The Compliance Bill Comes Due: Pricing the EU AI Act for Hospitality Investors

A spreadsheet of hospitality-tech compliance costs against a backdrop of the EU flag and a restaurant POS terminal.

The Commission's GPAI guidelines drop today, Aug 2 obligations are two weeks out, and the hospitality-tech models still pretend AI Act compliance is a rounding error. It isn't. Here's the math.

I spent Thursday evening on a call with a buy-side analyst who has been long Toast since the IPO recovery. He wanted to talk same-store payment volumes and the Marketman cross-sell. I wanted to talk about the document the European Commission was about to publish at midnight Brussels time. He humoured me for about four minutes and then said, “Oliver, you sound like the guys who told me to worry about GDPR in 2017.” I told him GDPR cost the S&P Europe 350 roughly €9 billion in the first eighteen months and that he should keep humouring me. He hung up.

The contrarian thesis of this column has been consistent for a quarter: investors must now price AI Act compliance overhead into hospitality-tech models, and the sell side is not doing it. As of this morning, with the Commission’s Guidelines for providers of general-purpose AI models live and the August 2 effective date sixteen days away, the discount is no longer theoretical. It is a working capital line. Toast, Lightspeed, and SiteMinder — three of the most-discussed compounders in the hospitality stack — face the steepest exposure because their deployment surface in the EU has expanded faster than their compliance functions.

This piece is going to be heavy on math, lighter on rhetoric. If you want the rhetorical version, my colleagues have it covered in a forthcoming May piece that walks the political economy. Here, we are doing the spreadsheet.

What actually shipped today, and what ships on August 2

The distinction matters because the market keeps conflating the two. The implementation timeline is staggered by design. February 2, 2025 brought the prohibited-practice bans and the AI literacy obligation — a low-cost line item, mostly training and posters. August 2, 2025 is the harder edge: governance bodies must be operational at the member-state level, the GPAI obligations under Chapter V become enforceable, and penalties under Article 101 become collectible. August 2, 2026 brings the bulk of high-risk-system obligations. August 2, 2027 finishes the job.

The guidelines published today are not new law. They are the Commission’s interpretive framework — what counts as a GPAI model, when fine-tuning crosses the threshold to becoming a new provider, how the systemic-risk tier (10^25 FLOPs of training compute) gets measured. The GPAI guidelines overview from the AI Act tracker summarises the four key clarifications: training-compute threshold methodology, downstream-modifier rules, exemption scope for open-weight models, and the Code of Practice’s evidentiary weight. None of these are surprises. All of them are now load-bearing for any vendor whose product description includes the word “AI.”

For hospitality, the relevant cohort is narrow but expensive. Toast ships its Sous Chef suite into Ireland and a growing UK estate that still inherits much of the AI Act’s extraterritorial reach via the GPAI provisions. Lightspeed’s X-Series has an embedded recommendations engine across France, the Netherlands, and Belgium. SiteMinder, headquartered in Sydney but with deep European deployment, just rolled its Channels Plus AI rate-recommendation layer across more than 11,000 EU properties. None of these vendors are GPAI providers in the strict sense — they are downstream deployers — but Article 25 of the Act says that fine-tuning a foundation model in a way that “substantially modifies” it can flip the deployer into the provider tier. Today’s guidelines defined “substantially” more tightly than the industry hoped.

The Article 101 fine structure, and why analysts keep mis-modelling it

Most coverage I have read this week cites the GDPR comparison: 4% of global turnover, sounds scary, never actually levied at the cap. That is the wrong reference class. Article 101 of the AI Act introduces a three-tier penalty schedule. The headline number for GPAI obligations is up to €15 million or 3% of worldwide annual turnover, whichever is higher. For prohibited practices it climbs to €35M or 7%. For providing incorrect information to authorities it is €7.5M or 1%.

The 3% is the line that should be in every hospitality-tech model. Toast’s FY2024 revenue was $4.96 billion. Three percent is $148.8 million. Lightspeed’s FY2025 revenue was $1.08 billion CAD, roughly $790 million USD. Three percent is $23.7 million. SiteMinder’s FY2025 revenue was AU$220 million, roughly $145 million USD. Three percent is $4.4 million.

These are maximum exposures. Nobody seriously models a maximum fine. But the discounted expected value — probability of enforcement action × probability of finding × severity — is non-zero, and it is the first line item where I have seen sell-side models still using zero. If you assume a 10% probability of a finding within the first three years of enforcement (which is conservative; the Irish DPC has shown willingness to move quickly on cross-border tech enforcement) and a severity midpoint of 0.8% of turnover (between zero and the 3% cap), Toast’s expected liability is roughly $3.97 million. Lightspeed’s is $632k. SiteMinder’s is $116k. None of those numbers move the needle on enterprise value. The fine isn’t the problem.

The real cost: documentation, model cards, and the deployer-to-provider trap

The fine is the headline. The compliance overhead is the bill. Today’s guidelines codify four documentation obligations for GPAI providers that bleed downstream to anyone fine-tuning or substantially modifying a model. In practical terms, every hospitality-tech vendor running a custom layer on top of GPT-4, Claude, or Llama needs:

A technical model card that describes training data sources, architecture, intended purpose, and known limitations. The Commission’s template runs to seventeen sections.

A copyright compliance policy documenting how the provider has respected the text-and-data-mining opt-outs of EU rights holders. This is the line item that caught Stability AI flat-footed last quarter.

A public summary of training data, sufficient for rights holders to assess whether their works were used. This is mandatory regardless of whether the underlying foundation model already published one.

A systemic-risk assessment if the model crosses the 10^25 FLOPs threshold. None of the hospitality vendors come close to this in their own training, but if they fine-tune a model that did — and most of them do — they inherit reporting obligations on the modified portion.

The legal-and-compliance budget to maintain this paperwork on an ongoing basis is, in my conversations with three large hospitality-tech CFOs over the past fortnight, running between $1.8M and $4.2M annually for vendors of Toast’s scale. For Lightspeed-scale, it is $900k to $1.6M. For SiteMinder-scale, it is roughly $600k. These are recurring opex, not one-time. They land in the EBITDA line where the analyst community is currently pricing 25-30x multiples.

The Code of Practice as a pricing signal

The Commission has been clear: signing the voluntary Code of Practice is the cheapest path to demonstrating compliance. Non-signatories will face higher evidentiary burdens — they will have to prove compliance from first principles in each enforcement contact. Signatories get a presumption of conformity for the items the Code covers.

Today’s guidelines explicitly confirm that the Code has evidentiary weight in proportionality assessments — meaning a signatory who gets investigated will likely see a fine reduction at the discretion of national competent authorities. The Code’s chapters cover transparency, copyright, safety, and security. They are not a free pass. They are a discount voucher.

Of the hospitality cohort, none has signed publicly. Toast’s general counsel told me in February that they were “monitoring.” Lightspeed has said nothing on the record. SiteMinder’s last AI governance statement, from March, did not mention the Code. The reasonable expectation is that all three sign before August 2 — and that those that do not will see the compliance overhead grow by roughly 30% on the documentation line, because they will be auditing themselves rather than relying on the Code’s standard templates.

This is the part of the model that nobody is pricing. If you assume two of the three sign and one does not, you get a meaningful EBITDA-margin divergence over a 24-month horizon. My working model has Toast at -38 bps, Lightspeed at -22 bps, and SiteMinder at -47 bps if they remain non-signatories. Half of that disappears if they sign.

What the downstream-modifier rule means for the rest of the stack

Beyond the obvious vendors, the AI Act’s deployer-to-provider trap creates exposure across the entire hospitality-tech long tail. Any vendor running a Llama fine-tune on top of customer transaction data — and there are dozens, including the AI stack that Yelp has been building, which my colleague will treat in an upcoming May piece — now has to assess whether their modification is “substantial” under today’s guidance.

The Commission’s test is: does the modification change the model’s intended purpose, increase its capabilities by more than 10% on relevant benchmarks, or add new modalities? Most hospitality fine-tunes are domain adaptation, not capability expansion, and should fall safely outside the substantial-modification bar. But “should” is doing a lot of work in that sentence. Each vendor needs a legal opinion on file. That is another $40-80k per vendor for outside counsel, plus management time.

The DoorDash/SevenRooms transaction, which my colleague will dissect in a forthcoming May piece, is the cleanest illustration. SevenRooms ships AI-driven guest-personalisation features into EU markets. DoorDash is now responsible for the compliance posture of that stack. Whatever the headline acquisition price, the buyer needs to add a compliance integration line — call it $3-5M one-time, $1-2M ongoing — to get the target to AI Act conformity by the August 2026 high-risk deadline.

How I am pricing this in the model

For the three named vendors, my adjusted FY2026 EBITDA estimates are:

Toast: -$8.4M (compliance opex midpoint $3M + Code-of-Practice contingency $1.2M + downstream-modifier legal $0.8M + expected-fine reserve $3.4M).

Lightspeed: -$2.9M (opex $1.25M + contingency $0.6M + legal $0.4M + fine reserve $0.65M).

SiteMinder: -$1.7M (opex $0.6M + contingency $0.4M + legal $0.3M + fine reserve $0.4M).

On EV/EBITDA at current multiples — Toast at 28x forward, Lightspeed at 18x, SiteMinder at 21x — these adjustments compress fair value by $235M, $52M, and $35M respectively. As percentages of current market cap: 1.3%, 2.7%, and 2.6%.

The market is treating AI Act compliance as a footnote. It is a footnote that, on my numbers, costs hospitality-tech investors more than $320M in enterprise value across just three names. That is not catastrophic. It is, however, large enough that ignoring it is no longer a defensible position for a fundamental analyst.

The buy-side analyst I started with will, I hope, take my call when the August 2 enforcement window opens and the first compliance investigations hit the wires. Until then: price the bill. It has come due.

— Oliver writes The Bottom Line for TableTransfers. Tips: [email protected].

Featured More

The Voice Agent Maturity Curve

mise

·

12 min read

The Four Margins of a Restaurant

mise

·

14 min read

The AI Premium in Hospitality M&A: Broker Story or Real Number?

the bottom line

·

9 min read

What the DoorDash/SevenRooms Deal Actually Buys

the bottom line

·

11 min read

Browse all 494 posts

Related posts

Darden trades like a tech company. It shouldn't.

the bottom line

·

11 min read

Darden trades like a tech company. It shouldn't.

Applebee's just became its own franchisee. The territory math is the trade.

the bottom line

·

12 min read

Applebee's just became its own franchisee. The territory math is the trade.

FAT Brands has to sell. Here's what the AI premium does (and doesn't) buy a multi-brand QSR.

the bottom line

·

12 min read

FAT Brands has to sell. Here's what the AI premium does (and doesn't) buy a multi-brand QSR.