The EU AI Act Is Already Live for Your Restaurant. Most Operators Don't Know It.
Two phases of the AI Act are in force. The big one lands 2 August. The text is real, the obligations are tangled, and most operators I've spoken with this spring assumed it was someone else's problem. It is not.
I had dinner with a friend who runs a 60-cover wine bar in Lisbon last Saturday. Halfway through the second glass I asked, casually, whether his staff had done their AI-literacy training yet. He looked at me the way you look at a relative who’s just told you they signed a timeshare. “My what,” he said.
This is the third EU operator in a month I’ve had this conversation with, which is why I’m leading The Pass with it today instead of Friday’s Resy news. The Regulation in question is real: it is Regulation (EU) 2024/1689, better known as the EU AI Act. It entered into force on 1 August 2024 and applies in phases. Two of those phases are already live. The biggest one lands on 2 August 2026, which is twelve weeks away.
It is, mechanically, not a complicated regulation if you read it. It catches operators off-guard because most of the coverage has been written for tech vendors, not for the people they sell to. So this piece is for the EU restaurateur or hotelier with six AI features in your stack who hasn’t yet asked which of them the Regulation actually touches.
What the Act actually covers, in restaurant terms
The Act is risk-based. It sorts AI systems into four buckets — unacceptable (banned), high-risk (heavy obligations), limited-risk (transparency obligations), and minimal-risk (nothing specific). The hospitality industry sits across the bottom three. (European Commission overview.)
The four things you need to know:
-
Some AI is now flatly prohibited. Article 5 has been in force since 2 February 2025. The two prohibitions most relevant to hospitality are the ban on AI that infers emotions of people in the workplace (Article 5(1)(f)) — except for narrow medical or safety uses — and the ban on “subliminal” or “purposefully manipulative” techniques that distort consumer behaviour and cause significant harm (Article 5(1)(a)). The workplace-emotion ban is the one operators keep tripping over: any tool that claims to read team-member mood, stress, or engagement from video, voice, or biometric data is, on its face, illegal to deploy. Fines for prohibited-AI violations top out at €35 million or 7% of global annual turnover (Article 99).
-
Your staff need an “AI literacy” baseline. Article 4 also took effect on 2 February 2025. It requires providers and deployers to take measures, “to their best extent”, to ensure their staff have sufficient AI literacy for their role. If you use AI in your business, you are a deployer. The Commission’s Q&A on AI literacy confirms there’s no mandated certification and that size is taken into account, but the obligation applies regardless of headcount. As Latham & Watkins put it: you should be able to point at something if asked.
-
Some guest-facing AI must disclose itself from 2 August 2026. This is Article 50. If you run a chatbot or AI-driven guest-service assistant, the user must be told they’re talking to an AI, unless that’s obvious to a reasonably well-informed person. If you publish AI-generated images of your dining room or AI-written copy intended to inform the public, the content must be marked as such — with a carve-out where the text has been put through “human editorial review”. The final Code of Practice on transparent AI is expected by June 2026, per Bird & Bird’s reading of the draft Commission guidelines.
-
A few systems you might be running are high-risk. Annex III lists eight high-risk categories. The two that catch hospitality are point 4 — AI used in recruitment, promotion or termination, allocation of tasks, and monitoring or evaluating performance — and point 1, remote biometric identification (face-based check-in falls in here, though one-to-one biometric verification is carved out). An AI résumé-screening tool, an AI scheduling system that decides shift allocation, or a biometric kiosk at a hotel entrance triggers the full Article 26 deployer obligations from 2 August 2026 — including the duty to inform staff and guests when they’re subject to it.
For the avoidance of doubt: a POS that forecasts prep volume, a reservations platform that scores no-show risk internally, a dynamic pricing engine the guest never sees the inner workings of — these are minimal- or limited-risk, not high-risk. There is no separate “EU AI-Use Disclosure for Consumer-Facing Services” regulation, contrary to a draft I had to throw out yesterday. There is only the AI Act, and within it, the four obligations above.
What this is not
It is not the bombshell consumer-disclosure rule that’s been circulating in operator WhatsApp groups. There is no requirement that every AI-generated upsell line or AI-set room price carry a label where the guest meets it. The Act’s transparency requirements are narrower than that, and tied to specific system types — chatbots, deepfakes, AI-generated public-information content, emotion and biometric categorisation.
It is also not extraterritorially safe to ignore. Per Article 2, the Act applies to providers placing AI on the EU market, to deployers established in the EU, and to systems whose output is used in the EU. A US-headquartered hotel group with a single Paris property is in scope.
Where the vendors are
Further behind than they should be. The bigger reservation and PMS platforms have shipped GDPR-grade transparency for years and will reuse most of that scaffolding. The smaller, AI-first vendors are the ones to ping. The right question to your account manager this month is narrow: “Which of the AI features you sell me are classified under the Act, who is provider versus deployer for each, and what documentation are you giving me for my compliance file?” If the answer is hand-waving, that is the story.
I’ll come back to specific platforms in the Desk Review series — Toast’s AI suite, SevenRooms and TableCheck, Yelp’s AI stack, and Lightspeed Restaurant. The broader vendor-power argument that’s downstream of this regulation runs in Four Margins. For the earlier reservations pieces on OpenTable and Resy, the through-line is the same: vendor-bundled AI features operators didn’t ask for are now vendor-bundled compliance exposure operators didn’t ask for.
What an EU operator should do by 31 July 2026
Five things, in this order:
- Inventory your AI. List every AI feature in your stack — vendor-provided or in-house — and the surface it touches: guest, employee, or back-of-house. If you can’t produce the list, you can’t comply.
- Kill any prohibited use today. If any vendor is selling you team-mood, fatigue, or emotion-scoring tools that read biometric signals, switch them off. That obligation has been live since February 2025.
- Write down your AI-literacy measures. A two-page internal note, a 30-minute briefing for managers, and a short checklist for new hires is, for a small group, defensible. Document who’s been trained and when.
- Flag your high-risk systems and demand vendor paperwork. For any AI used in hiring, shift allocation, performance monitoring, or biometric identification, ask the provider for the CE-marking, conformity assessment, and instructions for use required by Article 26. If they can’t produce them by mid-summer, plan to switch off before 2 August.
- Add a disclosure line to your chatbot. If you run a guest-facing AI assistant — booking concierge, WhatsApp bot, room-service ordering AI — add an opening message that the user is talking to an AI. Lightest obligation, easiest to get right.
The EU has, in its predictable way, written a regulation more reasonable on the page than it is in operator WhatsApp groups. The mistake is not over-compliance; the mistake is assuming you have until autumn. You have until August.
— Luca files The Pass and contributes to The Operator. Tips: [email protected].
The Voice Agent Maturity Curve
mise
·12 min read
The Four Margins of a Restaurant
mise
·14 min read
The AI Premium in Hospitality M&A: Broker Story or Real Number?
the bottom line
·9 min read
What the DoorDash/SevenRooms Deal Actually Buys
the bottom line
·11 min read