When a successful song is accused of copying an unreleased demo, the dispute rarely turns on whether the two works sound alike. It turns on who can prove what existed, and when.
Music copyright disputes have a particular shape. A song becomes successful, and someone comes forward to say it borrowed from a work the public never heard. The claim is not that a famous song was copied, but that an obscure one was: a demo circulated among a handful of industry contacts, a recording shared with a producer, a file passed between collaborators long before either version reached an audience.
To establish copying, a claimant must show two things: that the defendant had access to the earlier work, and that the two works are substantially similar in their protected elements. Similarity is a question a musicologist can address by comparing the recordings. Access is different. It asks whether the later writer had a reasonable opportunity to encounter the earlier work before creating their own. Where the earlier work was released, access is often straightforward to argue. Where it was never released, access becomes the whole case, and access is a question of records.
That is what makes these claims so difficult to resolve on their merits. A court cannot simply listen to both recordings and decide. It has to reconstruct who held what, and when, from whatever documentation the parties managed to keep — often years after the events, and always with both sides motivated to remember the sequence favourably.
The scale of the underlying problem is easy to underestimate. Spotify’s catalogue reached roughly 250 million recordings by early 2026, with around 60,000 new tracks uploaded each day, according to figures given by co-chief executive Gustav Söderström on the company’s first-quarter 2026 earnings call.
That is only the music that reaches a streaming service. Beneath it sits a far larger body of work that never gets that far: demos, session files, voice memos, rough mixes and shared drafts, held on the personal drives of the people who made them and carrying no external record of when they were created. Disputes over unreleased works depend on exactly this material, and almost none of it carries independent proof of the date it came into being.
When a dispute arises, both sides reach for the same thing: a timeline they can prove rather than assert.
The claimant needs to establish that their work existed, and was circulating, before the defendant’s version was created. The defendant, to argue independent creation, needs to show their own work took shape through its own development — early drafts, session files, dated project versions — before any alleged access could have occurred. Whoever produces the more credible record of what existed, and when, begins with a decisive advantage. Proving a song came first is, in evidential terms, the whole contest.
The difficulty is that neither party can build such a record once a dispute has started. The evidence was either captured at the time or it was not.
This is where a common assumption fails. Creators tend to believe that a file’s modification date, an email sent to oneself, or a dated social media post is sufficient proof of when a work existed. Each of these depends on a record the creator controls, and each can be questioned on that basis. A file’s modification date can be changed by the person holding the file. What these methods lack is independence: a record made by someone who gains nothing from the answer, at the moment the work existed, which a later challenger cannot plausibly claim was arranged afterwards.
A qualified electronic timestamp is designed to be that independent record. It is a specific legal instrument defined under the European Union’s eIDAS Regulation, and it differs from an ordinary timestamp in ways that matter in a dispute.
The process begins with a cryptographic hash. The work — a recording, a session file, a document — is passed through a hashing function such as SHA-256, which produces a fixed-length fingerprint of the file. That fingerprint belongs to that exact file alone: alter a single note, or one byte anywhere in it, and a completely different fingerprint results. It reveals nothing about the content of the work, so the file itself never has to leave the creator’s hands.
The fingerprint is then submitted to a timestamping authority, which binds it to a date and time drawn from an accurate source and returns a signed token conforming to the RFC 3161 standard. Where that timestamp is issued by a Qualified Trust Service Provider listed on an EU member state’s trusted list, and meets the requirements of Article 42 of eIDAS, it becomes a qualified electronic timestamp.
Those requirements are exact. The binding of moment to data must reasonably preclude undetected change. The clock behind it must trace to Coordinated Universal Time. And the token must carry an advanced electronic signature or seal from the provider. A qualified timestamp issued in any one member state is recognised as qualified across all 27.
The reason this distinction carries weight sits in Article 41 of eIDAS. A qualified electronic timestamp is presumed accurate as to the moment it records, and the bound data is presumed intact. The law starts from the position that the timestamp is correct, rather than requiring the holder to establish its reliability.
The practical effect is a shift in the burden of proof. Without a qualified timestamp, a creator seeking to prove that a work existed on a particular date carries that burden themselves: server logs, correspondence, metadata and often expert testimony, assembled to persuade a court, at uncertain cost and uncertain outcome. With a qualified timestamp, the position reverses. The party challenging the date must prove it wrong.
The difference shows in how a case unfolds. A claimant relying on ordinary evidence must persuade the court, piece by piece, that their assembled materials collectively point to a date, and every piece can be contested. A claimant holding a qualified timestamp starts instead from a date the law already treats as settled, and waits to see whether the other side can produce anything strong enough to displace that record. For a demo whose entire evidential value rests on when it existed, that reversal is the difference between a claim that can be substantiated and one that rests on assertion.
The strength of this presumption varies by jurisdiction. Within the European Union it applies directly under the Regulation across all member states. In the United Kingdom, the equivalent framework was retained after the country’s departure from the EU, and a qualified timestamp carries strong evidential weight. In the United States there is no equivalent statutory presumption; the admissibility and weight of a timestamp are assessed under the ordinary rules of evidence, where it functions as strong technical proof rather than a presumptive one.
The value of this kind of proof depends entirely on when it is created. A qualified timestamp applied to a demo the week it is written establishes, to a standard a later challenger must work hard to displace, that the work existed in that exact form on that date. The same timestamp cannot be applied retrospectively. There is no way to reach back and prove existence at a date that has already passed. This is the single most important practical point, and the one creators most often miss.
The sequence itself is automated. The work is hashed locally, producing its fingerprint. The fingerprint receives its timestamp under RFC 3161. The record is then anchored to the Bitcoin blockchain via OpenTimestamps, which provides a decentralised confirmation that does not depend on any single provider remaining in business. This is a single automated sequential process — each step depends on the output of the preceding one. Where a stronger evidential position is needed, the timestamp applied within that sequence can be a qualified electronic timestamp under Article 42, which carries the Article 41 presumption.
For a working writer or producer, the practical question is what to capture and when. The answer follows the shape of the disputes themselves. A demo deposited when it is first bounced fixes the version that circulated. A session file deposited at the point an arrangement settles fixes the stage the work had reached. A voice memo of a hook, deposited the day it is sung, fixes the earliest form of the idea most likely to be contested later.
None of this requires the material to leave the studio. Only the fingerprint is submitted, so the recording, the stems and the project file stay entirely under the creator’s control while the date becomes independently verifiable. For a catalogue built over years, the accumulated certificates form a dated chronology of how each work developed, which is the form the evidence needs to take when a claim concerns something written long before anyone expected it to matter.
What the sequence produces is a record with three properties that matter in a dispute. It fixes the content of the work, through the hash. It fixes the time, through the timestamp. And it does both through parties who gain nothing whichever way a dispute goes. That independence is what a creator’s own files, however carefully kept, cannot provide alone.
The limits matter, because overstating them helps no one. A qualified timestamp proves a narrow thing: that one exact file existed, unchanged, at one exact moment. It does not prove authorship. It does not prove originality. It does not prove that the person who applied it created the work, only that they held that file at that moment. And it does not, on its own, establish that a work came first if another party holds an earlier record for related material.
The established alternatives each have real strengths. Formal copyright registration, where available, creates a public record and, in some jurisdictions, unlocks remedies that are otherwise out of reach. Dated correspondence and witness accounts can corroborate a timeline. A distributor’s or platform’s record of who received a file, and when, can speak directly to the access question. None of these is worthless, and a well-prepared creator uses several in combination.
What a qualified timestamp adds is a single, independent, difficult-to-dispute anchor for the one fact everything else has to be built around: that this work, in this form, existed by this date. It does not replace the other evidence. It gives that evidence a firm and independent point of attachment.
A dispute over an unreleased song is really an argument about a date that nobody thought to record. The questions are almost all evidential, and the evidence is only ever as good as what was kept at the time.
Whether you are the writer who says a demo came first, or the one defending a song as your own, the case rests on what you can show about when the work took shape. Nothing can be done now for a date already gone. But every song still to be written is a different matter, and an easy one: the moment to record what exists, and when, is the moment it comes into being.
Related Reading
Regulation (EU) No 910/2014 (eIDAS) — Official Text, EUR-Lex
Sample Clearance Does Not Cover the Part You Wrote Yourself
The eIDAS Qualified Timestamp: What It Is and Why It Matters
James Snell is the founder of Provlyn, a platform providing cryptographic prior proof of IP ownership. provlyn.com