of its members." A pledge whose backers say they already comply is either proof the bar is sensible or proof it is low, and the launch material does not let you tell which.
Deezer's figures come from one service and its own detector, which it says is 99.8% accurate; that accuracy figure is self-reported. The Music Fights Fraud Alliance roster above is its 2023 founding list. The alliance's website currently shows only a holding page, so its present membership is not confirmed here.
Key Takeaways
- IFPI launched the Streaming Integrity Initiative on September 14: five baseline practices (verify, vet, act, share, measure) for music distributors, backed by 27 organisations including all three majors.
- Signatory distributors commit to KYC checks, AI-content detection, likeness protections, cross-platform bans for repeat offenders, and sharing fraud indicators so offenders cannot re-enter through another service.
- DistroKid, Believe/TuneCore, SoundOn and UnitedMasters are not on the launch list, although DistroKid, TuneCore and UnitedMasters co-founded the separate Music Fights Fraud Alliance in 2023.
- The AI link is measurable: Deezer receives about 90,000 fully AI-generated tracks a day, more than half of new uploads, and says up to 85% of their streams in 2025 were fraudulent versus 8% catalogue-wide.
- The rules target fraud and impersonation, not AI music itself, but AI creators using signatory distributors should expect identity checks and detection before release.
- There is no published enforcement mechanism, so the real tests are whether the unsigned DIY distributors join and whether shared ban signals actually flow.
Sources: IFPI press release, Streaming Integrity Initiative practices and signatories, Music Ally, Engadget, Deezer newsroom, July 2026, Deezer newsroom, April 2026, TechCrunch, Music Ally on Deezer, November 2025, TuneCore press release on the Music Fights Fraud Alliance, Help Net Security, US Attorney's Office, SDNY, Suno v6 announcement, IFPI AI labelling program, IFPI chart eligibility principles.