EU AI Act GPAI Obligations Kicked In Aug 2. September Is When Hospitality SaaS Realizes.
General-purpose AI obligations under the EU AI Act became applicable August 2. Most hospitality SaaS vendors I've spoken with this week haven't read the text. September quiet is the calm before Q4 enforcement design.
I was reading the Commission’s regulatory framework page at a hotel desk in Lisbon last week when the founder I’d come to interview asked, mid-sentence, whether his AI guest-messaging feature counted as a “general-purpose AI system.” He’d asked his lawyer in July. The lawyer said: come back in September. It is September. The obligations have been live for a month.
This is the pattern I keep finding. The general-purpose AI provisions of the EU AI Act became applicable on August 2, 2025. The Commission’s own enforcement powers don’t switch on until August 2, 2026 — a full year of compliance owed before the regulator can directly sanction. Member States had until August 2, 2025 to designate competent authorities. Most operators I’ve spoken with this week think the quiet means it isn’t real yet. The quiet is what it looks like when a Q4 enforcement framework is being drafted in conference rooms you aren’t in.
The thing nobody at hospitality SaaS has actually read
Here is the contrarian read I’m willing to defend: every hospitality vendor running an LLM-powered feature in the EU — concierge chatbots, voice booking agents, dynamic menu copy, AI-drafted review responses, smart upsell prompts — is touching obligations under Chapter V whether they built the model or not. Most are downstream deployers of GPAI systems supplied by OpenAI, Anthropic, Google, Mistral. That status carries documentation duties, transparency obligations, and — if the system is repurposed in a high-risk way, which “automated decisions affecting consumers” can be — escalating responsibilities. The Chapter V enforcement note from artificialintelligenceact.eu is the clearest plain-English version I’ve found, and I keep sending it to founders who tell me their lawyer hasn’t gotten back.
The numbers in the Act are not symbolic. Up to €35M or 7% of global turnover for prohibited practices. Up to €15M or 3% for high-risk breaches. For a Series B booking-platform vendor doing €40M ARR across the EU, 3% is a quarter of a year’s gross margin. For the GPAI providers themselves the calculus is different but the downstream effect is identical: their terms will harden, their indemnities will narrow, and the contract you signed in 2024 will be renegotiated by April.
Mark the interpretation: I don’t think September is quiet because the law is toothless. I think it’s quiet because nobody — vendors, operators, Member-State authorities — has yet had to make a public example of anyone. The first enforcement design choices are being made right now, in private, by the national competent authorities each Member State was supposed to designate by August 2. When those designations surface in October and November, the shape of Q4 becomes legible. That’s when the SaaS calls will start.
Italy is about to layer criminal penalties on top
The piece nobody outside Italian legal circles is tracking: Italian Law 132/2025, the national AI implementation statute, is set to take effect October 10. It layers national criminal penalties on top of the EU framework — including a specific deepfake offense — and it will apply to any hospitality tech operating in Italy regardless of where the vendor is headquartered. If your AI-generated marketing imagery features a synthesised host, a synthesised chef, or a stylised “guest review” video, you will want a lawyer who has read 132/2025 before October.
A vendor I spoke with on Tuesday — an Irish-incorporated booking widget used by perhaps 1,800 Italian restaurants — told me they had been planning to “look at the EU AI Act in Q1 2026.” Their feature set includes an AI-generated response template for negative reviews and an AI photo-enhancement tool for menu items. Both touch transparency obligations. Neither has a model card, a deployer-side risk assessment, or a Member-State-authority point of contact. Their lawyer is, again, getting back to them.
For operators reading this, the practical move in September is small and unglamorous: identify which of your stack vendors run LLMs in the EU, ask them for their GPAI-deployer documentation, and put the answer (or the silence) in writing. A forthcoming May piece on how the EU AI Act applies to restaurants directly digs into the operator-side obligations in more detail — but the September task is supplier mapping. Q4 is when the questions stop being abstract.
The quiet ends sometime between the first national competent authority publishing its enforcement priorities and the first GPAI provider quietly amending its EU customer terms. My bet is October. I’ll be wrong by weeks, not quarters.
— Hana edits the newsroom for TableTransfers. Tips: [email protected].
The Voice Agent Maturity Curve
mise
·12 min read
The Four Margins of a Restaurant
mise
·14 min read
The AI Premium in Hospitality M&A: Broker Story or Real Number?
the bottom line
·9 min read
What the DoorDash/SevenRooms Deal Actually Buys
the bottom line
·11 min read