Inside the GPAI Code of Practice and What Hospitality Signed Up For
The voluntary GPAI Code of Practice published earlier this month gives operators the cleanest compliance path under the EU AI Act — and the signatory list reveals exactly where the hospitality AI stack is most exposed.
I read the Code of Practice the way I read a new menu — once for structure, twice for what’s missing. The PDF was open on my laptop at the pass on a Tuesday service, and by the time the first ticket landed I’d circled three things in red: the carve-out for “significant modifications,” the SEND filing route, and the empty space next to two names I expected to see on the signatory list. That last one is the story. The voluntary Code, published earlier in July (I’ll mark this MEDIUM-confidence on the exact day — the document isn’t pinned to a single primary date in the EU’s own communications), is the cleanest compliance path operators have right now. But the names of who signed — and who didn’t — tell you where the AI hospitality stack is most exposed.
The Code, formally summarised on the Commission’s GPAI guidelines page and explained in plain English by artificialintelligenceact.eu, is a voluntary practical tool. It doesn’t replace the binding obligations that kick in for general-purpose AI providers — it complements them. Sign it, follow its three chapters (transparency, copyright, safety-and-security for systemic-risk models), and you get a presumption of conformity. Don’t sign it, and the Commission will assess you against the law itself, which is harder, slower, and more expensive. For the model providers operators depend on — the ones whose APIs sit behind your reservation summariser, your menu translator, your review-response drafter — the calculus is straightforward. Sign.
What the carve-out actually means for an operator
Here’s the line that matters at the pass: the Commission’s pragmatic interpretation says GPAI obligations only attach when there’s a “significant modification” to a model. If your group’s tech team is fine-tuning a frontier model on three years of guest data to power a concierge agent, you may have just become a downstream provider with your own obligations. If you’re using a hosted API with default settings — system prompt, RAG, a few function calls — you almost certainly haven’t. That distinction is the difference between an annual filing burden and none. The EU has set up the SEND platform to handle those filings when they’re required, and the Code lays out what goes in them: model cards, training-data summaries, evaluations, incident reporting commitments.
The forthcoming May piece on the EU AI Act (post 5) walks through the broader timeline — entry into force, the staged application dates, the role of the AI Office. The Code sits inside that frame. What it adds, for hospitality specifically, is a credible answer to the “are we exposed?” question that every operator with an AI vendor in the stack has been asking since the Act passed. The answer, in most cases, is “your vendor is, you’re not — provided you don’t significantly modify.”
The signatory list is the leading indicator
I won’t pretend to have a complete picture of who has signed and who hasn’t — the list was still moving as I wrote this, and any snapshot here will be stale by the time you read it. But the pattern visible in mid-July is the one to watch. The largest US frontier labs are split — some signed, some hedged, some signed only specific chapters. European providers signed broadly. The Chinese labs largely did not. The mid-tier specialist providers — the ones whose models sit inside hospitality-specific tools — are the most interesting bucket: a few signed early, most have not yet committed.
That matters because your AI stack is rarely one model. It’s a frontier model for reasoning, a smaller model for classification, a specialist model for translation or speech-to-text, and an embedding model for retrieval. Each layer has a different provider. Each provider has a different signature status. The upcoming May piece on the Yelp AI stack (post 9) is going to make this concrete with one operator’s actual dependency graph — and you’ll see how quickly the exposure compounds when even one layer is non-signatory.
Mark this as my working interpretation, not legal advice: if I were running procurement at a multi-site group today, I’d ask every AI vendor in the stack for their signature status on the Code, in writing, before the August renewal cycle. Not because non-signatories are non-compliant — they may well be — but because signatories have given you a shortcut through the diligence work, and non-signatories have just made that diligence your problem. The Code is voluntary for them. The consequences of their choice are not voluntary for you.
— Samuel hosts the Service podcast for TableTransfers. Tips: [email protected].
The Voice Agent Maturity Curve
mise
·12 min read
The Four Margins of a Restaurant
mise
·14 min read
The AI Premium in Hospitality M&A: Broker Story or Real Number?
the bottom line
·9 min read
What the DoorDash/SevenRooms Deal Actually Buys
the bottom line
·11 min read