In this article
You might already have a chatbot taking bookings, an AI answering your phone, or a tool drafting your review replies or job ads. What you probably don't know: since 2 August 2026, almost every one of those uses falls under a European law with fines of up to €15 million. This article adds up the seven numbers that decide what that actually means for your restaurant.
This isn't an article about what AI can DO for your restaurant — that overview (smart bookings, predictive analytics, chatbots) already exists on this site. This is the article about the law that now governs HOW you're allowed to use that AI, what you have to tell your guests, and what's simply banned — even if you never built an AI yourself and just use an off-the-shelf tool from a supplier.
The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024, then rolled out in four waves. The first wave (2 February 2025) banned a handful of AI practices immediately. The second (2 August 2025) mostly covered the large AI models themselves. On 2 August 2026 — less than a month before this article was written — the third and by far the largest wave took effect: almost every remaining obligation, including the transparency rules that reach an ordinary chatbot or AI text generator directly.
That makes this article urgent rather than theoretical. If you're already running a booking bot, an AI phone agent, AI-generated marketing photos, or an AI tool for reviews, job ads or staff documents, rules that didn't exist a year ago have applied for a few weeks now — and most restaurant owners have never heard of them.
Seven numbers, in this order: the date the heaviest wave took effect; the percentage of AI use that's completely banned the moment it's aimed at your own staff; the article that forces a chatbot to identify itself; the maximum fine — and the exception that specifically favours small businesses; the grey area around AI-generated photos; the exemption that keeps most AI-written text out of scope; and the number of different regulators actually enforcing this law.
Why almost no restaurant has looked into this yet
AI regulation sounds like something for tech companies and hospitals — not a restaurant that just uses a chatbot from a vendor. The AI Act itself contradicts that assumption: anyone who uses an AI system is a "deployer", and a deployer has its own obligations, even when a different company built the AI.
The problem also stays invisible because most AI tools simply work without ever pointing out what the law expects of you. A chatbot vendor sells you a working bot, not a legal checklist — and the law puts the responsibility for telling your guest on you, not necessarily on the vendor.
The rest of this article adds up what most restaurants have never looked into: which exact date matters, what's flatly banned, what you have to disclose, how much a breach can actually cost — and the detail that should reassure most owners: for a small business, the fine is never the headline-grabbing millions figure.
Free guide Everything about digitalising your restaurant, in one guide From point-of-sale to AI — the complete guide to technology in your restaurant. Read the guide7 numbers most restaurants have never looked into
Every number below comes directly from the text of Regulation (EU) 2024/1689 — never from an estimate by this site. This is not legal advice: the exact way it applies depends on how you actually use the AI, and national regulators are still working out the details. Consult a lawyer if you're unsure.
1. 2 August 2026: the date the heaviest wave took effect
The AI Act entered into force on 1 August 2024, but the obligations themselves became applicable in four waves. On 2 February 2025 the banned practices took effect immediately (see number 2 below). On 2 August 2025 came the rules for the large AI models themselves (the models behind tools like ChatGPT, Gemini or DeepSeek) and the governance framework around the law.
On 2 August 2026 — the date this article is built around — almost the entire rest of the Regulation became applicable: the rules for "high-risk" AI systems, and critically for an ordinary restaurant, the transparency obligations in Article 50 (numbers 3, 5 and 6 below). Only the strictest rules, for AI embedded in regulated products such as medical devices, still follow on 2 August 2027.
So for a restaurant this isn't a law that's "still coming" — it's a law most of which has already been in force for three weeks by the time you're reading this.
The AI Act didn't roll out all at once — this is what already applies today and what's still to come.
Only the strictest rules for AI embedded in regulated products (like medical devices) still follow on 2 August 2027 — rarely relevant for a restaurant.
2. 0%: AI reading the emotions of YOUR OWN STAFF is simply not allowed anymore
Article 5 of the AI Act lists a short set of AI practices that are simply banned, with no exception for "small business". One reaches hospitality directly: emotion recognition in the workplace — an AI system that infers an employee's emotions, stress or mental state from camera footage, voice or other data. That's been banned since 2 February 2025, with only a narrow exception for medical or safety reasons (think detecting driver fatigue).
That number is literally 0%: there's no legal version of "we use AI to monitor how stressed our staff are" in hospitality, however well-intentioned the reason. This covers both a standalone AI camera system pointed at the kitchen or floor staff, and a "wellness" feature quietly built into existing security software.
One thing worth not confusing: this ban specifically applies to your own staff, in the workplace. A system that measures general atmosphere or busyness in the restaurant without tracing individual staff emotions isn't covered — and AI reading a GUEST's mood (say, for marketing purposes) is a different question, one that falls under ordinary data-protection law (GDPR) rather than this specific ban.
3. Article 50(1): your chatbot has to say it's a chatbot
Article 50(1) of the AI Act requires any provider of an AI system "intended to interact directly with natural persons" to make sure that person knows they're talking to AI — unless that's already obvious from the context. For a restaurant this reaches two concrete uses: a chatbot handling bookings or questions on your website, and an AI phone bot answering calls.
"Already obvious" is a lower bar than it sounds: a chat window with a robot icon and the name "AI assistant" usually clears it easily. A phone voice that sounds convincingly human clears it far less easily — and that's exactly the scenario this rule was written for.
In practice this means one clear sentence, early in the conversation, telling the guest they're talking to an AI system. No lengthy disclaimer, no pop-up that interrupts the flow — just honesty at the moment it actually matters.
4. €15,000,000 or 3% of turnover — and the exception that specifically favours you
The AI Act works with three fine tiers. A breach of the banned practices from number 2 (like emotion recognition on staff) can reach €35 million or 7% of worldwide annual turnover, whichever is higher. Most other breaches — including the transparency duty from number 3 — fall under a lower ceiling: €15 million or 3% of turnover. Misleading a regulator with incorrect information sits at the lowest tier: €7.5 million or 1%.
For a business with eight staff on the payroll, that sounds absurd — and by design, it is: Article 99 contains an explicit exception for SMEs, including start-ups. For large companies, whichever of the percentage or the fixed sum is higher applies each time. For an SME, it's exactly the opposite: whichever of the two is lower.
In concrete terms, for an ordinary restaurant that means: never the headline-grabbing millions figure, but the percentage of your own (far smaller) turnover — still a real risk, but not an amount that could wipe out a business in one blow.
The maximum amount per type of breach — the higher of the percentage or fixed sum for large companies, the LOWER one for SMEs.
Amounts per Article 99 of Regulation (EU) 2024/1689. For SMEs, including start-ups, whichever of the percentage or the fixed sum is lower applies each time — for large companies, whichever is higher. Check the Regulation's current text if you're unsure.
5. AI-generated photos: the grey area nobody can draw with certainty yet
More and more restaurants use AI to generate or edit marketing photos — making a dish look better, an evening shot of the terrace. Article 50 touches this in two different ways. Paragraph 2 requires the AI tool's provider (the company behind the generator) to mark AI-generated content in a machine-readable format. Paragraph 4 only requires the deployer (your restaurant) to disclose when content would convincingly pass as real — what the law calls a "deep fake".
That's where the grey area sits: a clearly stylised, recognisably "AI-looking" marketing shot of a dish probably isn't a deep fake under the law. A photorealistic image of your terrace that a visitor would mistake for a genuine photo sits much closer to being one. Nobody — not even a lawyer — can say with full certainty today exactly where that line falls; it's one of the points national regulators are still working out how to interpret.
The safest advice is also the simplest one: if an AI image is realistic enough that a guest could mistake it for a genuine photo of your restaurant, just say it was AI-generated or AI-edited. It costs you nothing and removes the question entirely.
6. The exemption that keeps most AI-written text out of scope
Article 50(4) contains a second transparency duty: anyone publishing AI-generated text that informs the public on a matter of public interest has to disclose that the text was AI-generated. That could, in theory, reach an AI-drafted job ad, staff handbook or review reply — but the same provision immediately carries an exemption: it doesn't apply when the text has been reviewed by a human, and a natural or legal person holds editorial responsibility for the publication.
That's exactly how most restaurants already use AI tools today: an AI drafts a first version of a review reply, a job ad or part of a staff handbook, and the owner reads it, edits it, and only then publishes it. As long as that human review and that editorial responsibility genuinely happen, this kind of text usually falls outside the disclosure duty.
The point where that stops holding: the moment AI text is published in bulk, unread and with no human check at all — say, hundreds of review replies going out automatically without anyone ever having looked at them. At that point, the editorial responsibility the exemption requires is gone.
7. 27 different regulators, not one office in Brussels
The AI Act is a European regulation, but its enforcement isn't. Article 70 requires every EU member state to designate its own "market surveillance authority" or authorities — just like other EU laws on this site (think GDPR, or the rules on posted workers), there's no single Brussels desk where you file a complaint or ask a question.
In practice that means 27 different bodies, each moving at its own pace and with its own priorities for what they check first. Some countries had their regulator up and running well before 2 August 2026; others are, as this is written, still very much staffing up and getting equipped.
For a restaurant, the practical takeaway is: exactly how this law gets checked and enforced in your own country isn't fully settled everywhere yet. That's not a reason to ignore the rules — it's precisely the reason to take the basic steps now (see the action plan below), rather than waiting for a regulator to knock.
Which rule applies to your AI tools?
Each of the seven numbers above is general — it only gets concrete once you look at the AI tools you actually use. This checklist does that translation: tick what you use, and see immediately which obligation applies.
This is a simplified rule-by-rule check based on the seven numbers above, not a full legal risk assessment.
Tick what you use
Six AI applications restaurants actually use today.
Tick the AI tools you use above to see which rules apply.
A simplified check, not legal advice. Consult a lawyer if you're unsure about your specific situation.
This checklist covers the six uses restaurants rely on most today — not every possible AI application. Using an AI tool that isn't listed here? Check whether it talks directly to guests (Article 50(1)), generates content (Article 50(2)/(4)), or reads staff emotions (Article 5(1)(f)).
What the checklist doesn't measure: the administrative side — keeping a record of which AI tools you use and which checks you've run — which is often the first thing a regulator actually asks for.
How to check this before your next AI tool
Three steps, in the order they should happen.
1. Inventory the AI tools you already use
- Go through the checklist above for every AI tool your restaurant uses today, from chatbot to review replies.
- Ask every vendor explicitly whether their tool has already been updated for the AI Act transparency rules that have applied since 2 August 2026.
- Note specifically which tools talk directly to guests or generate content — those carry the clearest disclosure duty.
2. Make sure the disclosure is actually there
- Add one clear, short sentence to every chatbot or phone bot that talks directly to guests — like the sample sentences in the checklist above.
- Always have a human review any AI-written text (review replies, job ads, staff documents) before it's published, even if that costs an extra minute.
- Turn off any AI system trying to read the emotions or mental state of your own staff right away — that's not a grey area, it's banned.
3. Repeat this for every new AI tool
- Repeat this check for every new AI tool you're considering, before you actually deploy it, not after.
- If you're unsure about your specific situation, ask a lawyer or your trade association — this checklist doesn't replace that.
- Keep a short note of which tools you use and which checks you've run, in case a regulator ever asks.
The short answer
The EU AI Act has largely applied since 2 August 2026, and reaches an ordinary restaurant in three concrete ways: emotion recognition on your own staff is simply banned, a chatbot or phone bot talking to guests has to disclose that, and AI-generated content (photos or text) carries a disclosure duty that varies with how realistic or uncontrolled its publication is.
The fines sound eye-watering — up to €35 million — but for an SME, whichever of the percentage or the fixed sum is LOWER applies each time, not the higher one. That makes the risk real, not catastrophic.
The fix costs no new system — go through the checklist above for every AI tool you use today, add a clear disclosure to every chatbot or phone bot, always have a human review AI text, and turn off emotion recognition on staff right away.