The EU AI Act – the EU’s regulation on artificial intelligence – applies in full from 2 August 2026. For hotels, the core obligation is simple: any hotel that uses a chatbot, a digital concierge or another AI-powered communication tool must clearly tell guests they are talking to an AI. For many hotels, this affects day-to-day operations more than they realise.
A global study by h2c from October 2025 shows how hotels are handling AI: 78% of hotel chains use AI in their operations, but only 7% have a documented strategy. That documented approach is what makes the difference – it shows guests, employees and partners that AI is used deliberately and in line with the rules. The EU AI Act now sets the standard for how AI is used, and hotels that put the right rules in place position themselves as professional, future-ready operators.
Key takeaways:
The EU AI Act does not take effect all at once, but in stages.
With the EU legislative package “Digital Omnibus on AI” adopted in June 2026, the application deadlines for high-risk AI systems (e.g. in medicine or human resources) were postponed. In practice, however, this usually changes nothing for the hotel industry: The transparency obligations under Article 50 of the AI Act generally continue to apply from 2 August 2026.
Anyone who ignores the requirements risks far more than a simple warning. The text of the regulation provides for severe fines for disregarding the transparency and deployer obligations, which can quickly reach the millions or be calculated as a percentage of global annual turnover – whichever is higher. Similar consequences are also possible if misleading information is provided to the authorities. These requirements are monitored and enforced at national level by the market surveillance authorities and Europe-wide by the newly created European AI Office.
The EU AI Act follows a risk-based approach. Every AI application falls into one of four categories:
| Risk class | Meaning | Examples in hotel operations |
|---|---|---|
| Unacceptable risk | Prohibited | Social scoring, emotion recognition in the workplace, manipulative AI |
| High risk | Strict requirements & certification (risk management, human oversight, registration) | CV screening in staff recruitment, biometric identification systems |
| Limited/low risk | Transparency obligation only: users must know that they are dealing with AI | Hotel chatbot, virtual concierge, AI-generated marketing content |
| Minimal risk | No specific requirements | Spam filters, simple internal tools |
A standard hotel chatbot falls into the “limited risk” category. It would only be considered high-risk if it were used for one of the purposes listed in Annex III – for example, if a chatbot conducts initial job interviews in recruiting. A special case is automated price adjustment (dynamic pricing): although it is not classified as high-risk AI, it should still be reviewed regularly. This prevents the algorithm from developing unfair biases and thereby treating guests unequally or unfairly.
If the system learns, for example, to automatically show guests from certain countries or using certain devices higher prices than others, that would be unequal and unfair treatment. Hotels should therefore check the software regularly.
Since February 2025, the AI literacy obligation (Article 4) also applies. For hotels, this means: anyone who uses or procures AI must be trained to do so. The requirements include:
The EU AI Act does not prescribe a fixed format – but documented proof, for example through training certificates, is required. How teams can generally be won over to working with AI tools is described in our guide to introducing AI in hotel teams.
Yes. Article 50 of the EU AI Act requires providers (HiJiffy) and deployers (hotels) of AI systems to be transparent towards natural persons – guests must be able to recognise that they are talking to an AI. What this means in concrete terms for hotel operations:
The labelling requirement is straightforward. Guests must be informed clearly and understandably, at the latest at the time of the first interaction, that they are talking to an AI – unless this is already obvious from the context. There are no strict design requirements: a short notice at the start of the conversation, such as “Hello! I am the hotel’s digital assistant. As an AI, I can help you around the clock with…”, is sufficient. The notice does not need to remain visible throughout the entire conversation.
The obligation goes beyond the chat. It also applies to voice AI such as telephone assistants, as well as AI-generated or AI-altered image and video content in marketing. Such content must be recognisably labelled as artificially created, for example with a note such as “AI-generated”.
Hotels are usually deployers, not providers. If a hotel uses ready-made software like HiJiffy, it almost always counts as a deployer and not a provider. It only needs to focus on three things: transparency towards the guest, documented AI literacy of employees, and an up-to-date AI inventory with an internal usage policy.
The obligation applies regardless of the size of the business. There are support measures for start-ups and SMEs, such as guidelines and regulatory sandboxes. The transparency obligation towards guests applies regardless of the size of the business.
The impact extends beyond the EU. Just as with the GDPR, the EU AI Act applies extraterritorially: as soon as an AI system is used on the EU market or its outputs are used in the EU, the rules apply – including for hotels outside the EU that serve European guests.
The GDPR remains relevant too. As soon as a chatbot processes personal guest data, this must be done in a GDPR-compliant way. If guest data such as first and last names, allergy information or religious preferences are carelessly entered into public AI tools, an additional data protection risk arises, independently of the EU AI Act.
The figures from the h2c study from October 2025 show that this topic receives too little attention in many businesses: 78% of hotel chains use AI, but only 7% with a documented strategy.
The real risk rarely lies in the officially introduced system. It arises where there is no clear rule and employees improvise – with public AI tools for translating enquiries, drafting replies, checking grammar, often with guest data in the prompt. It is precisely this lack of clarity about which AI tools are permitted and which are not that leads in practice to the greatest data protection and compliance risks.
A central, officially adopted platform closes that gap: it gives staff one simple, data-protection-compliant way to communicate with guests.
HiJiffy is not just a chatbot solution, but a guest communication platform for hotel groups: from a central Console it reliably handles 90% of guest communication across web chat, WhatsApp, Instagram, Facebook Messenger, email, voice, OTA messages and other channels automatically and in line with brand guidelines, and connects them with a Booking Assistant and Digital Concierge. This is relevant for EU AI Act compliance because it creates exactly the structure that is often missing: a clear, official route, visible to all employees, for AI-powered guest communication – instead of individual, uncoordinated tools.
What this means in practice:
Important for setting expectations: this does not replace the hotel’s own responsibility. Even with HiJiffy, the hotel remains a deployer within the meaning of the EU AI Act and must maintain the transparency notices, the AI literacy of employees and the internal AI inventory itself.
Responsibility for this should not lie with the IT department alone. It makes sense to appoint a designated, responsible person at C-level – General Manager or COO – who has the mandate to enforce AI policies across all departments, from HR to Revenue Management.
From August 2026, one thing above all counts for hotels: guests must be able to recognise when they are talking to an AI. In addition, the AI literacy of employees must be demonstrable. Those who use a solution like HiJiffy carry, as a deployer, a considerably smaller share of the obligations than the software provider itself. The biggest source of error remains not the official chatbot, but unauthorised AI tools in employees’ everyday work. Hotels should therefore establish internal AI governance early on.
A clear, documented stance on where and how AI is used in guest contact is more than a box-ticking exercise. It takes no technical heroics, just one central, transparent platform instead of a scatter of uncoordinated tools. Hotels that put this structure in place now stay in control of how AI is used across their operation.
Want to see how a central Guest Communication Platform gets your hotel ready for 2 August 2026?
Yes. Under Article 50 of the EU AI Act, guests must be informed when they interact with an AI system – this must be clearly evident at the latest at the time of the first interaction.
Anyone who ignores the transparency obligations of the EU AI Act risks severe fines. Depending on the breach, these can amount to several million euros or a percentage of global annual turnover. Compliance is monitored by the national market surveillance authorities. Details on the penalties can be found on the official website of the AI Regulation or the European Commission.
No. A regular chatbot for guest service falls into the “limited risk” category and is only subject to the transparency obligation.
Yes. The regulation has extraterritorial effect, similar to the GDPR. As soon as an AI system is used on the EU market or its outputs are used in the EU, the rules apply.
Under the AI Regulation, a one-time, clear notice is sufficient, at the latest at the time of the first interaction. Continuous visibility throughout the entire conversation is not required.
Usually not. As the deployer, the hotel is responsible for transparency towards guests and the AI literacy of employees.
Yes, on both counts. HiJiffy automatically adds a fixed, non-editable AI disclosure across every chatbot channel – this fulfils the disclosure obligation under Article 50(1) of the EU AI Act without you having to configure anything yourself and your own greeting message stays untouched. HiJiffy supports you in meeting the AI literacy obligation under Article 4 with a structured onboarding tailored specifically to hotels. In addition, our Customer Success Team is available to you for personal support and regular quarterly Q&A sessions, along with a Help Centre with clear explanations of the AI technologies in use.
Sign up for our monthly newsletter to receive free resources and updates on impactful AI applications in hospitality.