Disclosure tells you what an uploader claims. Detection tells you what your model guesses. Neither is a record a regulator, a rights-holder, or a court can verify without trusting the platform. As Article 50 of the EU AI Act turns transparency from policy into law, the question stops being “did you label it” and becomes “can you prove the label was true, and that no one changed it.”
The 2026 stack is real and moving fast. But every layer of it produces a claim that the claiming party controls. That is exactly the property that fails when the claim is contested.
Spotify’s AI Credits and Apple’s Transparency Tags use the DDEX standard. An uploader ticks a box saying how AI was used. It is honest until it isn’t. A self-declaration is a claim by the party with the most incentive to shade it.
Deezer auto-tags fully-AI tracks. That is reportedly 44% of its daily uploads, about 75,000 songs a day. Detection is probabilistic, operator-owned, and contestable. “Your model guessed” is not the same as “the creator proved.”
C2PA credentials and SynthID-style watermarks are valuable, but metadata can be edited and watermarks can be laundered through re-encoding. A label that can be removed is not a record that can be relied upon.
Hive signs the asset together with its declared provenance: human, AI-assisted, or fully AI, the model, the rights basis, and the timestamp, using ML-DSA-65 (NIST FIPS 204), with a key the platform and the uploader do not hold. Anyone (a regulator, a rights-holder, a court) can verify it offline, with no access to the platform, forever. Change one byte of the declared provenance and verification fails. It does not replace DDEX, C2PA, or your detector. It sits underneath them and makes the claim they carry independently provable.
On June 10, 2026 the European Commission and the AI Office published the final Code of Practice on marking AI-generated content. On August 2, 2026, Article 50’s machine-readable marking obligation becomes enforceable, with penalties reaching 3% of global turnover. The platforms that distribute synthetic audio and video are squarely in scope.
A label satisfies the regulator until the day the label is disputed. On that day, “we marked it” and “our detector flagged it” are both self-attestations. An independent signature is the one form of marking whose truth does not depend on trusting the platform that applied it.
Hive is not another labeling scheme competing with C2PA or SynthID. It is the evidentiary layer that makes whatever label you apply hold up when an artist, a rights-holder, or a regulator asks you to prove it.
When a track or video is delivered, Hive signs a receipt binding the asset hash, the declared provenance fields (human / AI-assisted / fully AI, model, rights), and the timestamp. This happens out of band. It records, it does not gate ingestion.
The receipt rides with the existing metadata. Your disclosure and detection pipelines are unchanged; the signature simply makes their output independently verifiable.
An artist disputes a label, a rights-holder alleges a voice clone, a regulator audits. The receipt verifies, or it doesn’t, with the public key alone, and no access to your systems. You move from “trust our records” to “check the math.”
Verification costs nothing and needs nothing from Hive. The receipt outlives the dispute, the catalog migration, and Hive itself.
This is the real signer, not a mock. Pick your world, then your exact channel. The same independent signer receipts every one of them. You take the steps; these are the expected results: sign it, verify it independently, then relabel one field and watch verification fail.
1 · Pick your world
2 · Pick your channel
Streaming, video, social, advertising, live and broadcast, messaging, official data feeds, AI output, and human sign-offs. Every surface that produces, distributes, or recommends content has the same gap underneath its labels. The receipt does not change by platform: the same signer signs each one, and anyone verifies it offline. Hive sits underneath whatever you already run. It does not compete with it.
Three steps, the same for every channel. You take them; these are the expected results. Hive is the independent third party in the loop. It makes no decision about the content. It signs what you declare and lets anyone else check it.
Send the item and its declared provenance (what it is, which model, the rights, the time) to the signer through one API call from your channel.
result: typed fragments acceptedAn ML-DSA-65 receipt is produced over those exact fields. Post-quantum, tamper-evident, issued by a key that is not yours and not the platform’s.
result: independent receipt in ~77µsA regulator, rights-holder, or court checks the receipt with the published public key alone. No access to you, no access to Hive. Change one field and it fails.
result: VALID, or INVALID if alteredThe signature comes from an independent key, not the operator’s. A receipt you issue about yourself is a claim. This is evidence.
Hive attests only to what was declared and that it was unchanged. It does not assess whether the content is good, true, or allowed.
Runs beneath the DDEX, C2PA, SynthID, detection, and governance you already use. It does not replace or compete with any of them.
Pick your world, then the channel you publish to. You will land on a page that sets up your tenant and hands you a one-line call to sign your first receipt. No call, no demo, no one to talk to.
This is independent, third-party provenance and attestation. Hive signs what you declare and makes no decision about your content. You run the steps above; the expected results are VALID on an honest receipt and INVALID the instant a field is altered. Verification is free, forever, for anyone.
No call, no demo, no one to talk to. Sign a receipt above, verify it independently with the public key alone, then change one field and watch it fail. The same flow runs against your own channel through the SDK. It is independent, third-party provenance that sits underneath the DDEX, C2PA, detection, and governance you already run.
Sources: EU AI Act Article 50 enforceable Aug 2, 2026, fines to 3% of turnover: Chartlex, sota.io, Mintec. Final Code of Practice published Jun 10, 2026: ComplianceHub, Licentium. Platform policies (Spotify/Apple DDEX, Deezer detection): Chartlex, Deezer. YouTube auto-labels and C2PA: NerdLevel Tech.