WHERE WE ARE
Every A&R inbox, every distribution queue, every sync pitch now carries the same hidden question: is this real. The contracts already assume an answer. The instruments do not exist, so we measured what does.
We bought retail accounts at Suno and ElevenLabs and made tracks the way any customer does. Every download went through 38 attacks a real file meets in the wild: re-encodes for messaging apps, trims for socials, loudness for ingest, a simulated room for anything captured over air. Then we checked what a stranger could still prove.
Suno signs every download with a cryptographic label. Real technology, honestly implemented. After any of the 38 attacks the label is gone, including a lossless remux that leaves every sample untouched. Zero of 38. The moment a track leaves the download folder, its proof of origin leaves with it.
ElevenLabs ships the same brittle label on app downloads and no label at all on API deliveries. The audio itself carries a watermark, and that mark is the toughest thing we measured. It survives codecs, loudness, trims, splices, streaming. One tempo shift kills it. A simulated room kills it. All thirty-eight reads complete, thirty survive, against a vendor rate limit that drips one verdict an hour.
THE DETECTOR PROBLEM
The industry's other answer is detection: run the catalog through a model, trust the score. We ran the strongest published open detector against current tracks from both services. Six tracks, six misses, scores from 0.05 to 0.30 against a decision line of 0.5. The human control, a Joplin performance from 1899, scores 0.04. Correct.
Attack those same tracks and the detector wakes up in odd places: three trims, a reverb, a noise floor. Cut thirty seconds off an ElevenLabs song and the machine finally calls it synthetic. A score that moves when the audio gets shorter tells you nothing about where the audio came from.
WHAT IS SAFE
Human recordings, for now. Both controls read clean: the 1899 Joplin, and a machine-made track shown to the wrong vendor's detector. Nobody gets falsely accused by the public paths that exist today. For the working musician who never touched a model, that is the number that matters.
WHAT IS VERIFIABLE
Here is the part that should change the conversation: the capability exists. Sony's open research watermark, embedded into a track and run through the same battery, survives 13 of 20 attacks fully, recovers part of the payload on 5 more, and any stranger can decode it with public code. It agrees with ElevenLabs' commercial mark on every shared attack. The science works. What is missing is the shipping: a mark in every track, a reader anyone can open, a result a lawyer can cite.
What a stranger can actually check today is thin. An ElevenLabs track carries a mark that survives the usual trip to a listener and reads back with provider, model, and timestamp attached, as long as nobody shifts the tempo. A Suno track carries a signature that dies the first time anyone re-saves the file. Suno says a public watermark is coming; the August statement said weeks. The day it ships, it gets measured.
UNTIL NOW
None of this had an instrument. No public record of which marks survive the real world, which detectors can be trusted, which claims hold. The next fights make the gap expensive: policy asks written around proofs that do not exist yet, catalog deals priced on claims nobody verified, vendor rollouts that turn a claim into a measurement the week they ship, detection papers trained on models two generations old. The industry is about to write evidence requirements into contracts. The registry being built here is the instrument for honoring them: every track purchased, every attack run, every verdict published with its receipts.
The receipts stay public: corpus, hashes, commands, verbatim detector responses. Dispute a number and it gets rerun against the published files. The reads keep landing.