What the EU AI Act’s transparency rule actually asks of a hotel

Most summaries put the marking duty on the hotel. It sits with whoever built the generator. The exposure that actually reaches a hotel is older than the AI Act.

Ewa Lewandowska

5 min read

This is a description of a rule, not legal advice. A hotel with real exposure should take its own.

What the rule says

The EU AI Act contains a transparency obligation covering synthetic content. Images, audio and video generated or meaningfully altered by AI have to carry a marking that a machine can read, so a platform, a browser or a regulator can identify the content as artificial without a human having to judge it by eye.

The transparency provisions apply from 2 August 2026.

Who the marking duty actually falls on

This is the part most summaries get wrong, and it matters commercially. The duty to mark falls primarily on the provider of the AI system, meaning whoever built the generator, rather than on the hotel that used it. If you generate an image inside a tool, the obligation to mark that image is largely the tool’s.

That does not leave a hotel with nothing to think about, for two separate reasons.

A second rule covers the party publishing

Where content is a realistic depiction of people or events that did not happen, the party deploying it carries a disclosure duty of its own. A stylised render of a room is not that. A convincing photograph of a terrace your property does not have starts to look like it.

The same answer engines that will one day read these labels already describe your hotel to guests today, and you can see what they say with Hostli’s AI visibility check.

The older exposure has not gone anywhere

Consumer protection and misleading advertising rules already prohibit selling a stay on a picture of something the guest will not find when they arrive. That exposure predates the AI Act, applies whether or not the image is marked, and is the one most likely to actually reach a hotel.

What the marking physically is

The standard is Content Credentials, an industry specification usually referred to as C2PA. A signed manifest is embedded in the file itself, recording that the image was generated and by what. It travels with the file, and it can be stripped, deliberately or accidentally, by tools that rewrite an image on upload.

Marking is therefore a disclosure mechanism rather than a tamper-proof one. An unmarked image is not proof that nothing generated it.

Hostli signs every generated image and video with Content Credentials, and the rest of what we do and do not let a model touch is set out in our AI and acceptable use policy.

Three questions worth putting to your tools

  1. Do the images your tools and your agency produce carry the marking at all? Most cannot answer this yet, and the answer starts to matter as platforms surface these labels to guests.
  2. Do you have any record of which images in your library are AI-touched? Background extension, object removal and sky replacement are all in scope conceptually, and most hotels have never written any of it down.
  3. Would you be comfortable if the label were visible to a guest? That question needs no legal advice, and if a marking on one of your images would embarrass you, the problem was never the marking.

Limits

This describes the shape of the obligation as it stands before the provisions apply, and the detail of enforcement is not settled. Nothing here is a substitute for advice on a specific property’s exposure, and the consumer protection point is the one that would reach a hotel first in practice.

Designed for the modern hotelier

Run your entire digital footprint from your phone. We work with a small group of boutique hotels. Apply for access and we'll be in touch personally.