Skip to content

Insights

The fallacy of compliance rates

When a vendor quotes a perfect compliance rate, you have not learned about your protection. You have learned how they count.

Randy labs · 24 August 2026 · 6 min read

Two numbers that cannot both be innocent

Claims of perfect or near-perfect compliance circulate freely in the anti-piracy industry. Meanwhile, the only independent audit of the notice-and-takedown system at scale, published by Grant Thornton with the Live Content Coalition in September 2025, examined 26.2 million takedown notices sent by ten major rights holders between January 2024 and June 2025 and found that 11 percent resulted in the unauthorised stream being suspended. The trend is worsening: 19 percent in late 2024, 5 percent in the first half of 2025. For 57 percent of infringements there was no observable action at all.

A vendor reporting one hundred percent and an audit reporting eleven cannot be describing the same activity with the same words. Both numbers can be technically true at once, and that is precisely the problem: a compliance rate is not one metric. It is the output of four choices, and each of them can be made in a way that manufactures perfection.

The whistle trick: measuring after the clock stops

A pirated live stream is self-extinguishing. It exists to carry an event, and when the event ends, the retransmission ends with it. That gives live content a property no other enforcement domain has: wait long enough, and every stream is down, whether anyone acted or not.

The audited data shows how much room that leaves. Only 8 percent of infringements were taken down during the event. Only 6 percent were acted on within 30 minutes, and 21 percent took more than two hours, which is longer than most matches last. A compliance check run after the final whistle will find the overwhelming majority of streams gone and can book every one of them as a success. The number is not false. It is measuring entropy and calling it enforcement.

The denominator trick: choosing who counts

A rate is a fraction, and the denominator is a decision. In the audited period, 22 percent of intermediaries ignored every notice sent to them. A vendor that reports compliance only across intermediaries that respond, or only across notices deemed valid by the receiving side, has quietly removed the hardest part of the problem from the maths. You cannot fail against infrastructure you never counted.

The question is never what the rate is. The question is what population it was computed over, and who decided.

The definition trick: what counts as complied

The audit is explicit that notices recorded as not suspended include notices the intermediary acknowledged and then did not act on. Acknowledgement is not suspension. And suspension is not protection: the intermediaries with the best compliance rate in the entire dataset, online platforms suspending roughly 97 percent of noticed content, show a 90 percent reoccurrence rate within the same day. The URL went down. The operation did not. The box was ticked either way.

The contrast is instructive. Infrastructure-level providers in the same dataset act on far fewer notices during live events, but when they do act, reoccurrence is 2 percent. Speed and permanence are different achievements, and a single compliance figure hides which one, if either, you are buying.

The disposable-layer trick: counting what was built to vanish

Every trick above still assumes the rate is measured against something that matters. The deepest problem is that it usually is not. Everything a compliance rate counts, the stream URL, this hour’s address, this week’s hostname, is the disposable edge of a pirate operation: the layer designed to be lost, priced in as a running cost, replaced in minutes. The 90 percent same-day reoccurrence is that layer doing exactly what it was built to do.

Behind it sits the durable core: the systems and the commercial network the operation actually runs on, persisting from match to match and season to season. No notice is filed against a business, so the durable layer never appears in any compliance statistic. A vendor can post a perfect per-stream compliance rate every week of the season while the operation finishes it without losing a single asset it cares about.

A 100 percent compliance rate against assets designed to be disposable is a 0 percent impact on the assets designed to last.

Four questions that make a rate mean something

None of this means compliance tracking is useless. Tracked per intermediary, verified independently, it is how you build the record that supports escalation against the ones that ignore the process. The fallacy is the aggregate rate presented as proof of protection. When a vendor quotes one, four questions expose what it is made of:

  • When was it measured? During the event, or after the stream had already died on its own?
  • Who was counted? Every intermediary carrying the infringement, or only the ones that answer?
  • What counted as complied? Verified down, or acknowledged, and did it stay down past the same day?
  • And what happened to the infrastructure that does not vanish? If the answer only ever mentions streams, the operation is intact.

Randy labs builds Digital Rights Enforcement, an AI anti-piracy platform for live sport and premium content. See how the platform works or request a demo.

Infinite innovation,
limitless possibilities.

Content protection, compliance, and intelligence.

Address

Ideia Atlântico
Braga, Portugal

Co-financed by

Randy labs research and development is co-financed by the European Union through Portugal 2030 and the Recovery and Resilience Plan.

Lisboa 2030, COMPETE 2030, Portugal 2030 and Co-financed by the European UnionPRR Plano de Recuperacao e Resiliencia, Republica Portuguesa, and Financed by the European Union NextGenerationEU

© 2026 Randy labs. All rights reserved.

TermsPrivacy