Does your hotel meet the EU AI Act?
The Act's main obligations applied from 2 August 2026. Enter your address and answer five questions — get the AI Act and GDPR duties that reach your property, by article, each cited to the source text.
Note what the test is not. It does not turn on your guest's nationality, on taking a euro payment, or on having an EU entity. It turns on where the output is used. A chain with one EU property and forty outside it is usually in scope for far more than the one.
Six questions about your AI use
What counts as an “output”, and why this question is not a yes/no filter
Why it is asked. Article 2(1)(c) reaches providers and deployers established in a third country where the output produced by the AI system is used in the Union. It is the route that catches an operator with no EU entity, no EU server and no euro payments — and it is easy to miss, because nothing about the business looks European.
What an output is. Article 3(1) defines an AI system as one that infers how to generate outputs “such as predictions, content, recommendations, or decisions”. Those four are the Regulation’s own list, not a paraphrase. So the useful question is: which of the four does your system produce, and what is then done with it?
Where it is genuinely unsettled. A chatbot answering a guest sitting in Germany is close to the core of “used in the Union”. An internal marketing plan generated for a non-EU property, which a person later chooses to apply in Germany, is much further from it — there is a human decision in between. This register does not pretend that line is drawn. Article 96 empowers the Commission to issue guidelines on the Act’s practical application, and that is where a workable test will come from. Until it does, treat a close case as a question for counsel, not as an answer this tool gave you.
Answering “no” does not put you outside the Act. It only closes one of three doors. Article 2(1)(b) catches a deployer located within the Union — one EU property is enough, whatever the output does. Article 2(1)(a) catches you as a provider if you place a system on the Union market under your own name. And GDPR is a separate test entirely: Article 3(2) applies to processing the data of people in the Union where you offer them goods or services — expressly “irrespective of whether a payment of the data subject is required” — or monitor their behaviour there. Selling rooms to people in the EU is offering a service to them.
Four about the property — only affects the wider register
Answer nothing and you still get the full register, with anything uncertain marked conditional. Unknown never removes an obligation from your list.
See exactly what is required
Beyond AI: the register also holds 49 obligations covering fire safety, food hygiene, tourist tax and the rest — by journey or by law. Not the focus here, and not gone.
How to read it
Three things most operators get wrong
The EU ODR platform is gone — remove the link
Regulation 524/2013 was repealed with effect from 20 July 2025. Many hotel sites still carry the mandatory link to it.
“Accessibility” means your booking journey, not your building
The European Accessibility Act reaches hotels through e-commerce services. Physical accessibility of the premises is national building code — a different obligation with a different source. The register keeps them apart.
Legionella duties do not start at a swimming pool
They bind on accommodation use, with no size floor. A small hotel with no pool is still in scope.
The AI Act is not the end of the analysis
These instruments are flagged, not analysed. Each can materially affect how a hotel governs AI, and none is curated in the register — so this section names them and links to the source rather than pretending to a depth it does not have. Every CELEX identifier below was resolved against the EU’s own CELLAR service.