A significant vulnerability in digital music distribution systems allows AI-generated music to be uploaded directly to verified artist profiles on major streaming platforms, including Spotify, Apple Music, Tidal, and Amazon Music. This process occurs without the knowledge or consent of the actual artists.
The loophole enables individuals to collect royalties generated from streams of these unauthorized tracks. This method leverages the established popularity and listener base of legitimate artists to generate revenue from AI-created content.
The vulnerability was demonstrated when an AI-generated song, titled "Riding High," was uploaded to the verified Spotify page of the Brooklyn-based punk band Lathe of Heaven on September 10. The song, created using the AI music generator Udio, did not feature the band's lead singer, Gage Allison, and had an album cover inconsistent with their usual style.
Lathe of Heaven did not create, perform, or willingly release "Riding High." The upload was achieved by exploiting the existing distribution mechanism, proving that it is possible to place AI-generated music under the name of real artists.
The scheme involves using generative AI to create music and then utilizing a distribution loophole to insert these tracks directly into a pre-existing artist's catalog. This allows the uploaded tracks to appear as official releases from the artist.
The proceeds generated from these streams are directed to the uploader, not the original artist. This co-opting of an artist's name and profile page can lead to higher payouts for the fraudulent tracks compared to typical AI-generated music without an established artist association.
While the distribution loophole has existed for several years, its abuse has become more widespread with the advent of accessible AI music generation tools. The ease with which these fake songs can be posted under real artists' names, including both smaller bands and highly popular artists, highlights the scale of the issue.
The process was described as "shockingly easy," taking only minutes to accomplish, indicating a lack of robust verification or authentication steps in the current digital music distribution pipeline.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A report by 404 Media reveals that scammers are using a distribution loophole to place AI-generated songs on legitimate artist pages across Spotify and other streaming platforms, allowing them to collect royalties. This scheme bypasses current verification systems, enabling fraudulent tracks to appear as official releases and diverting revenue from actual artists.
A loophole in digital music distribution allows AI-generated music to be uploaded to verified artist profiles on platforms like Spotify, Apple Music, Tidal, and Amazon Music without the artists' knowledge. This enables scammers to collect royalties by piggybacking on established artists' popularity, as demonstrated by a successful upload to the band Lathe of Heaven's page.