Provenance you can prove

A catalog is a claim. Hive is the receipt.
The independent third party a regulator can verify.

Disclosure tells you what an uploader claims. Detection tells you what your model guesses. Neither is a record a regulator, a rights-holder, or a court can verify without trusting the platform. As Article 50 of the EU AI Act turns transparency from policy into law, the question stops being “did you label it” and becomes “can you prove the label was true, and that no one changed it.”

EU AI Act Article 50: machine-readable marking enforceable August 2, 2026
Aug 2, 2026
Art. 50 marking becomes law
up to 3%
of global turnover in fines
77µs
to sign a provenance receipt
0
access to the platform needed to verify

What the industry already has, and why it’s not enough.

The 2026 stack is real and moving fast. But every layer of it produces a claim that the claiming party controls. That is exactly the property that fails when the claim is contested.

Disclosure

The uploader self-declares

Spotify’s AI Credits and Apple’s Transparency Tags use the DDEX standard. An uploader ticks a box saying how AI was used. It is honest until it isn’t. A self-declaration is a claim by the party with the most incentive to shade it.

Detection

The platform infers

Deezer auto-tags fully-AI tracks. That is reportedly 44% of its daily uploads, about 75,000 songs a day. Detection is probabilistic, operator-owned, and contestable. “Your model guessed” is not the same as “the creator proved.”

Watermark / metadata

Strippable, editable

C2PA credentials and SynthID-style watermarks are valuable, but metadata can be edited and watermarks can be laundered through re-encoding. A label that can be removed is not a record that can be relied upon.

What Hive adds underneath

An independent, tamper-evident provenance receipt

Hive signs the asset together with its declared provenance: human, AI-assisted, or fully AI, the model, the rights basis, and the timestamp, using ML-DSA-65 (NIST FIPS 204), with a key the platform and the uploader do not hold. Anyone (a regulator, a rights-holder, a court) can verify it offline, with no access to the platform, forever. Change one byte of the declared provenance and verification fails. It does not replace DDEX, C2PA, or your detector. It sits underneath them and makes the claim they carry independently provable.

Why August 2 changes the question.

On June 10, 2026 the European Commission and the AI Office published the final Code of Practice on marking AI-generated content. On August 2, 2026, Article 50’s machine-readable marking obligation becomes enforceable, with penalties reaching 3% of global turnover. The platforms that distribute synthetic audio and video are squarely in scope.

A label satisfies the regulator until the day the label is disputed. On that day, “we marked it” and “our detector flagged it” are both self-attestations. An independent signature is the one form of marking whose truth does not depend on trusting the platform that applied it.

Hive is not another labeling scheme competing with C2PA or SynthID. It is the evidentiary layer that makes whatever label you apply hold up when an artist, a rights-holder, or a regulator asks you to prove it.

How it works on a catalog.

1 · At ingest

When a track or video is delivered, Hive signs a receipt binding the asset hash, the declared provenance fields (human / AI-assisted / fully AI, model, rights), and the timestamp. This happens out of band. It records, it does not gate ingestion.

2 · Alongside DDEX / C2PA

The receipt rides with the existing metadata. Your disclosure and detection pipelines are unchanged; the signature simply makes their output independently verifiable.

3 · On challenge

An artist disputes a label, a rights-holder alleges a voice clone, a regulator audits. The receipt verifies, or it doesn’t, with the public key alone, and no access to your systems. You move from “trust our records” to “check the math.”

4 · Free to verify, forever

Verification costs nothing and needs nothing from Hive. The receipt outlives the dispute, the catalog migration, and Hive itself.

Find your channel. Dial a receipt. Verify it live.

This is the real signer, not a mock. Pick your world, then your exact channel. The same independent signer receipts every one of them. You take the steps; these are the expected results: sign it, verify it independently, then relabel one field and watch verification fail.

Live endpoint · hive-typed-signer.onrender.com/sign · /verify · real ML-DSA-65

1 · Pick your world

2 · Pick your channel

The asset & its declared provenance

The independent receipt

Press “Sign provenance” to sign with the live endpoint.
Not signed
An independent ML-DSA-65 receipt over the provenance fields.
Step 1 of 3: sign the declared provenance.

One primitive across every digital surface.

Streaming, video, social, advertising, live and broadcast, messaging, official data feeds, AI output, and human sign-offs. Every surface that produces, distributes, or recommends content has the same gap underneath its labels. The receipt does not change by platform: the same signer signs each one, and anyone verifies it offline. Hive sits underneath whatever you already run. It does not compete with it.

Streaming & audioVideo & socialAdvertisingLive & broadcastMessaging & commsData & feedsAI & agentsHuman attestation

How a channel gets receipted.

Three steps, the same for every channel. You take them; these are the expected results. Hive is the independent third party in the loop. It makes no decision about the content. It signs what you declare and lets anyone else check it.

1

You declare

Send the item and its declared provenance (what it is, which model, the rights, the time) to the signer through one API call from your channel.

result: typed fragments accepted
2

Hive signs, independently

An ML-DSA-65 receipt is produced over those exact fields. Post-quantum, tamper-evident, issued by a key that is not yours and not the platform’s.

result: independent receipt in ~77µs
3

Anyone verifies, offline

A regulator, rights-holder, or court checks the receipt with the published public key alone. No access to you, no access to Hive. Change one field and it fails.

result: VALID, or INVALID if altered
Third-party provenance

The signature comes from an independent key, not the operator’s. A receipt you issue about yourself is a claim. This is evidence.

Third-party attestation

Hive attests only to what was declared and that it was unchanged. It does not assess whether the content is good, true, or allowed.

Sits underneath

Runs beneath the DDEX, C2PA, SynthID, detection, and governance you already use. It does not replace or compete with any of them.

Receipt my channel.

Pick your world, then the channel you publish to. You will land on a page that sets up your tenant and hands you a one-line call to sign your first receipt. No call, no demo, no one to talk to.

This is independent, third-party provenance and attestation. Hive signs what you declare and makes no decision about your content. You run the steps above; the expected results are VALID on an honest receipt and INVALID the instant a field is altered. Verification is free, forever, for anyone.

Prove it yourself in thirty minutes.

No call, no demo, no one to talk to. Sign a receipt above, verify it independently with the public key alone, then change one field and watch it fail. The same flow runs against your own channel through the SDK. It is independent, third-party provenance that sits underneath the DDEX, C2PA, detection, and governance you already run.

Sources: EU AI Act Article 50 enforceable Aug 2, 2026, fines to 3% of turnover: Chartlex, sota.io, Mintec. Final Code of Practice published Jun 10, 2026: ComplianceHub, Licentium. Platform policies (Spotify/Apple DDEX, Deezer detection): Chartlex, Deezer. YouTube auto-labels and C2PA: NerdLevel Tech.