AI Risk Depends on the Use, Not the Tool

All Insights

AI Governance

AI Risk Depends on the Use, Not the Tool

·4 min read
AI GovernanceArtificial IntelligenceHospitality Technology

The same AI tool could help a hotel generate ideas for a restaurant promotion, translate a serious guest complaint or summarise employee records. The product may be the same, but the purpose, data, people affected and possible consequences are completely different.

One tool can create several different risks

Consider three hotel examples.

A marketing employee asks an approved AI tool for ideas based on public information about the hotel. The employee checks the facts and rewrites the result before publication. The use is likely to require only routine oversight. The information is public, the output is easy to review and the AI is not making a decision about a person. That does not make the output automatically accurate or free from copyright and brand risks. It means the possible impact is limited and the controls can be proportionate.

A manager uses the same tool to translate a complaint involving a guest's name, booking details and health information. The risk has changed. Personal and potentially sensitive information is involved. A translation error could change the meaning of the complaint or the hotel's response. The manager also needs to know whether the tool is approved for that data and how the provider handles it.

HR uses an AI feature to rank CVs and recommend which applicants should be interviewed. This is a different category again. The system may materially influence access to employment. Bias, data quality, transparency, explainability and meaningful human review all become important. Certain AI uses in employment can be classified as high-risk under the EU AI Act, depending on their intended purpose and the detailed classification rules.

Calling all three uses "ChatGPT" or "generative AI" tells us very little about the actual risk.

Describe the use before trying to classify it

A useful description should answer six questions:

1. What is the system being used to do?

2. What data does it receive or access?

3. Whose interests could be affected?

4. What output, recommendation or action does it produce?

5. How much influence does that output have?

6. What does a human review before anything happens?

This is why an AI Use Register should record separate use cases rather than only listing products. "Microsoft Copilot" is a tool entry. "Summarising weekly management meetings containing employee and commercial information" is a use case that can be assessed.

Intended purpose matters

Under the EU AI Act, classification is tied closely to a system's intended purpose and the context in which it is used. High-risk classification can arise where an AI system is a safety component of certain regulated products or falls within specified use cases listed in Annex III, including some employment and worker-management uses.

The legal assessment is more precise than saying that anything used in HR is automatically high-risk. Article 6 also contains conditions under which an Annex III system may not be treated as high-risk when it does not materially influence decision-making or pose a significant risk of harm. Profiling of individuals is treated differently.

The European Commission published draft high-risk classification guidance in May 2026 with practical examples. The draft status matters. It is useful guidance, but not a substitute for checking the final rules and the circumstances of a particular system.

A practical rule for hotels

Whenever a new AI feature appears, write one sentence:

We use [system] to [purpose], using [data], to produce [output], which is reviewed by [person] before [effect].

If the sentence is vague, the hotel is not ready to approve the use.

If the sentence changes, reassess it. A tool approved for public marketing ideas is not automatically approved for guest complaints, employee data or automated decisions.

Start with visibility

AI risk management does not begin with a complicated scoring model. It begins with an accurate description of what is happening.

List the use. Identify the data. Understand who could be affected. Describe the role of the output and the reality of human review.

Only then try to classify the risk.

Phare IQ helps independent hotels build practical visibility and control over their AI use, including use registers, risk triage, staff guidance and supplier reviews.

This article provides general information, not legal advice or a legal classification of any particular system. Regulatory information was checked against European Commission and EUR-Lex sources on 4 August 2026 and should be rechecked before later reuse.

P

Phare IQ

Product strategy, workflow consulting, and practical AI adoption for SaaS founders and hospitality technology leaders.

Thinking about AI governance for your hotel?

If you want a clearer view of where AI is being used, which uses deserve closer attention and what practical controls may be needed, Phare IQ can help you build a proportionate starting point.

Get in touch