The Integrity Frontier: IFPI, DistroKid and the Geopolitics of KYC
On September 14, 2026, IFPI launched the Streaming Integrity Initiative, a voluntary framework designed to establish a common foundation of practices against streaming fraud from the moment content enters the digital ecosystem. Rights and customer identity verification, content screening, action against fraudulent behavior, information sharing and the continuous improvement of anti-fraud systems form an architecture whose significance extends beyond the fight against artificial streams alone, since by moving part of the control upstream, the initiative also shifts the frontier at which the distributor’s responsibility begins. Twenty-seven organizations are currently listed among the supporters announced by IFPI, including the three majors, Merlin, IMPALA, FUGA, CD Baby, AWAL, The Orchard and several independent distribution players, but DistroKid is not among them. Its absence might appear to be little more than a missing line in a list that may still evolve, if DistroKid did not claim to distribute roughly 40% of all new music released worldwide and if, at the same time, it were not a founding member of Music Fights Fraud. The divide that emerges is therefore subtler than an opposition between those fighting fraud and those that are not... it begins where practices that have so far belonged to individual infrastructures start seeking to become a common reference across the market.
Klem Loden
9/15/20268 min read


Control moves upstream
Streaming fraud generally becomes visible once it has already produced something. Artificial streams have been generated, royalties have been diverted or must be withheld, content has to be removed, an account sanctioned, sometimes an infrastructure pursued through the courts. In France, the Paris Judicial Court ordered OVH in 2025 to stop providing services to two companies linked to artificial streaming manipulation, following proceedings supported notably by IFPI, SNEP, Deezer, SoundCloud and Spotify. The action was necessary, but by definition it intervened after the risk had already entered the system. The Streaming Integrity Initiative moves part of that control to an earlier frontier, since the organizations supporting it commit notably to verifying claimed rights as well as the identity and legitimacy of their customers through robust KYC procedures, screening content to identify infringement, fraudulent activity and certain AI-related risks, detecting and then sanctioning suspicious behavior or repeat offenders, sharing certain information where legally permitted and continuously measuring the effectiveness of their systems. IFPI is therefore no longer asking only for fraud to be detected once it is circulating, it is seeking to strengthen the point through which it can enter.
The movement itself did not begin on September 14. In its Global Music Report 2026, published six months earlier, IFPI was already calling on distributors to verify the identity of those supplying content and the legitimacy of that content before release, while advocating better information sharing so that a fraudster identified in one part of the ecosystem could not simply move their activity elsewhere. The SII adds something to that direction, however, because an internal control belongs to the company exercising it, with its own criteria, its own thresholds and necessarily limited external visibility, whereas when several players publicly declare that they recognize the same set of responsibilities, control gradually ceases to be merely an internal matter... it becomes comparable. It is precisely at this point that DistroKid’s absence begins to take on another dimension.
DistroKid and the weight of an absence
DistroKid is not currently among the organizations publicly supporting the SII, but that absence establishes neither a rejection of its principles nor a disagreement with IFPI, still less a weakness in the company’s anti-fraud systems. The initiative is voluntary and the published framework currently provides for neither mandatory independent auditing, nor public reporting through which the effective compliance of each participant could be measured, nor sanctions attached to failure to honor the commitments. Appearing on the list does not therefore constitute certification and, by the same reasoning, remaining outside it does not constitute evidence of failure. Yet not every absence carries the same volume of music, and DistroKid claims to serve more than four million artists, to have processed more than 45 million tracks and to distribute roughly 40% of all new music released worldwide. The 40% figure remains a company claim rather than an independent measurement of the market, an essential distinction when scale itself becomes part of the reasoning, but even with that qualification, the volume claimed is sufficient to change the nature of the question. A common standard can perfectly well begin without encompassing the entire market, yet it becomes more difficult to regard it as universal when one of the infrastructures feeding that market most extensively remains outside the framework seeking to define it.
The situation would be relatively simple if DistroKid were operating outside collective anti-fraud efforts altogether, but that is not the case. The company was among the founding members of Music Fights Fraud when it was created in 2023, alongside CD Baby, TuneCore, Believe, UnitedMasters, Symphonic, Spotify and Amazon Music, among others, and it remains a member of the alliance today. DistroKid therefore already participates in a collective infrastructure designed to detect, prevent and combat streaming manipulation, meaning that its absence from the SII does not separate two camps, one committed to fighting fraud and another indifferent to it, but rather reveals the coexistence of several architectures of trust pursuing, in part, the same objective without yet converging. From that point, the real subject is no longer the absence itself, but what it allows us to observe when existing practices begin seeking some form of collective reference.
When internal practice becomes a collective reference
KYC is not new, any more than rights verification, audio recognition, content screening or the exchange of intelligence between certain market participants. Taken separately, none of the SII’s five commitments therefore constitutes a technical revolution, the shift lies instead in bringing them together under a single framework, presenting them as components of the diligence expected from infrastructures introducing content into the ecosystem, then inviting other players to join that reference.
An industry can pursue the same objective for years without necessarily possessing a common definition of what it considers sufficiently diligent. Two distributors can verify their customers, check metadata and look for signs of fraud while using very different procedures, thresholds and technologies, without the market necessarily having an external reference point through which those differences can be observed. The SII does not eliminate that fragmentation, since it does not publicly define a universal standard of KYC evidence, create any independent audit or assign certified status to the infrastructures supporting it, yet it does make a first documentary frontier visible by giving a name and an architecture to a set of responsibilities that certain players now agree to recognize publicly.
An industry standard does not, however, need to be mandatory before it begins to alter an environment. Sometimes it is enough for a sufficient number of players gradually to stop asking whether a practice should exist, and begin asking why it does not exist elsewhere. We are not there yet with the SII, but the mechanism is becoming visible enough for the composition of its supporters to deserve examination beyond the number displayed.
Behind the number, concentration
The list might suggest an especially broad consensus, but its composition tells a slightly different story. Universal Music Group appears alongside Virgin Music Group, FUGA and CD Baby, Sony Music Group alongside The Orchard and AWAL, while Warner Music Group is represented together with ADA and Revelator. Music Business Worldwide consequently noted that ten of the twenty-four organizations counted when its analysis was published belonged to the three majors. That finding does not, however, allow the SII to be reduced to a standard built by the majors and then imposed upon the independent market, since Merlin, IMPALA, WIN, Secretly Distribution, Symphonic, Ditto Music, RouteNote, Too Lost, IDOL and other independent organizations are also among the supporters currently announced by IFPI. The dividing line therefore runs through distribution models and ownership structures far more than it reproduces the familiar boundary between majors and independents.
Concentration nevertheless retains its analytical importance, because twenty-seven names do not necessarily represent twenty-seven independent centers of decision-making. When the same group controls several infrastructures positioned at different points in the chain, the participation of each increases the surface covered by the standard without increasing, in the same proportion, the number of economic actors that independently chose to adopt it. The number therefore tells us the extent of support, while ownership reveals its geography, a distinction that becomes particularly important when trying to understand how a voluntary practice might, tomorrow, acquire enough weight to become a market expectation.
From KYC to provenance
For synchronization, the shortcut would be tempting, since if a distributor verifies its customers’ identities more rigorously, checks the rights they claim and screens content more extensively before it reaches DSPs, the assets that have passed through that infrastructure might intuitively appear more reliable. Nothing currently allows us to make that claim, however. The SII certifies no catalog, establishes no presumption of legal reliability for tracks distributed by its supporters and provides no mechanism through which a music supervisor, studio, agency, DSP or Business Affairs team should consider an asset originating from a non-signatory distributor to present a higher level of risk. Turning a distributor’s participation into a criterion of sync-readiness today would therefore make the framework produce a consequence it does not yet produce.
More importantly, identity is not ownership, and knowing who introduced a recording into the system does not demonstrate that this person owns the master, any more than a verified identity is sufficient to establish publishing rights, sample clearances, contractual restrictions, personality rights or the complete Chain of Title required for audiovisual exploitation. KYC replaces none of these verifications and should not be confused with them. Yet when we travel far enough upstream, another question appears, because before anyone determines whether every authorization required for a particular use has been secured, someone introduced the asset, declared an identity, claimed certain rights and supplied the information that would subsequently begin traveling with it. The SII does not turn the distributor into the guarantor of that entire legal history, but it does seek to make its responsibility for the first chapter more explicit.
The geopolitics of KYC
It is perhaps here that KYC ceases to be merely an administrative mechanism and becomes an infrastructure question. Content may be created in one territory, uploaded from another, entrusted to a distributor established elsewhere, consumed simultaneously across several markets and generate revenue whose circulation will cross still other jurisdictions. Within this global architecture, verifying the person who opens the door obviously does not resolve everything that will happen afterwards, but it does determine part of what the rest of the system will receive when that door opens. The geopolitics of KYC lies precisely in this distribution of responsibility among private infrastructures feeding the same global market without necessarily applying the same control boundaries.
The SII creates no new legal sovereignty and, at this stage, possesses neither the mandatory nature nor the verification mechanisms that would allow it to function as genuine industry certification. Yet by making certain common expectations public, it introduces a distinction that could become increasingly important if adoption expands, the distinction between a company stating that it applies its own controls and one stating that it applies the controls its industry is beginning collectively to recognize as a common foundation. Within that configuration, DistroKid is not interesting because its absence would reveal something we know about its internal controls, since we do not, its claimed volume instead turns it into a full-scale test of the SII’s ability to move beyond the circle of its initial supporters. If one infrastructure claims to distribute roughly two out of every five new releases worldwide, can we genuinely speak of a market standard while it remains outside the framework? The question remains open, and that is precisely why it deserves to be watched.
Who verified whom?
The music rights economy has long rested upon a question whose wording is considerably simpler than its answer... who owns what? The Streaming Integrity Initiative does not replace that question, it brings another into view further upstream... who verified whom?
The difference may appear slight, yet it shifts responsibility. Ownership will continue to require evidence, Chain of Title will continue to require documentation and professionals responsible for clearance will continue to determine whether the necessary permissions actually exist, only, before any of those operations can take place, an asset has entered the ecosystem somewhere carrying an identity, claims and data that someone chose to let through. The SII begins to formalize that first passage, meaning DistroKid’s current absence is neither a condemnation of its infrastructure nor evidence of a definitive fracture in the market, it simply reveals the present boundary of a consensus still seeking its perimeter, a boundary made all the more visible because it runs across one of the largest claimed volumes of new music releases in the world.
If the SII remains one voluntary coalition among others, that absence will probably retain little structural significance. If, however, its principles eventually become the ordinary reference point for global distribution, the shift will be considerably deeper, since the industry will no longer ask distributors only how they protect their own pipelines... it will already know what it expects at the entrance.
Verified Sources and References
Music Business Worldwide, “DistroKid, distributing ‘roughly 40%’ of all new music, hasn’t yet signed IFPI’s new anti-fraud standards… unlike CD Baby,” September 14, 2026
Music Fights Fraud, About Us
