235,000 people listened to a fake KATSEYE member last month. The impersonation is at ingest, not at the DSP.
HYBE/Geffen-signed girl group KATSEYE just announced that Sophia Laforteza is stepping back on mental-health grounds — the second member on hiatus after Manon Bannerman in February. Bannerman's real name is now attached to a Spotify profile pulling 235,000 monthly listeners on AI-generated tracks she never made. A separate fake profile under the same name is live on Apple Music. Google's AI-powered search summarizes the fake Apple profile as authoritative. Bannerman has released no solo music.
TL;DR
- A fake "Manon Bannerman" Spotify profile — impersonating a real KATSEYE member — pulled 235,000 monthly listeners with AI-generated tracks.
- A separate fake profile under the same name is live on Apple Music. Both are the work of opportunists farming royalties off a trending artist name.
- The EU AI Act's labeling rules just took effect, targeting the uploader of commercial deepfakes — but leaving DSPs with a choice, not an obligation, on platform-side labeling.
- The structural fix is at the distributor ingest tier: block the impersonating upload before it hits the DSP. After ingest, the deepfake already has an audience.
What actually happened
Manon Bannerman is a real member of KATSEYE. She announced a hiatus in February 2026. She has released no solo music, on any platform, ever.
Since her hiatus was announced, a Spotify profile under her name has been quietly accumulating listeners. It is fully AI-generated — songs like False Sisterhood, Fresh Out This Hiatus, P1NKY D0WN, produced by a party with no connection to Bannerman. By the reporting cited above, it pulled 235,000 monthly listeners in the past month.
On Apple Music, a completely different fake profile — same name, different releases (SWEAT, DIVA, Hiatus, a No Signal EP) — is also live. Google's AI-powered search treats the Apple profile as canonical: "You can listen to pop artist Manon Bannerman on the Manon Bannerman Apple Music profile."
Two DSPs. Two different fake profiles. One real artist name. Zero solo releases by the actual person. The pipeline that got both of those uploads live is the failure point.
The numbers
Why the DSP-side fix is not enough
Spotify's answer to fake artist attribution is the Verified By Spotify tick — a manual signal that says "this profile is who it claims to be." That works for the fan who checks. It did not stop 235,000 people from pressing play on the unverified impersonator.
The deeper problem is that DSP-side signals are downstream of ingest. By the time Spotify or Apple has a fake artist profile in their catalog, three things are already true:
- The upload passed a distributor's checks and got a delivery slot.
- The DSP indexed it, matched it to a listenable page, and started serving plays.
- Third-party aggregators — Google's AI summary, social media, streaming-linking apps like Songwhip — began treating the fake as authoritative.
Removing the profile later is enforcement, not prevention. The 235,000 listeners already happened. The royalties have already been paid out to the operator. The Google AI summary has already been generated, cached, and served to the next round of searchers. Every additional day the fake profile lives is compounding damage that a takedown does not un-do.
The EU AI Act just made ingest-time labeling a legal duty
The EU AI Act's content-labeling rules took effect on August 2, 2026. Two provisions matter for the Bannerman case:
- Watermarking / embedded metadata on generation. AI generation platforms have until December 2026 to embed provenance signals in the content they produce. Suno's fresh transparency commitments last week are the industry pre-positioning for this deadline.
- Clear labeling of commercial deepfakes. Anyone who monetizes a deepfake — the uploader farming royalties off a fake "Manon Bannerman" catalog — has an obligation to label it clearly. The DSP that hosts it has a lighter obligation: a choice rather than a strict duty.
The asymmetry is where the enforcement bite lands. The EU AI Act catches the uploader, not the platform. And the uploader touches the pipeline exactly once — at ingest. Which means the distributor sitting between the uploader and the DSP is structurally the right layer to enforce the rule. Not because they want the compliance burden, but because they are the only party in the chain that can identify the deepfake before the DSP serves it to 235,000 people.
What ingest-time detection actually catches
The Bannerman impersonation is not one problem; it is three overlapping ones, and each maps to a signal that can be checked at ingest:
- The audio is AI-generated. A modern detector classifying human vs. Suno vs. licensed AI vs. unknown generator answers this in seconds, at the moment the master hits the delivery pipeline.
- The artist name is an impersonation. A name-similarity check against known-artist rosters — including hiatus-flagged members of active groups — flags "Manon Bannerman" as a name that already belongs to somebody who has not released solo material. That check does not require the DSP; it can run at the distributor.
- The catalog is anomalous. A new "artist" appearing simultaneously on multiple DSPs with different discographies, all AI-generated, all tied to a name trending in cultural news — that pattern is not human-artist behavior. It is royalty-farming behavior, and it is detectable in aggregate before the catalog matures.
None of these three checks require the DSP to change anything. They belong at the layer that already reviews every upload — the distributor.
How DistroShield fits
DistroShield is the ingest-time layer for this exact class of problem. Every track submitted to the API returns four evidentiary artifacts at once:
- A verdict (human / AI / hybrid) with per-generator attribution — Suno, Udio, other named sources.
- A signed PDF certificate with a SHA-256 hash of the analyzed audio, UTC timestamp, and independently verifiable signature. Anyone can rehash the file and validate at distroshield.com/verify without contacting our servers.
- Cross-catalog duplicate, cover, and version detection against 100M+ commercial recordings — catches when an incoming "new artist" release is actually recycling material tied to a different named artist.
- Cross-distributor identity fraud detection — if the same audio has already been submitted under a different artist name at any distributor using DistroShield, the second submission gets flagged with the conflict.
For the Manon Bannerman pattern specifically, the combination that matters is verdict + cross-distributor identity check. An AI-generated master submitted under a name matching a real charting artist, with no prior catalog under that name, is the exact ingest signature the EU AI Act's labeling rule is designed to catch. DistroShield returns that signature as a machine-readable API response — inside the ingest pipeline, before the delivery is queued to the DSP.
Catch impersonation before it hits the DSP
Analyze a single track for free at /lookup. Signed PDF certificate for $5. Distributor and marketplace pilots start at 100 tracks/month with volume pricing beyond.
The next distributor to catch this wins
The Bannerman case fits neatly into the enforcement arc we have documented all summer — Qobuz + FUGA at the distributor tier, Deezer's 90K AI tracks a day, Spotify's 75M removals, and Spotify's Merlin deal splitting the market into licensed and unlicensed lanes. Every one of those events pushed enforcement one step closer to ingest.
Impersonation-driven deepfakes are the natural next enforcement wave. A trending artist name is a targeting signal any royalty-farmer with a $10/mo AI subscription can exploit. The distributor that can prove — cryptographically, at ingest — that its catalog is free of impersonating uploads is the distributor the next Manon Bannerman story will not name.