# The rules travel companies actually have to follow
A guest walks up to a hotel lobby kiosk, looks into a camera, and checks in without touching a passport or a keyboard. In Frankfurt, that same system now needs a conformity assessment before it goes live. In Illinois, it may need written consent and a data retention schedule, or it triggers a lawsuit. In Shenzhen, the algorithm behind it needs to be filed with a government registry before deployment. Same technology, three completely different legal realities. If your travel or hospitality company is rolling out AI across markets, this is the terrain you're actually operating in, not a hypothetical.
Travel companies sit on two things regulators care about most: biometric data (faces, fingerprints, sometimes gait or voice) and dynamic pricingdynamic pricingAutomatically adjusting prices in real time based on demand, competition or user behaviour to optimise revenue, margin or conversion.Voir la définition complète → algorithms that affect consumer wallets in real time. Add cross-border data flows (a booking made in Paris, processed in a US data center, for a hotel in Dubai) and you have a compliance surface most other sectors don't face.
Three regulatory regimes matter most in 2026: the EU AI Act, US state-level biometric and laws, and China's algorithm governance rules. None of them agree on what counts as "risky," which is exactly the problem.
The EU AI Act (Regulation (EU) 2024/1689, entered into force August 2024, with obligations phasing in through 2026-2027) sorts AI systems into four risk tiers: unacceptable, high, limited, and minimal.
Unacceptable risk (banned outright): real-time remote biometric identification in public spaces by law enforcement is prohibited with narrow exceptions. This mostly doesn't hit hotels directly, but it sets the tone: biometric identification is treated as inherently sensitive.
High-risk: this is where hotel facial recognition check-in lands if it's used to identify or verify individuals in ways tied to fundamental rights. High-risk systems require a conformity assessment (a formal check that the system meets EU safety and rights standards), a risk management system, human oversight, technical documentation, and registration in an EU database before deployment. A hotel chain in Germany or Spain using face-based check-in as anything more than an opt-in convenience feature likely needs to treat it as high-risk.
Limited risk: systems like chatbots or AI-generated content need transparency, essentially telling users "you're talking to an AI" or labeling synthetic content. A hotel's AI concierge chatbot falls here: disclosure obligations, not conformity assessments.
Minimal risk: most dynamic pricingdynamic pricingAutomatically adjusting prices in real time based on demand, competition or user behaviour to optimise revenue, margin or conversion.Voir la définition complète → engines, if they're just adjusting airline or hotel rates based on demand signals, fall into minimal or limited risk under the AI Act itself, because pricing optimization isn't listed as a high-risk use case (unlike biometrics, employment, or credit scoring). But pricing algorithms aren't off the hook elsewhere, see below.
The European Commission's official AI Act explainer is the best free primer if you need the underlying text mapped to plain language.
The US has no single federal AI law equivalent to the EU AI Act. Instead, biometric and algorithmic rules come from individual states, and they hit travel companies unevenly.
Illinois' Biometric Information Privacy Act (BIPA), in force since 2008 and the most litigated biometric law in the US, requires written consent before collecting biometric identifiers (including facial geometry) and sets strict retention and destruction rules. Statutory damages run $1,000 to $5,000 per violation, and "per violation" has been interpreted broadly by courts, meaning class actions against companies using face recognition without proper consent can reachreachThe number of unique people exposed to your message in a given period. Unlike impressions, reach counts each person once, no matter how often they see it.Voir la définition complète → large settlements. Hotels or airlines using facial check-in for Illinois residents, even from an out-of-state HQ, can be exposed.
Texas and Washington have similar biometric privacy laws with somewhat different enforcement mechanisms (Texas enforcement runs through the state Attorney General, not private lawsuits).
Colorado, California, and a growing list of states have layered on AI-specific disclosure rules, especially around automated decision-making that affects consumers, which increasingly draws scrutiny on dynamic pricingdynamic pricingAutomatically adjusting prices in real time based on demand, competition or user behaviour to optimise revenue, margin or conversion.Voir la définition complète →. The Federal Trade Commission (FTC) has also flagged algorithmic pricingalgorithmic pricingAutomatically adjusting prices in real time based on demand, competition or user behaviour to optimise revenue, margin or conversion.Voir la définition complète → as an area of interest, particularly where it uses personal data to set individualized prices (sometimes called "surveillance pricing"). The FTC issued a 6(b) study order to several companies in 2024 to examine this practice.
The net effect: an airline's dynamic pricingdynamic pricingAutomatically adjusting prices in real time based on demand, competition or user behaviour to optimise revenue, margin or conversion.Voir la définition complète → engine that uses browsing history, device type, or loyalty status to personalize fares faces very different scrutiny depending on the state, and increasingly needs to survive an FTC-level fairness lens, not just an EU AI Act classification.
China's framework operates differently: it's built on pre-deployment registration rather than post-hoc risk tiers. The Cyberspace Administration of China (CAC) administers rules requiring companies to file "algorithm filings" for recommendation systems and generative AI before public deployment, under regulations including the 2022 Provisions on Algorithmic Recommendation and 2023 Interim Measures for Generative AI.
For a hotel chain or online travel agency operating in China, this means: before a personalized recommendation engine or dynamic pricingdynamic pricingAutomatically adjusting prices in real time based on demand, competition or user behaviour to optimise revenue, margin or conversion.Voir la définition complète → system goes live, it likely needs to be registered with details on training data and intended purpose. Facial recognition also faces separate rules under China's Personal Information Protection Law (PIPL, 2021), which requires clear consent and necessity justification for biometric collection, echoing GDPR-style logic but enforced through a different regulator.
The practical takeaway: China's system front-loads compliance into a filing gate, while the EU front-loads it into a risk classification exercise, and the US does neither at a federal level but exposes you to fragmented state litigation risk instead.
Before deployment, run each AI use case through this quick lens:
Use case: [e.g., hotel facial recognition check-in]
1. Does it process biometric data? → Y/N
2. Does it affect pricing or access based on personal data? → Y/N
3. Which markets does it touch? [EU / US states / China / other]
4. For each market, what's the trigger threshold?
- EU: high-risk category? → conformity assessment required
- US: which state law applies? → consent/disclosure required
- China: algorithm filing required? → CAC registration
5. Documentation owner assigned? Y/NThis isn't a legal compliance checklist, it's a governance triage tool to flag which use cases need legal review before a pilot becomes a full rollout.
Vérification des acquis
1. Why does the opening example (one facial-recognition check-in system facing three different legal requirements in Frankfurt, Illinois, and Shenzhen) matter for a travel company's AI rollout strategy?
2. According to the lesson, why is the travel and hospitality sector described as a 'regulatory hot zone' for AI compliance?
3. Under the EU AI Act's risk-tier structure, where would a hotel's facial recognition check-in system used to verify guest identity most likely be classified, and why?
4. Select ALL correct answers about the EU AI Act's risk-tier approach as described in the lesson.
Sélectionnez toutes les réponses correctes.
5. Select ALL correct answers about why a single AI feature (like biometric check-in) can create compliance obligations across multiple, non-aligned regulatory regimes.
Sélectionnez toutes les réponses correctes.
Even where a use case isn't strictly "high-risk" under any single law, three guardrails reduce exposure everywhere:
Opt-in, not default, for biometrics. Facial recognition check-in should be an alternative to standard check-in, never the only path. This alone defuses most BIPA-style claims and satisfies EU transparency expectations.
Human review for pricing anomalies. Dynamic pricingDynamic pricingAutomatically adjusting prices in real time based on demand, competition or user behaviour to optimise revenue, margin or conversion.Voir la définition complète → engines should flag and route extreme or demographically-correlated price variations to human review. This is cheap insurance against both EU fairness scrutiny and FTC-style "surveillance pricing" investigations.
Data minimization and retention limits. Delete biometric templates after the stay, not after the loyalty relationship ends. Most biometric laws (BIPA, PIPL, GDPR-adjacent EU rules) converge on this point even when they disagree on almost everything else.
*(Note: verify current video availability and content match before sharing with learners; search "EU AI Act explained 2025" on YouTube if this link has changed.)*