What's new

HTTPS for Music: Who Plays the Certificate Authority?

  • Thread starter Thread starter Elodie Aishwarya P. Remoissenet
  • Start date Start date
E

Elodie Aishwarya P. Remoissenet

Guest


Twenty years ago, most of the web ran in the clear. Anyone on the path could read the page, and nobody could prove which server they were talking to. The fix was not a law and not a detector. It was a protocol with a trust layer around it, and today a padlock in the address bar is so ordinary that nobody notices it. That is what winning looks like for infrastructure: invisibility.

Music has the mirror-image problem in 2026. Since August 2, Article 50 of the EU AI Act requires providers of systems that generate audio to embed machine-readable markings so that synthetic content can be detected as synthetic. The machines must confess. But the regime runs in one direction only: proving that content is artificial. Nothing in it attests that a piece of music was made by a person, on a date, before anyone had reason to doubt it. In a world where machines must confess, everyone who cannot prove their work is a suspect.

Detection will not close that gap, for a structural reason: detectors measure exactly the axis generators improve on, so every gain in synthesis quality is a loss in detectability. And Deezer's numbers show the clock: from 10,000 fully AI-generated uploads a day in January 2025 to roughly 90,000 a day at the June 2026 peak, more than half of new deliveries.

So the useful question is not "how do we detect fakes" but "how did the web make authenticated identity and secure transport free, universal and invisible", and whether music can copy the move.

Why HTTPS actually won​


HTTPS did not win because it was well designed. SSL shipped in the mid-1990s and spent two decades as a niche feature for banks and shops. It won late, and it won for four reasons that had little to do with cryptography.

1. The protocol was open and free at the base; the money was made around it. Nobody paid to use TLS. Certificate authorities, CDNs, hosting providers and integrators built businesses on top of a standard that anyone could implement. When Let's Encrypt began issuing free, automated certificates in 2015, cost and operational friction collapsed.

2. Browsers made absence visible. First a padlock for secure sites. Then, decisively, a "Not secure" warning for everything else. The default flipped: silence was no longer neutral, it was a signal. Site owners did not adopt HTTPS because they understood the threat model. They adopted it because their visitors could see the warning.

3. A handful of chokepoints imposed the standard. Nobody convinced every website. A few browser vendors, root-store operators and major infrastructure providers set the rules, and the long tail followed because the alternative was being flagged.

4. A trust infrastructure bound keys to identities. Proof of possession is not enough. The system has to establish which public key is authorised for which domain, and browsers have to trust the authority making that binding. That binding is the whole system. Everything else is plumbing.

The music equivalents​


Now map each reason onto music, where the asset is not a page but a work, and the question is not "which server" but "which human, when".

Open at the base, business on top. A provenance protocol for music has to be specified openly and implementable by anyone, or no DAW, distributor or rights society will build against it. The business, as with TLS, lives in verification, integration and the trust layer, not in the protocol itself. I am biased here: I designed one such protocol, and the technical paper is public. But the design principle holds whoever ends up writing the winning spec.

Absence made visible. The day a missing provenance record becomes a visible signal at ingest, the way a missing certificate became "Not secure", attestation stops being optional. Not because artists understand cryptography, but because a track without a chain of custody looks, to a distributor or a platform, like a site without a padlock. The industry is already halfway there without noticing: on July 10 its own bodies proposed voluntary, track-level AI-Generated and AI-Assisted labels. A sticker can carry the whether. It has nowhere to put the how. The signal exists; the record behind it does not yet.

Chokepoints. Music has two, and they are narrow. The DAW at the source, where the work is actually made and where attestation costs the artist nothing beyond a plugin and a keypair. And the distributor at ingest, the point every track passes through on its way to a platform, where verification is cheap and uploaders already contractually warrant that they hold the rights they deliver. Convince a few DAWs and a few distributors and the long tail follows, exactly as websites followed browsers.

Keys bound to identities. This is the part the cryptography cannot solve alone, and the part the industry is best placed to solve. A signature proves that the holder of a key ran a session at a time. It does not prove who the holder is. Someone has to bind the key to a person, and that someone has to already know the person, keep the register, and hold the authority to pay them.

Who plays the certificate authority​


That description fits one institution better than any other already operating at scale: the collective management organisation. In strict PKI terms, a society could perform the registration-authority function while a qualified trust service provider issues the credential or timestamp. Economically, however, the society is where that binding becomes operative. SACEM, GEMA, PRS, SOCAN, ASCAP, BMI and their peers already verify the identity of their members, already keep the register of works, already hold the legal mandate to distribute royalties. They are the natural certificate authorities of music, and they have every incentive to take the role, because as synthetic catalogues scale, the cost of paying on declarations rises and legitimate rightsholders absorb the friction.

A first pilot could be deliberately narrow: bind a member's signing key to a verified identity, and accept a provenance journal as supporting evidence alongside the work declaration. The institutional integration is not trivial. The initial test can be. And once one society pays on evidence, no neighbour will want to keep paying on trust.

Europe adds a prize. Under eIDAS, Article 41, a qualified electronic timestamp enjoys a legal presumption of accuracy and integrity. Anchor a provenance chain through a qualified trust service provider and the timestamp benefits from that presumption as to when, and that nothing has changed since. It does not prove authorship or originality. It proves the date and the integrity of what the author signed, which is precisely the evidence a court or a rights society lacks today.

And the courts are already pointing at the same institutions. On July 31, the Munich District Court ruled for GEMA in a non-final first-instance judgment, finding infringement in the US training, in the model's memorisation of protected works on German servers, and in certain outputs; it asserted jurisdiction over the US conduct through a forum available to collecting societies, not to other rightsholders such as labels. On September 2, SOCAN sued Suno in Canada, identifying 150 publicly available outputs that it alleges are identical or substantially similar to works in its repertoire. The certificate authorities are already in the fight. They are fighting with evidence of similarity, because nobody has given them evidence of creation.

The same week, Washington moved the border from the other side. On September 1, the United States filed a non-binding statement of interest in the OpenAI copyright litigation, arguing that the training use at issue, a language model trained on written works, is generally fair use, and that generalised competition from outputs lacking substantial similarity is not cognisable market harm in the fair-use analysis. On the European side, the Court of Justice is considering a related training question in Like Company v. Google, with the Advocate General's opinion pending. Read that alongside the Munich judgment and the Canadian filing: training may escape liability in some jurisdictions, substantially similar outputs remain contested, and, since four musicians sued Suno on August 31 alleging that their names and identities were used without consent to generate outputs, identity is litigated too. Two more receipts landed the same week. On August 31, India's Copyright Office found an AI-generated image original enough for protection, refused to enter the machine as author, and rejected the application because it named the AI as author and therefore had no coherent chain of title: originality met, chain of title missing. And on September 4, Microsoft told a New York court, in a summary-judgment filing rather than a ruling, that across 8.2 million Copilot conversations the authors' expert found 24 responses with thirty matching words: rare copying, while the plaintiffs say the products compete with them directly. Copying can be rare and competition industrial at the same time. The cross-motions now force the harder question into view: can the fair-use analysis recognise industrial displacement when particular outputs are not substantially similar? Not one of those fronts protects the economic place of a human work that is merely competed with. Provenance does not turn that competition into infringement. It creates a verifiable distinction on which contractual, platform and collective-payment rules can act. That is why the certificate-authority function just became strategic.

The honest reservation​


HTTPS took two decades to become the default, from the first SSL to free certificates and browser warnings. Standards are won through governance and chokepoints, not protocol quality, and governance is slow. Anyone promising music a two-year HTTPS is selling something.

But the web never had a counter doubling every six months. Deezer went from 10,000 to 90,000 synthetic tracks a day in eighteen months, and Article 50 arrived in two years. When the cost of inaction reads on a monthly chart, standards get decided in years, not decades. The padlock took twenty. The music industry does not have twenty.

The protocol is the easy part. The certificate authority is the whole game, and for once, the industry already owns it.

For the broader legal and economic argument, authorship, the royalty reservoir and why platforms come last, AI Music 01: The Royalty Reservoir is available on my Medium profile from Monday, September 7.




Discolusure:

I designed ACTA Music and am the named applicant on related patent filings.


Author’s note:

Proudly AI-assisted: AI refined the structure and language of this piece; the model, the argument and the judgment are mine. Image generated based on my concept with Recraft V4 Pro.
 

Thread statistics

Created
Elodie Aishwarya P. Remoissenet,
Replies
0
Views
4
Back
Top