The verdict I was proudest to ship is the one where the gate admits it can't prove anything
I remember the exact track that made me trust the thing I was building, and it was the one that failed. Radio Imaging Sweep 7 came back through the ingest gate marked NEEDS_REMEDIATION, soft binding not recoverable, confidence 0.699, and I felt relief instead of disappointment. Tessera, the demo I built, is an EU AI Act Article 50 ingest gate for audio. Its job is to look at a music release and decide, on evidence, whether the provenance an AI-generated track is supposed to carry actually survived the trip to the listener. For most of the twelve releases in the batch it says yes and shows its arithmetic. For Radio Imaging Sweep 7 it says the harder thing: I cannot demonstrate this survived, route it to a human, do not certify. That refusal took me longer to get right than anything the gate stamps COMPLIANT, and it is the part I would defend hardest in a room full of skeptics.
I built "just add C2PA" before I understood why it doesn't hold
I started this the way the whole industry is starting it, by reaching for C2PA. Article 50 of the EU AI Act takes effect on August 2, 2026, and it requires the outputs of generative audio to be marked in a machine-readable way that stays detectable after common modifications, with Article 99 penalties running up to 15 million euros or 3% of global turnover (EU AI Act; Commission draft Code of Practice, January 2026). The reflex answer is to attach a C2PA manifest and call the catalog covered. I did exactly that, then pushed a track through a plain social transcode, and the manifest was simply gone. C2PA hard binding is metadata, and metadata is stripped by essentially every social-platform upload, described in our own WP31 solution research (2026) as the single biggest operational weakness in the C2PA ecosystem today. The label that dutifully tagged its catalog is, operationally, uncovered the instant a track hits TikTok.
What survives is the unglamorous thing, and watching it work is the moment the design clicked for me. Neon Tide came back after the same social transcode with its C2PA metadata stripped, but the soft-binding watermark UUID recovered at confidence 0.989, and the manifest, a C2PA stand-in held in a SQLite soft-binding ledger, re-resolved from the recovered key. The survival matrix re-encoded the master through mp3-128, aac-128, and opus-96 with real ffmpeg and recovered the key at a bit-error rate of 0.0 on all three. I want to be precise about scope, because Veriprajna means true wisdom and the honest number is the whole point: that is our spread-spectrum mark on a fixed synthetic corpus of twelve releases through those three codecs, not an open-world guarantee and not a robustness contest against SynthID or AudioSeal, which sit in the demo as stub adapters. Every one of the twelve tracks is synthetic tones with a planted label, no real music and no real artists. The thing the screen makes undeniable is the contrast: hard binding survived none of the social channels, soft binding carried the provenance through.
Neon Tide (REL-001), delivered through the social channel. The C2PA hard binding is stripped by the transcode; the soft-binding watermark UUID is recovered at confidence 0.989 and the manifest re-resolves from the ledger. The survival matrix re-encodes the master through mp3-128 / aac-128 / opus-96 at BER 0.0 (real ffmpeg). Neon Tide is a synthetic test fixture, not a real release.
The week I almost trusted a corpus that was lying to me
I nearly recorded my proof numbers off a corpus that was quietly corrupt, and catching it is the most Veriprajna thing that happened in this whole build. I was re-running the batch to capture the figures for this launch, and the watermark keys were coming back as garbage, a bit-error rate hovering around 0.5, which for a 32-bit key is indistinguishable from a coin flip. My first instinct, the tempting one under a deadline, was to assume my decoder had regressed and start patching it. It had not regressed. A stale on-disk corpus had been cached from an earlier run, and every "measurement" I took against it was noise wearing the costume of data. I threw it out, rebuilt the corpus fresh from its deterministic seeds with build_corpus.py, and only then let myself write down a single number. The unit tests exist for precisely this failure: python tests/test_pipeline.py comes back 7 passed, and one of those seven asserts the clean watermark roundtrip, so a silently broken corpus can never again pass itself off as data. I trust a system more, not less, after I have watched it try to lie to me and been forced to catch it.
The track that broke, and why I left it broken
I keep bringing people back to Radio Imaging Sweep 7, because it is the release where the gate earns its name. It is a synthetic broadcast track, and in the demo it arrives through what I call the analog gap: a speaker-to-microphone recapture, the way audio gets pulled off an FM monitor instead of handed over as a clean file. That path destroys the watermark. The soft-binding key does not recover, the CRC fails, and the confidence lands at 0.699, well under the bar. The honest nuance I made the screen show rather than hide is this: the survival matrix, run on the clean master through the social codecs, proves the mark would have survived a normal transcode at BER 0.0. It was this specific delivery, the analog-gap recapture, that broke it. A lazier system would notice the mark is fundamentally fine and wave the track through. Mine does the opposite. It cites the draft Code of Practice on surviving common modifications and returns NEEDS PROOF, provenance not recoverable after the delivery channel, routed to human review, do not certify, with a named remediation owner on a five-day SLA. I wrote that behavior into a unit test called test_watermark_dies_in_analog_gap, so the abstention is an invariant I verify, not a mood the system happens to be in on a good day. Under Article 99's penalties, a false COMPLIANT is the expensive kind of wrong, and I would rather the gate route a track to a person than guess in its favor.
Radio Imaging Sweep 7 (REL-004), delivered through the analog gap. The soft-binding key is not recoverable (confidence 0.699, CRC fails), so the gate returns NEEDS PROOF and routes it to a human owner instead of certifying. Note the survival matrix on the clean master still reads BER 0.0: the mark would survive a normal transcode; it was this analog-gap recapture that broke it. A synthetic broadcast fixture.
A recovered watermark still isn't a compliant track, and I made the gate rude about it
I had to learn to distrust my own relief the first time a track recovered its watermark cleanly and I assumed it was finished. Glasshouse is that track. Its mark comes back at confidence 0.992, BER 0.0 across all three codecs, provenance genuinely intact. Early on I would have stamped it COMPLIANT and moved to the next one. The gate does not, and it is right not to. Glasshouse is BLOCKED under Article 50(4), because its DDEX AI-disclosure is incomplete: the instrumentation, mixing, and mastering fields never came through the aggregator, and shipping a track with an active disclosure gap is itself an Article 50 violation, not a paperwork nicety I get to defer. This is the point I most want a rights-tech buyer to sit with. Provenance recovery is necessary, and it is nowhere near sufficient. The gate checks the whole chain, the mark and the soft-binding recovery and the DDEX disclosure and a named takedown owner, blocks on any broken link, and cites the exact clause that broke. DDEX ERN 4.3 has no native AI-disclosure fields, and most aggregators do not pass granular disclosure through (Veriprajna WP31 solution research, 2026), which is how a track can be technically provenanced and still legally exposed.
Glasshouse (REL-003). The watermark recovers cleanly at confidence 0.992, BER 0.0 across all three codecs, and the track is still BLOCKED under Article 50(4): the DDEX AI-disclosure is missing instrumentation, mixing, and mastering. Mark present does not equal compliant. A synthetic test fixture.
What I keep coming back to
I keep coming back to how much of this work is refusing to certify rather than certifying. Across the twelve-release batch the gate clears seven automatically, routes two to human remediation, and blocks three, and every one of the twelve leaves with a verdict and a cited Article 50 clause in a regulator-ready dossier you can export as HTML or JSON. None of it rides on a model's judgment: the watermark recovery, the survival measurement, and the Article 50 pass or fail are deterministic code, and the two agents that draft remediation and adversarially review each certification can be switched off entirely with no change to the numbers. You can run the batch yourself, keyless, and watch a track get refused in real time at veriprajna.com/demos/ai-audio-licensing-provenance.
The exported regulator dossier (HTML / JSON). Every track carries a verdict and a cited Article 50 clause: a human-created release marked out of Article 50 scope with provenance recorded for audit, a COMPLIANT track, and Solstice Engine routed to remediation because its watermark recovered but no manifest was ever registered for that key. All entries are synthetic fixtures.
The question I have not stopped asking myself is this one. When your automated compliance system cannot prove something is safe, does it say so out loud and hand the file to a person, or does it round the confidence up and call it compliant? On August 2, 2026, that difference stops being a design preference and starts being an Article 99 line item.