Fraud in Music Streaming on Legit Platforms

By now, many people who pay attention to artists’ rights have read the David Segal New York Times story published on January 13 about the amateur folk duo Bad Dog discovering their songs on major streaming platforms, but with different titles and attributed to a different creator. In what should be a surprise to nobody, it is easy to game the music streaming system and siphon from the revenue pool, even if you’ve never composed or recorded a song in your life. It’s a classic case of The Internet Giveth, and The Internet Taketh Away—because many DIY tools promoted to help new artists launch careers can be used by bad actors engaging in fraud.

“David Post and Craig Blackwell have been devoted amateurs for decades, and they’re long past dreams of tours and limos,” Segal begins. Post and Blackwell are, oddly enough, both D.C. attorneys—and cyberlaw and copyright law attorneys to boot. Although they were more interested in regaining control of their music than the revenue, their difficulties point to the fact that control is everything, especially if the artist does care about revenue.

The problem lies in the fact that anybody can create an account with a music publisher/distributor, rename and reattribute a bunch of pirated tracks, and then upload the songs to multiple platforms to hijack the revenue that belongs to the real artists. Based on the Segal article, it seems that not all publisher/distributors are equal when it comes to verifying authorship or ownership of the tracks. The article cites the service called Level used in the Bad Dog incident, and I cannot comment on the specific anti-fraud efforts of all these services.

Naturally, this scam won’t work with mega hits for a variety of reasons, but for a niche indie like Bad Dog—or more critically for the new artist who is trying to start a music career—songs that are relatively obscure make a perfect target. The scammer won’t earn much from a small heist of songs, but at scale, the dividends can obviously provide sufficient passive income to make the “effort” worthwhile. I recommend the NYT article for a full account, but two segments struck me as deserving of comment—one editorial, and one semi-mercenary.

Citing these segments out of order, first is a comment by David Post, referring to the evolution of the Digital Millennium Copyright Act (DMCA) and the appearance of Napster. “In 1997, I don’t think people were thinking about this automated operation that just sucks up unprotected material, rejiggers it to make it unfindable and uploads to platforms where they can start monetizing it. That wasn’t on anybody’s radar.” For context, Post alludes earlier in the article to his own copyright skepticism, which echoes views many would describe as “copyleft.” But this was on nobody’s radar?

Okay, maybe this exact method of scamming was not envisioned in 1997, but it hardly takes a leap of imagination to see the progress from illegal P2P to legal downloads in tandem with illegal downloads, followed by legal streaming in tandem with illegal streaming. In fact, it doesn’t take any imagination because copyright piracy for profit has been a reality for about 30 years, and there are few systems on the internet that cannot be gamed—especially if the legit platform operator lacks an incentive (i.e., is shielded from liability) to remove scammers. Also, the nature of Bad Dog’s problem did not suddenly appear in late 2023. For instance, I wrote about fake Bob Seger and music tracks owned by Spotify in 2017, which can be seen as a prelude to the kind of scam at work in this instance.

So, if Post is suggesting the DMCA needs overhaul to address workarounds to notice-and-takedown, I welcome him to the cause because professional creators have been shouting into a hurricane for at least 20 years about the near uselessness of the provision as a viable remedy to piracy. Given Post and Blackwell’s day jobs, I do wonder whether they only just discovered the issue the moment it affected their music, but in any case, the DMCA brings me to the other quote from the article that I want to highlight:

To retrieve their songs, Mr. Post and Mr. Blackwell sent out what are called takedown notices, or formal requests to remove pirated music, to a bunch of different sites. The band members used their SoundCloud page to demonstrate that their recordings predated all the uploads on the streaming platforms.

As stated, the DMCA takedown provision is middling at best. Segal reports that Amazon and YouTube removed the pirated tracks quickly, but Apple and Spotify did not. What struck me about the above paragraph, though, is the duo’s use of their SoundCloud page to prove priority and ownership of the work, which is kind of a digital-age version of mailing a copy to oneself—a.k.a. the “poor man’s copyright,” which is meaningless as a mode of legal protection. That brings me to the slightly mercenary point I wanted to make that the musical artist in this same position would find it both easier, and possibly more effective, to send the Copyright Office registration numbers associated with the works that should be removed by DMCA takedown.

One aspect of a registration is that, by operation of law, it is prima facie evidence of ownership. Walk into federal court with those registration certificates, and the burden is on the opposite party to prove that you’re not the owner of the work. In fact, without registration, you can’t walk into a court with an infringement claim, but with regard to a DMCA takedown—especially sent to one of the major platforms—the registration is literally a government seal establishing ownership of the work. It doesn’t guarantee that every platform will expeditiously comply with a takedown request, but it does give them a good reason to do so.

Further (and this is the mercenary part) because I am a passionate advocate for the rights of independent creators, I highlight this incident as the co-founder of a software business called RightsClick. A suite of tools designed to make copyright management easy for the entrepreneurial creator, the app facilitates fast, simple registration that simultaneously builds a database of Titles with their associated registration numbers. Thus, the indie musician in the same position as Mad Dog could look up those numbers in about two minutes and include them in a DMCA notice. Again, not a guarantee of compliance by the platform, but a stronger incentive. Including registration numbers is, after all, what the attorneys prefer to do when they send takedown notices.

I hope readers will forgive the plug for RightsClick in this instance. I generally keep IOM commentary and that venture separate, but this story seemed like a good moment to don both hats. Regardless, the point worth emphasizing is that indie artists should register their work with the Copyright Office. No creator should ever be required to prove they own the work requested for takedown—the provision is already subject to penalties of perjury—but to the extent the platforms stall or play games in this regard, a registration number is a lot better than any other evidence one might otherwise provide.


 

UPDATE/CORRECTION:  Thanks to a representative of Bad Dog, who wrote to tell me that the duo did file a registration application for the album The Jukebox of Regret very soon after discovering the music had been pirated. This same source also states that the music was pirated within one week of publication to SoundCloud, hence the immediate use of that information to show priority and ownership. Based on this information, I wish to correct any implication that Post and Blackwell completely ignored copyright registration, though I would encourage indie artists to register before distributing work to the market. This story proves how quickly your work is likely to be pirated.

Thoughts on the No AI FRAUD Act

The acronym stands for No Artificial Intelligence Fake Replicas and Unauthorized Duplication. Introduced as a discussion draft by Rep. Maria Salazar et al., the No AI FRAUD Act would create a novel form of intellectual property in direct response to the use of AI to “clone” a likeness. With parallels to right of publicity (ROP) law, combined with a copyright-like, transferable ownership of rights, the No FRAUD bill is sweeping as currently proposed, citing a range of conduct, from deepfakes to create and distribute nonconsensual intimate material, to cloning an actor or singer’s voice for commercial exploitation.

In short, the law would prohibit replication of anyone’s likeness without permission, and then, the purpose of the unlicensed replication would determine the nature of the harm and available remedies. Although the intent of this bill is well-founded in addressing certain harms to individuals like performing artists, the bill’s current scope, combining permission and intent, and seeking to remedy a broad range of potential harms, raises some difficulties.

Permission vs. Intent

As discussed on this blog, Cyber Civil Rights Initiative (CCRI) leaders, Danielle Citron and Mary Anne Franks, have advocated a permission-based, rather than an intent-based cause of action for the nonconsensual distribution of intimate material, commonly referred to as “revenge porn.”[1] The CCRI has worked hard to demonstrate that merely distributing this material without permission is criminal, regardless of the intent to cause harm, and this makes sense in response to the nature of the conduct. But advancement in AI replication presents a unique challenge to the principle that permission is universally the signal event triggering liability.

No question that the guy who shares intimate material of an ex, a girl at school, a work colleague, etc. should be held accountable solely on the basis that he lacked permission, and this is valid whether the visual material is real (i.e., photographic) or synthetic (i.e., produced with an AI). First Amendment defenses for this type of conduct have reasonably failed when various parties challenged the constitutionality of several of the “revenge porn” laws, now in force in 48 states. The permission principle in harassment-based complaints should not be disturbed by the No FRAUD Act, and Congress should likely avoid any temptation to combine the intent of this bill with current or developing federal prohibitions for “revenge porn.”

But the use of AI to replicate a likeness cannot so broadly be proscribed for all purposes. As the Motion Picture Association notes in its response to the bill, “… any legislation must protect the ability of the MPA’s members and other creators to use digital replicas in contexts that are fully protected by the First Amendment.” Notwithstanding contractual conflicts that may arise in the future among performers and producers, the MPA is right to note that AI cloning for expressive purposes that constitute protected speech should not be swept into the scope of legislation like the No FRAUD Act.

The example I often use with friends and colleagues is the movie or TV series that casts a public figure (let’s call him Donald Trump) in a light he might not appreciate. Expressive portrayals—factual, dramatic, or sardonic—of public figures are paradigmatic forms of protected speech, and this principle should not be altered by vesting new IP rights in persons, premised solely on the use of AI models to achieve the same expressive results historically created with old-school “movie magic.” In other words, Trump should no more be empowered to enjoin the use of his AI likeness to comment upon his role in society than he would have been allowed to stop Saturday Night Live from producing the sketches featuring Alec Baldwin.

Vesting new “likeness IP” rights in all persons is a reasonable response to the potential harms—both financial and reputational—that may be caused to millions of creative professionals and ordinary citizens. But these goals must allow for expressive uses of AI replication, adhering to longstanding contours protecting the speech right and controlling limits like libel and defamation.

In another example, imagine a documentary about the events of January 6th that includes reenactments based on witness testimony describing the actions of the former president during the attack on the Capitol. The documentary producer’s legal responsibility to balance faithful reportage with reasonable expressive license should not be altered solely on the basis that the film may use generated AI likenesses of Trump, Meadows, Hutchinson, Ivanka, et al. rather than actors to produce the same scene.

With a documentary film, one can imagine a legal requirement to inform the viewer that what they are seeing is an AI-generated reenactment (rather than, say, someone’s cellphone recording), but no such requirement should apply to a non-documentary audiovisual work. In either case, misinformation is already thriving in a dangerously blurry space between fact and fiction and a decline in media literacy fostered by the ability of any individual to distribute any fragment of material without context on a public platform. In other words, the documentarian can do her job right, but she cannot stop every potential bad actor from taking a segment of that reenactment and publishing it in a manner that changes its context and feeds a false narrative. (Thank you to all those who celebrated “remix culture” as a rejection of copyright law.)

AI Generated Likeness and the Misinformation Problem

Regarding the documentary example, the preamble of the No FRAUD working draft cites the use of unauthorized likenesses for the purpose of disinforming the public about matters of a factual or newsworthy nature. And while this is indeed a problem that AI tools will be used to exacerbate, it is a challenge that should be addressed separately from the intent and sweep of the No FRAUD proposal. Congress must recognize that the capacity to cause widespread, societal harm through disinformation by means of AI likeness replication is too hazardous and too rampant to remedy on a case-by-case, civil-liability basis. And that’s even if the producer of the fake is operating within the reach of U.S. law rather than, say, China or Russia.

Further, there is a legal tension created by comparing and contrasting the entertainment satirist with the news provocateur who trades in misinformation, as we see in the claims of slander against Tucker Carlson of FOX News in 2020. Arguing that “no reasonable person” would truly believe everything Carlson says, Fox’s attorneys successfully defended the network against any cause of action, and while this may be a reasonable finding based on the facts presented, it is one of many examples in which the lines separating opinion, criticism, satire, and information have been blurred beyond relevance vis-à-vis public perception. Now add the ability to cheaply recreate anyone’s likeness with sophisticated AI, and how far can a “news” organization push the line under the same protections that apply to the satirical filmmaker or The Daily Show?

Of course, my references here to Trump and Carlson allude to a much bigger, underlying problem—namely that Congress is not going to effectively address the use of AI likeness for misinformation unless Members on both sides can agree to mutually define fact and fiction. Not to say that Dems never cling to narratives built on some rather shaky foundations, only that it’s hard to compete with the existential lies of whatever the hell the GOP has become in the thrall of Trumpism. That and no American political figure has ever proven to be so thin-skinned in response to criticism.

For the moment, my own view is that a bill like No FRAUD should be narrowly tailored to vest new “likeness IP” in persons to proscribe compelled speech and commercial exploitation that meets standards akin to unfair competition. Further, because such uses require a court to weigh the intent of likeness replication, this new right should not preempt or alter anti- “revenge porn” legislation, where lack of permission must remain the sole cause of action. While I see the potential of this bill to protect various artists and non-artists with novel rights against novel harms, difficulties like those addressed in this post must help define the contours of those new rights.


[1] “Revenge porn” is a problematic term because it implies intent to harm, which is anathema to the principle that lack of consent is the cause of action.

Image by: meyerandmeyer

“Fair Use” is Not a Great Business Plan

Lately, we’ve seen several headlines and comments from tech giants say that AI ventures simply cannot succeed if they are forced to contend with the copyrights in the billions of works they have scraped for the purpose of machine learning (ML). When these headlines are paired with the rampant assertions that ML is inherently fair use—a subject addressed in last Wednesday’s Senate Judiciary Committee (SJC) hearing on AI and journalism—one has to wonder about the business decisions being made before generative AI exploded last year.

In many posts on this blog, including at least a few written during “Fair Use Week,” I have repeated the caveat that “fair use” is not a magic phrase that makes infringement claims disappear. Usually, that advice is directed at small and independent users of works, suggesting they not listen to Big Tech and its network of academics and activists, who will not be on the hook for the small guy’s copyright infringement. I always assumed the big guys knew better, that they were merely chanting the “fair use” mantra as a rhetorical device in the blogosphere to promote the anti-copyright agenda. But maybe they don’t know better.

If I were an AI investor asking about potential liability, and the founders told me, “Don’t worry, what we’re doing is fair use,” my immediate response would be to ask whether there is sufficient funding for major litigation, to say nothing of predicting the outcome of that litigation. Because simply put, the party who conjures the term “fair use” has effectively assumed that a potential liability for copyright infringement exists. And if that assumption is a bad business decision, then that’s the founders’ problem, not a flaw in copyright law.

No matter what the critics say, or how hard certain academics try to alter its meaning, the courts are clear that fair use is an affirmative defense to a claim of copyright infringement, which means that building a business venture on an assumption of fair use is tantamount to assuming that lawsuits are coming. And if it’s a multi-billion-dollar venture that potentially infringes millions of works owned by major corporations, then the lawsuits are going to be big—perhaps even existential.

Do Not Expect Congress to Change Fair Use in Any Direction

Notably, as reported in Wired, Conde Nast CEO Roger Lynch stated at one point during questioning by the SJC last week, “If Congress could clarify that the use of our content, or other publisher content, for the training and output of AI models is not fair use, then the free market will take care of the rest,” to which Sen. Hawley replied that this seems reasonable. But I wonder about this exchange. While it is encouraging to find the senators more sympathetic with the news organizations than with the AI developers, I doubt (and would not even hope) that Congress is going to amend the law to explicitly state that ML is categorically never fair use.

Fair use comprises a history of judge-made law that was codified into statute as Section 107 of the 1976 revision of the U.S. Copyright Act. But the statute does not draw bright lines stating that X is always fair use and Y is never fair use, and for good reason. Because justice for all parties is best served by a court weighing the specific facts of a specific use of a specific work, or body of works. Hence, an attorney will tell you that fair use is a “fact intensive” consideration.

If Congress were to explicitly declare, for instance, that ML can never be fair use, this would be a significant departure from doctrine, and one that is preemptively unjust to the potential AI developer with a fact pattern that would favor a finding of fair use. As much as I find the major generative AI companies to be some combination of arrogant and/or useless, and as much as I scorn their generalizations to-date about fair use, it would be wrong to endorse legislative revision of the fair use doctrine as a sound response.

In fact, if the court were to find fair use for ML in New York Times v. Open AI (and I doubt it will), and Congress sought to remedy that outcome, it would still not make sense to amend Section 107. If anything, news organizations and other copyright owners would likely seek a new section of the Copyright Act tailored to the nature of the new form of harm, which Big Tech would then blindly oppose with every available resource. For instance, it is possible that the Times would not currently be suing Open AI if the tech industry had not opposed the Journalism Competition and Preservation Act (JCPA), which would have temporarily exempted news organizations from antitrust barriers to collective bargaining for licensing their content.

Regardless, no party should be asking Congress to “clarify fair use” in response to AI. If the AI founders and investors made a bad bet on an ultimate finding of fair use, that’s tough noogies for them. But neither should content creators want Congress to open that particular can of worms and disturb the fair use case law. Of course, where Congress should intervene is to address harms caused by AI where no law currently applies. On that subject, the next post discusses the recently proposed No AI FRAUD Act.


Phot source by areporter.