EU AI Act Article 50(2) applies on 2 August 2026. Providers of AI systems that generate synthetic audio must mark the outputs in a machine-readable format, detectable as artificially generated (Article 50 text). Cartesia already runs a dedicated EU endpoint, one of five regions (data residency docs). That endpoint serves exactly the population the article protects.
Hive comes alongside the engine as a sidecar. At the moment of each generation it makes an independent, signed origin receipt that anyone can check offline. It never synthesises audio, never clones a voice, never gates a request, and never sits in the inference path. It does not judge. The receipt proves what was generated, under which policy, on whose attestation. It does not decide legality and does not guarantee compliance. Signing costs 0.098 ms (p50), which is roughly a thousandth of the sub-90ms latency budget Sonic 3.5 targets (TTS API reference).
This section comes first on purpose. A pitch that pretends the gap is negligence is a pitch that has not read the trust centre. Cartesia has done the compliance work that most voice providers have not, including an attestation that is genuinely unusual for a model vendor.
| Artifact | Status | Detail | Source |
|---|---|---|---|
| SOC 2 Type II | held | Attested. | trust.cartesia.ai |
| PCI DSS 4.0.1 | held | Attested as a service provider. Unusual for a voice vendor. | trust.cartesia.ai |
| HIPAA | held | Compliant, with BAAs available. | cartesia.ai/security |
| GDPR | held | Declared 24 September 2025, with a published DPA. | cartesia.ai/dpa |
| Trust centre | held | Live, public, self-serve. | trust.cartesia.ai |
| Data residency | held | Five regions, including a dedicated EU endpoint. | data residency docs |
Swipe the table sideways for the source links ›
| Artifact | Status | Basis |
|---|---|---|
| ISO 27001 | not held | Absent from the public trust centre. |
| ISO 42001 | not held | Absent from the public trust centre. |
| FedRAMP | not held | Absent from the public trust centre. |
| AIUC-1 | not held | Absent from the public trust centre. |
SOC 2 Type II says controls were designed and operating over a period. PCI DSS says a cardholder-data environment met a standard. HIPAA and a published DPA say the contractual and administrative apparatus exists. All of that is real work and none of it is in question here.
No certificate in the table above produces an artifact a third party can check about a specific piece of generated audio. A rights-holder holding one 20-second clip cannot read a SOC 2 report and learn when that clip was made, under which policy version, or on whose attestation of consent.
The argument on this page is not that Cartesia is careless. It is that process proof and per-output proof are different objects, and only one of them can be handed to a regulator, a rights-holder, or an enterprise customer's counsel without access to Cartesia's systems.
Context, for scale rather than pressure: Cartesia raised $100M announced late October 2025, co-led by Kleiner Perkins and Index Ventures with Lightspeed and NVIDIA participating (Reuters), and describes a reach of 50K companies (Line launch). No valuation has been disclosed and none is stated here.
Article 50(2) is short, and it asks for an artifact rather than a policy.
Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated. EU AI Act, Article 50(2) · artificialintelligenceact.eu/article/50
The EU endpoint sharpens the point rather than softening it. Cartesia has already built regional infrastructure for European customers across US, EU, UK, India, and Australia endpoints (data residency docs). The population served by that endpoint is exactly the population Article 50(2) protects. The regional work is done. The marking artifact is the piece that is missing.
A generated clip leaves the API as audio. Downstream, nothing distinguishes it from a recording of a person, and there is no documented endpoint anyone can call to ask.
Media Origin Receipt™ is cut per generation, and MoRSo™ carries it alongside the audio. Machine-readable. Verifiable offline by anyone, with no dependency on Cartesia being reachable or willing to confirm.
No model change, no retraining, no change to the audio itself. The receipt is a separate object. If Hive is unreachable, generation proceeds exactly as it does today. Fail-open by design.
Cartesia shipped zero data retention for agents plus a Call Redaction API in June 2026 (changelog). It is a real control. The documentation is also explicit about where it stops.
ZDR is not available for voice cloning, PVC, voice creation, and other features that intrinsically require data storage. Cartesia ZDR documentation, verbatim · docs.cartesia.ai/enterprise/zero-data-retention
The strongest privacy control the company offers is unavailable on the single workflow that carries biometric, right-of-publicity, and consent exposure. This is not a criticism of the engineering. A cloned voice must be persisted to be usable. The observation is narrower and harder to answer: the control and the risk do not overlap.
Voice cloning cannot be self-hosted. Enterprise self-hosting exists, but the clone path runs in Cartesia's cloud, which is consistent with the retention carve-out (ZDR docs).
Terms §5.3(c) makes self-serve inputs and outputs trainable by default, with opt-out available rather than opt-in (Terms of Service). Enterprise terms differ. The self-serve default is the one that scales fastest.
Where data must persist, prove what happened to it. PBS™ for continuous runtime-control proof. Egress Bond™ for semantic-class and volume caps on voice-sample movement. ViewKey™ for role-scoped projections, so an auditor reads the event without receiving the voice. Retention you can prove beats retention you promise.
Instant cloning takes 10 seconds of audio and is free on every plan, including the free tier (clone-voices docs). An exhaustive read of the cloning docs, the API reference, and the OpenAPI schema finds no identity verification, no spoken verification statement, no voice captcha, and no consent attestation of any kind.
The acceptable use policy (AUP) and the deceased-person and political-candidate restrictions in the Terms (Terms of Service) live on web pages. Web pages change without notice and without version history. A customer who needs to demonstrate to their own regulator which policy was in force on a given date has nothing to point at.
An enterprise customer's counsel can read today's AUP. They cannot prove what it said in March, whether a bar existed then, or when a threshold moved. The vendor's own assertion is the only record.
Refusal Ledger™ puts the refusal and consent policy on a signed mutation chain with bounded zero-knowledge envelope proofs. A rights-holder, auditor, or regulator verifies the policy bounds and when they changed, without seeing the internals.
Howler™ cuts a signed alarm when a cloning request drifts toward a flagged or public-figure voice. Diurnal Bond™ requires k-of-n approval for off-hours clone creation, so a 3am pipeline cannot mint a voice on one key.
The doctrinal map for voice was drawn in Lehrman v. Lovo, No. 1:24-cv-03770 (S.D.N.Y.). Judge Oetken's opinion of 10 July 2025 let breach of contract, New York right-of-publicity, and New York consumer-protection claims proceed, while dismissing the Lanham Act claims and most copyright claims (Reuters, opinion PDF).
Cartesia has never been named in any lawsuit, enforcement action, or public misuse incident. That is a confirmed negative from exhaustive search, and it is the asset worth protecting. A never-sued vendor holding PCI DSS 4.0.1 and SOC 2 Type II (trust centre) has more to lose from a first incident than a vendor already in the news. The point of a receipt is that the record is built before the first claim, not after it.
Post-incident analysis runs under a threshold-signed consortium credential and is deterministic-replayable by a regulator, a court, an enterprise customer's auditor, or a rights-holder's expert.
An append-only record of the receipts themselves, so the absence of an expected receipt is an evidentiary signal rather than a gap nobody can see.
A rights-holder, a regulator, and an enterprise customer each read the same event from their own vantage, without a shared database and without granting anyone new access to Cartesia's systems.
Every row below names the Hive primitives that apply and then names what the receipt cannot decide. The second line is not a disclaimer bolted on. It is the reason the first line is worth reading. Hive proves conditions, never verdicts.
Nothing above is forced onto a use it does not fit. Every primitive named is a receipt-making object that sits alongside the engine. None of them synthesise audio, clone a voice, refuse a request, or enter the inference path. Hive does not judge.
For a company that competes on latency, the first and correct question is what a receipt costs. Sonic 3.5, sonic-3.5-2026-05-04, targets sub-90ms across 42 languages (TTS API reference). Hive signing at 0.098 ms (p50) is roughly a thousandth of that budget. Ink 2, launched 22 May 2026 at around 100ms, sits in the same order of magnitude (Ink 2 launch).
| Operation | Measured | Note |
|---|---|---|
| Sign | 0.098 ms (p50) | Roughly a thousandth of the sub-90ms Sonic 3.5 target. |
| Verify | 0.136 ms (p50) | Offline. No account, no network round-trip, no vendor dependency. |
| Dual-signed envelope | 0.678 ms (p50) | Hybrid path, both signatures present in one envelope. |
| ML-DSA-65 signature | 3,309 bytes | Per NIST FIPS 204. Post-quantum, federal standard. |
| Smoke tests | 37 of 37 pass | Same run, 27 July 2026. |
Swipe the table sideways for the full notes ›
Production integrations are pilot-ready rather than deployed. The signing and verification path is measured and reproducible. The integration into a live voice pipeline is the thing a proof of concept establishes, and it has not been established at Cartesia or on Cartesia's behalf.
The seven upstream pre-effect controls were filed as USPTO 64/119,279 on 26 July 2026. A filing is a filing. It is not a granted patent, and nothing on this page depends on it.
The certificate-transparency-style log for receipt publication is designed, not yet serving. Offline verification does not depend on it. Anyone who wants a public inclusion proof today should treat that as roadmap, not as running infrastructure.
In plain words: Cartesia would hold the pen that signs. Hive never touches model weights, never receives voice samples, never gates a generation, and never holds your keys.
The private key that stamps a receipt stays on your own hardware. Nobody else can sign in your name. The signature is yours, not Hive's.
Hive gives you the way to make and check receipts. It does not synthesise audio, clone a voice, refuse a request, or run the platform, does not enter the inference path, and does not move or store reference audio or model weights. Each event is recorded as a one-way fingerprint and a cryptographic commitment, never the underlying voice data. If Hive is unreachable, generation proceeds exactly as it does today.
One surface, not a platform migration. The sharpest candidate is the EU endpoint plus Media Origin Receipt™ on a single model route, because the deadline is dated and the endpoint already exists (data residency docs). The second candidate is the clone-creation path plus OriginProof™ and SPR™, because that is where consent exposure concentrates. Hive builds it, measures it on your hardware, and hands you the receipts and the verifier. Nothing changes in the engine. Naming Cartesia does not imply any agreement, and this page does not state or imply that Cartesia is a customer, partner, pilot, or endorser, or that Cartesia uses Hive.
One line to start: [email protected]
Stephen Rotzin, Founder, Hive Civilization Inc (Wyoming) · [email protected]
This page is illustrative only. It was prepared privately by Hive Civilization Inc. and is not affiliated with, sponsored by, or endorsed by Cartesia AI, Inc. or any of its affiliates. It does not state or imply that Cartesia is a customer, partner, pilot, or endorser, or that Cartesia uses Hive. No commercial relationship of any kind exists or is claimed.
Every fact about Cartesia on this page is drawn from Cartesia's own public documentation, terms, policies, and trust centre, or from named reporting, and is linked inline at the point of the claim. No valuation is stated because none has been disclosed. Cartesia has never been named in any lawsuit, enforcement action, or public misuse incident, and nothing here suggests otherwise.
A signed receipt proves that something happened and what it recorded. It does not decide legality, does not guarantee compliance with the EU AI Act or any other law, is not a Commission-approved marking method, and does not adjudicate any court matter. Every court matter named on this page is a pending allegation unless a court has finally found otherwise. Benchmarks are p50 measurements from a 40-sample run on 27 July 2026; production integrations are pilot-ready rather than deployed, and the transparency log is designed, not yet serving. Re-verify every cited source before any external use.
Each link opens that entry in the canon implementation explorer, where its schema, mint route, open verify route, auth requirement and implementation state are stated. The state shown here is read from the same registry file the explorer renders from, so the two cannot drift apart. Nothing here implies a customer, a deployment or an endorsement.
Search the explorer for Cartesia proof surface