AI Governance
The EU AI Act's Four Risk Levels, Explained for Hotels
The EU AI Act uses a risk-based approach. The greater the potential threat to safety, livelihoods or fundamental rights, the stronger the rules. Understanding the four broad levels helps hotels ask the right questions before adopting any AI system.
Four levels, one framework
The European Commission describes four broad levels: unacceptable risk, high risk, transparency risk, and minimal or no risk.
These labels sound straightforward. Applying them to a real hotel system can be less simple.
Our previous article explained why AI risk depends on the use case, not the tool. This article looks at how the EU AI Act's risk levels apply in practice.
1. Unacceptable risk: prohibited practices
Some AI practices are prohibited because they present an unacceptable threat to people and fundamental rights.
The prohibited practices include specified forms of harmful manipulation, exploitation of vulnerabilities and social scoring. They also include certain biometric practices and emotion recognition in workplaces and education institutions, subject to the precise wording and exceptions in the legislation.
For a hotel, the employment point deserves attention. A system that claims to infer employee emotions through cameras, voice or other biometric signals should not be treated as an ordinary workforce-management feature. Emotion recognition in workplaces is among the prohibited practices, with limited exceptions for medical or safety reasons.
The practical response is not "add more human review". It is to stop and obtain specialist advice before purchase or use.
The relevant prohibitions have applied since 2 February 2025.
2. High risk: specified systems with significant potential impact
High-risk AI is not simply any system that feels important or processes personal data.
Under Article 6, high-risk classification can arise in two broad ways:
The AI is a safety component of, or is itself, a product covered by specified EU product-safety legislation and subject to third-party conformity assessment.
The system falls within use cases listed in Annex III, subject to the detailed classification conditions.
Annex III covers areas including biometrics, critical infrastructure, education, employment, access to certain essential services, law enforcement, migration and justice.
The hotel example most likely to raise this question is employment. AI used to recruit or select people, place targeted job advertisements, filter applications, evaluate candidates, allocate tasks or monitor and evaluate workers may fall within the high-risk provisions, depending on what it actually does.
There are important qualifications. An Annex III system may not be high-risk where it performs a narrow procedural or preparatory task and does not materially influence the outcome or pose a significant risk of harm. A system that profiles individuals is treated as high-risk when it falls within Annex III.
This is why "we use AI in HR" is not enough information to classify the system. A tool that improves the wording of a job advert is not doing the same thing as one that scores candidates.
High-risk classification carries substantial requirements, particularly for providers, including risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness and cybersecurity. Deployers also have responsibilities for appropriate use, oversight and monitoring.
The implementation timetable for high-risk rules has changed. Following the AI Omnibus, the rules for Annex III systems in areas including employment apply from 2 December 2027. Rules for high-risk AI embedded in regulated products apply from 2 August 2028. Hotels should still prepare early and check the current official timeline rather than relying on an old presentation or supplier summary.
3. Transparency risk: people need to know
Some uses are permitted but require transparency.
The most relevant hotel example is a guest-facing chatbot. People should be informed when they are interacting with an AI system unless this is obvious to a reasonably well-informed and observant person in the circumstances.
The relevant transparency rules have applied since 2 August 2026.
A clear label is only part of good implementation. The guest should also understand what the chatbot can do, avoid being misled about live information and have a sensible way to reach a person.
Other transparency requirements address certain AI-generated or manipulated content. The exact obligation depends on who provides or deploys the system and the type of content involved.
4. Minimal or no risk: light regulation does not mean no responsibility
The majority of AI systems are expected to fall into the minimal or no-risk category under the AI Act, where the Act does not impose additional mandatory rules.
A hotel using AI to suggest headings for an internal presentation or generate ideas from public information may sit here.
But "minimal risk under the AI Act" does not mean the output is accurate, that personal data can be entered freely, that copyright and confidentiality do not matter, that a supplier does not need checking, or that existing consumer, employment or data-protection law disappears.
The AI Act classification answers one legal question. The hotel still needs sensible operational controls.
Keep legal classification separate from internal triage
Phare IQ uses three governance-attention levels to help a small business prioritise its review: Routine Oversight, Management Review and Specialist Review. These are not the EU AI Act's legal risk levels.
A use can be outside the AI Act's high-risk category and still deserve close attention because it involves sensitive guest information, weak supplier answers or unreliable outputs. Conversely, a simple internal triage cannot decide whether a system is legally high-risk.
Use the two approaches for different purposes. EU AI Act classification asks what legal category and obligations may apply. Governance attention asks whether this use needs Routine Oversight, Management Review or Specialist Review.
When the use involves prohibited practices, employment decisions, biometrics, surveillance, safety or significant effects on individuals, move beyond an informal checklist and obtain appropriate specialist advice.
Phare IQ helps independent hotels build practical visibility and control over their AI use without confusing internal prioritisation with legal classification.
This article provides general information, not legal advice. Regulatory information was checked against European Commission and EUR-Lex sources on 4 August 2026. The Commission's high-risk classification guidance remained in draft, with final guidance expected by the end of 2026.
Phare IQ
Product strategy, workflow consulting, and practical AI adoption for SaaS founders and hospitality technology leaders.
Need a clearer view of AI risk in your hotel?
Phare IQ helps independent hotels understand where AI is being used, which uses deserve closer attention and what practical controls may be needed.
Get in touch