Provider or Deployer? Where a Creator Actually Sits in the Transparency Code
The EU's Code of Practice on AI transparency covers two very different groups under one document. Knowing which one you are decides what you can skip.
Open the European Commission's Code of Practice on Transparency of AI-Generated Content and the first thing you have to decide, before any obligation applies to you at all, is which half of it is even talking to you. The Code is written for two populations at once — providers and deployers — and it reads, on a skim, like it's mostly aimed at the companies that build the models. For most creators, brands and agencies publishing AI-made content, that skim is wrong in a way that costs you nothing to fix and something to get backwards.
One code, two very different signatory sections
The Code splits cleanly along the same line Article 50 of the EU AI Act already draws: it's open to providers and deployers subject to Article 50(2) and/or 50(4), and each half signs onto a different section with different commitments. Section 1 is for providers — the obligation to mark generative AI outputs in a machine-readable way, so the content is technically detectable as AI-made after the fact. Section 2 is for deployers — the obligation to disclose and label deepfakes and certain AI-generated public-interest text to the actual human audience looking at it.
Those are not two flavors of the same task. One is an engineering commitment about embedding detectable markers inside a model's output. The other is a publishing commitment about what a viewer sees before they watch. A single document covering both, under one name, is exactly the setup that makes a reader assume it's one obligation instead of two aimed at two different jobs.
The test that actually resolves it
Skip the legal language and ask one plain question: did you build the generative AI system, or did you use someone else's to make and publish something?
If you trained or operate the underlying model — you're a foundation model company, or you run a generation service on your own infrastructure — you're the provider, and Section 1's marking obligations are the ones with your name on them. If you're a creator, a brand, an agency or a marketing team using a tool like Versely, an image model, a video model or a voice clone built by someone else, to make content you then publish to an audience — you're the deployer, and Section 2 is the section actually written for you. For the overwhelming majority of people reading a post like this one, that second description is the accurate one, and it's worth saying plainly: the marking-and-detection engineering work is not something you need to build, budget for, or lose sleep over. It's the job of the company whose model you're calling.
What you can actually stop worrying about
This is the part the classification buys you directly. Section 1's commitments — embedding provenance metadata, building detection tools, maintaining machine-readable marking across every export — sit on the providers who signed it: the foundation model companies and the platforms operating generative systems at the infrastructure level. If you're a deployer, none of that engineering is yours to build. You don't need a watermarking pipeline. You don't need a detection API. That work, to the extent it needs doing at all, is being done upstream of you, by the company whose model produced the pixels.
What's actually yours
Section 2 is shorter to describe and harder to skip: disclose and label deepfakes and certain AI-generated public-interest text to the people looking at it. In practice, this is the visible, on-screen or audible label — not a metadata tag nobody sees — attached to realistic synthetic content before it reaches a viewer, exactly the same obligation Article 50(4) already places on deployers directly regardless of whether the Code is signed at all. The Code doesn't invent this duty; it gives you a documented, Commission-recognized way to operationalize and demonstrate you're meeting it.
The signatory list as a sanity check
If the provider-deployer split still feels abstract, the roster of who actually signed each section confirms it's a real, working distinction rather than a legal nicety. The Commission's own count puts Section 1 at 82 signatories — Anthropic, Google, Meta, Microsoft, OpenAI and Synthesia among them, the companies actually building the generative systems in question. Section 2 draws a larger and structurally different list: 152 signatories, including Getty Images, Lenovo, Lufthansa and Bulgari — a media licensor, a hardware manufacturer, an airline and a luxury brand, none of which build foundation models, all of which publish content that might include AI-generated material to a real audience. That's the deployer population in miniature: not AI companies, but ordinary businesses that use AI-made content and have to tell people when they have.
If your organization looks more like Lufthansa's role in that list than Anthropic's, you now know which section actually describes your obligations.
A Versely walkthrough: adding the disclosure a deployer actually owes
Since the deployer-side commitment is a visible, human-perceivable label rather than embedded metadata, the practical version of compliance is a text element on the content itself, not a settings toggle:
- Identify which asset needs it — a realistic AI avatar, a voice clone, or any generated footage that could pass as an ordinary recording of a real person, place or event, headed for an audience that includes EU viewers.
- Add a visible disclosure directly onto the video: a prompt like "Add the text 'Contains AI-generated content' as a small overlay in the bottom corner of this video for the full clip" calls the fixed-text-overlay tool with your exact wording and a position, burning a perceivable label onto the file itself rather than relying on a platform metadata field a viewer would never open.
- Size and time it to actually be noticed — a flash-frame disclosure at the very end satisfies nothing the Code or Article 50 is asking for; the label needs to be readable in real time, not technically present.
- Keep this step independent of whatever the model provider's export does or doesn't embed. Their Section 1 marking, once it exists, is a separate, upstream layer — your Section 2 disclosure is the one a human viewer actually needs to see, and it doesn't wait on theirs.
Where this sits next to the law itself
The Code is voluntary infrastructure for demonstrating compliance with an obligation that exists independently of it — synthetic media disclosure is the underlying legal requirement, and the platform-level AI content label toggle most creators already use is a separate, additional layer on top of both. None of the three substitutes for the others; they stack. For the mechanics of what counts as a regulated deepfake and when the underlying legal deadline actually bites, that's a deeper explainer than a classification post needs to re-run — the point here is narrower and, for most readers, more immediately useful: know which signatory column has your name in it before you spend a minute worrying about obligations that were never yours.
The takeaway
A document that talks about "providers and deployers" in the same breath reads like it's addressed to someone else's compliance team. For almost every creator, brand and agency publishing AI-made content, it's addressed to you specifically — just to the deployer half of it. Section 1's marking engineering belongs upstream, to the companies whose models you call. Section 2's visible disclosure belongs to whoever hits publish — which, if you're building content across Versely's audience-specific guides for agencies, brands and creator teams, is almost certainly the section with your name already on it.