AI Act deployer for an agency: the legal person, not each hand

Per the Commission FAQ, a company stays the deployer when contractors or freelancers operate the AI system for it. How that maps to one Sume workspace key.

4 min readSume
All posts

When an agency makes AI video, the FAQ says the legal person remains the deployer, even if contractors or freelancers operate the system on its behalf and under its responsibility and control. Employees acting under its instructions are not separate deployers. This summarises the Commission text and is not legal advice.

Quotes and criteria are from the Commission's Article 50 FAQ, read 2026-10-01. Sume facts are from Authentication and the public API overview.

Who is a deployer when several people touch the work?

The FAQ names examples: for an advertising company, "digital animators, web designers, content creators, journalists" acting under the instructions and control of the company are not separate deployers.

Who is the deployer, per the Commission FAQ, read 2026-10-01: https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
Who operates the systemDeployer per the FAQ
Employees under the company's instructions and controlThe company; employees are not separate deployers
Contractors or freelancers acting on its behalf and under its responsibility and controlThe company remains the deployer
A natural person using it professionally for themselvesThat person

How does one Sume workspace key fit that structure?

Sume resolves workspace, owner and API key metadata from the key; request bodies never carry workspace_id or user_id. If the agency issues keys per project, every job a contractor submits is attributable to that workspace, which matches the FAQ idea that the company is the party using the system under its authority.

GET /v1/catalog lists capabilities, models, runtime readiness and pricing metadata, so everyone on a team can check what a workspace can run before they submit.

What should the agency write down for contractors?

Because responsibility stays with the company, put the disclosure rule in the brief: whether a clip needs a visible label, who approves it, and where it is burned in. Standalone captions burn text onto an existing public video URL, which is one way to add that text. For what to record per job, see the evidence log post.

Does an avatar video change who the deployer is?

No. The docs describe avatar video as turning a ready avatar into a script-driven talking video; it is a tool the company uses. Whether the output needs a label is a separate deepfake question, covered in what creators must do.

Sources

Related posts

More in Use cases

All Use cases posts

Written by Sume