Home/Vendor Selection · Hotels
Hotel Operator's Checklist

Questions to ask any AI vendor
before signing

The demo looked good. The sales rep answered everything smoothly. Here are 15 questions to ask before you sign — covering data, EU compliance, accountability, real costs, and what happens when you want to leave.

By Andreas Donner·May 2026·12 min read
15 questions across 5 categories. For each question: why it matters and what answer to accept.

The vendor pitch is designed to close deals, not surface problems

Hotel AI vendors invest considerably in their sales process. The demo environment works perfectly. References are pre-selected. Pricing is quoted without integrations, training, or support tiers. Implementation timelines are optimistic. EU AI Act compliance is described as "in progress."

None of this is unique to hotel tech. It is how software sales works. The questions below are not accusatory — they are the ones that require real answers before a contract makes sense. A vendor that cannot answer them has not done the work. A vendor that answers them clearly has.

The list is organised by category. Work through each section before your next vendor meeting.

Data & Privacy

"Where exactly is our guest data stored — and in which country?"

Why it matters: EU data protection law (GDPR) requires that personal data transferred outside the EU is covered by appropriate safeguards. If the vendor stores data in the US, India, or "the cloud" without specifying a region, you have an open compliance issue before you have even turned on the product.

What to accept

A precise answer: country, data centre provider, and EU standard contractual clauses if outside EEA. Vague answers like "secure cloud infrastructure" are not answers.

"Is a Data Processing Agreement (DPA) included in the contract — or do we have to request one?"

Why it matters: Under GDPR, any vendor that processes personal data on your behalf must sign a DPA. It is not optional. Vendors who do not have one ready, or who describe it as a premium add-on, have not taken GDPR seriously.

What to accept

A standard DPA ready to sign. The vendor should send it to you, not the other way around.

"Can we delete guest data on request — and in what timeframe?"

Why it matters: Guests have the right to request deletion of their data. If the vendor cannot delete individual records within a defined period (typically 30 days), you inherit the compliance exposure.

What to accept

A specific timeframe and a confirmed process. "We handle deletion requests" is not sufficient without a defined procedure.

EU AI Act

"What risk category does your system fall under according to the EU AI Act?"

Why it matters: The EU AI Act requires that AI systems are classified — prohibited, high-risk, limited-risk, or minimal-risk. Vendors operating in the EU should know the answer for their own product. If they do not, they either have not done the analysis or do not believe the regulation applies to them.

What to accept

A clear category with a brief rationale. If the vendor says "we're still assessing," note the date and follow up. If they say "the EU AI Act doesn't apply to us," ask them to explain why in writing.

"Do you provide EU AI Act documentation for your system — technical specifications, conformity assessment, or a system card?"

Why it matters: The EU AI Act requires documentation for limited-risk and high-risk systems — from vendors, not just from hotel operators. Vendors deploying chatbots, automated communication tools, or recommendation systems in EU hotels should be able to produce this.

What to accept

An actual document or a clear timeline for when it will be available. "We're working on it" is less reassuring with the 2 August 2026 deadline in place.

"Does your system require a transparency disclosure to guests — and does your product support implementing one?"

Why it matters: The EU AI Act requires guests to be informed when interacting with AI systems, particularly chatbots and virtual assistants. If the vendor's product does not support adding a disclosure notice, you cannot meet this requirement without custom development.

What to accept

Confirmation that guest-facing AI interactions include a disclosure, and a description of where and how it appears. Ideally: a screenshot.

Performance & Accountability

"What happens when the system produces a wrong answer or makes a bad recommendation — who is responsible?"

Why it matters: AI systems make errors. Revenue management tools occasionally produce unrealistic pricing. Chatbots occasionally give guests incorrect information. The question is not whether this will happen, but who owns the outcome when it does, and what the resolution process looks like.

What to accept

A clear accountability statement: what the vendor will do, in what timeframe, and whether there is contractual liability for harm caused by system errors. "We are not responsible for outputs" buried in a terms of service is a meaningful risk.

"What is your SLA for system availability — and what happens if you miss it?"

Why it matters: A guest-facing chatbot that goes down during peak check-in creates an operational problem that falls on your team. If the SLA does not include meaningful financial remedies for downtime, the vendor has no incentive to prioritise availability.

What to accept

A specific percentage (99.5%+), a measurement window, and a concrete remedy — typically service credits. Check whether scheduled maintenance is excluded from the SLA calculation.

"Can we turn the system off — completely and immediately — if needed?"

Why it matters: Human oversight is a requirement under the EU AI Act for AI systems. In practice, it means someone at your property must be able to disable the tool quickly if it behaves unexpectedly. Some SaaS tools make this harder than it sounds — the off-switch may require vendor involvement or carry contractual penalties.

What to accept

Confirmation that you can disable the system via your admin panel without contacting the vendor. Note any contractual provisions that penalise pausing or stopping the service.

Pricing & Exit

"What is the total cost of ownership — including implementation, integrations, training, and ongoing support?"

Why it matters: The advertised price is rarely the total cost. PMS integrations often carry one-time fees. Staff training is rarely included. Custom configuration for your property structure may be billed separately. Ongoing support beyond basic ticket handling may require a premium tier.

What to accept

An itemised breakdown of all costs in year one and year two. Ask specifically: integration fees, training, onboarding, support tier, and whether pricing changes at renewal.

"What does the exit process look like — how do we get our data out, and are there penalties for leaving?"

Why it matters: Switching costs are how many SaaS vendors retain customers after quality declines. If your guest data is in a proprietary format, if exports are expensive, or if the contract includes significant early termination fees, you are less free than the initial contract implies.

What to accept

A data export format (ideally standard: CSV, JSON), an export process that does not require vendor assistance, and early termination costs stated in writing — not in a future "order form."

"What happens to pricing and service levels if your company is acquired?"

Why it matters: The hotel technology sector consolidates regularly. A vendor acquired by a larger platform may change pricing, discontinue products, or modify service terms on short notice. Your contract should address what happens to your agreement in this scenario.

What to accept

Contract language that gives you the right to exit without penalty if the vendor is acquired and materially changes terms. Absent this, you are betting on the acquirer's goodwill.

Implementation Reality

"What is the actual implementation timeline for a property like ours — from contract to live?"

Why it matters: Demo timelines are rarely implementation timelines. PMS integration alone can take four to six weeks if the vendor's engineering queue is backed up. Staff training adds time. If you are approaching a high season or a regulatory deadline, the gap between "we can go live in two weeks" and "we went live in eight weeks" is operationally significant.

What to accept

A specific timeline based on your PMS, your property size, and the vendor's current queue. Ask: "What are the most common causes of delay with implementations like ours?"

"What does my team need to do to make this work — and what ongoing management does it require?"

Why it matters: AI tools are not passive. Revenue management tools require regular calibration. Chatbots require content updates when policies change. Automated messaging tools require someone to monitor escalations. If no one at your property has the time or context to manage the tool, it will underperform — and the vendor will attribute this to user error.

What to accept

A specific description of what the vendor expects from your team: time per week, which role, and what ongoing tasks. If the answer is "nothing, it's fully automated," probe further.

"Can I speak to a general manager at a comparable property who went live in the last 12 months?"

Why it matters: References given by vendors are curated. Asking for a reference from a property similar to yours — by size, market, and PMS — and requiring it to be recent (last 12 months) filters out legacy success stories that may not reflect the current product.

What to accept

A specific reference, not a general testimonial. A vendor unwilling to provide a reference call from a recent customer at a comparable property should be asked why directly.

How to use the answers

After a vendor meeting, score each of the five categories: Green (clear, written answers), Yellow (incomplete or deferred answers), Red (no answer or evasion). A vendor with two or more Red categories in Data, Compliance, or Exit is not ready for a responsible deployment at your property — regardless of how good the demo looked.

Green: Clear, written answer — acceptable to proceed

Yellow: Incomplete or deferred — request written confirmation before signing

Red: No answer, evasion, or "we're working on it" — risk flag, investigate further

The EU AI Act question is a proxy for overall readiness

In practice, vendors who can answer the EU AI Act questions clearly — risk category, documentation available, transparency disclosure implemented — tend to also have cleaner answers on data, accountability, and exit. The EU AI Act requires that vendors document exactly what their system does, how it processes data, and what safeguards exist. Vendors who have done this work have, by necessity, thought carefully about their product.

Vendors who cannot answer the EU AI Act questions by mid-2026 are unlikely to be ready by August. That is itself useful information before your next contract renewal.

The checklist above is designed to surface this quickly, without requiring legal support or deep technical knowledge. The answers — or the absence of answers — tell you what you need to know.

Frequently asked questions

What are the most important questions to ask an AI vendor as a hotel operator?

Start with data storage (country, DPA) and EU AI Act risk classification — these two areas reveal the most about how seriously a vendor takes compliance. Then ask about accountability for errors, total cost of ownership, and the exit process. Finish with a reference call request.

What EU AI Act compliance documentation should a hotel AI vendor provide?

At minimum: the risk classification of their system with a rationale, a technical description of how the system works, evidence that guest transparency disclosures are implemented (for limited-risk tools), and a DPA for data processing. Vendors who cannot provide these by 2 August 2026 are not compliant.

What are common hidden costs when buying AI tools for hotels?

PMS integration fees (often one-time), staff training not included in base price, custom configuration billed separately, premium support tiers, and price increases at renewal. Request a full year-one and year-two breakdown itemised by category.

How do I evaluate an AI vendor's implementation claims?

Ask for actual timelines at comparable properties in the last 12 months. Ask what the most common causes of delay are. Ask what your team needs to do during implementation. Then ask for a reference call with a GM at a property of similar size and PMS who went live recently.

What contract protections should a hotel request for AI software?

Data export in standard format (CSV, JSON) without vendor assistance. Deletion on request within 30 days. Exit rights without penalty if the vendor is acquired and changes terms materially. SLA remedies (service credits) for missed availability targets. These are standard in well-drafted SaaS contracts.

Should I use the same questions for all hotel AI vendors?

Yes — consistency is the point. The questions let you compare vendor responses directly. A vendor who answers all 15 clearly is demonstrably more prepared than one who deflects on data, compliance, and exit. The scoring framework (Green/Yellow/Red by category) makes that comparison concrete.

AI Readiness Check

Evaluating an AI vendor — or already committed to one?

A structured 30-minute conversation to review your current or planned AI tools — what questions remain open, what compliance gaps need to be closed before 2 August 2026, and what your team needs to manage this without external support.