The EU AI Act and the TravelTech ecosystem (I): what is in force today, who it applies to, and why almost nobody knows
This is the first of three entries on how Regulation (EU) 2024/1689, the EU Artificial Intelligence Act, affects companies in the TravelTech ecosystem. This first entry explains what is in force as of September 2026, which role each company plays in relation to each system, and how risk is classified. The second one goes down to eight concrete use cases in the sector. The third covers what the Regulation does not regulate but still affects you (GDPR, consumer law, contracts) and a 90-day work plan.
On 7 September I had the chance to open the legal block of the TechTur Legal Series, organised by the Tech Tourism Cluster, with a session on the EU AI Act and how it applies to tourism companies. Codurance took care of the technical block. The room was full of product, technology and management people from TravelTech companies, and the question that came up most often at the end was the same one I have been hearing since 2024: “but does this apply to us?”.
The short answer is yes, almost certainly, although not in the way many fear. What follows is an extended written version of what I explained that day, meant for someone at an OTA, a bedbank, a hotel group, a channel manager or an activities startup to read it and know where they stand.
The essentials in five lines
- The AI Act has been in force since 1 August 2024 and applies in phases. As of today, the prohibited practices, the AI literacy obligation, the obligations for general-purpose models, the sanctioning regime and, since 2 August 2026, the transparency obligations of Article 50 are already enforceable.
- Regulation (EU) 2026/1744, the so-called AI “Digital Omnibus”, in force since 27 July 2026, has postponed the high-risk regime to December 2027 (Annex III) and August 2028 (Annex I). It has not touched transparency.
- Obligations depend on the role you play in relation to each AI system (provider, deployer, importer, distributor), not on your sector or your size.
- The regime depends on the risk of the specific use, not on the fact of using AI. In tourism, most cases fall under transparency risk or minimal risk.
- In Spain the supervisory authority is AESIA, and there is a draft Organic Law on the good use and governance of AI going through Parliament since June 2026.
Why this matters to TravelTech even if you don’t sell “AI”
AI is already inside the product of almost any company in the sector, even if you don’t call it that. A customer service chatbot on WhatsApp, a revenue management engine adjusting rates by demand, a destination recommender on the home page, automated CV screening, identity verification at online check-in, an internal copilot for the operations team, a generator of room photos and descriptions, or a tool to analyse and answer reviews. Many of these uses may fall within the scope of the Regulation if they meet the definition of an AI system.
What I see in the sector, and I say this knowing it first hand, are three risks that are already on the table. The first is regulatory: transparency is enforceable since 2 August 2026 and there is already an authority, AESIA, with competence to supervise. The second is reputational: generated images that don’t match the real hotel, or bots that pass themselves off as people in front of a traveler who thinks they are talking to reception. The third is contractual, and it is the one fewer people look at: your AI vendor shifts the liability to you by contract, or simply doesn’t guarantee anything at all.
In my humble opinion, the problem with the AI Act in TravelTech is not that the rules are harsh. It is that most companies still don’t know which role they play in relation to each system, nor in which risk level each use falls. And without that, you can neither comply nor negotiate with any criteria with whoever sells you the technology.
The legal framework you need to have located
Regulation (EU) 2024/1689. The Artificial Intelligence Regulation, known as the AI Act. In force since 1 August 2024, with staggered application between 2025 and 2028.
Regulation (EU) 2026/1744. The AI “Digital Omnibus”. In force since 27 July 2026. It postpones the application of the high-risk regime and adjusts the scope of the AI literacy obligation in Article 4. It does not modify the transparency obligations of Article 50.
Spain. The Spanish Agency for the Supervision of Artificial Intelligence (AESIA) is the supervisory authority. In addition, the draft Organic Law on the good use and governance of AI has been going through Congress since June 2026. Unless I have missed something, there is no closed date for its approval yet, and Spain has historically been late with this kind of adaptation, so it is worth following but not worth waiting for.
It applies for what you do with the system, not for your sector or size
This is the idea that is hardest to internalise and the one that changes everything. The Regulation does not regulate “AI companies”. It assigns obligations according to the role you play in relation to each specific AI system. And you can play several roles at once, with different systems.
Provider
A provider is whoever develops an AI system or places it on the market under its own brand. In TravelTech you are a provider if you sell your own AI engine to hotels or agencies. You are also one if you integrate a third-party model (an LLM from OpenAI, Anthropic or Google, for example) and commercialise it white-label as if it were yours. This second case is far more frequent than people think: a channel manager offering “our AI assistant” built on top of someone else’s model is, for the purposes of the Regulation, the provider of that system.
Deployer
A deployer is whoever uses an AI system under its authority in the course of its professional activity. It is the most common role in tourism: the hotel with a contracted chatbot, the OTA with a third-party recommender, the agency with pricing supplied by its technology partner, the tour operator using a copilot to draft itineraries. You did not build the system, but you operate it and decide what it is applied to.
Importer and distributor
The importer introduces into the EU a system from a provider established outside. The distributor makes it available on the market without being provider or importer. It is less frequent, but it shows up when you resell AI software from outside the EU to your clients, something that happens in B2B hotel distribution more often than it seems.
Reach outside the EU
The Regulation also applies to providers and deployers established in a third country when the output of the system is used in the EU (Article 2). A bedbank in Dubai or a pricing engine in the United States serving European hotels is not out of scope just for being abroad. And if you are the European client of that vendor, you are the deployer of a system whose provider may have no idea that the Regulation applies to it. That is where the contractual problem I will cover in the third entry begins.

Timeline in force as of September 2026
After Regulation (EU) 2026/1744, this is how the timeline stands. I separate what already applies, what is coming and what has been postponed.
| Date | What enters into application | Status |
|---|---|---|
| 1 August 2024 | Entry into force of the AI Act | Applies |
| 2 February 2025 | Prohibited practices (Art. 5) and AI literacy (Art. 4) | Applies |
| 2 August 2025 | General-purpose AI models (GPAI), governance and sanctioning regime | Applies |
| 27 July 2026 | Digital Omnibus in force: postpones high risk, adjusts Art. 4 | Applies |
| 2 August 2026 | Transparency (Art. 50): chatbots, generated content, deepfakes | Applies |
| 2 December 2026 | End of the transitional period for technical marking of systems already on the market. New prohibitions (Art. 5) | Next milestone |
| 2 August 2027 | National regulatory sandboxes operational | Pending |
| 2 December 2027 | High risk Annex III (HR, biometrics, creditworthiness, among others) | Postponed |
| 2 August 2028 | High risk Annex I (AI embedded in regulated products) | Postponed |
Two important nuances. First: the postponement of high risk changes the calendar, not the content. The obligations on risk management, technical documentation, human oversight and conformity assessment remain the same, they just arrive later. Second: the next relevant milestone for TravelTech is 2 December 2026, when the transitional period for technical marking of synthetic content ends for systems that were already on the market. If your image or text generation tool was operational before August, you have until December for the marking to work without exception.
The regime depends on the risk of the use, not on the fact of using AI
The Regulation establishes four levels. In tourism, most cases fall in the bottom two, and that is the best news you can give a company in the sector today.
Prohibited
Cannot be used in the EU. It includes subliminal manipulation or exploitation of vulnerabilities, emotion recognition in the workplace and biometric categorisation to infer ethnic origin or other sensitive categories. In TravelTech this is rare but not impossible: a “wellbeing analysis” tool for the reception team based on facial expression, or a check-in system that classifies travelers by features, would fall here. The only possible action is to drop the use.
High risk
This is Annex III, applicable from 2 December 2027. It includes recruitment and employee evaluation, remote biometric identification and creditworthiness assessment if you offer financing to the traveler. This is where HR tools with automated screening, certain biometric verification systems and, careful with this one, BNPL or financing flows embedded in a booking checkout fall if they include automated scoring. It requires risk management, documentation, human oversight, registration and conformity assessment.
Transparency risk
This is Article 50, applicable since 2 August 2026. It includes chatbots and voicebots, generated images, video and audio, deepfakes and generated texts on matters of public interest. This is where the bulk of the sector sits: the booking assistant, the after-sales bot, the generated photos for a hotel listing, the synthetic promotional videos. The obligation is to inform the user that they are interacting with an AI and to mark or label the content.
Minimal risk
No specific obligations under the AI Act. It includes the destination recommender, results ranking, demand-based pricing or review analytics. That there is no obligation under the AI Act does not mean there is no obligation: the GDPR, consumer law and your contracts keep applying, and in many of these cases they are more demanding than the Regulation itself would be. That is what the third entry is about.
General-purpose AI models (GPAI)
A separate note, because it creates confusion. The obligations on general-purpose models (documentation, copyright, marking) fall on whoever develops them. If you build on top of them, which is the usual case in TravelTech, your job is to read their documentation and their terms, and to classify the system you build on top. The base model has its obligations, and your system has its own, and they are not the same.

The real question is not “do we use AI?” but “which role do we play and in which level does each use fall?”
I have been reviewing platforms in this sector for enough years to know that the conversation about AI usually starts in the wrong place. It starts by discussing whether the product “has AI” or whether the vendor “complies with the AI Act”, and it ends without knowing anything useful.
I have seen pricing engines that management considered “a business rule” and that were actually models trained with data from specific clients. I have seen chatbots deployed in more than twenty markets that technically worked perfectly and that, in turn, delivered cancellation conditions in a way that no product team had checked against local consumer law. I have seen contracts with AI vendors where the only clause on compliance was that the client assumed all the liability, and so on with everything…
In none of those cases was the rule the problem. The problem was that nobody had done the exercise of inventorying which systems existed, which role the company played in relation to each one and in which risk level each use fell. That exercise does not require an in-house lawyer and is, by far, the most profitable thing a TravelTech company can do today regarding the AI Act.
In the second entry I go down to eight common use cases in the sector and say, for each one, where it sits and what it means for you today.
Frequently asked questions
Does the AI Act apply to an OTA or a bedbank that only uses third-party tools? Yes. Using a third-party AI system under your authority in your professional activity makes you a deployer, with the obligations of that role. Not having developed the system does not take you out of scope.
What is in force today for a TravelTech company? As of September 2026: the prohibited practices, AI literacy (Art. 4), the obligations on general-purpose models, the sanctioning regime and the transparency obligations of Article 50 for chatbots, generated content and deepfakes.
What changed with the AI Digital Omnibus? Regulation (EU) 2026/1744 postpones the high-risk regime to 2 December 2027 (Annex III) and 2 August 2028 (Annex I), and adjusts the literacy obligation. It does not modify the transparency obligations.
Is an AI vendor outside the EU out of scope? No, if the output of its system is used in the EU (Article 2). And its European client remains a deployer in any case.
Who supervises compliance in Spain? The Spanish Agency for the Supervision of Artificial Intelligence (AESIA).
Borja Rivas Lozano is legal partner and founder of Mylegalinbox, a law firm specialised in the tourism and TravelTech sector, with offices in Barcelona and Palma. If you have doubts on how the AI Act applies to a specific system in your company, however small, feel free to contact us.