EU AI Content Code: Section 1 providers or Section 2 deployers?
Section 1 of the EU Code is for providers marking AI output; Section 2 is for deployers labelling deepfakes. A team shipping API video starts with its own role.

The Code of Practice on transparency of AI-generated content has two sections: Section 1 is for providers (marking and detection of AI-generated content) and Section 2 is for deployers (labelling of deepfakes and certain AI-generated text). A team that calls a generation API and publishes the file usually reads Section 2 for its own use of the output, and checks whether it also acts as a provider before skipping Section 1. This post is a plain reading of public pages, not legal advice.
The split comes from the Commission's Code of Practice page and its signing Q&A, both read 2026-10-01.
What is in each section of the Code?
The Commission page says the Code has 2 sections. Section 1 (Providers) covers rules for marking and detection of AI-generated and manipulated content. Section 2 (Deployers) covers rules for labelling of deepfakes and AI-generated and manipulated text.
The Q&A ties the sections to the AI Act: providers within Article 50(2) are invited to sign Section 1, and deployers within Article 50(4) are invited to sign Section 2. An organisation that is both is invited to sign the whole code. Each section is signed as a whole.
| Section | Audience | Covers |
|---|---|---|
| Section 1 | Providers of generative AI systems | Marking and detection of AI-generated and manipulated content |
| Section 2 | Deployers of generative AI systems | Labelling of deepfakes and certain AI-generated text |
| Both | An organisation acting as provider and deployer | Sign the entire code |
Which section does a team calling a video API read first?
Role decides it, not the tool. The Commission FAQ describes a person or company using an AI system under its authority in a professional activity as a deployer, so a studio that publishes generated clips reads Section 2 for what it does with the file.
If you also operate a generative system that other people use, you may be a provider as well, and the Q&A points you to the whole code in that case. Work that out with your own counsel; the pages do not decide it for you.
What do Sume's docs say about your side of the API?
Sume's public API overview lists a catalog route, GET /v1/catalog, to discover capabilities, models, runtime readiness and pricing metadata, so you can see what you are calling. Per Authentication, Sume resolves workspace, owner and API key metadata from the key, so your workspace is the account that requests the files.
The sources cited here do not describe a marking or detection feature in Sume's output. Do not assume one: check the current docs, and plan your own labelling step for the published file.
When does the Code matter in time?
The Commission pages say Article 50(2), (4) and (5) apply from 2 August 2026, and the AI Office encouraged signing until 27 July 2026. Signing later is possible in principle. Those who do not sign must show compliance by other means, which market surveillance authorities assess.
Next step: write down whether you are a deployer, a provider, or both, then read that section of the Code. For a practical creator view see what creators must do under Article 50.
Sources
Related posts
More in Developers
- AI music exactly 30 seconds: no duration field, use Timeline
Music Router rejects duration and duration_seconds. Ask for the length in the prompt, then fix the exact output length with Timeline 1.0 audio.duration_seconds.
- Akool talking photo links expire in 7 days: what to archive
Akool says talking photo image, video and voice resources are valid for 7 days, so save them early. Sume media URLs do not expire; archive by need.
- Alibaba's Sora 2, Veo 3.1, Kling 3.0 migration table vs Sume ids
Alibaba Model Studio maps Sora 2, Veo 3.1 and Kling 3.0 to happyhorse-1.1 models. Which of its targets are Sume catalog ids, and how model: sume/auto fits in.
- Nova Reel start_async_invoke S3 output vs a Sume result URL
Nova Reel's start_async_invoke writes output.mp4 to your S3 bucket and needs IAM. A Sume job returns a result_url and durable media.sume.com links.
Written by Sume