The EU AI Act Just Turned On — Here's What Changes for Restaurants and Hotels Using GPAI
August 2 quietly redrew the lines: hospitality operators in Europe are now deployers of general-purpose AI, and their voice-AI vendors are providers. The paperwork, the literacy program, and the contract changes nobody scoped.
I spent the morning of August 2 in a back-of-house office in the 11th arrondissement, sitting across from a group GM who runs four restaurants and a thirty-room hotel above one of them. He had three browser tabs open: the European Commission’s announcement that the GPAI rules had begun to apply, a forwarded note from his telephony vendor saying “we’ll handle compliance, don’t worry,” and an espresso going cold. He wanted to know what he was supposed to do, by when, and whether the voice agent on his reservations line — the one that had been answering calls in three languages since March — was about to become a legal problem.
The honest answer is that nothing exploded that morning. But the floor underneath hospitality’s relationship with AI vendors did shift, and most operators haven’t quite noticed. The contrarian read: August 2 turned hospitality operators into deployers of general-purpose AI under EU law, while their voice and chat vendors became providers. The practical effect is not a fine in the mail. It is that operators in the EU now need provenance documentation from every vendor that wraps a foundation model, plus an AI literacy program nobody has scoped, before the supervisory machinery finishes calibrating.
That distinction — between the rules being in force and the rules being enforceable with fines — is the one to plant a flag on early, because almost every group GM I’ve spoken to has either over-panicked or under-reacted, and both reactions trace to the same misread.
What actually went live on August 2
The thing that went live is the second wave of obligations under the AI Act. The first wave, in February, banned a short list of prohibited practices — social scoring, certain biometric categorization, manipulative AI — and required deployers to put AI literacy programs in place. The second wave switches on the rules for general-purpose AI models: the foundation models from OpenAI, Anthropic, Google, Meta, Mistral, and others that sit underneath almost every voice agent, chat agent, and “ask your data” tool a restaurant or hotel has bought in the last two years.
The Commission’s July guidelines on GPAI provider scope are the clearest plain-English read of what counts as a provider, what counts as a downstream modifier, and where the line sits between “we fine-tuned a model” and “we put a wrapper on someone else’s model.” Worth reading once if you have any vendor that uses “our proprietary AI” in their marketing.
The DLA Piper writeup is the cleanest legal summary of which obligations apply on which date, and the Baker McKenzie briefing is the one I keep sending to operations directors because it separates “this is in force” from “this is enforceable with penalties.” The artificialintelligenceact.eu implementation timeline is the bookmark to keep.
Here’s the structure as it applies on a hospitality balance sheet. The penalties are real and large: up to €35 million or 7% of global turnover for prohibited practices, up to €15 million or 3% for other infringements (including most GPAI-related ones). The Commission’s AI Office became operational on August 2 as the body that supervises GPAI providers. Systemic-risk obligations attach to models trained above 10²⁵ FLOPs, a threshold the largest frontier models cross and most others do not.
But — and this is the load-bearing “but” — the AI Office’s enforcement powers over GPAI providers do not begin until August 2, 2026. Models placed on the market before August 2, 2025 have until August 2, 2027 to come into compliance. So what we have right now is a year in which the rules are legally in force, the supervisory body is operational, the templates and codes of practice are being finalized, and the penalty meter is not yet running for the GPAI part of the regime. That is the window. It is not a holiday. It is a working window.
Deployer, provider, and why the label matters
The AI Act sorts every party into a role: provider, deployer, importer, distributor. For a restaurant or hotel group, the two that matter are provider and deployer, and the line between them is what changed on August 2.
A provider develops an AI system or general-purpose AI model and places it on the market under its own name. OpenAI is a provider of GPT-class models. Anthropic is a provider of Claude. The smaller voice-AI companies that take one of those foundation models, wrap it in telephony, add a fine-tune or a system prompt, and sell it to restaurants as “our reservation agent” are — depending on what they actually do — either providers of an AI system, downstream modifiers, or both. The Commission’s guidelines spend a lot of time on this question because it determines who owes which document to whom.
A deployer is anyone using an AI system in the course of a professional activity. That’s the hotel. That’s the restaurant group. You were a deployer in February too — that’s why the AI literacy obligation in Article 4 applied to you starting then. What changed in August is that the model underneath your vendor’s product is now subject to a separate regime, and the documentation flow that regime creates is going to land on your desk whether you ask for it or not.
The reason this matters practically: deployers have to be able to explain, in basic terms, what AI is operating on their premises, what it does, what data it touches, and what the foreseeable risks are. You cannot do that if your vendor cannot tell you which foundation model is underneath their product, what the training data summary looks like, and whether the model has been flagged as systemic-risk. August 2 is the moment vendors are supposed to be producing that information. The question for you is whether they are, and whether the contract you signed in 2024 obliges them to share it.
The provenance document you didn’t know you needed
Here is the most concrete thing that changed for hospitality operators on August 2: every GPAI provider now owes downstream users a set of technical documentation, including a sufficiently detailed summary of the training data used. The template for that summary was published by the AI Office, and the obligation to produce it is on the upstream model developer — OpenAI, Anthropic, Mistral, and so on. The obligation to pass it through sits with your direct vendor.
In practice, what that means is your voice agent vendor should now be able to answer three questions in writing:
The first is which foundation model or models sit underneath the product, and whether the provider of that model has classified it as a general-purpose AI model with systemic risk. The second is a pointer to the model provider’s training-data summary or, if the vendor has further trained or fine-tuned the model in a way that triggers their own provider obligations, the vendor’s own summary. The third is the vendor’s posture on the EU code of practice for general-purpose AI — whether they are aligned with it, whether their upstream model provider has signed on, and what their plan is for the period before enforcement begins in August 2026.
None of those three questions were answerable in any practical way before August 2. The templates didn’t exist, the AI Office wasn’t operational, and the code of practice was still in negotiation. After August 2, they are answerable, and a vendor who cannot answer them is telling you something about how seriously they have taken the last twelve months.
I started asking those three questions in vendor reviews. The split among the eleven voice-AI vendors I’ve checked so far is roughly: three had clean, written answers and a one-page provenance attestation ready to send; four could answer verbally but had not yet put it in writing; three said some version of “we’re working on it”; and one — a vendor I will not name but whose product is in production at two groups I advise — could not name the foundation model underneath their own system on a Wednesday afternoon call. That is the spread. It should inform how you weight vendors in your next renewal cycle. The broader vendor-readiness picture is the subject of a forthcoming May framework piece on voice agent maturity, where the provenance question slots into a wider evaluation grid.
AI literacy: the obligation everyone forgot
Article 4 — the AI literacy provision — went live in February 2025, not August. But almost nobody in hospitality scoped it then, and the August turn-on has surfaced it as a question people are now asking late. The obligation is short: providers and deployers of AI systems shall take measures to ensure a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account technical knowledge, experience, education, training, and the context of use.
That is essentially the entire text. It does not specify a syllabus, a certification, or a vendor. What it does is create a documentable expectation. If a supervisory authority — or a journalist, or a litigant — asks how you trained your reservations team to handle the voice agent that mis-routes a wheelchair-access request, you need an answer that is not “we sent them a vendor PDF.”
The literacy program I’m recommending has four components, none of which require a vendor. First, a one-page internal explainer that names the AI systems in operation, what they do, what they don’t do, who owns escalation, and what the failure modes look like. Second, a quarterly thirty-minute session with front-of-house and reservations that walks through three recent edge cases — anonymized — and how they were handled. Third, a written attestation, signed annually, that staff have read the explainer and attended at least one session in the last twelve months. Fourth, a log of incidents — not bugs, but moments where the AI’s behavior was surprising, ambiguous, or wrong — that gets reviewed before each session.
Roughly ten hours per year of program time for a single-property hotel, plus an hour of GM time per quarter. Not expensive. On August 2026 timelines, the difference between being able to demonstrate compliance and not.
Contract clauses to look for, and to add
I have read more vendor contracts in the last six weeks than is healthy, and a pattern emerges. The contracts signed in 2023 and 2024 almost universally lack three clauses you now want.
The first is an obligation on the vendor to pass through upstream provider documentation — training-data summaries, model cards, systemic-risk classifications — within a defined window, typically thirty days of the vendor receiving them. Without this, you are dependent on the vendor’s goodwill for documents you may need to produce to a supervisory authority or to a guest who exercises their information rights.
The second is a representation that the vendor knows whether they themselves qualify as a provider of a general-purpose AI model — most do not, but some who have done significant fine-tuning might, and the line is in those Commission guidelines I linked earlier. If they do qualify, you want to know, because the documentation chain shortens by one link and your contractual posture changes.
The third is an obligation to notify you of material changes to the underlying foundation model. If your vendor was running on GPT-4 in March and quietly swapped to a different model in July, that is a change you need to know about, both for your own literacy program and for your incident log. The contracts I’ve reviewed almost universally do not require that notification today.
None of these clauses are exotic. They are versions of clauses your legal counsel has written before for cloud services and data processors. They just need to be ported into AI vendor agreements, and the August 2 turn-on is the credible reason to reopen the contract.
What about the smaller vendors who built their own models?
A small number of hospitality-adjacent AI vendors claim to have built their own models from scratch rather than wrapping a foundation model. They are rare, and I’m skeptical of most claims — most “proprietary model” claims dissolve on inspection into “our prompt and our fine-tune on someone else’s base.” But genuinely-from-scratch ones exist, and the AI Act treats them differently.
If a vendor has trained their own general-purpose model, they are a GPAI provider in their own right. They owe the full documentation set, including the training-data summary in the AI Office template. If their model crosses 10²⁵ FLOPs — which no hospitality-vertical vendor has done or is likely to — they owe additional obligations including evaluations, adversarial testing, and incident reporting.
Practical effect: if a vendor in this category serves you, the documentation chain is cleaner (one party, not two), but you should ask harder questions, because the burden of proof for “we trained this ourselves” is now considerably higher than when the phrase was marketing. A vendor who genuinely qualifies will have a model card, a training-data summary, and a clear answer on systemic risk. A vendor who waves at you and changes the subject is telling you the claim was marketing.
The drive-thru question
Anyone who has watched the McDonald’s IBM AI drive-thru saga — which I revisit in an upcoming May piece — has a sharper instinct than they realize for what deployer obligations look like in operation. The drive-thru wasn’t an EU story, but the failure modes were the same ones the Act is trying to make visible: a deployer who could not explain, in real time, what the AI was doing, why, what the foreseeable failure modes were, and what the customer’s recourse was. The Act, in its deployer obligations, is partly a forcing function to make those explanations exist before the failure does.
Hospitality has a structural advantage QSR does not. Most restaurant and hotel AI deployments are narrower in scope, lower in throughput, and operate against a smaller universe of guest queries than a drive-thru. The literacy program scales. The provenance documentation is tractable. The incident log is short enough to actually review. The question is whether operators will do the work in the August 2025 to August 2026 window, or wait until enforcement powers begin, at which point the work becomes a fire drill. More on how the Act lands on restaurants specifically in a forthcoming May piece.
The systemic-risk threshold and why it (probably) doesn’t apply to you
The 10²⁵ FLOPs threshold is worth understanding even though it will not directly bind any hospitality operator. The threshold defines which general-purpose AI models are presumed to pose systemic risk and therefore carry additional obligations on their providers: evaluations against state-of-the-art protocols, adversarial testing, tracking and reporting of serious incidents, cybersecurity protections for the model and physical infrastructure.
The only frontier models above the threshold today are the largest from a handful of major labs. None of the hospitality-vertical voice or chat vendors have trained anything close to that scale, nor are they likely to. So the systemic-risk obligations land entirely on your upstream model providers, not on you, and not on your vendor.
What you should care about is whether your vendor’s upstream model is on the systemic-risk list, because that affects the documentation flow. A model classified as systemic-risk produces a richer documentation set, including evaluation summaries and incident reports, that your vendor should be passing through. A non-systemic-risk model produces a lighter set. Either way, the documentation should be reaching you, and “we don’t know if our upstream model is systemic-risk” is a vendor answer that should make you ask follow-ups.
What I’m telling operators to do this quarter
Concretely, the work I’m scoping for clients in the August-to-November window:
Build a one-page register of every AI system in operation, naming the vendor, the foundation model underneath, the deployer role (you), the provider role (the vendor or the upstream lab), and the contractual instrument that governs the relationship. Most groups can do this in an afternoon. Almost no groups have done it.
Send the three-question provenance request to every vendor: which foundation model, where is the training-data summary, what is your code-of-practice posture. Give them thirty days. Track responses. Use the response quality as a renewal-cycle input.
Stand up the literacy program in the form I described — explainer, quarterly session, attestation, incident log. Do not wait for a vendor to build it for you. The Article 4 obligation is yours as a deployer, not theirs as a provider, and the supervisory authority will look at what you did, not what your vendor offered.
Reopen one or two key vendor contracts and add the pass-through clauses. If renewal is more than six months away, send a written request for the documentation under the existing contract and start the paper trail.
Diarize August 2, 2026, as the date the enforcement powers begin, and August 2, 2027, as the date by which pre-existing models must come fully into compliance. Both dates are working deadlines for the year ahead, not panic dates.
What I’m not telling operators to do
I’m not telling anyone to pull a voice agent out of production because of the August 2 turn-on. The system that was answering calls in three languages in March is still answering calls in three languages now, and removing it would be a self-inflicted operational wound for no compliance benefit. The Act does not retroactively prohibit anything that wasn’t already prohibited; it adds documentation and literacy obligations on top.
I’m also not telling anyone to budget for fines this year. The enforcement powers for the GPAI part of the regime begin in August 2026. The penalty figures — €35 million, €15 million — are real, but they are not in play in 2025 for the obligations we are talking about. What is in play is reputational and contractual: a vendor who cannot produce documentation in 2025 is a vendor whose position weakens in 2026, and a deployer who has not built a literacy program in 2025 is a deployer who is improvising one in 2026 under whatever pressure the first round of enforcement actions creates.
And I’m not telling anyone that the Act is settled law in its final operational form. The Commission’s guidelines have been out for about a month. The code of practice is still in negotiation. The supervisory authorities are still building their teams. There will be clarifications, carve-outs, and edge cases over the next year that we cannot see today. The work I’m describing — register, provenance requests, literacy program, contract clauses — is robust to those clarifications. None of it depends on a particular interpretation that might shift.
The vibe
The vibe of August 2, sitting in that back-of-house office in Paris, was not crisis. It was the quiet, slightly disorienting feeling of a regime turning on around you while the espresso machine still works. The group GM I started this piece with sent me an email last week. He had built his register, sent the provenance requests, scheduled the first literacy session for September, and gotten his lawyer to draft the pass-through clause. Two of his four vendors had responded within the thirty-day window with clean documentation. One had asked for more time. One had not responded at all, and was now on his renewal-cycle watch list.
That is, basically, what the work looks like. Not heroic. Not expensive. Not even, in the scheme of things, particularly disruptive. Just the patient, document-heavy work of being a deployer in a regulated regime, which is the thing that hospitality operators in the EU now are, whether they have noticed or not.
The vendors who are going to win the next twelve months are the ones who turn the provenance document into a sales asset rather than a compliance burden, and who treat the August 2025 to August 2026 window as the moment to differentiate on documentation quality before everyone has to. The operators who are going to come through cleanly are the ones who treat the register and the literacy program as one-afternoon and one-quarter projects respectively, rather than as a thing to defer. The middle of the market — vendors who can’t answer the three questions, operators who haven’t built a register — will be fine in 2025 and uncomfortable in 2026.
The floor moved on August 2. Most people didn’t feel it. The ones who did are quietly doing the paperwork. The ones who didn’t will, eventually, get the memo from a supervisory authority or a guest or a journalist, and by then the easy version of the work will have closed.
— Sofia leads Vibe Check vendor reviews for TableTransfers. Tips: [email protected].
The Voice Agent Maturity Curve
mise
·12 min read
The Four Margins of a Restaurant
mise
·14 min read
The AI Premium in Hospitality M&A: Broker Story or Real Number?
the bottom line
·9 min read
What the DoorDash/SevenRooms Deal Actually Buys
the bottom line
·11 min read
Related posts
vibe check
·16 min read
Desk Review: Lightspeed Restaurant, the Quiet Half of the Duopoly
vibe check
·18 min read
Desk Review: OpenTable's 'System of Record' — what restaurants are actually agreeing to on April 16
vibe check
·18 min read