Aug 26, 2026

The AI Act high-risk deadline moved to December 2027. What a hotel rate engine should still log today

The AI Act high-risk deadline moved to December 2027. What a hotel rate engine should still log today

For most of the year the hospitality trade press told hotels that their dynamic pricing would become a "high-risk AI system" on 2 August 2026 and needed conformity assessments by then. Two things then happened. On 24 July 2026 the Digital Omnibus on AI, Regulation (EU) 2026/1744, was published and entered into force three days later; it defers the obligations for standalone high-risk systems under Annex III to 2 December 2027 (and for AI embedded in regulated products to August 2028). And the date itself came and went with only the parts that were never deferred taking effect: the Article 50 transparency duties, on top of the prohibited practices in force since February 2025 and the general purpose model obligations since August 2025.

So the honest position for a hotel or a PMS vendor is: you have sixteen more months for the heavy obligations, a small set of duties that apply right now, and a classification question you should answer before deciding how much of the heavy work applies to you at all.

Is a rate engine high-risk?

Read Annex III rather than the vendor blogs. The high-risk list covers biometrics, critical infrastructure, education, employment, access to essential private and public services (credit scoring, life and health insurance pricing), law enforcement, migration and justice. Hotel room pricing is not there, and a rule-based or demand-forecast rate engine that sets a price for a room is not, on its face, a high-risk system. Where a hotel platform can drift into scope is around the guest rather than the room: a system that scores individual guests and denies or degrades service on that basis starts to look like an essential-services access decision; a profiling model that infers protected characteristics to price against them runs into the prohibited practices outright, which are already enforceable. The useful question is therefore not "does this price change", it is "does this system make a decision about a person".

What applies today

  • Article 50 transparency. If guests interact with an AI system, a chat assistant on the booking page for instance, they must be told they are talking to a machine unless it is obvious. AI-generated text published as news or information of public interest must be labelled, and synthetic images and audio must be marked in a machine-readable way. A generated room description or a generated reply to a review is in scope of the labelling logic; build the disclosure into the template.
  • Prohibited practices. No emotion recognition of staff at work, no inferring sensitive attributes from guest data to manipulate or discriminate. These have had teeth since February 2025.
  • AI literacy. Providers and deployers must ensure staff who operate the systems understand them. A half-day session for revenue managers, recorded, satisfies this.

What to log now, regardless of classification

Even if the rate engine stays outside Annex III, three other regimes already expect the same evidence: consumer law on price transparency, competition authorities' growing interest in algorithmic pricing, and GDPR Article 22 where a decision about an individual is automated. Building the record once is cheaper than arguing three times. What we keep in our platform for every automated rate change:

  • The inputs at decision time: occupancy, pickup, competitor set, events calendar, rule set version.
  • The output and the rule or model that produced it, with a human-readable reason.
  • Who, if anyone, overrode it, and the override is always available from the rate calendar.
  • A per-guest view that proves price was set per room, date and channel, not per person.

Retention of twelve months covers a full seasonal cycle and any inspection that follows a complaint.

Using the extra time

If you do operate anything that scores guests, the deferral is the time to do the classification properly: document the intended purpose, decide with counsel whether it is Annex III, and if so plan the risk management system, technical documentation and human oversight design against the December 2027 date rather than leaving it to autumn 2027. If you do not, write down why, and keep the logs above. Either way, the work described here is the same instrumentation we would want for revenue reporting anyway; the regulation mostly asks you to keep what a good revenue manager would already want to see.

Tags: AI, Hospitality

leave a comment