AI Act deployer for an agency: the legal person, not each hand
Per the Commission FAQ, a company stays the deployer when contractors or freelancers operate the AI system for it. How that maps to one Sume workspace key.

When an agency makes AI video, the FAQ says the legal person remains the deployer, even if contractors or freelancers operate the system on its behalf and under its responsibility and control. Employees acting under its instructions are not separate deployers. This summarises the Commission text and is not legal advice.
Quotes and criteria are from the Commission's Article 50 FAQ, read 2026-10-01. Sume facts are from Authentication and the public API overview.
Who is a deployer when several people touch the work?
The FAQ names examples: for an advertising company, "digital animators, web designers, content creators, journalists" acting under the instructions and control of the company are not separate deployers.
| Who operates the system | Deployer per the FAQ |
|---|---|
| Employees under the company's instructions and control | The company; employees are not separate deployers |
| Contractors or freelancers acting on its behalf and under its responsibility and control | The company remains the deployer |
| A natural person using it professionally for themselves | That person |
How does one Sume workspace key fit that structure?
Sume resolves workspace, owner and API key metadata from the key; request bodies never carry workspace_id or user_id. If the agency issues keys per project, every job a contractor submits is attributable to that workspace, which matches the FAQ idea that the company is the party using the system under its authority.
GET /v1/catalog lists capabilities, models, runtime readiness and pricing metadata, so everyone on a team can check what a workspace can run before they submit.
What should the agency write down for contractors?
Because responsibility stays with the company, put the disclosure rule in the brief: whether a clip needs a visible label, who approves it, and where it is burned in. Standalone captions burn text onto an existing public video URL, which is one way to add that text. For what to record per job, see the evidence log post.
Does an avatar video change who the deployer is?
No. The docs describe avatar video as turning a ready avatar into a script-driven talking video; it is a tool the company uses. Whether the output needs a label is a separate deepfake question, covered in what creators must do.
Sources
Related posts
More in Use cases
- AI Act closed-loop film previs: where preview ends, output begins
The EU FAQ puts closed-loop film production outside marking scope unless the output is final. Avatar preview stills are never captioned; the final MP4 can be.
- AI background music for a video: Lyria 3.5 plus Timeline soundtrack
Google lists background music as a Lyria 3.5 template. Generate a bed with Sume's Music Router, then lay it under narration with Timeline soundtrack ducking.
- AI birthday song generator by API: Lyria 3.5 on Sume
Google lists custom birthday tracks as a Lyria 3.5 template. Here is how to generate a birthday song with the Sume Music Router and what it costs.
- AI brand jingle generator by API with Lyria 3.5 on Sume
Google lists brand jingles as a Lyria 3.5 template. How to brief a short jingle with the Sume Music Router, keep it instrumental or sung, and cost it.
Written by Sume