Lead Hospitality

Legal Obligations for AI in Hotels

THE IDEA

AI deployment in hotels is already subject to European and Spanish requirements on transparency, data protection, employment, consumer protection and human oversight. I propose an internal deployment licence to review every use case before it is procured, connected to operations or allowed to affect guests and employees.

Some time ago, I took part in reviewing a tool that promised to automate part of guest service. The demonstration had convinced the sales team, the provider assured us that the solution complied with European regulations, and the projected return was attractive. Everything seemed ready to move forward until we asked a question far less eye-catching than those included in the presentation: what data would the system actually receive, what would it use it for, and who would be accountable if its recommendation harmed a guest? The meeting changed tone. We discovered that we had talked a great deal about functionality and very little about legality.

This scenario is repeated in different forms across Hospitality. One application analyses CVs, another drafts responses to reviews, a chatbot speaks with prospective guests, an engine recommends prices, a camera recognises faces, and a platform scores employee performance. Each solution arrives with a specific promise, but its legal implications rarely remain within the department that procures it. A decision initiated in Marketing may affect data protection; a productivity improvement in HR may become an employment issue; an automation in Front Office may ultimately alter the guest experience in hotels and liability towards consumers.

I have learned to distrust one particularly common phrase: “The provider already takes care of compliance.” The provider may supply documentation, contractual assurances and technical expertise, but the hotel decides what it uses the tool for, what information it feeds into it, who is exposed to its outputs and what authority it grants the system. In most cases, the property or hotel company will act as the deployer. That position does not disappear because the software is paid for through a monthly subscription or because the infrastructure is hosted thousands of kilometres away.

As of 20 September 2026, this issue no longer belongs in the realm of future recommendations. The European Artificial Intelligence Regulation has been generally applicable since 2 August 2026; prohibited practices and the AI literacy obligation had already applied since 2 February 2025, and transparency obligations began to apply on 2 August 2026. Part of the specific regime for high-risk systems has later deadlines, but waiting until the latest possible date would be poor hotel strategy, as well as a rather expensive way to learn the law.

My position is not to slow innovation or turn every initiative into an endless case file. AI can improve productivity, personalisation, hotel revenue management, hotel marketing and decision quality. Precisely because of that potential, it should be implemented methodically. A prepared hotel does not ask only whether a solution works. It also asks whether it can use it, under what conditions, with what limits, what documentation it must retain and how it can stop it if results deviate from expectations.

Equipo hotelero revisando las implicaciones legales antes de implementar una solución de inteligencia artificial

Legality is determined by use, not by the product label

The first mistake is to speak of “AI” as though all its applications carried the same risk. An assistant that summarises internal documents, a system that selects candidates and a facial-recognition solution may use related technologies, but they occupy very different legal positions. The European Regulation adopts a risk-based approach and requires an assessment of the intended purpose, the people affected, the system’s autonomy and the consequences of its outputs.

For a hotel, this means that classification should not be based on the tool’s brand name. It must be carried out for each use case. The same platform could be used to write a room description, recommend whom to hire or assess which employee deserves a promotion. The product is the same; the legal exposure changes completely. It may also change if the hotel substantially modifies the system, changes its purpose or markets it under its own brand. In certain circumstances, someone who believed they were merely a user may assume obligations of a provider.

HotelGEX
Guest Companion

Not another chatbot. An intelligence that stays with the guest.

From the first booking intent to the next stay, Guest Companion uses context to understand when to help, what may be relevant and when the best action is simply to stay silent.

Guest Companion
Example journey
01
Discover Understand what kind of stay the guest is looking for.
02
Book Connect intent with the Booking Engine and real options.
Prepare Arrival, preferences, relevant experiences and services.
04
Stay Useful help at the right moment — without unnecessary noise.
05
Return The next stay does not have to start from zero.
Understand · Anticipate · Recommend · Act · Stay silent — depending on context and timing.
Intelligence throughout the journey

The dates should be set out precisely. General transparency obligations and supervisory powers have been active since 2 August 2026. The specific regime applicable to high-risk systems listed in Annex III, which includes certain employment-related uses, is scheduled to apply from 2 December 2027. High-risk systems embedded in regulated products have a period extending until 2 August 2028. These deferrals do not suspend the GDPR, employment law, consumer rules, anti-discrimination legislation or image rights, all of which may already limit a project today.

In Spain, there is another important clarification. The Draft Organic Law on the proper use and governance of artificial intelligence was introduced on 28 May 2026 and, as of the date of this article, remains under parliamentary consideration. It should therefore not be cited as though it were already enacted law. Its text outlines national governance, the central role of the Spanish Agency for the Supervision of Artificial Intelligence and the sanctions regime, but its content may still change. The European Regulation, by contrast, is directly applicable and coexists with the powers of the Spanish Data Protection Agency, the Labour Inspectorate and other sectoral authorities.

The sanction figures demonstrate the seriousness of the framework, although they should not be the only reason for compliance. Breaches of certain prohibited practices may reach €35 million or 7% of worldwide annual turnover, while other infringements may reach €15 million or 3%. The GDPR, meanwhile, maintains maximum fines of €20 million or 4%. Proportionality criteria apply to smaller businesses, but an independent hotel SME is not outside the scope of regulation simply because it is small. Proportionate penalties do not amount to an exemption from obligations.

In hotel operations, several areas deserve particularly careful review:

  • Chatbots and assistants that interact with guests. Since 2 August 2026, systems intended to interact directly with people must be designed so that they know they are dealing with AI, unless this is obvious from the context. The hotel must ensure that the notice appears at the right time, clearly and in the relevant languages. Hiding it at the end of a privacy policy does not serve the same purpose as informing guests before the conversation begins. It is also necessary to define when a guest may request human assistance, which matters the bot should not resolve and what happens to stored conversations.
  • Employee recruitment, assessment and management. Systems used to filter applications, make decisions on recruitment, promotion or termination, assign tasks based on personal characteristics or monitor performance may be considered high risk. In addition, in Spain, employees’ legal representatives are entitled to receive information on the parameters, rules and instructions of algorithms that influence access to employment, continued employment or working conditions. This obligation already exists and does not wait until 2027. Turning a KPI into an algorithmic score does not eliminate the problems of poorly designed management by objectives; it can only make them faster and less visible.
  • Emotion recognition in the workplace. Inferring whether someone is tired, angry, disengaged or stressed from their face, voice or gestures may appear attractive for assessing service and wellbeing. However, the use of emotion-recognition systems in the workplace is prohibited, except for exceptions linked to medical or safety reasons. A hotel should not procure such a solution in the belief that replacing the word “emotion” with “engagement” changes its nature. Fortunately, legislators usually read beyond the sales brochure.
  • Biometrics for clocking in, access or guest identification. Fingerprints and facial recognition involve particularly sensitive processing where they enable the unique identification of an individual. The question is not only whether the technology is accurate, but whether there is an adequate legal basis, whether it is necessary, whether it passes a proportionality assessment and whether less intrusive alternatives exist. Consent may be insufficient if the employee or guest has no genuine equivalent alternative. A slightly faster entry process does not, by itself, justify building a database of biometric templates.
  • Commercial personalisation and pricing. Dynamic pricing, which changes according to demand, inventory or booking lead time, is not automatically personalised pricing. The situation is different when the price offered to an individual is adapted through an automated decision based on their profile, behaviour or estimated ability to pay. In distance contracts, there is an obligation to clearly inform customers when a price has been personalised in that way. Revenue and Marketing must distinguish between segmenting demand and individually pricing a person based on signals they may never have expected to be used to charge them.
  • AI-generated or AI-altered marketing. Not every AI-assisted text requires a visible label. Specific obligations concerning deepfakes, synthetic content, images of people, imitated voices and communications that may mislead do need to be reviewed. Using the image of a supposed guest who never existed may be lawful in certain contexts and misleading in others, especially if it is presented as a genuine testimonial. Editorial oversight must verify authenticity, usage rights, accuracy and consistency with the experience the hotel can deliver.
  • Generative AI used by teams. Copying a guest’s passport, a complaint containing identifying information, a performance assessment or a confidential contract into a public tool is not an innocent way to save time. Before allowing these uses, the provider’s role, processing purposes, prompt retention, subsequent training, international transfers, subprocessors and deletion options must be reviewed. AI literacy largely consists of knowing what information should not be entered.
  • Automated decisions with significant effects. The GDPR recognises the right not to be subject to certain decisions based solely on automated processing when they produce legal effects or similarly significantly affect individuals. This may be relevant in recruitment, fraud-related blocks, service cancellations, customer classification or the automatic denial of certain terms. Adding a person at the end of the process does not constitute human oversight if that person simply accepts the result without understanding it or having the authority to change it.

One of the most frequent misunderstandings I encounter is the belief that complying with the AI Regulation means complying with all legislation. It does not. A system may be limited risk under the European Regulation and, at the same time, breach the GDPR by using data without a legal basis. It may comply with data protection requirements and create employment discrimination. It may work correctly and still constitute a misleading commercial practice. It may produce technically original content and infringe image rights, confidentiality or intellectual property rights.

It is also useful to distinguish between two assessments that are often confused. A data protection impact assessment may be mandatory where processing presents a high risk to rights and freedoms, particularly in cases of extensive profiling, biometrics, systematic monitoring or significant automated decisions. The fundamental-rights impact assessment provided for under the AI Regulation has its own scope and does not automatically apply to every private hotel using a high-risk system. Even where it is not mandatory in every case, conducting a structured rights analysis may be a prudent decision when the use affects employees, candidates or vulnerable groups.

The essential point is that buying compliance is not the same as demonstrating compliance. A generic provider certificate may demonstrate certain product features, but it does not validate the specific way in which the hotel configures, feeds and uses it. If a tool was designed to support decisions and the hotel allows it to decide without review, the deviation belongs to the hotel. If the provider prohibits the entry of special categories of data and the team enters them, the contract will not make that practice lawful.

The internal deployment licence turns compliance into a hotel decision

To prevent legal review from arriving after the contract has already been signed, I propose introducing an Internal AI Deployment Licence. I am not referring to a public authorisation or another decorative document. It is an internal decision gateway that must be cleared before any system accesses real data, influences an individual or connects with hotel operations. Its purpose is to bring together, in one file, the answers that are usually scattered across Procurement, IT, HR, Marketing, Operations and Legal.

This licence should belong to the use case, not the provider. If a platform is used for three purposes, it requires three analyses, because the data, people affected, risk and oversight may vary. Likewise, a licence approved for summarising anonymous comments does not automatically authorise use of the tool to score employees or decide guest compensation.

In my experience, the licence is useful when it requires answers, at a minimum, to the following areas:

  • Defined operational purpose. The hotel must describe the problem it wishes to solve, the decision it will improve and the uses expressly excluded. “Optimising the experience” is not a sufficiently precise purpose. “Classifying incoming requests by language and department to reduce assignment time” does allow the assessment of necessity, data and risk. The more ambiguous the purpose, the easier it is for the tool to end up being used for something no one reviewed.
  • Affected individuals and potential consequences. It is necessary to identify whether the system affects guests, candidates, employees, suppliers, minors, people with disabilities or other groups. The worst reasonably foreseeable outcome should also be described. A poor translation may cause inconvenience; an incorrect accessibility classification may put someone at risk; a biased employment filter may systematically exclude certain candidates. Not all errors deserve the same tolerance.
  • Complete data map. A record must be kept of what data enters the system, where it comes from, what inferences the system generates, where it is hosted, how long it is retained, who has access and whether it will be used for training. It is important to include derived data. Sometimes the hotel does not provide sensitive information directly, but the tool infers it from behaviour, voice, spending or history. An inference about a person remains relevant information even if it did not appear on the original form.
  • Legal basis and transparency. The file must explain why each processing activity may be carried out and what information people will receive. Consent, contractual performance, legal obligation and legitimate interest are not interchangeable terms. Transparency should not be limited to a corporate policy either. It is necessary to decide what notice will appear in the chatbot, job application, employee portal, booking flow or identification process.
  • Classification under the AI Regulation. The hotel must document whether it is dealing with a prohibited practice, a high-risk system, a use subject to specific transparency requirements or a lower-risk application. Where there is reasonable doubt, the classification should be reviewed with specialist advice. It is also advisable to record the hotel’s role as deployer, importer, distributor or potential provider, especially where it relabels, integrates or modifies the solution.
  • Required impact assessments. The licence must determine whether a data protection impact assessment, prior consultation with the authority, a fundamental-rights assessment or another employment, safety or consumer analysis is required. The review must begin before the pilot uses real data. Assessing after implementation is like checking the brakes at the bottom of the hill.
  • Human oversight with real authority. The documentation must state who reviews the outputs, what training they have, how much time they have and which decisions they can override. It is also necessary to define the situations in which the system may not act. A chatbot should not improvise compensation, interpret medical conditions or guarantee services without confirmed availability. An employment algorithm should not turn a score into an automatic sanction.
  • Reversibility test. Before connecting the system, I would require proof that the hotel can stop it, restore the manual process, correct data, reconstruct a decision and handle a challenge. If no one knows how to disconnect the automation without bringing operations to a halt, the project is not ready yet. Reversibility protects rights, continuity and hotel profitability.
  • Provider evidence. It is not enough to ask whether the provider complies with the Regulation. The hotel must request the intended purpose, instructions for use, limitations, security documentation, data location, subprocessors, training policy, accuracy levels, change log, incident management and support for rights requests. For high-risk systems, conformity, applicable marking and required technical documentation will be especially relevant.
  • Contractual exit conditions. The contract must allocate responsibilities, establish notification deadlines, permit reasonable audits and govern the return or deletion of data. It should also provide for what happens if the underlying model changes, a new subprocessor appears, quality declines or an authority challenges the lawfulness of the use. Automatic renewal should not also renew a risk that no one has reviewed again.
  • Operational legality indicators. In addition to measuring savings, conversion or speed, it is advisable to record relevant errors, complaints, human interventions, reversed decisions, affected groups, transparency failures and uses outside the approved purpose. The absence of sanctions does not prove that the system is functioning correctly. It may simply mean that the problem has not yet been detected.
  • Authorisation expiry date. The licence must be reviewed when regulations, the provider, the model, the data, the purpose or the degree of autonomy changes. Even without visible changes, a regular review should be established. AI is not a machine that is installed and remains identical for ten years; sometimes it changes in an overnight update while the contract still describes the previous version.

The inventory is the starting point. Many hotels do not know all the AI applications they already use because some are integrated into the PMS, CRM, booking engine, reputation platform, HR software or productivity tool. Others appear through individual accounts opened by employees. Before designing a policy, it is advisable to identify which systems exist, who procured them, what data they receive and which decisions they support. What is not inventoried can hardly be governed.

That inventory should include free tools and features that the provider activates by default. I have seen organisations review a corporate project with great solemnity while dozens of people copied internal documents into public assistants through their browsers. The most serious exposure does not always come from the highest-value contract. Sometimes it enters the hotel through a free extension that someone installed to answer emails more quickly.

The next decision is to assign a hotel owner for the use case. IT may control integrations and security, but it should not decide on its own what employment data is relevant. Legal may interpret obligations, but it needs to understand the operation. HR knows the recruitment process, although it may not be able to assess the technical model. Approval must be cross-functional, while day-to-day accountability needs a specific name rather than an abstract committee.

I also consider it necessary to separate three permissions that are often confused. The first allows the solution to be tested with fictional or anonymised data. The second authorises a limited pilot with real data, enhanced controls and a small group. The third permits operational deployment. A satisfactory demonstration does not automatically grant the other two permissions. Commercial enthusiasm often travels faster than governance, especially when the free trial expires on Friday.

During the pilot, I would apply a shadow-operation period. The system generates recommendations, but these do not reach the guest directly or determine employment decisions. The team compares its outputs with human decisions and analyses false positives, differences across languages, errors by segment and situations the model does not understand. This phase makes it possible to measure not only average accuracy but also the distribution of errors. A 95% accuracy rate may be unacceptable if the remaining 5% is concentrated among people with disabilities, foreign candidates or sensitive complaints.

Human oversight deserves a particularly honest review. In many projects, it appears in the procedure because it sounds reassuring, but disappears when workload is calculated. If one person must review five hundred recommendations a day, the organisation will eventually accept them as routine. Oversight exists only when the reviewer understands the output, has sufficient information, has time, can disagree without penalty and has the authority to stop the process.

AI literacy, required since February 2025, should not be addressed through a generic one-hour course either. Training must be adapted to the role. Front Office needs to know when to escalate a conversation and what data not to enter. Marketing must distinguish between assisted content, synthetic imagery and fictitious testimonials. HR needs to understand bias, automated decisions and representation rights. Revenue needs to identify the difference between dynamic pricing and personalised pricing. Those who approve contracts must know what documentation to request, and those who oversee a tool must understand its limitations.

At the same time, the hotel needs a channel for reporting incidents and unforeseen uses without turning every mistake into a witch hunt. If an employee discovers that a tool reveals confidential information, discriminates, invents terms or retains data it should have deleted, they must know whom to notify and how to suspend it. A culture that punishes the messenger ends up protecting the algorithm. Leadership in Hospitality is demonstrated here through the ability to hear an uncomfortable warning before it turns into a complaint.

Governance must extend to marketing and the commercial promise. I would not allow AI personalisation, biometric security or intelligent service to be advertised without verifying what those claims actually mean. A technological claim can also become an obligation towards the consumer. If we promise immediate and accurate responses, secure identification or personalised recommendations, we must be able to demonstrate those attributes and explain their limitations.

From an economic perspective, this discipline is not a cost separate from the business. A legally unviable tool may require replacement, data migration, complaint handling, professional advice, crisis communications and manual reconstruction of the process. Its total cost includes the possibility of having to stop using it after systems have been integrated, teams trained and procedures modified. The hotel profitability of AI should be calculated after compliance, oversight, remediation and exit are included, not before.

That is why I recommend including a specific governance line in every business case. It should cover legal review, impact assessment, security, training, contractual adaptation, oversight, auditing and contingency. If the project ceases to be profitable once these costs are added, perhaps it was never profitable. It was simply shifting part of its bill into the future.

I am not arguing that every AI-assisted email should go through a committee or that the hotel should write one hundred pages to automate a minor task. Control must be proportionate. A simple matrix can combine impact on people, data sensitivity, autonomy, reversibility and scale. Low-impact uses may be approved through general rules; those with greater exposure require a full licence. Good hotel management avoids both improvisation and bureaucracy that no one can sustain.

My initial advice is simple: before looking for new tools, take an inventory of those already in operation. Ask each department what it uses, for what purpose, under which account and what information it enters. Do not begin by sanctioning informal uses, because that will only conceal them. Begin by understanding them, withdrawing those that are clearly unacceptable and offering secure alternatives that enable people to work better.

Then establish a rule that is difficult to misinterpret: no AI may access real data, communicate autonomously with guests or influence decisions about people without an owner, an approved purpose, legal review and a disconnection mechanism. That rule protects the guest and the employee, but it also protects the professional who needs to know the limits of their authority.

Hospitality has always depended on combining human judgement, reliable processes and the ability to adapt. AI can strengthen those three capabilities or weaken them if we implement it in haste. I would not ask only how much work a tool can take on. I would ask what responsibility we are willing to retain, because technology may execute a decision, but the hotel will still have to explain it.

KEEP EXPLORING

This article ends here. The archive does not.

Lead Hospitality brings together 1200 English articles published since 2018: years of experiences, decisions and lessons you can keep exploring.

CONTINUE FROM HERE

What would you like to explore next?

Choose a direction and keep reading around what you want to solve, learn or challenge.

Discover something interesting ↓Surprise me ↗
01MAKE MOREProfitability, revenue and decisions that reach the bottom line. 02LEAD BETTERTeams, culture, talent and the conversations that matter. 03SELL BETTERPositioning, marketing, distribution and customers. 04CREATE EXPERIENCESService, loyalty and details guests remember. 05UNDERSTAND WHAT'S NEXTInnovation, AI and new ways of thinking about Hospitality. SURPRISE MEShow me something worth five minutes of my time.
✦ LEAD AI · KEEP THINKING

Take this analysis one step further