The global music industry’s campaign against digital copyright infringement has taken a sharp turn toward open-source software development. In a formal policy submission to the European Commission, the International Federation of the Phonographic Industry (IFPI) has officially flagged yt-dlp—the heavily relied-upon open-source media downloading utility—as a "major problem" for the recorded music sector.
The prominent music industry group is pushing for yt-dlp to be explicitly added to the upcoming 2027 EU Counterfeit and Piracy Watch List. If adopted by European regulators, the inclusion would place the widely used developer project alongside traditional stream-ripping domains and commercial download portals that rightsholders have spent years trying to suppress.
The move marks a significant escalation in the ongoing tension between copyright enforcement bodies and open-source software communities. While the recording industry has frequently targeted commercial stream-ripping websites and dedicated desktop applications, training its sights directly on an active open-source project and singling out individual developers represents a notable shift in strategy.
The Current Status and Long History of YouTube Downloading Tools

The friction between media giants and download utilities is far from new. In October 2020, the Recording Industry Association of America (RIAA) deployed a Digital Millennium Copyright Act (DMCA) takedown notice to purge the original youtube-dl repository from GitHub. At the time, the RIAA argued that the software circumvented YouTube’s rolling cipher technology, making it an unauthorized tool designed to bypass technical protection measures.
That aggressive legal maneuver sparked an immediate backlash from developers, privacy advocates, and open-source software enthusiasts. Just weeks after the takedown, GitHub reversed its decision, reinstated the original repository, and established a $1 million developer defense fund specifically designed to assist software creators facing similar copyright-related legal challenges.
Despite that reprieve, the music industry found more fertile legal ground in Europe. In Germany, major record labels initiated a high-profile legal battle against Uberspace, the hosting provider responsible for powering the official website of youtube-dl. The litigation culminated in November 2024 when the Hamburg Court of Appeal formally rejected an appeal from the hosting provider, cementing a major victory for the rightsholders and establishing legal liability precedent for infrastructure providers servicing download tools.
Although youtube-dl was never formally shut down by court order, its active development pipeline was largely absorbed by yt-dlp, an open-source fork that emerged in 2021. Today, anyone attempting to visit the original youtube-dl.org domain is automatically redirected to the yt-dlp project page. The successor project has achieved massive popularity within the global developer community, accumulating more than 16,000 forks and over 190,000 stars on GitHub, which ranks it among the site’s most popular repositories.
IFPI Flags yt-dlp as a "Major Problem"

The music business has monitored the explosive growth of yt-dlp closely. In its recent consultation submission for the 2027 EU Counterfeit and Piracy Watch List, the IFPI explicitly categorized the software as a severe threat, grouping it alongside commercial stream-ripping services such as Savefrom.net and two prominent Y2mate domains.
According to the industry submission, yt-dlp poses a fundamental challenge because it provides freely available, open-source software that enables everyday users to download and permanently store music and audiovisual material from licensed streaming platforms, including YouTube, without proper authorization or compensation.
The IFPI submission outlines the history of the utility, highlights its advanced stream-ripping capabilities, and draws attention to the permissive Unlicense under which the software is distributed. Furthermore, the submission addresses the inherent difficulties regulators face when attempting to restrict such technology.
The open-source nature of the project, combined with an extensive global community of contributors and decentralized distribution networks, makes the tool exceptionally difficult to contain or remove, the music group noted. Consequently, the industry argues that the software continues to facilitate large-scale stream-ripping, depriving rights holders, independent artists, and licensed streaming services of legitimate revenue streams.
Four GitHub Handles Named in the Filing

In an unusual move for public policy filings of this nature, the IFPI submission specifically identifies four individual developers by their public GitHub user handles. The documentation names the project’s original founder as user pukkandan, noting that he served as the lead maintainer from 2021 through 2024. Additionally, the filing lists three current core maintainers: coletdjnz, bashonly, and Grub4K.
All four handles are publicly visible on the platform’s repository pages, but their inclusion in a formal anti-piracy submission to European regulators marks the first time that developers associated with youtube-dl or yt-dlp have been explicitly named in a Notorious Markets or Watch List filing.
Despite naming the developers and calling out the project, the submission does not formally request immediate punitive legal actions, formal takedowns, or specific ISP blocking measures against the maintainers themselves. Moreover, the filing makes no mention of the various lawful, non-infringing purposes for which open-source media downloading utilities are frequently employed by archivists, educators, journalists, and researchers.
Technical Arguments Surrounding Circumvention and Hosting
The legal debate surrounding tools like yt-dlp often hinges on the technical definition of copyright circumvention. While the overarching section on stream-ripping in the IFPI filing explicitly uses the word "circumvention," the specific entry for yt-dlp avoids the term. Instead, the music group argues more broadly that commercial and unauthorized streaming platforms utilize technical protection measures to control access and prevent downloads, protections that enjoy robust legal backing under international treaties and European Union law.

The IFPI cites the German court ruling against Uberspace to reinforce its position that infrastructure providers can be held liable for aiding and abetting the circumvention of these security frameworks. However, the submission’s own technical description characterizes the tool simply as a program that parses webpage and player data while interacting directly with platform-specific playback endpoints, leaving the precise legal mechanism of circumvention open to interpretation.
When examining the geographical infrastructure of the project, the European Commission’s Watch List primarily targets marketplaces and services operating outside the EU that facilitate infringement. While the physical or residential locations of the individual developers are not detailed in the filing, GitHub is explicitly identified as the primary distribution hub.
GitHub serves as the official source for accessing the script’s latest updates, source code repositories, pre-compiled binaries, and installation documentation, though alternative forks and mirrors exist across the wider web. Because GitHub is owned by Microsoft and headquartered in the United States, the primary repository remains hosted under US jurisdiction.
Expanding Threats to Include AI Music Generation
The IFPI’s comprehensive policy submission extends beyond traditional stream-ripping utilities, also addressing emerging technological threats posed by generative artificial intelligence applications. The music group specifically flagged two consumer-facing mobile apps, Rythmix and MusiQ AI, which allow users to input a YouTube link and automatically transform the underlying recording into an AI-generated cover song featuring cloned artist voices.

Both applications have maintained a presence in mainstream digital storefronts, with Rythmix available on Apple’s App Store and Google Play, where it has reportedly surpassed five million downloads.
Over the coming months, the European Commission will thoroughly review all policy submissions submitted during the consultation period to determine which platforms, services, and software projects will ultimately be included in the final 2027 edition of the EU Counterfeit and Piracy Watch List. Whether regulators will decide to incorporate open-source development tools like yt-dlp or target AI voice-cloning applications remains to be seen.
Representatives for the yt-dlp project maintainers and GitHub were reached for comment regarding the IFPI submission, but neither party responded prior to publication.
Leave a Reply