Applied AI

The Risk of Unchecked Innovation: Navigating the New Reality of AI Regulation

By Ed Richards,

The prevailing narrative surrounding Artificial Intelligence often focuses on the 'arms race' for adoption. In the events and hospitality industry, the pressure to modernise operations is intense. However, a critical oversight is emerging: the belief that AI regulation is a future problem rather than a present reality.

For leadership teams, understanding the intersection of digital infrastructure and global compliance is now a strategic necessity.

The Myth of the Regulatory Horizon

Many organisations operate under the impression that AI is currently a 'wild west' and that rules will be codified in several years. This is a misunderstanding of the legal landscape.

For any business operating in the UK or Europe, the framework for AI governance is already established. The EU AI Act is active, impacting any organisation that provides or uses AI systems within the EU market. Simultaneously, the UK GDPR remains the standard for anyone processing personal data, regardless of whether that processing is done by a human or an algorithm.

What many designate as 'experimentation' is, in the eyes of regulators, 'processing'.

High-Risk Exposure Points

Regulatory exposure often hides in standard operational workflows. In our industry, three areas are particularly vulnerable:

**Internal Strategy and Data Leakage**
Using public LLMs (Large Language Models) to summarise confidential client contracts or draft sensitive internal strategies often inadvertently places proprietary data into the public domain, violating both privacy laws and client NDAs.

**Automated Human Resources**
Using AI to screen CVs for event staffing or to automate hiring decisions is now subject to strict transparency requirements. If a candidate cannot be told exactly how an algorithm assessed them, the employer is at risk.

**Behavioural Profiling**
Analysing attendee data to predict future booking patterns is a staple of modern hospitality. However, when AI performs this profiling without a clear 'human-in-the-loop' or explicit data consent, it may breach current protection standards.

Speed vs Infrastructure

The competitive advantage in 2026 will not belong to the companies that adopted AI the fastest. It will belong to the companies that built the sturdiest guardrails.

Modernisation requires more than just new tools; it requires a sophisticated digital infrastructure that accounts for data sovereignty and ethical AI use. Leadership teams must shift their focus from 'what can this tool do' to 'how does this tool fit into our compliance framework'.

Practical Steps for Governance

To mitigate risk, directors should consider the following:

1. Conduct an audit of all 'shadow AI' currently used by staff.
2. Implement formal policies on the input of sensitive data into third-party tools.
3. Consult the UK Information Commissioner’s Office (ICO) guidelines on AI and data protection to ensure current workflows are compliant.

Innovation is essential for growth, but it must be sustainable. In the current regulatory environment, the most confident move a leader can make is to pause, assess, and build with purpose.

More insights