Free · no account

Does your hotel meet the EU AI Act?

The Act's main obligations applied from 2 August 2026. Enter your address and answer five questions — get the AI Act and GDPR duties that reach your property, by article, each cited to the source text.

A hotel outside the EU is not outside the Act. Article 2(1)(c) reaches providers and deployers established in a third country where the output produced by the AI system is used in the Union. Your booking chatbot answers guests sitting in Berlin and Paris before they travel — that output is used in the Union, and it does not matter that the hotel, the company and the server are all somewhere else.

Note what the test is not. It does not turn on your guest's nationality, on taking a euro payment, or on having an EU entity. It turns on where the output is used. A chain with one EU property and forty outside it is usually in scope for far more than the one.
Six questions about your AI use
What counts as an “output”, and why this question is not a yes/no filter

Why it is asked. Article 2(1)(c) reaches providers and deployers established in a third country where the output produced by the AI system is used in the Union. It is the route that catches an operator with no EU entity, no EU server and no euro payments — and it is easy to miss, because nothing about the business looks European.

What an output is. Article 3(1) defines an AI system as one that infers how to generate outputs “such as predictions, content, recommendations, or decisions”. Those four are the Regulation’s own list, not a paraphrase. So the useful question is: which of the four does your system produce, and what is then done with it?

Where it is genuinely unsettled. A chatbot answering a guest sitting in Germany is close to the core of “used in the Union”. An internal marketing plan generated for a non-EU property, which a person later chooses to apply in Germany, is much further from it — there is a human decision in between. This register does not pretend that line is drawn. Article 96 empowers the Commission to issue guidelines on the Act’s practical application, and that is where a workable test will come from. Until it does, treat a close case as a question for counsel, not as an answer this tool gave you.

Answering “no” does not put you outside the Act. It only closes one of three doors. Article 2(1)(b) catches a deployer located within the Union — one EU property is enough, whatever the output does. Article 2(1)(a) catches you as a provider if you place a system on the Union market under your own name. And GDPR is a separate test entirely: Article 3(2) applies to processing the data of people in the Union where you offer them goods or services — expressly “irrespective of whether a payment of the data subject is required” — or monitor their behaviour there. Selling rooms to people in the EU is offering a service to them.

Four about the property — only affects the wider register

Answer nothing and you still get the full register, with anything uncertain marked conditional. Unknown never removes an obligation from your list.

See exactly what is required

The EU AI Act, article by article All 13 duties that reach a hotel →
What each requires, who owes it, when it applied from
Ask the expert Have C2MD classify your systems →
Live, free — returns your risk category, role and which assessments you owe

Beyond AI: the register also holds 49 obligations covering fire safety, food hygiene, tourist tax and the rest — by journey or by law. Not the focus here, and not gone.

How to read it

Always citedEvery obligation links to the instrument it comes from, and every quoted phrase is checked to be an exact substring of the source text on EUR-Lex. Article-level reading is cross-checked against the AI Act explorer. Nothing is asserted without a source you can open.
Honest about gapsIt tells you which layers it did not search. Municipal rules are not in this version, and it says so on every result.
Never says you complyIt reports what applies and where it is written. Whether you meet it is your compliance officer's call.

Three things most operators get wrong

The EU ODR platform is gone — remove the link

Regulation 524/2013 was repealed with effect from 20 July 2025. Many hotel sites still carry the mandatory link to it.

“Accessibility” means your booking journey, not your building

The European Accessibility Act reaches hotels through e-commerce services. Physical accessibility of the premises is national building code — a different obligation with a different source. The register keeps them apart.

Legionella duties do not start at a swimming pool

They bind on accommodation use, with no size floor. A small hotel with no pool is still in scope.

The AI Act is not the end of the analysis

These instruments are flagged, not analysed. Each can materially affect how a hotel governs AI, and none is curated in the register — so this section names them and links to the source rather than pretending to a depth it does not have. Every CELEX identifier below was resolved against the EU’s own CELLAR service.

GDPR — Regulation (EU) 2016/679 Partly curated here. Its territorial rule is separate from the Act’s: Article 3(2) reaches you for processing the data of people in the Union where you offer them goods or services, irrespective of payment, or monitor their behaviour there.
ePrivacy Directive 2002/58/EC Governs cookies, tracking and unsolicited marketing on the booking journey — a separate consent regime from GDPR, and a directive, so what binds you is the national transposition.
Digital Services Act — Regulation (EU) 2022/2065 Reaches intermediaries and platforms. Relevant if you host guest reviews or user content, far less so for a chatbot on your own site.
Data Act — Regulation (EU) 2023/2854 Access to and sharing of data generated by connected products and related services — in-room IoT, connected locks, building systems.
NIS2 — Directive (EU) 2022/2555 Cybersecurity duties by sector and size. Whether hospitality is in scope turns on the national transposition, which is exactly why it is flagged rather than answered.
Product Liability Directive (EU) 2024/2853 Brings software and AI within the product-liability regime. It shapes what a failure costs you, rather than adding a compliance step.
National law is where this gets decided, and this register curates one country. Member States set their own penalty regimes and designate their own authorities, some have their own AI or privacy legislation on top, and every directive above binds you only through its national transposition. The register says which national layers it has curated and which it has not — it never returns a thin answer and calls it complete. For where each Member State has got to, see the national implementation tracker; for the supervisory authority that would actually contact you, the EDPB members list.

What it covers today

EU
covered
Hand-curated, cited to CELEX, verified against EUR-Lex. Most instruments are directives — the rule you are held to is the national transposition.
National
Netherlands
Other countries are not curated yet and the register says so rather than returning a thin answer.
Regional
not in this version
Municipal
not in this version
Tourist-tax rates, night-register mechanics, licensing, noise and terrace hours are commonly municipal. They almost certainly apply to you.