prepared for Fish Audio · illustrative only · not affiliated with Fish Audio · not indexed

On 2 August 2026, synthetic audio in the EU must carry a machine-readable mark. The docs say nothing about one.

EU AI Act Article 50(2) applies from 2 August 2026. Providers of AI systems that generate synthetic audio must mark the output in a machine-readable format, detectable as artificially generated (Article 50 text, European Commission FAQ). The complete Fish Audio developer documentation corpus, 362,947 bytes, contains zero occurrences of watermark, C2PA, provenance, or content credential (llms-full.txt).

Hive comes alongside a voice stack as a sidecar. At the moment of each generation, each clone creation, and each takedown, it makes an independent, signed receipt that anyone can check offline. It never generates audio, never blocks a request, never decides whether a consent was valid, and never holds your keys. It is invisible to your users, invisible to your inference path, and fail-open. If Hive is unreachable, generation runs exactly as it does today.

Non-customer notice. This page is illustrative only. It is prepared privately by Hive Civilization Inc. It is not affiliated with, sponsored by, or endorsed by Fish Audio, Hanabi AI Inc., or 39 AI, INC. It does not state or imply that Fish Audio is a customer, partner, pilot, or endorser, or that Fish Audio uses Hive. Nothing here is an accusation. Every claim about Fish Audio is quoted from a Fish Audio surface or a named public source and linked to it.
$52M seed · 28 July 2026
A $52M seed round announced 28 July 2026, led by Coreline Ventures and Capital Today, headquartered in Palo Alto, California. The legal entity is Hanabi AI Inc., a Delaware company.
$21M ARR · 22 people
The company describes going from "zero to $21M in annual recurring revenue" with enterprise at two-thirds of revenue, and sums itself up as "5 Models, 22 People, $52M Raised" after scaling from 3 people to 22.
8M users · 2M voices
"More than 8 million creators, developers, and enterprises" and "over 2,000,000 community-uploaded voices spanning 8 languages." S2.1 Pro launched publicly 28 July 2026 with 83 languages and more than 15,000 control tags.
The exposure, in one line
The developers page promises watermarking and consent attestation. The documentation corpus contains neither. Under Article 50(2) that difference stops being a marketing question on 2 August 2026 and becomes an evidentiary one.
exposure 1 · the statutory deadline · this is the lead argument

Article 50(2) applies on 2 August 2026

This is the strongest fact on the page. It is not an opinion, a benchmark, or a competitive comparison. It is a date in force law, and it is days away.

·
days
·
hours
·
minutes
·
seconds

Four days on the calendar from 29 July 2026. The counter above runs to 2 August 2026, 00:00 UTC, the date Article 50 transparency obligations begin to apply, so it reads in exact hours rather than calendar days.

Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated. EU AI Act, Article 50(2) · artificialintelligenceact.eu/article/50
● the date

Applies from 2 August 2026

Article 50 transparency obligations apply from 2 August 2026. Relief to 2 December 2026 is available only for systems already placed on the market before that date, so a system launched on 28 July 2026 is a live question rather than a settled one (European Commission FAQ).

● the penalty

Up to EUR 15 million or 3 percent

Non-compliance with Article 50 carries administrative fines of up to EUR 15 million or 3 percent of total worldwide annual turnover, whichever is higher (European Commission FAQ).

● voice is in scope

Confirmed 20 July 2026

The Commission's final Article 50 guidelines, adopted 20 July 2026, confirm that "persons" covers "digital replicas of real people... and personal characteristics or expressions such as a person's image, voice, behaviour and performances" (Bird & Bird).

"watermark" in the docs corpus
0 occurrences
"C2PA" in the docs corpus
0 occurrences
"provenance" in the docs corpus
0 occurrences
"content credential" in the docs corpus
0 occurrences

Verified against the complete published developer documentation corpus, 362,947 bytes: docs.fish.audio/llms-full.txt. A term count is a fact about the published documentation. It is not a statement about what runs in production.

The Hive answer, in one paragraph

Media Origin Receipt™ and MoRSo™. A machine-readable, signed origin receipt emitted with every generation. Verifiable offline by anyone. No dependency on Fish Audio being available, reachable, or willing to confirm it. The mark travels with the file rather than living in a vendor database.

what a receipt cannot decide

A receipt is not a Commission-approved marking method, and no regulator has reviewed it. It makes the origin of a file independently checkable. Whether a given marking approach satisfies Article 50(2) is a legal determination for Fish Audio's counsel, not one a receipt makes.

exposure 2 · stated on one surface, absent on another

The claim that cannot be verified

Handled factually. This is not an allegation of bad faith. It is an observation that two published Fish Audio surfaces do not currently line up, and that the gap is visible to anyone who reads both.

Cloned voices require consent verification. Audio watermarking is built into the cloning pipeline.

Consent attestation is part of the API call. Fish Audio developers page, verbatim · fish.audio/developers
● what the docs contain

Zero occurrences, three terms

The word consent appears zero times in the 363KB documentation corpus. So do watermark, C2PA, provenance, and content credential (llms-full.txt).

● what the API exposes

No consent field

There is no consent field, parameter, or endpoint in the API reference or in the published OpenAPI schema (api.fish.audio/openapi.json). Authentication is a static bearer key (developers).

● what is missing around it

No spec, no verifier, no attestation

There is no published watermark specification, no verification endpoint, no robustness claim, and no third-party attestation to point a reviewer at (llms-full.txt).

Why this costs more than an absent feature

A security reviewer at a regulated-industries buyer will read the marketing page, search the documentation for the feature it promised, fail to find it, and escalate. That escalation is not about the feature. It is about the difference between the two pages.

An unverifiable claim costs more in procurement than an absent feature, because it converts a product gap into a credibility question. A gap can be closed on a roadmap. A credibility question follows the vendor into every subsequent review.

Fish Audio does publish the enterprise posture a reviewer will also ask about, including that a SOC 2 Type II "audit is currently underway" (enterprise). The assurance table further down sets out what exists and what does not, in the company's own words.

The Hive answer

R3Pv™ turns the claim into a checkable artifact. The consent attestation and the watermark assertion become one grouped, signed receipt that the buyer's own reviewer verifies offline, without taking anyone's word for it. The marketing sentence and the technical reality become the same object.

what a receipt cannot decide

A receipt does not decide whether the original marketing sentence was accurate, does not certify a watermark as robust, and does not resolve a disclosure question. It fixes what was asserted, by which system, under which key, at which moment.

exposure 4 · the brand travels past the control

Open weights leave. The name goes with them.

Weights are downloadable from Hugging Face under cc-by-nc-sa-4.0 (s1-mini) and the fish-speech repository carries 31.7k stars (GitHub). Anyone can self-host and generate voices Fish Audio never sees.

The licence, the Fish Audio Research License, is free for research and non-commercial use only, requires a paid licence for commercial use, and requires "Built with Fish Audio" attribution (LICENSE). Model copyright sits with a second entity, 39 AI, INC. Reputation therefore attaches to output that Fish Audio cannot observe, under an attribution requirement that is currently an honour system.

● today

Attribution is a promise

A self-hosted deployment can honour the "Built with Fish Audio" requirement or quietly ignore it. Either way, the output carries the name in the eyes of anyone who hears it and no signal distinguishes the two cases.

● with Hive

Attribution becomes an artifact

S2S™ hardware-rooted GPU attestation and PBS™ provenance-bonded sandbox. A self-hosted deployment still emits a signed receipt proving which weights ran in which environment. MiR™ binds which model answered.

● what it buys

A boundary you can point at

When an unattributed clip surfaces, the question stops being "was this yours" and becomes "is there a receipt". A receipted deployment can be separated from an unreceipted one without inspecting anyone's servers.

what a receipt cannot decide

A receipt cannot compel an unlicensed self-hoster to emit one, cannot decide whether a licence was breached, and cannot attribute an unreceipted clip to any origin. It proves the environment and weights for deployments that opt in, which is what separates a compliant integrator from an unknown one.

exposure 5 · precedent, and it is vendor-fatal

When the claim lands, your own logs are not the evidence

In Lehrman v. Lovo, No. 1:24-cv-03770 (S.D.N.Y.), Judge Oetken's 10 July 2025 opinion let breach of contract, New York right-of-publicity, and New York consumer-protection claims proceed, while dismissing the Lanham Act and most copyright claims (Reuters, opinion PDF).

Lovo appears here only as litigation precedent. No comparison to any voice vendor is drawn or implied anywhere on this page.

● the doctrinal holding

Copyright is not the shield

Copyright does not protect against imitation of a voice, only direct copying of a fixed recording. Vendor exposure therefore runs through state right-of-publicity and contract, not federal IP (Loeb & Loeb, Skadden).

● the clock does not save you

Continuing replication

The court rejected a one-year limitations defence, reasoning that a model trained on the plaintiffs' voices "was arguably continuing to replicate those voices each time the model generated new clips" (opinion PDF). A trained model keeps the exposure current.

● how it ended for the defendant

Bankruptcy, then a stay

Lovo filed for bankruptcy and the copyright suit was automatically stayed in May 2026 (case tracker). The precedent survives the defendant.

The statute that reaches the tool, not just the user

Tennessee's ELVIS Act, in force 1 July 2024, reaches vendors directly. It creates liability for distributing "an algorithm, software, tool or other technology, service or device, the primary purpose or function of which is to produce a particular, identifiable individual's photograph, voice or likeness" without authorisation (Holland & Knight).

A tool-provider clause is what makes "the user agreed to our terms" an incomplete answer. The question becomes what the provider can show about the moment the voice model was made.

The Hive answer

Forensic Rail™ for threshold-signed, deterministic replay under a consortium credential. Hive Ledger for append-only history. ViewKey™ so a rights-holder, a regulator, a union, and an enterprise customer each read the same event from their own vantage, without a shared database and without new access.

what a receipt cannot decide

A receipt does not decide a right-of-publicity claim, does not satisfy a discovery obligation on its own, and does not make a filing go away. It replaces a self-authored log with an independently checkable record of what the system did.

the assurance gap · company language, quoted · re-verify before external use

What a buyer's reviewer will find and will not find

Nine artifacts a regulated-industries security review asks for, with the current published status in Fish Audio's own words. One row is confirmed strong. Two are in progress or contract-gated. The rest are absences, and an absence is easier to close than a contradiction.

Assurance gap · status as published on the linked surfaces
ArtifactFish Audio statusSource
SOC 2 Type II"audit is currently underway... available to customers under NDA once it is complete"enterprise
ISO 27001No mention anywhereenterprise
HIPAA"HIPAA-aligned configurations and can sign a BAA for qualifying healthcare workloads"; plan note "SOC2 / HIPAA upon requests"enterprise
Zero data retention"available on enterprise contracts", not the default; consumer policy retainsenterprise, Privacy
On-premisesConfirmed: "Deploy to your VPC, data center, sovereign cloud, or air-gapped environment"developers
Trust / security pageDoes not exist. /security/, /trust/, /compliance/ all 404probed
Published AUPDoes not exist, despite the licence incorporating one by referenceLICENSE
WatermarkingMarketing claim only. Zero occurrences in 363KB docs corpusllms-full.txt
Consent attestationMarketing claim only. Zero occurrences in docs corpus; no API fieldllms-full.txt

On a narrow screen, scroll the table sideways to read the source column. The on-premises row matters more than it looks. An air-gapped deployment is exactly the environment where a signed receipt is the only evidence that can leave, because the audio, the reference clip, and the logs cannot.

the Hive answer per exposure · every row names what a receipt cannot decide

Each exposure, mapped to a named primitive

Nine rows. Every one names the primitive, the receipt it cuts, and the boundary it refuses to cross. The last line of each row is the point of the page. Hive proves conditions, never verdicts.

exposure 1 · Article 50(2) marking

Media Origin Receipt™ · MoRSo™

A machine-readable, signed origin receipt emitted with every generation, verifiable offline by anyone, with no dependency on Fish Audio being available or willing to confirm it. The mark is carried by the artifact rather than looked up in a vendor system.

Media Origin Receipt™ · MoRSo™
what a receipt cannot decide

It is not a Commission-approved marking method and no regulator has reviewed it. Whether a marking approach satisfies Article 50(2) is a legal determination for counsel, not one a receipt makes.

exposure 2 · the unverifiable claim

R3Pv™

The consent attestation and the watermark assertion become one grouped, signed receipt that a buyer's own reviewer verifies offline. A marketing sentence becomes a checkable artifact, so the review ends at verification instead of escalation.

R3Pv™ · grouped proof vector
what a receipt cannot decide

It does not judge whether the original claim was accurate, does not certify watermark robustness, and does not clear a disclosure question. It fixes what was asserted, by which system, under which key.

exposure 3 · consent at clone time

OriginProof™ · SPR™ · Physiological Provenance Receipt™

OriginProof™ attests human origin. SPR™ proves the instruction came from an authorised party. Physiological Provenance Receipt™ binds the reference audio to a live capture rather than a downloaded clip, which is the exact distinction a ten-second podcast cut erases.

OriginProof™ · SPR™ · Physiological Provenance Receipt™
what a receipt cannot decide

It does not establish that consent was legally sufficient, does not resolve a rights dispute, and does not decide a UK GDPR lawful-basis question. It fixes the record of what was attested, by whom, and when.

exposure 4 · open weights and self-hosting

S2S™ · PBS™ · MiR™

S2S™ gives hardware-rooted GPU attestation. PBS™ runs the model in a provenance-bonded sandbox whose kernel, engine hash, and firmware version are on a signed heartbeat chain. MiR™ binds which model answered. Attribution stops being an honour system for deployments that opt in.

S2S™ · PBS™ · MiR™
what a receipt cannot decide

It cannot compel an unlicensed self-hoster to emit anything and cannot decide whether a licence was breached. It separates a receipted deployment from an unknown one.

exposure 5 · litigation and regulator replay

Forensic Rail™ · Hive Ledger · ViewKey™

Forensic Rail™ gives threshold-signed, deterministic replay under a consortium credential. Hive Ledger keeps append-only history. ViewKey™ lets a rights-holder, a regulator, a union, and an enterprise customer each read the same event from their own vantage, without a shared database and without new access.

Forensic Rail™ · Hive Ledger · ViewKey™
what a receipt cannot decide

It does not decide a right-of-publicity claim, does not discharge a discovery obligation, and does not adjudicate any filing. It replaces a self-authored log with an independently checkable record.

operational · upload and takedown thresholds

Refusal Ledger™

The thresholds that govern which voice uploads are refused, and which takedown conditions trigger removal, live on a public Merkle mutation ledger with a zero-knowledge envelope-bond. A union, a rights-holder, or an auditor can verify that the bounds were in force without seeing the exact numbers.

Refusal Ledger™ · ZK envelope-bond
what a receipt cannot decide

It does not decide whether a threshold was set correctly, adequately disclosed, or lawful. It proves which threshold was in force when a refusal or a removal ran.

operational · likeness features at inference time

Howler™

A signed freeze receipt fires the instant an identifiable-likeness feature activates during a clone or generation request. The event is recorded at the moment it happens, not discovered later in a support thread.

Howler™ · SAE-triggered freeze receipt
what a receipt cannot decide

It does not identify a person, does not decide whether a likeness was used without authorisation, and does not block the request. It records that a flagged feature activated.

operational · reference audio and voice-library egress

Egress Bond™ · Diurnal Bond™

Egress Bond™ meters caps on reference-audio and voice-identity egress per semantic class using Pedersen commitments, and a cap breach retroactively invalidates the downstream graph. Diurnal Bond™ requires k-of-n countersign before a high-impact action, such as reinstating a removed voice, runs during evening or weekend hours.

Egress Bond™ · Diurnal Bond™
what a receipt cannot decide

It does not decide what the correct cap should be, does not classify a transfer as lawful, and does not answer an international-transfer question. It proves the cap that applied and whether the second key signed.

the floor under all of it

Hive Ledger · append-only history

Every receipt above folds into one append-only history, so the absence of an expected receipt is itself a signal. A certificate-transparency style log for receipt inclusion is designed, not yet serving. Nothing on this page depends on it, because verification is offline.

Hive Ledger · CT log designed, not yet serving
what a receipt cannot decide

An append-only history cannot prove that an event nobody receipted ever happened. It can prove that a receipted event was never altered, and it can make a missing receipt visible.

Nothing above enters the inference path, refuses a generation, or decides a rights question. Each primitive proves that the thing that made a call was itself the thing it claimed to be. Hive proves conditions, never verdicts.

measured 27 July 2026 · n=40 · pilot-ready, not deployed

The numbers, stated plainly

A receipt is only usable if it is free at the millisecond level. These are the measured figures, with the sample size and date attached, and with an honest label on maturity.

0.098 ms (p50)
Sign one receipt. Median of the measured run.
0.136 ms (p50)
Verify one receipt, offline, no network.
0.678 ms (p50)
Dual-signed envelope, end to end.
3,309 bytes
ML-DSA-65 signature size, per NIST FIPS 204.

Method and maturity, without decoration

Sample size n=40. Measured 27 July 2026. 37 of 37 smoke tests pass. Figures are reported as medians and labelled as such.

Production integrations are pilot-ready rather than deployed. That is the accurate state today. The signing and verification path is measured and reproducible. The integrations into a live voice pipeline are not yet running in production anywhere, and this page does not claim they are.

The seven upstream pre-effect controls were filed as USPTO 64/119,279 on 26 July 2026. A filing is a filing. It is not a granted patent, and nothing on this page depends on it.

The certificate-transparency style inclusion log is designed, not yet serving. Verification does not depend on it. A receipt is checked offline against the signature and the content-addressed roots, with no call to Hive and no call to anyone else.

Signatures use a hybrid of Ed25519 and ML-DSA-65, the NIST FIPS 204 federal standard. Receipts carry one-way fingerprints and cryptographic commitments, never raw audio, never a reference clip, and never a voice embedding.

Numbers on this page are measurements of the Hive signing path, not projections about any Fish Audio system, and not a benchmark of any voice model.

The keys stay with you

In plain words: your organization holds the pen that signs. Hive never touches raw audio, never holds your keys, and never enters the generation path.

You hold your own signing keys

You keep the private key that stamps your receipts. Nobody else can sign in your name, and the key never leaves your own hardware. The signature is yours, not Hive's.

Hive stays a non-custodial sidecar

Hive gives you the way to make and check receipts. It does not generate audio, clone a voice, refuse a request, decide whether a consent was valid, or run your pipeline. Each event is recorded as a one-way fingerprint and a cryptographic commitment, never the underlying audio.

THE ASK · PICK ONE SURFACE. HIVE RUNS THE POC.

One surface. Not the platform, not a migration, not a rebuild. The obvious candidate is the generation endpoint, where a Media Origin Receipt™ can be emitted alongside the audio and checked offline by anyone. The second candidate is voice-model creation, where a consent receipt is cut at the moment the model is made. Hive builds it, runs it, and hands over receipts that verify without Hive in the loop. Nothing changes in the inference path. If the receipt rail is unreachable, generation proceeds exactly as it does today.

Naming Fish Audio does not imply any agreement. This page does not state or imply that Fish Audio is a customer, partner, pilot, or endorser, or that Fish Audio uses Hive. Customers referenced anywhere in Hive materials are HeyGen, LiveKit, Retell, and Telnyx integrations confirmed on the customer side (HeyGen, LiveKit, Retell, Telnyx), which are facts about Fish Audio's own integrations rather than about Hive.

Legal & policy Trust & safety Compliance & enterprise Engineering & platform

One line to start: [email protected]

Stephen Rotzin, Founder, Hive Civilization Inc (Wyoming) · [email protected]

illustrative and non-endorsement notice

This page is illustrative only. It is prepared privately by Hive Civilization Inc. and is not affiliated with, sponsored by, or endorsed by Fish Audio, Hanabi AI Inc., 39 AI, INC., or any of their affiliates. It does not state or imply that Fish Audio is a customer, partner, pilot, or endorser, or that Fish Audio uses Hive.

Every statement about Fish Audio on this page is quoted or counted from a published Fish Audio surface or a named public source and linked to it. Nothing here is an accusation of wrongdoing. Where two Fish Audio surfaces differ, both are quoted and both are linked, and the difference is presented as a published fact rather than an inference about intent. Facts were verified on 29 July 2026 and should be re-verified before any external use.

A signed receipt proves that a step ran and what it returned. It does not decide legality, does not guarantee compliance with the EU AI Act or any other law, does not resolve a rights or consent dispute, and does not adjudicate any court matter. Lehrman v. Lovo is cited only as litigation precedent on the doctrinal question of voice imitation and vendor exposure. The Equity demand letter is a published demand, not a finding. Production integrations are pilot-ready rather than deployed, and the certificate-transparency style inclusion log is designed, not yet serving.

Private, illustrative overview · noindex / nofollow / noarchive / nosnippet · not affiliated with Fish Audio, Hanabi AI Inc., or 39 AI, INC.; this page does not state or imply that Fish Audio is a customer, partner, pilot, or endorser, and does not imply Fish Audio uses Hive · no comparison to any other voice vendor is made or implied; Lovo is named only as litigation precedent · Hive is a sidecar; it does not generate audio, clone a voice, refuse a request, or decide whether a consent was valid, does not enter the inference path, and does not move or store raw audio, reference clips, or voice embeddings · a signed record that a step ran is not a statement of legality and does not guarantee compliance · every court matter named on this page is a pending or stayed allegation unless a court has finally found otherwise · each event is recorded as a one-way SHA-256 fingerprint and cryptographic commitment, not the raw signal · verification is free, works offline, and needs no account · signatures use a hybrid of Ed25519 and ML-DSA-65 (NIST FIPS 204), a federal standard; ML-DSA-65 signature size 3,309 bytes · benchmarks: sign 0.098 ms (p50), verify 0.136 ms (p50), dual-signed envelope 0.678 ms (p50), n=40, measured 27 July 2026, 37 of 37 smoke tests pass; production integrations are pilot-ready rather than deployed; the CT-style inclusion log is designed, not yet serving · public reference material used in preparing this overview, to be re-verified before external use: EU AI Act Article 50 (artificialintelligenceact.eu); Article 50 transparency FAQ (European Commission); final Article 50 guidelines adopted 20 July 2026 (Bird & Bird); Fish Audio developer documentation corpus, 362,947 bytes (llms-full.txt); Fish Audio OpenAPI schema (api.fish.audio); Fish Audio developers page (fish.audio/developers); voice-clone FAQ (fish.audio/voice-clone); voice-cloning best practices (docs.fish.audio); capabilities (docs.fish.audio); enterprise page (fish.audio/enterprise); privacy policy (fish.audio/privacy); terms (fish.audio/terms); voice library (fish.audio/voice-library); seed-funding post (fish.audio/blog); funding release (PRNewswire via Yahoo Finance, PR mirror); funding and takedown reporting (TechCrunch); model licence (LICENSE); repository (GitHub); weights (Hugging Face); Equity demand letter, 22 May 2026 (Equity); Lehrman v. Lovo, No. 1:24-cv-03770 (S.D.N.Y.) (Reuters, opinion PDF, Loeb & Loeb, Skadden); bankruptcy stay, May 2026 (case tracker); Tennessee ELVIS Act (Holland & Knight); confirmed integrations, customer side (HeyGen, LiveKit, Retell, Telnyx) · prepared by Stephen Rotzin, Founder, Hive Civilization Inc (Wyoming), [email protected]