EU AI Content Code: Section 1 providers or Section 2 deployers?

Section 1 of the EU Code is for providers marking AI output; Section 2 is for deployers labelling deepfakes. A team shipping API video starts with its own role.

4 min readSume
All posts

The Code of Practice on transparency of AI-generated content has two sections: Section 1 is for providers (marking and detection of AI-generated content) and Section 2 is for deployers (labelling of deepfakes and certain AI-generated text). A team that calls a generation API and publishes the file usually reads Section 2 for its own use of the output, and checks whether it also acts as a provider before skipping Section 1. This post is a plain reading of public pages, not legal advice.

The split comes from the Commission's Code of Practice page and its signing Q&A, both read 2026-10-01.

What is in each section of the Code?

The Commission page says the Code has 2 sections. Section 1 (Providers) covers rules for marking and detection of AI-generated and manipulated content. Section 2 (Deployers) covers rules for labelling of deepfakes and AI-generated and manipulated text.

The Q&A ties the sections to the AI Act: providers within Article 50(2) are invited to sign Section 1, and deployers within Article 50(4) are invited to sign Section 2. An organisation that is both is invited to sign the whole code. Each section is signed as a whole.

Code sections per the Commission pages, read 2026-10-01
SectionAudienceCovers
Section 1Providers of generative AI systemsMarking and detection of AI-generated and manipulated content
Section 2Deployers of generative AI systemsLabelling of deepfakes and certain AI-generated text
BothAn organisation acting as provider and deployerSign the entire code

Which section does a team calling a video API read first?

Role decides it, not the tool. The Commission FAQ describes a person or company using an AI system under its authority in a professional activity as a deployer, so a studio that publishes generated clips reads Section 2 for what it does with the file.

If you also operate a generative system that other people use, you may be a provider as well, and the Q&A points you to the whole code in that case. Work that out with your own counsel; the pages do not decide it for you.

What do Sume's docs say about your side of the API?

Sume's public API overview lists a catalog route, GET /v1/catalog, to discover capabilities, models, runtime readiness and pricing metadata, so you can see what you are calling. Per Authentication, Sume resolves workspace, owner and API key metadata from the key, so your workspace is the account that requests the files.

The sources cited here do not describe a marking or detection feature in Sume's output. Do not assume one: check the current docs, and plan your own labelling step for the published file.

When does the Code matter in time?

The Commission pages say Article 50(2), (4) and (5) apply from 2 August 2026, and the AI Office encouraged signing until 27 July 2026. Signing later is possible in principle. Those who do not sign must show compliance by other means, which market surveillance authorities assess.

Next step: write down whether you are a deployer, a provider, or both, then read that section of the Code. For a practical creator view see what creators must do under Article 50.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume