The rapid adoption of generative AI tools, such as ChatGPT, without adequate safeguards could lead to significant privacy breaches. According to van Roon, this trend represents not only a legal risk but also a major threat to the trust hotels have built with their guests over the years.
As hotels continue to experiment with AI, Ireckonu emphasizes that the use of public AI models poses serious security concerns. These tools, like ChatGPT, are not designed to handle sensitive guest data, such as names, preferences, and booking histories. If this information is uploaded into public AI systems, it could be exposed to external servers, often located in jurisdictions with weaker privacy laws. This data could potentially be stored or used to train future models, leading to significant privacy risks and regulatory fines under stringent laws like the General Data Protection Regulation (GDPR).
AI Risks: How Guest Data Could Be Exposed
The core issue lies in the nature of public AI platforms, which are typically not built to secure sensitive data. When hotel staff or systems upload guest data—whether it’s booking history, personal preferences, or payment information—into platforms like ChatGPT, that data could be processed by external servers. These servers, which are often located in regions with weaker privacy protections, might store the data indefinitely, putting it at risk of being exposed or misused.
In the worst-case scenario, sensitive guest information could be used to train future AI models, which may inadvertently contribute to privacy breaches. Under laws such as the GDPR, which governs data protection across Europe, this could lead to significant fines and reputational damage for hotels. The fines for non-compliance with GDPR can reach up to 4% of a company’s global turnover, highlighting the severity of the risks involved.
Hotels, especially those with international guests, could face severe consequences for using public AI models without the necessary privacy safeguards. This makes it essential for hotel groups to reconsider their approach to AI integration.
The Solution: Secure Internal AI Models
Ireckonu’s solution to this problem is the use of internal or private AI models that are securely integrated into a hotel’s existing infrastructure. By training AI models within the hotel’s own ecosystem, hotels can benefit from AI-driven personalization and automation without jeopardizing guest privacy or violating data protection regulations.
Van Roon suggests that hotels must invest in secure infrastructure that ensures data is kept within the property’s secure environment. This includes training staff on proper AI use and implementing internal policies that govern how guest data is handled and processed. By choosing secure internal systems, hotels can ensure they remain compliant with privacy laws, such as GDPR, and avoid external risks associated with public AI tools.
One of the safer alternatives, as highlighted by van Roon, is the use of tools like Microsoft Copilot, which can be securely integrated into a hotel’s internal systems. These models allow hotels to leverage AI-driven automation while keeping guest data private and secure, protecting them from the risks associated with using public AI platforms.
Industry-Wide Standards Needed
Ireckonu calls for the hospitality industry, technology providers, and regulators to take proactive steps in creating clear global standards and guidelines for the use of AI in the hotel sector. The company believes that a collective effort is needed to establish best practices for AI usage, ensuring that hotel groups can adopt new technologies without compromising guest privacy.
“Hotels must lead by example, ensuring accountability for both technology providers and themselves. We cannot wait for a privacy scandal to trigger change. The industry must act now,” van Roon emphasized.
By establishing industry-wide standards, Ireckonu aims to guide hotels in making informed decisions about AI adoption while minimizing risks to privacy and regulatory compliance.
What Hotels Can Do: Quick Guidelines to Protect Guest Data
To help hotels navigate these privacy challenges, Ireckonu offers a set of practical steps that can be taken immediately to safeguard guest data:
-
Adopt Private AI Models: Invest in internal AI models that can be securely integrated with hotel systems to process guest data. Tools like Microsoft Copilot can offer a safer alternative to public AI tools.
-
Train Staff on Privacy Policies: Ensure hotel staff are well-trained on data privacy policies and the proper handling of guest information when using AI tools.
-
Use Secure Infrastructure: Hotels must invest in secure, private cloud services to store guest data, ensuring compliance with privacy regulations like GDPR.
-
Establish Internal Policies for AI Use: Create clear, documented policies outlining how guest data can be used with AI, ensuring data protection is always a priority.
-
Regular Audits and Assessments: Conduct regular security audits and privacy assessments to ensure that all AI tools used comply with current data protection laws.
Impact on Business and Leisure Travel
The use of AI in the hospitality industry holds great promise for improving efficiency, personalization, and customer experience. However, it also poses significant risks if not handled responsibly. For business travelers and tourists alike, knowing that their data is secure is critical in maintaining trust and loyalty to hotel brands.
If hotels fail to implement proper safeguards, both business and leisure travelers could be exposed to risks. Travelers are becoming increasingly aware of data privacy concerns, and any incidents involving breaches could significantly damage a hotel’s reputation. Therefore, protecting guest data not only ensures legal compliance but also strengthens relationships with customers, promoting long-term business success.
Conclusion: A Call for Action in the Hospitality Industry
As AI becomes more integrated into the hospitality industry, it’s crucial for hotel groups to take proactive steps to protect their guests’ privacy. Ireckonu’s warning highlights the risks of using public AI models like ChatGPT with sensitive guest data and emphasizes the need for secure, internal AI systems. By investing in secure infrastructure and adopting industry-wide standards, hotels can mitigate risks, ensure compliance, and protect the trust they’ve built with their guests.

