EU AI Act · in force since 2 August 2026

Do you have to label AI content? For a restaurant, mostly no.

Three cases actually matter — and the text you wrote with ChatGPT isn't one of them. This page walks through every AI use a restaurant really has, one at a time, in plain English. Start with whether the rules reach you at all.

First things first

Does this even apply to you?

The AI Act is EU law, but "I'm not in the EU" is not the end of the sentence. Article 2 extends it to businesses established outside the Union where the output produced by the AI system is used in the Union. That is a wider net than most people expect.

Inside the EU

Ireland, Malta, Cyprus, and every other member state. It applies directly. No national law needed for the obligations themselves.

Outside, EU guests

A London hotel restaurant advertising to German tourists. A Zurich bistro with a booking bot serving EU visitors. You are closer to scope than you think.

Outside, local only

A neighbourhood diner in Ohio. The AI Act does not reach you — but your own country's rules on misleading ads and fake reviews absolutely do.

The honest test. Ask whether the AI output — the image, the chatbot reply, the ad copy — ends up in front of someone in the EU as part of how you do business. If yes, plan as though the Act applies. If no, skip to the section for everyone else, because the rest of this page still tells you what a regulator in your own country would say about the same content.
The short answer

Three sentences and you know where you stand.

Text: no

Menu copy, social posts, review replies, job ads — written with AI and read over by you. No label needed.

Photorealistic images: yes

An AI image that looks like a real photograph of your plate, your room or a person. That one has to be marked.

Chatbots and AI phone: yes

If a machine is talking to your guest, the guest has to know. One sentence at the start does it.

Self-check: do I need a label?

Three to five questions. Runs entirely in your browser — nothing is stored and nothing is sent.

Based on Article 50 of Regulation (EU) 2024/1689 as interpreted in the European Commission's FAQ of 24 July 2026. Orientation, not legal advice — for a borderline case, ask a lawyer.

What this is

One article. Not the whole Act.

The EU AI Act is a large piece of law and most of it has nothing to do with you. The bulk of it governs high-risk systems — AI in medical devices, in large-scale recruitment, in law enforcement. For a restaurant, exactly one article matters: Article 50, the transparency obligations. It has applied since 2 August 2026.

Worth knowing, because it is being reported badly: the Digital Omnibus that entered into force at the end of July 2026 did push several AI Act deadlines back. It moved the high-risk obligations to late 2027 and 2028. It did not touch the deployer duties in Article 50. If you have read that AI labelling was delayed, that is wrong. (One technical deadline did move, and it belongs to the tool vendors: providers who put a generative system on the market before 2 August 2026 have until 2 December 2026 for the machine-readable marking. Nothing changes for you.)

The distinction everything hangs on

Provider or deployer?

The Act defines two roles, and nearly every misunderstanding comes from mixing them up.

A provider builds the AI system and puts it on the market: OpenAI, Google, Canva, Midjourney. Providers have to mark their outputs in a machine-readable format so software can later detect them as AI-generated. That is Article 50(2), and it is not your job. You do not need to embed anything in a file, add watermarks, or manage metadata.

A deployer is you: someone using an AI system in the course of business. Deployers are covered by Article 50(4), which is short. It contains exactly two duties — one for image, audio and video, one for text.

The one-liner: you are a guest in the system, not the manufacturer. The tool handles the technical marking. Your only job is telling the human in front of you what they are looking at — and only in the cases where they would not otherwise notice.
Case by case

Your restaurant, gone through properly.

This is the part worth printing out. Every AI use that actually comes up in a restaurant, with a clear verdict.

Text

What you're doingLabel?Why
Menu copy, dish descriptionsNoNot a matter of public interest in the legal sense — and you read it over.
Instagram, Facebook, TikTok postsNoMarketing your own business is outside the text obligation. But only the text. An AI image in the same post is judged separately — see the table below.
Replies to Google reviewsNoYour own reply, approved by you. But writing reviews is a completely different matter — see below.
Job adsNoSame principle. Separately, watch the wording for discrimination law — different topic.
Guest newslettersNoAs long as it’s about your business. Turn it into a nutrition or sustainability column and the bottom row applies.
Translating your menuNoIt’s text, so the image rule can’t apply at all — and it isn’t public-interest text either.
Website copy, "About us"NoSame reasoning.
Blog posts on allergens, nutrition or hygieneDependsHealth is a matter of public interest. If you publish this kind of thing, read it over properly and put your name to it — then the exemption applies and no label is needed. Publishing it unread is the one text case that flips.

The reason so much of this is green is the wording itself. The text duty covers text published with the purpose of informing the public on matters of public interest. The Commission's FAQ spells out what that means: politics and democratic processes, public administration, justice and law enforcement, fundamental rights, public security, public health, environmental protection, consumer safety, and any economic, financial, political, scientific or cultural developments that could be a relevant subject of public debate. Your daily special is none of them. Note that this is a list of examples, not a closed one — anyone publishing regularly on nutrition or sustainability should look twice.

And even if a text did fall inside, the exemption follows immediately: no duty where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. The Commission is explicit that a spellcheck does not count — it has to be a real look at the substance. Which is what you already do before hitting publish.

Images, video, audio

What you're doingLabel?Why
Photorealistic AI image of a dishYesLooks like a real photo of something that could exist. That is the definition.
AI image of your dining room or terraceYesSame — and separately risky under advertising law if it flatters reality.
AI-generated people: "guests", "team", "chef"YesThe clearest case there is. Photorealistic people who don't exist.
Real photo, AI-enhancedDependsColour, light, cropping: no, that's assistive editing. Retouching in a dish that wasn't there, or filling a half-empty room: yes.
Illustration, cartoon, clearly stylised graphicNoNobody would take it for a photograph. The "falsely appears authentic" element is missing.
Background patterns, abstract decorationNoDoesn't depict anything that could exist.
AI voiceover in a promo videoDependsAn obviously synthetic narrator: fine. A cloned voice of a real person: yes — and you need their consent too.
AI music in a reelNoOutside the deep-fake definition as long as it isn't imitating anyone.

The Act calls this a deep fake, and the word misleads — it sounds like political videos, but the definition is sober: content that resembles existing persons, objects, places, entities or events and would falsely appear authentic. The Commission’s guidelines break that into three tests that must all hold — close resemblance, something that exists or could plausibly exist, and the false impression of authenticity. A photorealistic burger that never came out of your kitchen ticks all three. Photorealism alone isn’t decisive, though: the Commission looks at the whole picture — resemblance, message, context and what the audience expects.

The point most people miss: there is no "but I checked it myself" exemption for images. The editorial-review carve-out sits only in the paragraph about text. With images, your only protection is that they are visibly artificial — or a label.

The paragraph does soften the duty for evidently artistic, creative, satirical or fictional works. Don’t lean on that as a business: the Commission reads it narrowly for advertising, and where informative and creative elements mix, the informative character prevails. An ad photo stays an ad photo.

When AI talks to your guest

What you're doingLabel?Why
Website chatbotYesDirect interaction with a person. Must be clear from the first exchange.
AI answering Instagram or WhatsApp messagesYesSame — and more sensitive, because a guest expects a human there.
AI taking bookings by phoneYesOne sentence at the start of the call. Not only when asked.
Voicemail greeting recorded with an AI voiceNoNo interaction, no dialogue — nothing is answering.
Cameras reading guests' mood or ageYes — and moreEmotion recognition carries its own information duty on top of data protection law. Leave it alone until someone has reviewed it properly.

Strictly, the chatbot duty falls on the provider of the system first. That helps you very little in practice: your logo is on the page and the guest comes to you. The exemption only bites where it is obvious anyway, judged by a reasonably well-informed, observant person. A chat window with a human name and a profile photo is the opposite of obvious.

Everything that stays internal

What you're doingLabel?Why
Analysing supplier invoicesNoNot published. Neither duty is triggered.
Rotas, food cost, pricing calculationsNoSame.
Training material for the teamNoInternal. Tell them anyway, out of fairness.
Emails to suppliersNoNot published to the public.

The whole internal side is clear. Which is also where AI actually saves a restaurant money — and precisely there, no labelling question arises at all.

The three red cases

How to actually write it.

The Act prescribes no fixed wording. It requires the disclosure to be clear and distinguishable, no later than the first interaction or exposure, and perceivable without any special tools. A metadata entry expressly does not count — a human has to be able to see or hear it.

Images

On the image itself, not three paragraphs below it, and not buried in a caption that Instagram collapses. What works:

Wording that holds up
Created with AI
AI-generated image
Illustrative image, AI-generated
Image: AI-generated

On social, put it visibly in the image or at the very start of the caption. Instagram and Facebook also have their own AI flag you can set on upload — useful, but it does not reliably replace your own disclosure, because it renders differently depending on where the post is seen.

Chatbot

First line in the window, before the guest types:

Opening message
Hi! I'm the digital assistant at [name] — an AI, not a person.
I can help with opening hours, bookings and questions about the menu.
If you'd rather speak to someone from the team: [phone number].

That last line isn't legally required, but it saves you guests. People who realise they're talking to a machine usually want to know immediately how to get out of it.

Phone

Call opening
Hello, this is the automated booking assistant at [name].
I'm a voice system. What date would you like to book?

Deliberately at the start, deliberately in one sentence. Push it to the end and you have technically complied while annoying the guest anyway.

If you don't

What can actually happen.

This is where the internet exaggerates most, so here are the numbers straight. Article 99(4) sets the ceiling for Article 50 breaches at 15 million euro or 3 percent of total worldwide annual turnover, whichever is higher. That is the figure in the headlines.

Paragraph 6 of the same article reverses it for small and medium enterprises: there, the lower of the two applies. For a business turning over two million euro, the ceiling is 60,000 euro. Still real money — but a different order of magnitude from what compliance vendors are currently advertising, and it is a worst-case maximum, not a standard penalty.

One caveat almost every article omits: that only holds if you actually are an SME. The EU definition applies — under 250 staff and turnover no more than 50 million euro — and linked enterprises count towards it. A restaurant owned by a larger group or chain can fail that test, and then the higher figure applies again: 15 million. It’s a cliff edge, not a sliding scale.

Enforcement is national and uneven. Germany named the Bundesnetzagentur at the end of July 2026 and it runs a free AI service desk aimed explicitly at small businesses. Spain has AESIA, though its national AI law was still a bill in Congress as of August 2026. France and Austria had not formally designated an authority at all. That does not mean the obligations aren't in force — they are, everywhere — only that who knocks on the door varies.

Outside the EU

UK, US and everywhere else.

United Kingdom. No AI Act, and no general legal requirement to disclose AI in advertising — the ASA's position is that the existing rules apply regardless of how content was made. What bites instead is misleadingness. An AI image of a dish that doesn't reflect what you serve is a CAP Code problem exactly as a heavily retouched photo would be, and the ASA has been blunt that labelling something as AI does not cure a fundamentally misleading message.

The sharper regime is the Digital Markets, Competition and Consumers Act, in force since April 2025. Fake reviews are explicitly banned — writing them, commissioning them, hiding incentivised ones — and AI-generated reviews are fake reviews. The CMA can now decide infringements itself, with penalties reaching 10 percent of global turnover. That is a far bigger number than anything in the AI Act, and it is aimed squarely at exactly the thing some restaurants are tempted to use AI for.

Switzerland. Not an EU member, no AI act in force. The Federal Council decided in 2025 to ratify the Council of Europe AI convention and adjust sector rules rather than write a Swiss AI Act; a consultation draft is expected around the end of 2026. What applies today is unfair-competition law — the ban on misleading statements, which needs no AI-specific rule — plus guidance from the data protection commissioner that manipulating an identifiable person's face or voice must always be clearly recognisable.

United States and elsewhere. No federal labelling duty. State law varies and moves fast. The constant everywhere is that consumer protection authorities treat a misleading image as a misleading image, whatever made it — and that fake reviews are enforced hard.

The practical upshot for everyone outside the EU: the AI Act's list of red cases is a good checklist regardless, because it maps almost exactly onto what your own regulator would call misleading. And if any part of your business touches EU guests, the Act may reach you directly through Article 2 in any case.
The biggest misconception

"Anything made with AI has to be labelled."

That sentence is wrong, and it does damage. It makes operators either stop touching AI out of fear, or stamp "AI-generated" under every piece of copy as a precaution — which makes them look worse than they need to.

The Act does not ask was AI used here? It asks is someone being misled about something they ought to know? That is why the drawn image is free and the photorealistic one isn't. Why the chatbot is covered and the invoice analysis isn't. And why the ad copy you read over yourself needs no label — you're putting your name to it, exactly as you did when an agency wrote it for you.

The honest summary: if you use AI to work faster and a human looks at it before it goes out, you're fine. If you use AI to show something that doesn't exist, say so.

Free guide: getting started with AI Social media guide
Prompt of the month

One tested prompt a month — free.

Drop your email in: you get the setup and your first prompt straight away. After that, one more each month that we've tested first — plus a heads-up when rules like this one change.

No spam, no data selling. Unsubscribe any time with one click.

When the labelling story went round the restaurant groups, two people stopped using AI altogether — not because they'd done anything wrong, but because nobody could tell them what the rule actually was.

bridge. — built out of a two-year study with 26 restaurant managers worldwide. Founded by Nikolaus Gugenberger: 14 years a restaurant manager, founder of simply-olivia.com (a product of All You Can Reserve Ltd).

FAQ

Questions, answered.

Do I have to label text I wrote with ChatGPT?

Almost never. The text duty only covers text published to inform the public on matters of public interest — politics, justice, health, environment, consumer protection and the like. Menu copy, captions and review replies are none of those. And even then the duty falls away once a human reviews the content and takes editorial responsibility for it.

Do I have to label AI-generated photos of my food?

If the image looks like a real photograph and shows something that could plausibly exist — your dish, your dining room, a person — then yes. An obviously drawn illustration doesn't count, because nobody would mistake it for a photo. Note there is no human-review exemption for images.

Does my chatbot have to say it's AI?

Yes, unless it's obvious at a glance. One sentence at the start of the conversation is enough. Same for an AI answering the phone.

I'm not in the EU. Does this apply to me?

It can. The Act reaches businesses outside the Union where the AI output is used in the EU. A restaurant marketing to EU guests, or running a booking bot that serves them, is closer to scope than it looks. Purely local trade isn't caught — but your own rules on misleading ads and fake reviews still are.

When did this start?

2 August 2026. The Digital Omnibus of late July 2026 delayed several AI Act deadlines but expressly not the Article 50 transparency obligations.

What are the penalties?

Up to 15 million euro or 3 percent of worldwide turnover, whichever is higher. For SMEs the lower of the two applies — so 60,000 euro for a business turning over two million, as a worst-case ceiling. That assumes you meet the EU definition of an SME — linked enterprises count, so a restaurant inside a larger chain falls back to the higher figure.

Can I use AI to write Google reviews?

Replies to reviews: yes, no label needed. Reviews themselves: never. Fake reviews are banned independently of the AI Act and are enforced far harder than a missing label — in the UK, with penalties up to 10 percent of global turnover.

Not legal advice. This page reflects the position as at 19 August 2026 and is intended as orientation. It draws on the text of Regulation (EU) 2024/1689, the European Commission's FAQ on Article 50 of 24 July 2026, and published guidance from national authorities. We are not lawyers. For a borderline case — and especially before investing in an AI phone system or camera analytics — get a proper legal view.