A track appearing on an artist’s Spotify page normally carries a powerful implication: it is music the artist made, approved, or at least knows exists. A reported weakness in digital music distribution is undermining that assumption. Scammers can create AI-generated audio, submit it through a distributor while falsely claiming to represent a real act, and have the material placed alongside that act’s legitimate catalog on major streaming services.
The result is not merely an awkward search error. These releases can be presented as new music from the impersonated artist across Spotify, Tidal, Apple Music, Amazon Music, and other services. The person behind the submission can receive revenue generated by the fraudulent track, while the real artist must deal with the reputational harm and the practical work of discovering and contesting it.
It is a striking example of how automation can magnify an old identity problem. Impersonation in music distribution existed before generative AI, but tools that can rapidly produce a song and a passable cover image lower the effort required to make submissions at volume. An artist page has effectively become a target for account-less identity theft: the attacker may not need access to the artist’s streaming login if a distribution workflow accepts false ownership information and matches the release to the wrong profile.
How the false-release route works
The reported process is alarmingly straightforward. First, an impersonator creates an audio track using a generative music tool such as Suno or Udio. “Generative AI” here means software that produces new-seeming output from a user prompt or other input rather than a musician recording a performance in the conventional sense. The audio may be low quality, but it does not need to be convincing enough to fool a devoted listener for the scheme to cause damage.
Next comes artwork, which can also be generated with AI. The person then creates an account with a digital music distributor and submits the track as though they are the legitimate artist. A distributor is the intermediary that packages release details and sends music, artwork, credits, and artist metadata to streaming platforms. Metadata is the structured information surrounding the recording: names, titles, release data, rights details, identifiers, and the artist profile with which a track should be associated.
That matching stage is where the apparent loophole becomes especially consequential. If a bad actor submits the real artist’s name and the relevant platform does not adequately verify the claimant or flag the mismatch, the distributor and streaming service can deliver the impostor song to the genuine artist’s page. The platform’s catalog then gives the upload an appearance of authenticity it has not earned.
A test involving Brooklyn band Lathe of Heaven reportedly confirmed that the workflow could be completed through DistroKid, a distribution service, with a fraudulent track subsequently reaching major streaming platforms. The core failure is not just that AI music exists. It is that a release can apparently be routed into an established public catalog on the strength of unchecked claims.
Why a real artist page is valuable to a scammer
Uploading anonymous AI-made music offers little built-in attention. Attaching it to an existing artist profile changes the equation. The fake release inherits a recognizable name, an audience that may follow the artist, and a catalog page listeners may already trust. Those factors can increase the odds of clicks and streams compared with a freshly created fake identity.
The money trail matters, too. Streaming royalties are the payments tied to listens and rights administration. In this scenario, revenue from the bogus upload reportedly goes to the submitting party rather than the artist whose identity has been misused. The exact amount a track can earn will vary, and no single per-stream payout figure settles the issue. The more fundamental concern is that false attribution can turn another artist’s name and audience into a revenue source for an impersonator.
There is also a less measurable cost. Artists cultivate expectations around their sound, their release schedule, their collaborators, and the work attached to their name. A strange or poor-quality song landing in that catalog can confuse fans, distort recommendation systems, and create the impression that the artist released work they did not make. Lathe of Heaven’s vocalist described the prospect as deeply discouraging, emphasizing the value of putting work into the world as a product of the band’s own hands and the fear that unwanted material could damage its reputation.
That concern should not be reduced to a debate over whether every AI-assisted song is legitimate. The reported abuse is about deception and identity misuse: an uploader claiming to be someone else, a release being linked to a profile it does not belong to, and royalties potentially flowing on that false basis. Those are separate issues from an artist openly using AI tools in their own work.
Smaller and inactive catalogs face the sharpest exposure
High-profile musicians may have labels, managers, legal teams, and staff watching release pages closely. Independent acts often do not. That does not make a lesser-known artist’s identity less valuable or the consequences less serious; it simply means an erroneous release may stay live longer before anyone notices it.
Inactive profiles are also particularly vulnerable. Spotify has acknowledged that pages which are not actively managed can be at elevated risk. That category can include artists who have stopped releasing music as well as deceased musicians whose catalogs remain available for listeners. In both cases, there may be no person regularly checking for an unfamiliar single that suddenly appears in the discography.
Music group Odette Child has been tracking the issue since July and says it identified more than 300 AI-generated songs impersonating a broad set of people and acts, including major artists, celebrities, and deceased jazz musicians. The reported volume is important because it shifts the problem from isolated bad submissions to a moderation challenge. A system designed to clean up occasional mistakes can be overwhelmed when inexpensive generation tools let people create and upload many tracks quickly.
Estimates cited in reporting place the number of AI-generated tracks uploaded to Spotify at roughly 50,000 per day, though such estimates vary. Even if any individual estimate is imperfect, the operational point remains clear: high-volume submissions make review, attribution, and enforcement harder. Platforms need ways to distinguish harmless mistakes, legitimate releases, spam, and purposeful impersonation before those materials are exposed to listeners.
What platforms say they are doing
Spotify says protecting artist identities is a priority and that it is investing in detection and prevention. It also says it is working with distributors to stop bad submissions at the point of entry. That emphasis is sensible: if a fraudulent upload is rejected before distribution, it cannot be copied across multiple services or collect streams while a dispute works its way through the system.
The company is developing a feature that would allow musicians to review releases before they go live and become associated with their profiles. The tool remains in limited beta despite having been announced in March. A pre-release review mechanism could add an important human checkpoint, particularly for artists able to monitor their pages. It does not, by itself, solve the vulnerability for inactive catalogs, artists who do not receive or see alerts, or cases where an upload must be handled immediately.
Spotify has also introduced a verification badge intended to confirm that a song is not AI-generated, alongside a spam filter aimed at mass uploads, duplicate material, search-manipulation tactics, unusually short tracks, and other low-value content. These measures address different parts of the wider flood of automated music. But an “AI or not AI” marker is not the same as identity verification. A human-made recording falsely attached to an artist would still be a problem, while an openly disclosed AI-assisted release from its rightful creator is a different case altogether.
Amazon Music likewise says it is improving enforcement through detection technology, monitoring systems, and discussions with partners and rights holders. Such commitments point to the right areas—detecting suspicious behavior, monitoring catalogs, and coordinating with the companies that submit releases—but the reported ability to get a fake release through shows why measurable safeguards matter more than broad assurances.
The practical fix is about proving authority
Analysis of the reported workflow points toward a simple principle: platforms and distributors need stronger evidence that the person submitting a release has authority to use a given artist identity. That is more precise than trying to judge whether a song “sounds AI.” Audio detection can be fallible, and it cannot determine who has the right to release material under a particular name.
More robust controls could focus on the relationship between the uploader, the artist name, and the destination profile. A claimed artist identity should not be enough to attach a new track to a pre-existing catalog. Confirmation from an established artist-management channel, a verified profile owner, or a rights representative would create friction—but it is friction directed at the exact claim being abused.
Speed is equally important. Once a false track goes live, it can be played, saved, recommended, shared, and added to playlists. A credible reporting route and rapid temporary removal process would limit the period in which the impersonator can benefit and fans can be misled. The current limited-beta review concept suggests that the industry recognizes the need for artist-side control; the remaining question is how quickly that control becomes widely available and how it works for artists who are not constantly online.
For listeners, the episode is a reason to be careful with surprise releases, especially from artists who have been inactive for years. An unfamiliar track is not proof of fraud, and listeners should not harass artists or assume wrongdoing based solely on an odd recommendation. Still, checking the artist’s official channels or established social pages before sharing a suspicious release can prevent an accidental boost for an impersonator.
The larger takeaway is that streaming pages are not just shelves of audio anymore. They are identity systems, discovery engines, and payment channels. When a false claimant can place a track on a real artist’s page, the flaw affects all three at once. As music platforms expand automated detection and artist-review tools, preventing fraudulent association at submission time—not merely labeling AI output after the fact—will be the test that matters most.
The music industry’s broader AI questions will continue, from disclosure to compensation and creative ownership. This case is more immediate: nobody should be able to use a few unchecked fields and a generated song to borrow someone else’s name, audience, and royalty stream. For more on how online music culture continues to intersect with digital platforms, see our coverage of Lofi Girl’s 24/7 house music stream and vinyl compilation.






