NEWS

Musician Sentenced to Prison for $10 Million AI-Bot Streaming Fraud

Michael Smith got 18 months and an $8M forfeiture for using AI songs and 1,000+ bots to fake billions of streams and steal royalties.

Dylan H.

News Desk

October 7, 2026
7 min read
Musician Sentenced to Prison for $10 Million AI-Bot Streaming Fraud

North Carolina Musician Gets 18 Months for $10 Million AI Streaming Fraud

Michael Smith, a 54-year-old musician from Cornelius, North Carolina, was sentenced to 18 months in federal prison on October 6, 2026, for running a seven-year scheme that used AI-generated songs and automated bot networks to siphon more than $10 million in royalty payments from Spotify, Apple Music, Amazon Music, and YouTube Music. U.S. District Judge John G. Koeltl of the Southern District of New York also imposed two years of supervised release and ordered Smith to forfeit $8,091,843.64. Prosecutors had asked for at least 46 months behind bars; Smith's defense sought probation. The Department of Justice says the case is the first criminal prosecution in the U.S. for music streaming fraud carried out with the help of artificial intelligence.


Incident Details

AttributeValue
DefendantMichael Smith, 54, Cornelius, North Carolina
ChargeConspiracy to commit wire fraud (pleaded guilty March 19, 2026)
Original indictmentSeptember 2024 — wire fraud conspiracy and money laundering conspiracy
Scheme duration2017 – 2024 (approximately 7 years)
Platforms targetedSpotify, Apple Music, Amazon Music, YouTube Music
Fraud mechanismAI-generated tracks + automated bot streaming
Bot infrastructure1,000+ bot accounts across 52 cloud service accounts (≈20 bots each)
Evasion techniqueVPN-masked connections to defeat anti-fraud detection
Scale claimed by SmithOver 4 billion streams and $12 million in royalties since 2019 (per his own email)
Peak single-platform volume80.9 million YouTube Music streams in April 2023
Sentence18 months prison, 2 years supervised release
Financial penalty$8,091,843.64 forfeiture, plus restitution
Prosecuting officeU.S. Attorney's Office, Southern District of New York

How the Scheme Worked

Sourcing the catalog

Smith did not write or perform the music he profited from. According to court filings, he worked with the chief executive of an AI music company and an unnamed music promoter to obtain hundreds of thousands of AI-generated songs, which he then uploaded to major streaming services under his own catalog. The volume was the point: a large enough library of tracks meant a large enough surface area to spread fraudulent plays across, making any single song's stream count look less anomalous.

Building the bot farm

To generate royalty-qualifying plays at scale, Smith operated a distributed bot infrastructure rather than a single automation script. Court records cite an email Smith sent to himself on October 20, 2017, laying out the mechanics: 52 cloud computing accounts, each running roughly 20 bot accounts, for a peak network of more than 1,000 bots continuously streaming his AI-generated catalog. Each bot account was built to mimic a real listener session closely enough to register as a billable stream under each platform's royalty rules.

Evading anti-fraud detection

Streaming platforms already run automated fraud-detection systems that look for streaming patterns inconsistent with human listening — repetitive IPs, abnormal session lengths, and device fingerprint reuse chief among them. To get around these controls, Smith's bots connected through virtual private networks (VPNs), rotating apparent geographic origin and IP address to make the fraudulent traffic look like it was coming from thousands of distinct, geographically dispersed listeners rather than a single operator's server farm.

Scaling to billions of streams

The combination of AI-generated volume and bot-driven plays let the operation run at an industrial scale. At its peak the network generated roughly 661,440 streams per day, worth an estimated $3,307 daily in royalty payouts. In April 2023 alone, Smith's bot accounts produced 80.9 million streams on YouTube Music — for comparison, prosecutors noted that Taylor Swift's entire catalog drew only 9.3 million family-plan streams on the same platform that month. By February 2024, Smith told associates by email that the catalog had amassed over 4 billion streams and $12 million in royalties since 2019.


Impact Assessment

Impact AreaDescription
Royalty pool dilutionStreaming royalty pools are largely fixed and shared proportionally; fraudulent plays divert real money away from legitimate artists and rights holders
Platform integrityDemonstrates that bot detection combined with VPN rotation can sustain fraud undetected for years at billion-stream scale
AI content riskShows AI-generated music can be weaponized as cheap, disposable fraud inventory rather than only a creative or copyright concern
Industry trustFeeds into broader concerns, echoed by trade body IFPI, that streaming fraud undermines confidence in royalty accounting across the industry
Legal precedentFirst U.S. criminal case explicitly charging AI-assisted streaming fraud, setting a template for future prosecutions
Financial lossMore than $10 million fraudulently obtained; only a portion ($8,091,843.64) recovered through forfeiture

Recommendations

For streaming platforms

  • Treat VPN-exit-point clustering combined with repetitive catalog-level play patterns as a high-priority fraud signal, not just per-account anomalies.
  • Correlate upload-account ownership with listening-account behavior — the same actor controlling both the catalog and an unusually large share of its plays is a strong fraud indicator.
  • Expand monitoring for AI-generated content uploaded in bulk, since mass-produced tracks are cheaper to use as fraud "inventory" than licensed or human-performed catalogs.
  • Share fraud-pattern indicators across platforms and with the industry's Streaming Integrity Initiative to shorten detection time on cross-platform schemes.

For rights holders and labels

  • Audit royalty statements for catalogs with disproportionate streams relative to audience size or marketing spend, which can indicate bot inflation diluting the shared royalty pool.
  • Support and participate in industry-wide fraud data-sharing efforts rather than relying solely on individual platform detection.

For security and fraud teams generally

  • Recognize that AI-generated content plus bot automation is a repeatable fraud pattern that extends beyond music — the same playbook (mass-produced content + distributed automated engagement + VPN evasion) applies to ad fraud, review fraud, and engagement farming.
  • Build detection around behavioral correlation across accounts and infrastructure, since individually convincing bot sessions can still reveal fraud when analyzed in aggregate (cloud account counts, shared infrastructure, timing patterns).

Key Takeaways

  1. Michael Smith was sentenced to 18 months in prison and ordered to forfeit $8,091,843.64 for a streaming fraud scheme that ran from 2017 to 2024 and netted more than $10 million.
  2. The scheme combined hundreds of thousands of AI-generated tracks with a bot network of 1,000+ accounts across 52 cloud service accounts to generate billions of fraudulent streams.
  3. VPN rotation was the key evasion technique, making bot traffic appear to originate from many distinct human listeners rather than a centralized operation.
  4. At peak, the fraudulent network out-streamed Taylor Swift's entire catalog on YouTube Music by nearly 9x in a single month.
  5. The DOJ has designated this the first U.S. criminal prosecution for AI-assisted music streaming fraud, establishing legal precedent for future cases.
  6. The sentence (18 months) was less than half of the 46 months prosecutors requested, highlighting ongoing debate over appropriate penalties for large-scale digital fraud.

Sources