No AI policy — staff already using tools on their own

Reception translates guest emails with ChatGPT, the chef has menus written, reservations pastes enquiries — names included — into a tool, and nobody ever decided it should be this way.

Typical for: family businesses with a young team · houses without an IT lead · operations where digitalisation is the boss's job but nobody has time for it

Documented by Hospis

Updated: 6 September 2026

How you recognize it

  • There is no written rule on what may and may not be entered into an AI tool
  • Staff use private accounts because there are no company ones
  • Guest correspondence is copied one-to-one into a tool for translating or drafting
  • AI does not appear in the record of processing activities
  • Whoever uses a tool well keeps it to themselves — there is nowhere to share it
  • The question “are we actually allowed to do this?” has been asked and never answered

Matching Hospi

JW

Josef Walch

Digitalisation · AI in operations · Systems — Lech am Arlberg
Works with protel · Mews · Mews POS · Smart Host
AdviseImplement

Puts rules before tools: a one-page policy, two data categories, company accounts and one owner — from hands-on AI practice in hotel operations.

Mapped to root cause
One-page policyTwo data categoriesCompany accountsOwnership
View profilePersonally vetted · independent match

Which path fits your situation?

01

Diagnosis

390 € fixed price

A vetted Hospi analyses your situation in a structured way — in conversation and with a written result. Every statement clearly labelled: FACT, BENCHMARK, HYPOTHESIS or CONCLUSION. You get a concrete path, not a sales meeting.

  • A legitimate outcome is also: no engagement needed.
  • If an engagement follows, the diagnosis fee is fully credited.
02

Urgent support

Acute situation? Your case is reviewed with priority — response within 48 hours.

Cause fields — how to tell them apart

The problem is not that the team uses AI. The problem is that it does so without a frame — and the frame is missing because nobody set it, not because it would be hard.

These fields are complete, and many properties get there on their own — that is what this page is for. The cost simply does not appear on an invoice: internal hours, a few attempts, and a season that keeps running in the meantime.

01

Use came before the decision

How you spot it

The tools arrived via private phones, not via a purchase. There was never a moment when someone had to say yes or no — so nobody said anything.

The way out

A one-page policy: which tools are allowed, on which account, what is never entered, who decides when in doubt. No handbook. One page, read and signed by the team.

02

Data protection is seen as a brake, not a rule

How you spot it

The GDPR question gets asked, then postponed, because the answer seems complicated. Meanwhile guest data keeps flowing — arrivals, allergies, complaints, names.

The way out

Two categories are enough to start: personal guest data never goes into a tool without a data processing agreement. Everything else — copy, menus, translations without names — is fine. That one distinction resolves most cases.

03

There are no company accounts

How you spot it

Because the house provides no access, everyone uses their own. Chat histories containing guest data sit on private accounts — and leave the business with the person who leaves.

The way out

A company account for the tools the house permits, with settings that exclude training on your own data. Access is granted and revoked like PMS access — and documented in the same place.

04

Nobody owns it

How you spot it

Digitalisation is the boss's job, and the boss is in season. Questions from the team pile up and go unanswered. Whoever experiments does so alone.

The way out

One person in the house owns the policy, answers questions and reviews the tool list once a quarter. Since February 2025 the EU AI Act requires that staff using AI are trained for it anyway — without an owner, that does not happen.

Frequently asked

Should we simply ban AI?
A ban moves use onto private phones and makes it invisible. Permitting with rules is safer than banning without control.
Do we need a data protection officer for this?
Whether a house needs one depends on size and data processing. Regardless, it needs a rule on who may enter what, and a contract with the tools that see guest data. That is operational work, not legal work.
What goes on the one page?
Permitted tools and accounts. What is never entered. Who decides when in doubt. Where good uses get shared. Nothing more — anything longer does not get read.

Describe your situation

The problem context is automatically included — you do not need to repeat anything.

Problem
No AI policy — staff already using tools on their own