a440 Dive in Corpus

State of the Union

September 24, 2026

Your next delivery queue will ask a question nobody can answer today: which of these tracks are real. We bought the generators and measured what a stranger can actually verify.

WHERE WE ARE

Every A&R inbox, every distribution queue, every sync pitch now carries the same hidden question: is this real. The contracts already assume an answer. The instruments do not exist, so we measured what does.

We bought retail accounts at Suno and ElevenLabs and made tracks the way any customer does. Every download went through 38 attacks a real file meets in the wild: re-encodes for messaging apps, trims for socials, loudness for ingest, a simulated room for anything captured over air. Then we checked what a stranger could still prove.

Suno signs every download with a cryptographic label. Real technology, honestly implemented. After any of the 38 attacks the label is gone, including a lossless remux that leaves every sample untouched. Zero of 38. The moment a track leaves the download folder, its proof of origin leaves with it.

ElevenLabs ships the same brittle label on app downloads and no label at all on API deliveries. The audio itself carries a watermark, and that mark is the toughest thing we measured. It survives codecs, loudness, trims, splices, streaming. One tempo shift kills it. A simulated room kills it. All thirty-eight reads complete, thirty survive, against a vendor rate limit that drips one verdict an hour.

Suno signed label 0 / 38 attacks ElevenLabs signed label (app downloads; API ships nothing) 0 / 8 processing steps ElevenLabs in-audio watermark 30 / 38 reads
Fig 1 - What survives the battery. Watermark column: all 38 reads complete.

THE DETECTOR PROBLEM

The industry's other answer is detection: run the catalog through a model, trust the score. We ran the strongest published open detector against current tracks from both services. Six tracks, six misses, scores from 0.05 to 0.30 against a decision line of 0.5. The human control, a Joplin performance from 1899, scores 0.04. Correct.

Attack those same tracks and the detector wakes up in odd places: three trims, a reverb, a noise floor. Cut thirty seconds off an ElevenLabs song and the machine finally calls it synthetic. A score that moves when the audio gets shorter tells you nothing about where the audio came from.

0.5 - detector's line 0 1 human .04 s03 .05 el02 .08 s05 .12 s01 .17 s07 .18 el01 .30
Fig 2 - The baseline. One open detector (SpecTTTra, ICLR 2025), un-attacked current tracks. Every AI track missed; the human recording read correct.

WHAT IS SAFE

Human recordings, for now. Both controls read clean: the 1899 Joplin, and a machine-made track shown to the wrong vendor's detector. Nobody gets falsely accused by the public paths that exist today. For the working musician who never touched a model, that is the number that matters.

WHAT IS VERIFIABLE

Here is the part that should change the conversation: the capability exists. Sony's open research watermark, embedded into a track and run through the same battery, survives 13 of 20 attacks fully, recovers part of the payload on 5 more, and any stranger can decode it with public code. It agrees with ElevenLabs' commercial mark on every shared attack. The science works. What is missing is the shipping: a mark in every track, a reader anyone can open, a result a lawyer can cite.

What a stranger can actually check today is thin. An ElevenLabs track carries a mark that survives the usual trip to a listener and reads back with provider, model, and timestamp attached, as long as nobody shifts the tempo. A Suno track carries a signature that dies the first time anyone re-saves the file. Suno says a public watermark is coming; the August statement said weeks. The day it ships, it gets measured.

ElevenLabs SilentCipher DUR-04 remux, lossless DUR-05 metadata strip DUR-25 trim first 30 s DUR-26 trim middle 30 s DUR-27 trim last 30 s DUR-28 clip 10 s DUR-31 streaming upload sim DUR-32 acoustic path sim
Fig 3 - The control: 8 attacks read against both marks. ElevenLabs through its public detector; SilentCipher decoded by us. Green survives, amber partial, red dead.

UNTIL NOW

None of this had an instrument. No public record of which marks survive the real world, which detectors can be trusted, which claims hold. The next fights make the gap expensive: policy asks written around proofs that do not exist yet, catalog deals priced on claims nobody verified, vendor rollouts that turn a claim into a measurement the week they ship, detection papers trained on models two generations old. The industry is about to write evidence requirements into contracts. The registry being built here is the instrument for honoring them: every track purchased, every attack run, every verdict published with its receipts.

The receipts stay public: corpus, hashes, commands, verbatim detector responses. Dispute a number and it gets rerun against the published files. The reads keep landing.

Corpus  ·  The full standings  ·  Methodology