Most hotel GMs I speak to say the same thing: "We're not really using AI yet."
Then I ask three questions: Do you use a revenue management system? Do you have automated guest communication or a chatbot? Does your team use tools like ChatGPT — even informally?
In almost every case, at least one answer is yes. And that means the EU AI Act applies.
What the EU AI Act actually says about hotels
The EU AI Act (Regulation 2024/1689) entered into force in August 2024. From 2 August 2026, the Article 50 transparency obligations — covering guest-facing AI such as chatbots and automated guest communication — become enforceable.
Limited-risk systems don't mean low-importance. They include any AI system that interacts with guests (chatbots, virtual assistants), generates or personalises content, or makes recommendations that influence guest-facing decisions.
Higher-risk categories — such as systems that make consequential decisions about individuals — carry stricter requirements. Some hotels are closer to this territory than they realise, particularly with AI-driven credit risk assessment for corporate accounts or AI-assisted hiring tools.
The 3-question test
If you answer yes to any of these, the EU AI Act applies to your property:
- → Does your hotel use a revenue management system that sets or recommends prices automatically?
- → Do you have a chatbot, automated messaging, or AI-driven review response system?
- → Does your team use AI tools informally — even without official approval?
The problem most hotels don't see: Shadow AI
Shadow AI refers to AI tools that employees use without official approval or management awareness. In every hotel I've worked with, it exists — usually to a greater extent than management expects.
A reservations manager using ChatGPT to draft guest communications. A front desk team member using an AI translation tool found online. A revenue analyst feeding occupancy data into a free AI pricing tool.
Each of these creates a compliance exposure — not primarily because they're AI, but because they're undocumented, unmanaged, and invisible to the business. The EU AI Act requires that you know what AI systems you're running. Shadow AI, by definition, means you don't.
The 5 steps that matter now
I want to be direct about something: for most independent and boutique hotels, the path to EU AI Act compliance is not complicated. It requires discipline and documentation, not a six-figure consulting engagement.
Build an AI inventory
List every AI-powered system your hotel runs — officially and informally. Include the vendor, what it does, what data it processes, and what decisions it influences or automates. A structured spreadsheet is sufficient for this step.
Classify by risk level
The EU AI Act uses four risk tiers: unacceptable (banned), high, limited, and minimal. Most hotel applications fall into limited or minimal risk. This classification determines your documentation obligations — higher risk means more detailed requirements.
Document what each system does
For each AI system: what is the intended purpose? What data does it use as input? What does it output? What human decisions does it replace or support? This doesn't need to be a legal document — it needs to be accurate and retrievable.
Assign internal responsibility
The Act requires that someone within the organisation is responsible for AI governance. In a small hotel, this is typically the GM or Operations Manager. It doesn't need a dedicated role — it needs a named person and a process for regular review.
Set a review schedule
AI systems change. New tools get added. Staff find new workarounds. A quarterly review of your AI inventory — to add new tools, update documentation, and confirm responsibilities — keeps you compliant on an ongoing basis rather than only at a single point in time.
What happens if nothing is done
High-risk obligations do not apply here. Following the Digital Omnibus, standalone Annex III high-risk duties start on 2 December 2027 — and hotel operations are not listed in Annex III at all. What does apply from 2 August 2026 is transparency: guests must be able to tell when they are interacting with AI.
For most hotels, the more immediate risk is not a fine but the audit exposure. A formal inquiry triggered by a guest complaint, a competitor report, or a sector-wide enforcement action would require you to produce documentation that, if it doesn't exist, creates significant legal and reputational risk.
The argument I make consistently: the cost of documentation done proactively — in time and money — is a fraction of the cost of documentation done reactively under regulatory pressure.
A note on timing
The deadline is 2 August 2026. For hotels that haven't started, that is enough time — but only if the process begins now.
In my experience, the AI inventory (Step 1) takes 2–4 hours for a well-organised property. Classification and initial documentation (Steps 2–3) can typically be completed in a single working day. Assigning responsibility and setting up a review schedule (Steps 4–5) is a one-hour management conversation.
The total time investment for a compliant baseline is 1–2 working days. The cost of not having that baseline is open-ended.
Frequently asked questions
Does this apply to small or independent hotels?
Yes. The EU AI Act applies to any organisation operating in the EU that uses AI systems, regardless of size. Independent hotels are often less prepared than chains — and face the same obligations.
What if our revenue management system is provided by a vendor?
The Act covers both AI developers (the vendor) and deployers (you, the hotel). As the deployer, you have obligations around transparency and documentation even if you didn't build the system.
Is ChatGPT covered by the EU AI Act?
General-purpose AI models like ChatGPT fall under a separate framework within the Act. However, the way your staff uses them — particularly with guest data or operational data — may create additional obligations under GDPR and related regulations.
Do we need a lawyer for this?
For the initial compliance baseline, typically no. The documentation steps outlined above can be completed by hotel management. Legal review becomes important if your property uses high-risk AI applications or if you receive a regulatory inquiry.
Andreas Donner
Founder, peakcareai.com · 25+ years in luxury hotel project development and construction worldwide.