Skip to main contentSkip to footer

    Top Rated & Verified

    Top Clutch App Development Company Black Owned United StatesTop Clutch Java Developers France 2026Top Clutch Service Line Blind Company Black Owned 2026Top Clutch App Development Company Minority Owned 2026Top Clutch Web Developers Black Owned 2026Top Clutch App Development Company Black Owned 2026Top Clutch Flutter Developers France 2026Top Clutch Health & Wellness App Developers France 2026Top Clutch Swift Company France 2026Top Clutch Machine Learning Company France 2026Top Clutch Chatbot Company France 2026Top Clutch Artificial Intelligence Company France 2026Top Clutch App Development Company Minority Owned Los Angeles
    Back to Blog
    AI Agents
    August 23, 2026
    32 min read

    Top 10 AI Agents forHotels and Resorts in 2026

    Every other ranking of this category scores accuracy, deflection and ROI. Every one of those numbers is published by the vendor about itself. So this ranking scores only what an owner can re-check from a browser — pricing, integrations, compliance, ownership — and then spends the rest of its length on the four rules that decide whether any of it is legal to run.

    AI agents for hotels and resorts in 2026 — guest messaging, concierge and booking agents ranked on verifiable attributes
    3 of 14
    Hotel AI vendors that publish a price on their own site — HiJiffy, Duve and Visito. Every other cell in our table reads “not publicly disclosed”
    Frenchy Digital review of fourteen vendors' own pricing pages, checked 2026-08-23; Asksuite's pricing URL returned HTTP 404
    50 req/s
    Oracle Hospitality Integration Platform throttling ceiling — per gateway, and shared by every integration on it. Excess is rejected with HTTP 429
    Oracle, OPERA Cloud Hospitality Integration Platform documentation, “Limits” (retrieved 2026-08-23)
    $10,000
    Maximum California civil penalty per violation for advertising a room rate that excludes required fees, or omitting taxes from the total before a guest reserves
    Cal. Bus. & Prof. Code §17568.6(e), added by AB 537 (Stats. 2023, Ch. 805); operative 1 July 2024
    $16.86
    Median hourly wage of a US hotel, motel and resort desk clerk — $35,070 a year, base only. The honest denominator for any AI payback claim
    US Bureau of Labor Statistics, Occupational Employment and Wage Statistics, May 2025, SOC 43-4081

    Key Takeaways

    • Every competing ranking of hotel AI scores accuracy, deflection or ROI. Every one of those figures in this market is published by the vendor about itself, so we scored only what an owner can re-check from a browser in an hour — and we say in the text what we refused to score.
    • Three of the fourteen vendors we checked publish a price on their own site: HiJiffy, Duve and Visito. Every other cell reads “not publicly disclosed,” and we never estimate. Aggregator figures from software directories are not vendor-published prices.
    • Article 50 of the EU AI Act was not delayed. The Digital Omnibus entered into force on 27 July 2026 and deferred only the high-risk obligations — Annex III to 2 December 2027 and Annex I to 2 August 2028. Article 50 transparency applied on 2 August 2026 and binds guest-facing hotel agents today.
    • The FTC junk fees rule regulates disclosure, not the existence of resort fees — and California is stricter. 16 CFR §464.1 permits excluding government charges from “total price,” but Cal. B&P §17568.6(a)(2) requires taxes and government fees to be inside the total price before the guest reserves, at up to $10,000 per violation. An agent tuned to the federal floor is non-compliant in California.
    • FTC v. Hopper, D. Mass. 1:26-cv-13058: complaint filed 2 July 2026, Stipulated Order entered by the court on 20 August 2026, $35 million. Six counts, but only Count VI is a Fees Rule count under §464.2(c) — and it is pleaded on short-term lodging, which is why it reaches hotels.
    • Alliants is the only vendor in this market that publishes a human-in-the-loop boundary, and it does so by disclaiming autonomy outright: staff approve, edit or replace before sending, and no message reaches a guest without a human decision. That is a vendor conceding, in its own words, the question every competitor's marketing dodges.
    • The best-documented failure mode in this vertical is not the agent. Oracle's OHIP throttles to 50 requests per second per gateway, shared by every integration on it, bursting to 100 and then rejecting with HTTP 429 — so a chatty agent degrades your other tools, not itself.
    • Oracle shipped OPERA Cloud Assistant on 16 June 2026 at no additional cost to OPERA Cloud customers worldwide — but it is staff-facing only. There is no guest-facing concierge in it, which is exactly why this third-party market still exists.
    • The roster is the trap. Quicktext is now Quinta; OpenKey went to Canary and Easyway to Duve, both in January 2026; Whistle went to Cloudbeds, NAVIS to Revinate, and Dack and STAYmyway to Operto. None of those may be listed as standalone vendors in 2026.
    • Frenchy Digital bands: discovery and workflow audit $9k–$22k; single-workflow agent $28k–$70k; multi-workflow platform with system integration $70k–$180k; enterprise, multi-site or regulated build $180k–$420k+.

    The Claim Under Test

    Every ranking of hotel AI you will read this year is built on numbers nobody outside the vendor has ever checked. Open five of them and the shape repeats: a product automates 97% of guest messages, deflects 80% without handoff, delivers 23x ROI, triples conversion against the website. Those are printed as though they were measurements. They are not measurements. They are marketing assertions about the seller, published by the seller, with no methodology, no denominator, and no published definition of the word being measured.

    The claim under test in this article is narrow: can an independent hotel owner rely on any published performance figure in this category?After opening every vendor's own pricing, product, integration and trust pages on 23 August 2026, our answer is no — and the useful consequence is that you should stop trying. Rank on what you can verify from a browser and a contract, put the performance question into your RFP as a written commitment rather than a number you read on a homepage, and measure the thing yourself, at your own property, with your own guests.

    That is not a counsel of despair. It turns out that when you score only checkable attributes, the table separates sharply — and it separates along lines that no competing listicle reports. Three vendors publish a price; eleven do not. One vendor publishes a human-in-the-loop boundary; thirteen do not. Two vendors publish anything at all about the European transparency regulation that started binding their product three weeks before this was published. One vendor rebranded in January and is still listed under its dead name across most of the internet.

    The single best piece of evidence in this market is a vendor disclaiming autonomy. Alliants states on its own Allin AI product page that staff approve, edit or replace before sending, and that no message reaches a guest without a human decision. That is a hospitality AI vendor voluntarily conceding, in writing, the exact question every competitor's marketing dodges. Read it next to the accuracy claims and ask which one is describing the same product category.

    There is a second reason to distrust the figures, and it comes from a regulator rather than from us. In January 2025 the Securities and Exchange Commission entered a settled order against a drive-thru voice AI company over exactly this kind of number, finding that the product lacked the capability to take orders on its own and required substantial human involvement, and that people abroad processed the vast majority of orders. That order is discussed in detail in the restaurant edition of this series — see our ranking of the top AI agents for restaurants in 2026 — and the framing there matters: the company consented without admitting or denying the findings, the remedy was a cease-and-desist order with no civil penalty, and the findings run against that company only. It is not evidence that any hotel vendor is doing the same thing. It is evidence of what happened the one time anyone with subpoena power actually audited a published AI performance metric in hospitality-adjacent technology.

    This piece sits inside a wider set of vertical rankings built on the same method; the cross-industry version, with the same refusals applied to general-purpose tools, is our guide to the top AI agents in 2026. What follows is the hotel edition: what we scored, what we would not score, ten vendors in order, four constraints that decide whether any of it works, and the parts we could not verify.

    How We Ranked, and What We Refused to Rank On

    We scored eight attributes, every one of which you can re-check from a browser in under an hour. That constraint is the entire method. If an owner cannot independently confirm a cell in our table, the cell does not belong in a ranking — it belongs in a sales deck.

    What we scored — every attribute re-checkable by the reader

    • Documented public integrations — named systems on the vendor's own site, with a docs URL, not a count with no directory behind it
    • Whether the vendor publishes compliance documentation on its own trust page, and at what level of specificity
    • Pricing transparency — a published amount versus “contact sales”
    • Whether the product is standalone or locked to a suite, and whether choosing it means replacing your property management system
    • Ownership and corporate status from the public record: dated funding announcements, completed acquisitions, redirects, footers
    • Whether any independent evaluation of the product exists
    • Data residency, retention and DPA availability as published, not as promised in a call
    • Whether the vendor publishes any statement about the EU AI Act transparency obligations that started applying on 2 August 2026

    We refused to score accuracy, deflection, containment, resolution rate, ROI, hours saved, RevPAR lift and conversion.Not because they do not matter — operationally they are the only things that matter — but because every published figure in this market is self-reported by the seller and there is no neutral party checking any of them. Printing one vendor's deflection rate beside another's in a comparison table implies a common measurement standard. There is no common standard, and there is not even a common definition: one vendor's automated conversation may be a conversation a guest abandoned.

    Metric we refused to scoreWhy it is unusableWhat we scored instead
    Accuracy or automation rateSelf-reported by the seller, with no published definition and no neutral party checking. The one time a US regulator audited such a figure in an adjacent market, it did not surviveWhether the vendor publishes any human-in-the-loop boundary at all. Exactly one does
    Deflection or containment rateThe denominator is chosen by the vendor. A conversation the guest abandoned can be counted as containedNamed, documented integrations on the vendor's own site, which decide whether the agent can see the data it would need
    ROI multiples and cost savingsOne vendor publishes a 23x average ROI figure on its homepage with no methodology. Another publishes a payback period on a pricing page that carries no price, so the buyer cannot compute the denominatorPublished pricing, which three of fourteen vendors provide, and the BLS wage the saving is implicitly measured against
    RevPAR, conversion and direct-booking liftNo methodology, no control group, no named sample in any instance we found. The direct-booking claim is also structurally unfalsifiable as usually stated, because it books commission against zero and ignores the acquisition cost of the direct channelWhether the vendor publishes a DPA, data residency and retention terms, which are contract facts rather than performance claims
    Awards and “#1 for the Nth consecutive year”Hotel Tech Report awards are user-review popularity awards. Laundering one into a benchmark is the precise error this method exists to refuseOwnership and corporate status from the public record: dated funding announcements, completed acquisitions, and a 301 redirect

    Two refusals are worth naming individually, because they are the cleanest illustrations available. A large Brazilian vendor publishes a 23x average ROI figure on its homepage with no methodology, no sample and no definition of return. And a major PMS publishes, on the same pricing page that declines to publish a price, a claim about payback in as little as seven months. A payback period whose denominator the vendor will not disclose is not a number. It is a marketing asset shaped like a number, and no buyer can compute it.

    We also refuse the third-party aggregator prices that circulate for this category. Software directories carry figures for several vendors here, quoted per room, per user or per year. Those are not vendor-published prices, they are not attributed to a source document, and printing one would launder a directory's guess into a fact. Where a vendor declines to publish, the honest cell reads not publicly disclosed, and we never estimate.

    Methodology block — how to re-check every cell yourself. Date checked: 23 August 2026. Method: we opened each vendor's own pricing, product, integration and trust pages directly and recorded what rendered, including HTTP status codes where a page failed; we pulled corporate status from dated funding announcements, completed-acquisition press releases and one HTTP 301 redirect; we pulled statutory and regulatory text from the eCFR, the Federal Register, California's own legislative site, the FCC document archive and the European Commission; we pulled platform limits from Oracle's own documentation; and we pulled wage and turnover figures from the Bureau of Labor Statistics. Where a page returned 404, 403 or would not resolve, the cell says so. We never estimate a price. To re-check: open the vendor URL in the sources list, look for a published number, and note the date you looked. If your result differs from ours, the vendor changed the page — which is itself worth knowing.

    On benchmarks, stated precisely. No independent benchmark of these hotel products exists — no head-to-head evaluation of Canary, Duve, HiJiffy, Asksuite, Akia, chatlyn or any other vendor here has been published by a party that is not selling one of them. That is a narrow claim and we hold it narrowly. The nearest thing to independent measurement in adjacent hospitality is the Intouch Insight study released with QSR Magazine on 1 October 2025, which mystery-shopped quick-service drive-thru lanes and found AI-enabled orders 83% accurate against an 87% study average, reaching 95% only when staff intervened. That study measures drive-thru ordering in restaurants, not hotel guest messaging, and it identifies brands rather than vendors. We label the transfer explicitly rather than borrowing its authority. It is not a hotel benchmark; it is simply the only place anyone has measured this modality against a human baseline, and the result points the opposite way from the marketing.

    What Oracle Did to This Market in June

    On 16 June 2026 Oracle announced new AI capabilities inside OPERA Cloud, and its own release states that all these capabilities are available today at no additional cost to OPERA Cloud customers worldwide. Most rankings of this category published since then do not mention it, which is a reasonable proxy for how carefully they were built. It changes the competitive picture, and it changes it in a specific direction that an independent operator needs to read correctly.

    What shipped is the Oracle OPERA Cloud Assistant: natural-language access to operational knowledge, hotel procedures and Oracle documentation; AI-assisted room assignment drawing on reservation details, guest preferences and stay history; AI-generated rate code descriptions; and AI translation of configuration and operational content, supporting operations across 230 countries and territories. Oracle's framing throughout is about empowering associates.

    It is staff-facing, not guest-facing. There is no guest chatbot and no guest concierge in OPERA Cloud Assistant. That is precisely why the third-party guest-messaging market still exists — and it is also why any vendor selling a staff copilot into an OPERA property now has to explain why it beats free. If your shortlist includes a product whose main pitch is helping front-desk staff find an answer faster, and you run OPERA Cloud, that is the first question to ask.

    The second reading is the one that applies to most people holding this article. OPERA is the enterprise-brand property management system — Oracle's release notes that Wyndham has more than 2,100 properties running on OPERA Cloud. An independent hotel or a small group is far more likely to be on Mews, Cloudbeds, Apaleo, StayNTouch, RoomRaccoon or Little Hotelier, in which case none of this reaches you at no cost or at any cost. Do not let the headline imply otherwise.

    One more note on quotation discipline, since this is a market where vendor language gets reprinted as fact. Oracle's release also carries productivity and efficiency language — faster decisions, increased productivity. That is marketing, and we quote the capability rather than the benefit. The cost sentence is a capability statement and we quote it; the productivity sentences are claims and we do not.

    The Comparison Table

    Every cell below is either a citation you can open or the words “not publicly disclosed.”Nothing here is estimated, inferred from a directory, or taken from a vendor's claim about a competitor. Where a vendor's page returned an error, the cell records the error, because a 404 on a pricing page is itself a finding about how the vendor sells.

    Vendor (checked 2026-08-23)What it actually isPublished pricingCompliance published on its own trust pageNamed integrations on the vendor's own siteOwnership of record
    1. MewsA property management system with an AI layer — not an add-on agentNot publicly disclosed. Essentials, Advanced and Enterprise tiers, each behind a “Get Pricing” formSOC 2 Type 2, ISO/IEC 27001:2022, PCI DSS v4.0.1, NF525, GDPR, CCPA, an EU AI Act entry, plus a PCI DSS Shared Responsibility Matrix and named subprocessors — the deepest disclosure in this tablePublic Connector API docs with no login; scope includes reservations, rates, payments, bills and customer messaging, with webhooksMews Systems B.V., Amsterdam. $300M Series D announced January 2026 led by EQT Growth at a reported $2.5B; fourteen acquisitions to date
    2. HiJiffyGuest communication hub — conversational AI across webchat, WhatsApp, social and booking assistancePublished to the euro: Basic from €99/mo, Pro from €159, Premium from €319, Enterprise custom, with setup stated per five properties. These are floors that scale with rooms and bedsNot publicly disclosed — the /security URL returned HTTP 404 on the day we checkedChannel coverage is described; we found no canonical named-system integration directory to citeIndependent, Lisbon, Portugal, founded 2016, roughly 66 employees as of 30 June 2026. Funding totals conflict across sources, so we print none
    3. DuveGuest-experience platform: pre-arrival, online check-in, upsells, unified messaging, AI agentsPublished as minimums: Basic $120/mo, Pro $150, Premium $200, Enterprise custom, labelled “Minimum package” and described as modularISO/IEC 27001, ISO/IEC 27701 and SOC 2 Type II, all three named on its own security page. PCI DSS is not mentioned; no DPA, residency or retention statement on that pageNot enumerated as a named-system directory on the pages we checkedIndependent, Tel Aviv. $60M Series B announced 9 December 2025 led by Susquehanna Growth Equity; acquired Easyway in January 2026
    4. Canary TechnologiesGuest management suite: contactless check-in, digital authorisations, upsells, messaging, AI voice, mobile keyNot publicly disclosed. Core, Advanced and Pro tiers, each with a “Get Quote” buttonSOC 2 Type 2 and PCI DSS (version not stated), plus a Record of Processing Activities and an EU AI Act transparency compliance statement — unusual disclosure for this market. No ISO 27001, no residency or retention statementPMS-agnostic with integrations; no canonical named list cited on the trust centreCanary Technologies Corp., San Francisco. $80M Series D June 2025 led by Brighton Park Capital; acquired OpenKey, finalised January 2026
    5. chatlynAI communication hub: unified inbox across WhatsApp, email, Booking.com, Instagram and webchatNot publicly disclosed — one plan, quoted per property, and the vendor explains on the page why it declines to publish a numberNo SOC 2 or ISO 27001 located. It does publish architecture claims: EU-hosted AI, personal data masked before processing, no direct external LLM connection, per-account isolation, an audit log for every external AI call, EU AI Act disclosure to guests, and a DPA in the contract. Disclosed but unauditedNative integration claimed with Oracle OPERA Cloud, Mews, apaleo, Guestline and CASABLANCA — a named list, which is worth more than an unnamed countIndependent, Vienna, Austria, founded late 2022. €8M Series A led by Smedvig Ventures, with an FFG innovation grant
    6. AkiaGuest messaging and text platform with AI, marketed with genuine autonomy languageNot publicly disclosed. Basic, Pro and Max tiers with no amountsA Security footer link exists; contents not verified this pass. Treat as not publicly disclosedThe strongest named list we found: 18+ PMS platforms including Oracle Opera, Mews, Cloudbeds, Apaleo, Guesty, Escapia, Hostaway, WebRezPro, Hospitable, Infor HMS, OwnerRez, Maestro, Hostfully and Clock PMSIndependent, San Francisco, founded 2018 by Evan Chen. Last funding Series A, 9 September 2024. Legal entity not disclosed on the site; 2026 trading inferred from a live site, not proven by a dated item
    7. CloudbedsPMS, channel manager and booking engine; the messaging and AI lineage comes from WhistleNot publicly disclosedPCI DSS certification stated as validated by VikingCloud, with the statement that it does not store card data and uses a third-party tokenised vault. The supporting article returned HTTP 403 to automated fetch, so we mark it unverified. SOC 2 and ISO 27001 not locatedPublic developer docs covering REST and GraphQL, credentials by approval, plus a machine-readable llms.txt index — genuinely good for an integratorIndependent, San Diego, founded 2012. No funding round since a $150M Series D on 3 November 2021; acquired Whistle on 27 June 2022
    8. AlliantsExperience platform — messaging, concierge, guest app, trip planning — with an AI layer branded Allin AI, which the vendor describes as a copilot rather than an autonomous agentNot publicly disclosedISO 27001 certified by BSI Group, shown in the footer. A Trust Center exists; SOC 2 not shown on the product pageNone named. The product page states Allin AI is built natively within the platform rather than through external APIs — which means locked to the suite. Score it that wayAlliants Ltd, Locks Heath, England, founded 2009, roughly 89 employees as of May 2026
    9. Quinta (formerly Quicktext)Conversational assistant Velma — now Velma Works, Velma Knows and Velma Plays — repositioned toward structured hotel data and AI visibilityNot publicly disclosed. A “Rates” nav link exists but renders no figuresNot verified this passA partnership with IDS Next was announced under the old company name; we did not verify its current statusIndependent — this was a rebrand, not an acquisition. quicktext.im returns HTTP 301 to quinta.im. Legal entity not disclosed; the site lists contact offices in fourteen countries, which are offices rather than incorporation
    10. AsksuiteAI reservation assistant and omnichannel CRM across WhatsApp, Instagram, Facebook, email and webchat, plus AskFlow AgentsNot publicly disclosed — the /pricing/ URL returned HTTP 404 on 23 August 2026Not publicly disclosed — no security or compliance page locatedClaims 400+ booking engine integrations with no named systems and no documentation URL. Under this methodology an unnamed count scores as undocumentedIndependent, Curitiba, Brazil. No acquisition located

    Read the pricing column first, because it is the column that most changes a small operator's day. Three of the fourteen vendor names we checked publish a price at all. HiJiffy publishes tier floors in euros, dollars and pounds, with setup fees stated per five properties. Duve publishes minimum package amounts. Visito publishes a credit-metered ladder — and Visito is the vendor we could not rank, for reasons in the next section. Everyone else asks you to book a call before you can find out whether the product is in your budget range at all.

    Read the compliance column second, and read it for specificity rather than for logos. There is a real difference between a trust page that says PCI DSS and one that says PCI DSS v4.0.1 and publishes a shared responsibility matrix. Only one vendor here does the latter. And be alert to a trap this method has caught repeatedly in other verticals: a vendor citing a certification that belongs to its cloud hosting provider rather than to its own legal entity. Before you credit any compliance cell, confirm the certificate names the vendor.

    The Ten, in Order, and the Four We Would Not Rank

    The order below reflects how much a buyer can verify before signing, not how good the AI is. We have no way to score how good the AI is, and neither does anyone else writing a ranking of this category. Each entry states what the product does, what is verifiable, what is not disclosed, who it fits, who it does not, and who owns it.

    1. Mews — the deepest disclosure in the market, attached to the largest commitment

    What it is: Mews Systems B.V. of Amsterdam sells a property management system with payments and an AI layer on top. It is not an agent you bolt onto an existing stack.

    What is verifiable: more than for anyone else here. Its trust centre names SOC 2 Type 2, ISO/IEC 27001:2022, PCI DSS v4.0.1, NF525 French fiscal certification, GDPR, CCPA and an EU AI Act entry, and it publishes a PCI DSS Shared Responsibility Matrix, a named subprocessor list including Twilio, Datatrans, Salesforce, Google and Microsoft Azure, DPA availability and cyber insurance. Its Connector API documentation is public with no login, covering reservations, customers, rates and availability, bills, payments, customer messaging and webhooks. Ownership is on the record: a $300M Series D announced in January 2026 led by EQT Growth, with Atomico and HarbourVest joining existing investors, at a reported $2.5B valuation.

    What is not disclosed: price. Essentials, Advanced and Enterprise each sit behind a contact form.

    Who it does not fit, and say this out loud: anyone looking for an AI add-on. Choosing Mews as your AI answer means replacing your property management system, which is a six-to-twelve-month operational project, not a chat deployment. That is the difference between a decision measured in hundreds of dollars a month and re-platforming the hotel. Also weigh the roll-up honestly: fourteen acquisitions to date means product lineage and support quality vary by component. That is a public, checkable fact and a legitimate buyer risk, not a criticism.

    2. HiJiffy — the only vendor an independent can budget against without a sales call

    What it is: a guest communication hub out of Lisbon, founded 2016 — conversational AI across webchat, WhatsApp, social channels and booking assistance.

    What is verifiable: the number. Its pricing page publishes Basic from €99 per month, Pro from €159, Premium from €319 and a custom Enterprise tier, each with a setup fee stated per five properties, with annual billing discounted. These are floors that scale with rooms and beds, and we print them as floors rather than as what it costs. In a market where eleven of fourteen vendors gate the number entirely, that single act of publication is why HiJiffy ranks second on a verifiability method.

    What is not disclosed:compliance. The security URL returned HTTP 404 on the day we checked, so we record no SOC 2, no ISO and no PCI status. Funding is contradictory across sources — one aggregator reports a total under $7M, another reports the company as self-funded, and the company's own release announces €3.8M — so we print no total raised. Deployment counts also conflict between sources, so we print no hotel count either.

    Who it fits: the independent operator who needs to know whether a product is in range before spending an hour on a demo. Who it does not fit: a group whose procurement requires a current SOC 2 report, until that page reappears.

    3. Duve — the strongest privacy certification set, and a published floor

    What it is: a Tel Aviv guest-experience platform covering pre-arrival flows, online check-in, upsells, unified guest messaging and AI agents.

    What is verifiable: its security page names ISO/IEC 27001, ISO/IEC 27701 and SOC 2 Type II. ISO 27701 is the privacy information management extension, and almost nobody else in this list holds it — for a group with a European data-protection posture that is a genuine differentiator rather than a badge. Pricing is published as minimum package amounts of $120, $150 and $200 per month across Basic, Pro and Premium, with Enterprise custom. Ownership is dated: a $60M Series B announced 9 December 2025 led by Susquehanna Growth Equity.

    What is not disclosed: PCI DSS is not mentioned on that security page, and there is no DPA, residency or retention statement on it. The published amounts are labelled minimums for modular plans that stack, so the headline is a starting point rather than a quote.

    One roster note: Duve acquired Easyway in January 2026. Easyway must not appear as a standalone vendor in any 2026 ranking, and if you see it in one, you have learned something about that ranking. Duve also publishes a roadmap of additional specialised agents for housekeeping, maintenance and guest services. That is a roadmap, not shipped capability, and we do not describe it as existing.

    4. Canary Technologies — the most complete regulatory disclosure, minus the price

    What it is: Canary Technologies Corp. of San Francisco sells a guest management suite: contactless check-in, digital authorisations and e-signature, upsells, guest messaging, AI voice and mobile key.

    What is verifiable: its trust centre lists SOC 2 Type 2 and PCI DSS, with a penetration test report and network diagram available behind a portal request. More interestingly, it publishes a Record of Processing Activities and an EU AI Act Transparency Compliance Statement. Two vendors in this entire market publish anything about the regulation that began binding guest-facing agents on 2 August 2026, and this is one of them. Ownership is on the record: an $80M Series D in June 2025 led by Brighton Park Capital, and the acquisition of OpenKey, finalised January 2026. OpenKey is therefore not an independent vendor, whatever any 2026 listicle says.

    What is not disclosed: price, ISO 27001, the PCI DSS version, and any data residency or retention statement. The PCI point is worth dwelling on — PCI DSS as a bare phrase is a materially weaker claim than PCI DSS v4.0.1 with a shared responsibility matrix, and a buyer should score the specificity rather than the logo. A widely reported valuation of around $600M circulates for the company; it is press-reported rather than filed, and we do not print it as fact.

    On autonomy:Canary markets AI Voice and AI Guest Messaging. The checkable claim is that this is a suite with AI features, not a single autonomous agent, and we found no public architecture documentation. We do not assert autonomy on the vendor's behalf.

    5. chatlyn — the most detailed architecture disclosure we found anywhere in this market

    What it is: a Vienna company founded in late 2022 selling an AI communication hub for hospitality — a unified inbox across WhatsApp, email, Booking.com, Instagram and webchat.

    What is verifiable: a named integration list — Oracle OPERA Cloud, Mews, apaleo, Guestline and CASABLANCA — which under this method is worth far more than a large unnamed count. Ownership is dated: a €8M Series A led by Smedvig Ventures, with angel participation and an FFG innovation grant from Austria's national R&D agency.

    What is disclosed but unaudited: a set of architecture commitments no competitor here publishes — GDPR-compliant processing under EU law, EU-hosted AI, personal data masked before processing, no direct external LLM connection, per-account isolation so customer data never mixes across properties, an audit log for every external AI call, a DPA that forms part of the contract, and explicit EU AI Act disclosure so guests are informed when AI replies. Score those honestly: they are architecture claims, not certifications, and we located no SOC 2 or ISO 27001. Disclosed-but-unaudited is still a great deal more than most of this list offers.

    What is not disclosed:price. chatlyn runs one plan quoted per property and explains on its own pricing page why it declines to publish a number — the honest answer depends on rooms, on the property management system and on how the implementation runs, so rather than publish a figure most properties would have to correct, it quotes against the actual setup. That is an unusually straight refusal, and it is a better answer than a directory's guess. Note that a software directory carries a per-year figure for chatlyn; that is not the vendor's price and we do not print it.

    6. Akia — the best named integration list, and an autonomy claim with nothing behind it

    What it is: a San Francisco guest messaging and text platform, founded 2018 by Evan Chen.

    What is verifiable: the integration list, and it is the strongest we found — 18 or more named property management systems including Oracle Opera, Mews, Cloudbeds, Apaleo, Guesty, Escapia, Hostaway, WebRezPro, Hospitable, Infor HMS, OwnerRez, Maestro, Hostfully and Clock PMS. A named list beats an unnamed count by a wide margin under this method because you can check it: open two of those PMS partner directories and see whether Akia appears. That takes ten minutes and it is exactly the kind of verification this article is arguing for.

    What is not disclosed: price, and the legal entity name. A security footer link exists but we did not verify its contents. The last funding we located was a Series A on 9 September 2024; the site is live with current customer logos and a working demo booker, but we found no dated 2026 item, so 2026 trading is inferred rather than proven. That is why it is sixth and not higher.

    The autonomy question, which matters here more than anywhere else in the table: Akia markets genuine autonomy — the agent answers guests herself, knows their reservation, and is configured through skills described as telling her the steps the way you would tell a coworker. Its service-recovery example describes the agent offering to make up for a problem. That is an agent making a goodwill concession, which is precisely the category that belongs behind human approval. Treat all of this as a claim rather than a verified capability: there are no architecture docs, no published human-in-the-loop boundary and no independent evaluation. Ask the vendor where the authority limit sits and get the answer in the contract, because it is not on the website.

    7. Cloudbeds — good documentation, the PMS caveat, and a capital-position fact worth knowing

    What it is: a San Diego platform founded in 2012 — property management system, channel manager and booking engine. Its guest messaging and AI lineage comes from Whistle, acquired on 27 June 2022, so Whistle is not a standalone vendor.

    What is verifiable: its developer documentation is public and unusually integrator-friendly — REST and GraphQL, credentials by request and approval, and a machine-readable llms.txt index with Markdown versions of documentation pages. Architecturally, its stated card-handling pattern is the right one: Cloudbeds says it does not store credit card information and connects to a third-party tokenised vault, with PCI DSS certification validated by VikingCloud.

    What we could not verify: that PCI article returned HTTP 403 to automated fetch on the day we checked, so we mark the compliance claim unverified rather than crediting it. SOC 2 and ISO 27001 were not located. Pricing is not published.

    One neutral, checkable fact:Cloudbeds has raised no round since a $150M Series D on 3 November 2021 — nearly five years. We state that as capital-position context next to Mews's $300M in January 2026, not as a solvency claim, and no solvency inference should be drawn from it. Same caveat as Mews on category: this is a PMS, so choosing it as your AI answer means re-platforming.

    8. Alliants — the honest one, and the reason this article has a thesis

    What it is: Alliants Ltd of Locks Heath, England, founded 2009, roughly 89 employees as of May 2026. The Alliants Experience Platform covers messaging, concierge, guest app and trip planning, with an AI layer branded Allin AI.

    What is verifiable, and it is the single most useful sentence any vendor in this market publishes: Alliants describes Allin AI as a copilot rather than an autonomous agent, on its own product page.

    Staff approve, edit, or replace before sending. No message reaches a guest without a human decision.

    Alliants, Allin AI product page, alliants.com/products/allin-ai (read 23 August 2026)

    Set that beside the deflection and automation percentages published elsewhere in this category and the contrast does the argument for us. One vendor is telling you where the human is. The others are publishing a number that only makes sense if there is no human, and declining to say whether there is one.

    What is not disclosed: price, and any named third-party integration. The product page states that Allin AI is built natively within the Alliants platform rather than bolted on through external APIs — which means it is locked to the suite, and we score it that way. ISO 27001, certified by BSI Group, appears in the footer; SOC 2 is not shown on the product page.

    Who it does not fit: realistically, the independent hotel reading this. Alliants is an enterprise and multi-property luxury group product. We rank it eighth because it discloses the most important thing and the least commercial detail, and because most readers of this article will not be the buyer.

    9. Quinta, formerly Quicktext — the roster trap, and the test for every other ranking you read

    What it is: the company behind the conversational assistant Velma, now split into Velma Works, Velma Knows and Velma Plays, and repositioned toward structured hotel data and AI visibility — being findable and quotable by AI assistants — rather than pure chatbot.

    What is verifiable, in about thirty seconds:quicktext.im returns an HTTP 301 Moved Permanently to quinta.im, and the new site describes itself as Quinta, formerly Quicktext. This was a rebrand, not an acquisition, and reporting it as a sale would be its own error. Use it as a test: any 2026 ranking that still lists Quicktext as a current product name has not opened the vendor's own site this year, which tells you what the rest of its roster is worth.

    What is not disclosed: nearly everything else. Price is gated behind a Rates link that renders no figures. Compliance was not verified. The legal entity is not stated on the site; the footer lists contact offices across fourteen countries, which are offices and not incorporation. A partnership with IDS Next was announced under the old company name, and we did not verify its current status.

    10. Asksuite — the widest gap between what is claimed and what is disclosed

    What it is: a Curitiba, Brazil company selling an AI reservation assistant and omnichannel CRM across WhatsApp, Instagram, Facebook, email and webchat, plus a product line called AskFlow Agents marketed as autonomous for booking, check-in and check-out, promotions and surveys.

    What is verifiable: corporate independence — we located no acquisition. That is close to the whole list.

    What is not disclosed: the pricing URL returned HTTP 404 on 23 August 2026. No security or compliance page was located. The integration claim is 400+ booking engine integrations with no named systems and no documentation URL, which under this method scores as undocumented — an integration count without a directory behind it is not a verifiable integration, it is a number. No public architecture or API documentation was found to substantiate the autonomy claim, so we treat autonomy as marketing until documents appear.

    Two claims we refuse to reprint: a 23x average ROI figure on the homepage, which is exactly the category this method excludes; and a run of consecutive Hotel Tech Awards wins presented as evidence of product quality. Those awards are user-review popularity awards. They may well reflect happy customers, and they are not an independent benchmark, and laundering one into the other is the precise error this ranking exists to correct.

    Considered and not ranked: four names appear on most competing lists and are not in our table, and the reasons are worth as much as the table. A vendor we cannot confirm still trades in 2026, under a name we can attach to a legal entity, does not get ranked — because the first thing a ranking owes a buyer is that the companies in it exist as described.

    Revinate — a CRM with AI features, not an agent

    Revinate of Palo Alto, founded 2009, is a hotel customer data platform and CRM with email marketing, voice reservations and direct-booking tooling. It is independent and Serent Capital-backed, and it merged with NAVIS in July 2021, keeping the Revinate name — so NAVIS is not a standalone vendor either. We leave Revinate out of a top-ten AI agents table not because it is weak but because it is a different product category, and an entry that did not say so would mislead. Its published customer and revenue-influenced figures are vendor marketing and we do not reprint them.

    Operto — trading in 2026, but the entity is undisclosed and the AI product is a different category

    Operto Guest Technologies sells contactless check-in, smart access control, digital guidebooks and staff operations, and its footer carries a 2026 copyright, so 2026 trading is evidenced. It acquired STAYmyway in 2022 and Dack in 2024 — sources disagree on the month for Dack, so we print none — meaning neither is a standalone vendor. Two things keep it out of the ranked table: the legal entity and headquarters are not stated on the site, and its AI product, Operto ONE, is marketed around OTA visibility rather than guest service. That is a different category from the rest of this list, and comparing them in one table would be a category error. Pricing is not published.

    Visito — publishes pricing, which is rare; corporate identity we could not establish, which is disqualifying

    Visito sells a WhatsApp, Instagram and Messenger AI agent for hotels, and it launched an AI Bookings capability letting guests search, book and pay inside the conversation. It is one of only three vendors here that publishes a price, and its model is materially different from everyone else's: credit-metered rather than per-room, so an agent that handles more conversations costs more. For a seasonal resort that inverts the usual unlimited-support pitch and is worth modelling before you sign. But we could not establish the legal entity, country, ownership or funding, and under this method unconfirmed corporate identity keeps a vendor out of the ranked table. We state the gap rather than quietly ranking it.

    There is also a design point here that applies well beyond one vendor. An agent that takes payment inside a WhatsApp thread is the highest PCI-scope design in this entire category. The questions to ask are exactly two: how is the card captured, and does the primary account number ever enter the message store? We located no compliance page for Visito, so neither question is answered publicly. And its published performance claims — automating over 97% of guest messages, reducing support costs by up to 90%, deflecting more than 80% without handoff, tripling conversion against web bookings — are the clearest single example in this market of the category we refuse. Every one is vendor-published and unsourced.

    Nomi — we could not find it

    No 2026 hotel AI vendor trading under the name Nomi was located in this pass; the name collides with several unrelated products. We do not assert that it shut down or never existed. We assert only that we could not confirm it trades in this market, which under our own rule means it does not go in the table. If you have been shown it in a shortlist, ask for the legal entity name and the product URL before anything else.

    The acquisitions that must not appear as standalone vendors in any 2026 hotel AI ranking: OpenKey, acquired by Canary Technologies in January 2026; Easyway, acquired by Duve in January 2026; Whistle, acquired by Cloudbeds in 2022; NAVIS, merged into Revinate in 2021; Dack and STAYmyway, both acquired by Operto; and DataChat, acquired by Mews. Ranking an acquired product under its dead independent name is the error that gets an article dismissed by exactly the operator it was written for.

    The Binding Constraint: What Your Agent May Say About Price

    The thing that decides whether any of this works is not the model. It is that a hotel AI agent quoting a rate is making your offer, and there is now a federal rule and a stricter California statute governing what that offer must contain. No vendor safe harbour exists. The FTC would name the business that offered the room, not the chat vendor that rendered the sentence.

    The Trade Regulation Rule on Unfair or Deceptive Fees, 16 CFR Part 464, was published at 90 FR 2166 on 10 January 2025 and took effect on 12 May 2025. Section 464.1 defines a covered good or service to include short-term lodging — temporary sleeping accommodations at a hotel, motel, inn, short-term rental, vacation rental or other place of lodging. It defines total price as the maximum total of all fees or charges a consumer must pay, plus any mandatory ancillary good or service, except that government charges, shipping charges, and fees for optional ancillary items may be excluded.

    Section 464.2(a) makes it an unfair and deceptive practice to offer, display or advertise any price of a covered good or service without clearly and conspicuously disclosing the total price. Section 464.2(b) requires the total price to be disclosed more prominently than any other pricing information. Section 464.2(c) requires disclosure, before the consumer consents to pay, of the nature, purpose and amount of any excluded fee, and of the final amount of payment. And §464.3 prohibits misrepresenting a fee's nature, purpose, amount or refundability.

    Two errors are epidemic in secondary coverage, and both would misdirect an operator. The rule does not ban resort fees; a mandatory resort, destination or amenity fee remains lawful if it is inside the up-front total price and honestly described. And taxes do not have to be in the federal headline number; §464.1 expressly permits excluding government charges from total price, subject to disclosure before consent.

    There are two provisions written for exactly the technology this article is about. The clear-and-conspicuous definition at §464.1 states that in any communication using an interactive electronic medium — the internet, a mobile application, or software — the disclosure must be unavoidable. And an audible disclosure, including by telephone, must be delivered at a volume, speed and cadence sufficient for ordinary consumers to easily hear and understand it. A voice booking agent that recites a total price at machine pace is inside that sentence. So is a chat agent that puts the total behind a “see details” expander.

    California is stricter, and this is the most useful sentence in the article

    Cal. Bus. and Prof. Code §17568.6, added by AB 537 and operative 1 July 2024, requires taxes and government fees to be inside the total price before the guest reserves. Subsection (a)(1) bars advertising, displaying or offering a room rate that does not include all fees required to stay, except taxes and government fees. Subsection (a)(2) then closes the gap the federal rule leaves open: the place of lodging, platform or any other person must include in the total price to be paid, before the consumer reserves the stay, all taxes and fees imposed by a government on the stay.

    Read those two side by side and the operational consequence falls out. An AI booking agent tuned to the federal floor is non-compliant in California. The federal rule lets you keep tax outside the headline; California does not, once the guest is at the point of reserving. And FTC §464.4 expressly preserves stricter state law — a state statute affording greater protection is not inconsistent with the rule — so the two obligations stack rather than one displacing the other. Section 17568.6(f) says the same from the California side: the duties are cumulative with other law.

    Three further details matter for configuration. Section 17568.6(c) treats California tourism assessments and business-improvement-district assessments as government fees, which is a useful precision — a California Tourism Assessment is not a resort fee and should not be presented as one. Section 17568.6(d) reaches advertising made before the public in California or from California before the public in any state, so a California-hosted agent quoting a guest in Nevada is inside the statute. And §17568.6(e) sets a civil penalty not exceeding $10,000 per violation, enforceable by a city attorney, district attorney, county counsel or the Attorney General. That is per violation, it is a California civil penalty rather than an FTC fine, and it should not be rounded.

    FTC v. Hopper — the enforcement pattern your upsell agent is built to reproduce

    Status first, because most write-ups got it wrong. In FTC v. Hopper (USA) Inc. and Hopper Inc., D. Mass., Civil Action No. 1:26-cv-13058, the complaint and a proposed stipulated order were filed on 2 July 2026, and the Stipulated Order for Permanent Injunction, Monetary Judgment and Other Relief was entered by the court on 20 August 2026, with a $35 million monetary judgment. Between those dates every secondary write-up said Hopper had agreed to pay, which is not the same thing as a judgment. The FTC's docket still shows the case status as pending, because the matter remains open for compliance.

    Count-level precision, because this is routinely overstated. The complaint pleads six counts. Five are Section 5 counts under the FTC Act — unfairly charging fees without express informed consent, misrepresentations about fees and charges, failure to disclose material information about a Tip fee, misrepresentations about VIP Support, and misrepresentations about Price Freeze. Only Count VI is a Fees Rule count, under 16 CFR §464.2(c). Saying the FTC sued Hopper under the junk fees rule, without that qualifier, overstates it.

    And the Fees Rule count is grounded in lodging, which is why an OTA case reaches this reader at all. Complaint paragraph 108 alleges that the defendants are businesses that offer, display, or advertise prices of short-term lodging, a covered good or service as defined by the Fees Rule at 16 CFR §464.1. Count VI is pleaded in connection with the defendants' short-term lodging booking services.

    The most operationally instructive allegation is paragraph 114, which alleges a failure to clearly and conspicuously disclose the nature, purpose and amount of the Tip fee at the end of the purchase flow, including that consumers could decline to pay it or pay a zero amount. That is a disclosure-at-the-end-of-flow failure— precisely the failure mode of a conversational upsell agent that mentions a charge after the guest has committed. The FTC's Bureau of Consumer Protection Director, Christopher Mufarrige, put the theory in one sentence: Hopper deceived consumers by showing them a total price that did not include hidden, pre-selected fees.

    Paragraph 107 of the same complaint is worth having in your pocket for any vendor conversation that suggests the rule went away: the Fees Rule became effective on 12 May 2025 and remains in full force and effect — the FTC's own words, in July 2026.

    One caveat on scope. Hopper is a travel app booking airfare, lodging and cars, not a hotel, and the brand-level attorney-general activity around resort fees over the past several years has run against large chains rather than independents. We are not going to print specifics on those settlements, because we did not verify them to the underlying orders, and an assurance of voluntary compliance is not a consent decree and neither is a judgment. The honest framing is that those actions are why the big brands' booking engines now show all-in pricing, which resets the expectation your agent is measured against — and revenue-management questions of the same shape are worked through in our guide to AI agents for hospitality revenue and dynamic pricing.

    EU AI Act Article 50 Is In Force Now

    If your property takes European guests, the transparency obligation applied on 2 August 2026 — three weeks before this article was published — and it binds your guest-facing agent today. The most common summary in circulation right now is that the EU delayed the AI Act to 2027. That summary is wrong for the only provision that reaches a hotel chatbot, and it is the kind of wrong an operator acts on.

    Here is what actually moved. The Digital Omnibus, in the European Commission's own words, entered into force on 27 July 2026, bringing extended timelines. It deferred the high-risk obligations: high-risk AI systems in Annex III now apply from 2 December 2027, and high-risk AI embedded in physical products under Annex I from 2 August 2028. Those two dates are real, and if you have been told the AI Act slipped, those are the obligations being described.

    The Omnibus did not defer Article 50. The transparency obligations applied on the original schedule, 2 August 2026. Article 50(1) requires that AI systems intended to interact directly with natural persons be designed and developed so that those persons are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person — and the information must be provided at the latest at the time of the first interaction. There is a narrow exception for systems authorised by law to detect, prevent, investigate or prosecute criminal offences. None of that describes a concierge bot. We paraphrase rather than quote here deliberately: the Official Journal text would not serve to us on the day we checked, and we do not present a mirror's wording as the regulation.

    Notice why the mistaken summary spreads so easily. The Commission's own omnibus announcement does not mention Article 50 at all — it is about the obligations that moved. Read quickly, an announcement about extended timelines reads as though everything moved. Nothing about the guest-facing transparency duty moved.

    There is one nuance an operator must not be talked out of. A hotel is normally a deployer of an AI system, not its provider, and the Article 50(1) design duty sits on the provider. It is therefore tempting for a vendor to say your vendor handles it. The practical consequence for you is different: the disclosure has to actually appear in the guest interaction, on every channel, and a hotel that configures it away — because it looks clumsy in the brand voice, or because someone removed it during a redesign — owns that outcome. Treat the disclosure as non-configurable and audit it quarterly by opening the widget as a guest. The engineering detail of doing this well, across chat, voice and email, is covered in our guide to engineering EU AI Act Article 50 transparency.

    This is also a scoring column no competing listicle has. Three vendors in this market publish anything at all about the regulation that started binding their product three weeks ago: Canary Technologies, with an EU AI Act Transparency Compliance Statement on its trust centre; chatlyn, which states that guests are informed when AI replies; and Mews, which carries an EU AI Act entry on its trust centre. Eleven do not. That is not proof the other eleven are non-compliant — it is proof that you will have to ask them, in writing, and that three of them have already answered.

    Cards, Recordings and Text Messages

    Three more constraints decide whether a hotel agent is deployable, and all three are about what the agent touches rather than what it says. Cards pull the messaging archive into payment-card scope. Voice pulls it into state recording law. Outbound messaging pulls it into the TCPA. None of these is exotic, and all three are routinely discovered after launch.

    PCI DSS v4.0.1 — the version question, and the two requirements nobody expects

    PCI DSS v4.0.1 is the only active version of the standard. It was released on 11 June 2024, replaced v4.0 on 31 December 2024, and made no changes to the requirements — it is a limited revision clarifying focus and intent. The part that matters operationally is that the 51 future-dated requirements introduced in v4.x became mandatory on 31 March 2025. Every assessment conducted in 2026 is against the full requirement set, and the transition period is over.

    Two of those requirements catch hotel AI projects specifically, and they concern payment pages rather than chatbots: an inventory and authorisation obligation for scripts loaded on payment pages, and a change-and-tamper-detection mechanism for those pages. Both were future-dated and are now mandatory. A chat widget or AI concierge script injected into your booking engine's payment page is in scope for both — which is the most-missed consequence of dropping a conversational agent onto a booking flow. A third requirement covers third-party service provider management: written agreements, acknowledgement of responsibility for cardholder data, and a documented responsibility matrix per provider. We cite the requirement numbering as summarised rather than quoting it, and you should confirm the exact wording against the PCI Security Standards Council document library before it goes into a policy.

    Never accept the phrase “we are PCI compliant.”Validation attaches to an entity, at a point in time, against a scoped environment. The buyer's question is whether the vendor will produce a current Attestation of Compliance, and at what level and SAQ type. Most hotel AI vendors publish SOC 2 and go quiet on PCI. In this table, exactly one names a version.

    The architectural line is simple and non-negotiable: an AI agent should never take a card number in free-text chat or over voice.The defensible pattern is a tokenised hand-off — the agent sends a PCI-scoped payment link or hosted field, and the card data never enters the language model's context or the transcript store. Any vendor that captures a primary account number in a message thread has put your entire messaging archive, its backups and its search index into scope.

    Recording consent — the provision that actually bites a reservations line

    Hotel AI voice agents transcribe by design, and a stored transcript produced by an automatic recording or processing device is exactly what state wiretap statutes reach. Roughly a dozen states require all-party consent, and the trackers genuinely disagree about which ones — the commonly listed set includes California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Oregon, Pennsylvania and Washington, with Nevada disputed and two states treating in-person and telephone conversations differently. We name no count as settled and neither should your vendor.

    California is the one to design against, because it is the most litigated. Penal Code §632(a) punishes intentionally recording a confidential communication without all parties' consent, and §632(b) makes explicit that a person includes a corporation, partnership, limited liability company or other legal entity. Section 632(c) then excludes communications made where the parties may reasonably expect the communication may be overheard or recorded — which is why the disclosure at the top of the call is the entire compliance mechanism rather than a courtesy.

    The provision most often missed is §632.7, which reaches the recording of communications transmitted between cellular or cordless telephones and landlines, and which contains no confidential-communication element at all. Guests call hotels from mobile phones. And §637.2 supplies a private right of action for the greater of $5,000 per violation or three times actual damages, with subsection (c) stating expressly that suffering or being threatened with actual damages is not a prerequisite. Statutory damages, no injury requirement, private plaintiffs. For a property taking a few thousand recorded calls a quarter, that arithmetic is what makes the disclosure line non-optional.

    Do not let anyone tell you California has fixed this. SB 690 passed the Senate 35–0 on 3 June 2025 and passed the Assembly Privacy and Consumer Protection Committee as amended on 1 July 2026, but as of 23 August 2026 it is not signed and not law — it still needs Assembly passage, Senate concurrence and the Governor's signature, and would be operative 1 January 2027 if enacted without an urgency clause. Its scope also narrowed in amendment toward attorney-general jurisdiction over pen-register and trap-and-trace claims arising from websites and apps, which would not obviously reach call recording at all.

    TCPA — and the waiver that would be catastrophic to misread

    FCC Declaratory Ruling 24-17, adopted unanimously and released 8 February 2024, holds that AI-generated voices are artificial voices under the TCPA, and it expressly refuses any carve-out for technologies that purport to provide the equivalent of a live agent. Callers need prior express consent, prior express written consent for marketing, identification and disclosure of the party responsible for the call, and an opt-out. An AI voice agent placing calls is squarely inside all of it.

    The trap that inverts the law: Insurance Marketing Coalition v. FCC (11th Cir., 24 January 2025) vacated only Part III.Dof a 2023 order — the one-to-one consent provision — and the court's own footnote states that the 2012 Order is not at issue. The prior express written consent requirement survives, and so does the artificial-voice classification. Anyone telling you the TCPA got easier for AI callers has read a headline rather than the opinion.

    The transactional-versus-marketing line is the whole ballgame for a hotel. A booking confirmation, a check-in link, a room-ready alert: informational. An AI upsell agent offering a paid upgrade: marketing, requiring prior express written consent rather than the consent implied by making a reservation. That is the single most common design mistake in hotel messaging deployments, and it is usually made by pointing one agent at both jobs.

    On revocation, get the scope of the waiver exactly right. The revocation rule at 47 CFR §64.1200(a)(10) is in force: if a called party uses any reasonable method to revoke consent, that consent is definitively revoked and the caller may not send additional robocalls or robotexts. FCC Order DA 26-12, adopted and released 6 January 2026, waives one narrow sub-part until 31 January 2027 — the requirement that a revocation made in response to one type of informational message be treated as applying to all future robocalls and robotexts from that caller on unrelated matters. That is the revoke-all carry-over, and it is the only thing waived. Writing that TCPA revocation has been delayed would tell an operator to stop honouring opt-outs, which is the single most damaging sentence available in this subject. A guest who texts STOP to a housekeeping thread has revoked, and the agent must stop — within ten business days. Build for the 2027 state now, because the waiver is temporary.

    A Worked Example: 140 Rooms, Two Channels

    This is an illustrative worked scenario, not a client result. No hotel described below exists. We build it from figures that are published and cited elsewhere in this article, because inventing a client outcome in an article that spends four thousand words refusing unsourceable vendor statistics would destroy its own standing. Every number here is either a published price, a Bureau of Labor Statistics figure, or arithmetic you can redo.

    The property. Consider a 140-room independent resort handling roughly 2,400 inbound guest messages a month across web chat, WhatsApp and SMS, plus about 1,100 inbound phone calls. It sells a mandatory $32 nightly resort fee. It takes European guests in summer. It is in California.

    The labour denominator, done honestly. The Bureau of Labor Statistics puts the median hotel, motel and resort desk clerk at $16.86 an hour, or $35,070 a year, in its May 2025 estimates, across 261,420 people employed nationally. That is base wage only — it excludes employer payroll taxes and any benefits. Now add the sleeper fact: average weekly hours in accommodation were 29.6 in June 2026. Accommodation is a part-time-heavy industry, so any vendor model that prices its savings against a 40-hour full-time equivalent is overstating the labour it displaces by roughly a quarter before it starts.

    The message arithmetic. Suppose each of those 2,400 monthly messages consumes a median four minutes end to end — reading, checking the reservation, answering, logging. That is 160 hours a month, 1,920 hours a year, or about $32,371 of base wage at the median. If an agent genuinely handles half of them without a human touching the thread, the notional saving is 960 hours, roughly $16,186 of base wage a year.

    Now the costs, using only published numbers. The lowest published subscription floor in our table that would plausibly cover this property is HiJiffy's Pro tier at €159 a month, with a setup fee stated per five properties — call it roughly $2,100 a year at the floor, before any scaling for room count. Set against a $16,186 notional saving, that looks like a landslide. It is not, and the reason is the line item vendors do not quote: integration. Connecting an agent to your property management system, your booking engine, your payment tokenisation and your knowledge base, then instrumenting it so you can measure it yourself, is our single-workflow agent band — $28k to $70k over four to nine weeks. On the low end, year one is net negative and the crossover lands early in year two.

    And here is the question the crossover conceals. Hours saved only become money when a shift disappears from the schedule. In an industry averaging 29.6 weekly hours, the shift usually does not disappear — the work gets reabsorbed, and the desk clerk who was answering WhatsApp now does something else that also needed doing. That may be an excellent outcome. It is not a cost saving, and it should not be modelled as one. The honest business cases we see in this vertical are built on three things instead: response coverage at hours when nobody is at the desk, consistency of answers when the person who knew the property left last quarter, and revenue from upsells that were previously never offered. Note that the third one is the one that carries all the fee-disclosure and TCPA exposure described above.

    The turnover point, stated precisely. The quits rate in accommodation and food serviceswas 4.5% in June 2026 — roughly one in twenty-two employees voluntarily leaving every month — against a job openings rate of 4.6% and total separations of 5.7%. That series is NAICS 72, which combines accommodation with food services and is dominated by restaurants; it is not hotels alone, and no hotels-only series exists. Say it that way. The reason it belongs in the business case is that it reframes the pitch honestly: the operator's problem is often not headcount cost but institutional memory walking out, which is a real argument for encoding knowledge in a system and requires no vendor statistic at all.

    Two figures we will not use, and you should not either. The claim that it costs five times more to acquire a guest than to retain one is sold alongside CRM and loyalty tooling in this exact market. Its origin was traced by Ipsos Loyalty, in a published excerpt from the book Loyalty Myths, to research conducted by the Technical Assistance Research Project in Washington, D.C. in the late 1980s that nobody can now produce — with several other consultancies claiming the same finding as their own, and credibility arriving via a 1990 Harvard Business Review article about service recovery. The same document says there is enough contrary information to bury or significantly qualify the truism, and closes by warning that a retention strategy based wholly on the myth is a recipe for financial disappointment. That is the firm that published it for years, retracting it in print. The second figure is any specific percentage for how much more profitable direct bookings are. We found no primary source for any of them, and the claim is structurally unfalsifiable as usually stated because it books commission against zero while ignoring metasearch bids, brand advertising, booking-engine fees, payment processing, loyalty discounts and the labour of running the channel. A direct booking bought with a 12% metasearch cost of acquisition is not commission-free. Write the arithmetic for your own property; do not print the statistic.

    The same discipline applies to OTA commission percentages. Every figure we surfaced in this market traces to a company selling hotels a way to reduce OTA commissions, which is textbook circular sourcing. If you need the number, read your own OTA contract — which is verifiable by you, and is the whole point of this method.

    Book a 60-Minute Hotel AI Discovery Call

    Bring your message volumes, your PMS name and your fee schedule. You leave with a channel baseline from your own data, a fee-disclosure and consent map for the states and countries you sell into, the two questions to put to every vendor in writing, and a fixed-price phased proposal within 5 business days.

    What Breaks First

    The first thing that breaks is usually not the agent. It is something else on the same integration gateway. This is the most useful technical fact in this vertical, it is documented by Oracle in public, and we have not seen it in a single competing ranking.

    Oracle's documented limits for the Hospitality Integration Platform state that API throttling permits up to 50 requests per second per gateway, shared by all consumers and clients accessing that gateway, with a short-term burst allowance to 100 requests per second, also shared. Excess requests are delayed; beyond the burst threshold they are rejected with HTTP 429. Read the word shared twice, because it carries the whole failure mode.

    Your AI agent competes for throughput with every other tool you have connected. A property running a messaging agent, an upsell agent, a review-response tool and a revenue management system through one gateway has them drawing on one budget. Add an agent that re-queries availability on every guest turn and you may not degrade that agent at all — you degrade the others, and the failure surfaces as HTTP 429s in a system nobody was watching, hours later, with no obvious cause. Instrument 429 rates per application key, not in aggregate, or you will not see it.

    Three more documented ceilings belong in any design review before you scale. Streaming API management is limited to 12 requests per minute, bursting to 100 per minute. Only one client may consume events from a single chain, in a single gateway, on a single application key — which turns two vendors both wanting the event stream into a straight architectural conflict rather than a configuration setting, and the symptom is an absence of events rather than an error. Streaming consumers must reconnect at least once every 24 hours or pass an offset, with a minimum of 10,000 milliseconds between closing and reopening a websocket. A maximum of 100 applications may be registered in the developer portal. And total HTTP header size is capped at 8 KB including the OAuth token and application key, which is small enough to matter once you are passing both. Oracle also notes it may adjust these thresholds as needed, so treat the numbers as current rather than permanent.

    There is a buying heuristic hiding in this. The two property management systems with the most open public documentation — Apaleo, whose developer platform exposes separate Swagger surfaces for core, payment, identity, webhooks, distribution and automation with OAuth 2.0 grants for both multi-hotel and single-hotel apps, and Mews, whose Connector API needs no login — are the ones where an independent can actually get an agent integrated without a partnership negotiation. Oracle's OHIP is well documented but gated by partner onboarding and hard shared limits. That difference, not any vendor's feature list, is what decides whether an AI project at an independent hotel is a six-week job or a six-month one.

    Failure modeDetection signalRollback
    Gateway throughput contention on OPERA Cloud — the agent polls availability on every guest turn and consumes the shared 50 req/s budgetA rising HTTP 429 rate on integrations that are not the agent: the revenue system, the review tool, the channel manager. Watch 429s by application key, not in aggregateCache availability with a short TTL, batch reads, implement exponential backoff, and move high-frequency polling off the shared gateway before you scale the agent
    Event-stream conflict — two vendors both want the streaming API on the same chain and key, and only one client may consume itOne integration silently stops receiving events after the other is provisioned. There is no error; there is an absenceDecide which system owns the stream, and fan out from it internally rather than provisioning a second consumer
    A rate quote that omits a mandatory fee, or omits tax in CaliforniaRead fifty of your own transcripts and compare the first number the agent says against the number on the confirmation. If they differ, you have the defectMake the total price the only price the agent is permitted to emit, computed server-side, with the itemisation available on request
    An upsell that is pre-selected, or disclosed after the totalAny flow where the guest says something like “I did not mean to add that.” Log those turns and read them weeklyRemove default acceptance entirely. State the amount, the purpose and the fact that it can be declined, before the guest consents
    PCI scope contamination — a card number arrives in a message threadA scheduled regular-expression scan of the message store for PAN patterns. If you have never run one, run one this weekPurge and re-scope, then move to a tokenised payment link. Assume the archive, its backups and its search index were all in scope until proven otherwise
    Prompt injection through an OTA message, a guest email or a review the agent summarisesAgent actions that no guest asked for: an unexplained refund draft, an outbound message to an address not in the reservation, a tool call outside the current conversationReduce the blast radius rather than trying to filter the input. Read-only by default, an allowlist of tools, per-reservation scoping, and human approval on anything that moves money or leaves the property
    The AI disclosure gets configured away during a brand refreshA quarterly manual check: open the widget as a guest and confirm the disclosure appears at first contact, on every channelMake the disclosure a non-configurable part of the deployment and put the requirement in the vendor contract
    Knowledge drift — the agent quotes last season's cancellation policyRising handoffs on policy questions, and guest complaints that cite something no current document saysVersion the knowledge base, date-stamp every entry, and treat any answer sourced from an entry older than the last policy change as requiring review

    One failure mode deserves its own paragraph, because it has no clean fix. Prompt injection is unsolved. An agent that reads untrusted guest input — an OTA message, an inbound email, a review, an uploaded document — is reading text that an adversary may have written specifically to redirect it. There is no filter, no model and no vendor that has solved this, and any vendor telling you they handle it is telling you they have not thought about it. The only reliable posture is blast-radius reduction: read-only by default, an explicit allowlist of tools rather than a denylist, scoping every action to the current reservation, and human approval on anything that moves money, changes a booking, or sends a message outside the thread. Design as though the agent will one day be successfully instructed by a guest, and decide now what you are comfortable with it doing on that day.

    The Human-in-the-Loop Boundary

    Every row below traces to a constraint verified earlier in this article, not to opinion. This is the table to put in front of a vendor and ask them to sign, because with one exception nobody in this market publishes one. That exception is Alliants, which publishes a boundary by disclaiming autonomy outright.

    What the agent is asked to doBoundaryThe verified constraint behind it
    Answer property questions — hours, parking, wifi, pet policy, directionsMay act aloneNo legal constraint, but the interaction must still carry the Article 50 AI disclosure at first contact
    Quote a room rateMay act alone only if the quote is the total price including every mandatory fee16 CFR §464.2(a)–(b); in California, all taxes and government fees must also be inside the total before the guest reserves, under Cal. B&P §17568.6(a)(2)
    Offer a paid upsell, upgrade or late checkoutThe offer design needs human review, and the charge must never be pre-selected or disclosed after the totalFTC v. Hopper Count VI under §464.2(c); complaint ¶114 describes a disclosure failure at the end of the purchase flow
    Describe a fee as refundable or non-refundableMust never improvise16 CFR §464.3 prohibits misrepresenting a fee's nature, purpose, amount or refundability
    Send a transactional SMS — confirmation, check-in link, room-ready alertMay act alone, with consent on fileTCPA; informational messaging
    Send a marketing SMS — an offer, an upgrade promotionMust never send without prior express written consentTCPA. Insurance Marketing Coalition v. FCC vacated only Part III.D of the 2023 order; the written-consent regime stands
    Honour an opt-outMust act alone, immediately, and no later than ten business days47 CFR §64.1200(a)(10) is in force. DA 26-12 waives only the unrelated-matters carry-over, to 31 January 2027
    Place or answer a recorded or transcribed callMust disclose at the top of the call, every timeCal. Penal Code §632.7 has no confidentiality element and reaches mobile calls; §637.2 supplies $5,000 per violation to private plaintiffs with no actual damages required
    Take a card numberMust never let a PAN enter the chat or voice transcript — tokenised hand-off onlyPCI DSS v4.0.1. A card number in a message thread pulls the entire messaging archive into cardholder-data scope
    Grant a refund, comp or goodwill concessionNeeds human approvalNot a legal rule — a blast-radius rule. Note that at least one vendor's marketing implies the agent makes goodwill concessions on its own
    Be the only service channelMust neverHotels are ADA Title III public accommodations and there is no Title III web rule to comply with, so there is no checkbox that makes an AI-only channel safe
    Read untrusted guest input — OTA messages, guest email, reviews, uploaded documentsAssume prompt injection is unsolved and design for blast radiusNo production defence is reliable. The control is what the agent is permitted to do after it reads, not what it is permitted to read

    Two rows are worth arguing about, and you should argue about them internally before a vendor does it for you. The first is the goodwill concession. At least one vendor here markets service recovery in language implying the agent decides what to offer a disappointed guest. There is no law against that. There is a blast-radius argument against it, and it is the same argument as for prompt injection: an agent authorised to give things away is an agent an adversary is motivated to talk to. Put a hard currency limit in configuration and a human on anything above it.

    The second is being the only channel. It is tempting, especially overnight at a small property, to let the agent be the entire front desk between midnight and six. Do not. There is no ADA Title III web accessibility rule to comply with, which means there is no checkbox that makes an AI-only channel defensible, and the absence of a rule is worse for an operator than a rule would be. Keep a human path, publish it, and make it reachable from the first turn of the conversation.

    Cost and Timeline

    These are our published bands, identical across every vertical we write about, and they cover the build rather than the vendor subscription. A hotel AI project has two cost lines and vendors quote one of them.

    EngagementRangeTimeline
    Discovery plus workflow audit$9k–$22k2–4 weeks
    Single-workflow agent$28k–$70k4–9 weeks
    Multi-workflow platform with system integration$70k–$180k9–16 weeks
    Enterprise, multi-site or regulated build$180k–$420k+14–24 weeks

    Senior-led work is $150–$225 per hour. Retainers run $2,500–$9,500 per month. There is a 30-day post-launch warranty, and a fixed-price phased proposal follows within 5 business days. Full source-code and IP ownership transfers on delivery. We are a senior-led Black-owned agency in Los Angeles, reachable on +1 (424) 272-5601, and the only booking link we use is calendly.com/frenchydigital/discovery-call.

    One sequencing note that saves more money than any technical decision: do the fee-disclosure and consent work during discovery, not after the pilot succeeds. Rewriting how your agent quotes a rate costs one sprint before launch. Discovering after eight months that every California quote omitted tax before the reservation step is a different kind of problem, and §17568.6(e) prices it at up to $10,000 per violation.

    Red Flags When Evaluating a Vendor

    Each of these is something we observed while building this ranking, not a generic warning list. Treat any two appearing together as a reason to slow the process down.

    • A deflection, automation or ROI figure with no published definition. Ask what the denominator is, whether an abandoned conversation counts as contained, and whether any human — including a remote one — touches the thread.
    • A payback period published on a page that carries no price. If the vendor will not disclose the denominator, the buyer cannot compute the number, and it is not a number.
    • Refusal to state a human-in-the-loop authority limit in writing. Exactly one vendor in this market publishes one voluntarily. The ones that will commit contractually are telling you something the others are not.
    • An integration count with no directory behind it. “400+ integrations” with no named systems and no docs URL scores as undocumented. A named list of eighteen platforms you can spot-check beats it outright.
    • A compliance badge with no version. “PCI DSS” is a materially weaker claim than “PCI DSS v4.0.1” with a shared responsibility matrix, and the difference is exactly the part a buyer needs.
    • A certification that belongs to the vendor's cloud host rather than to the vendor's own legal entity. Confirm the certificate names the company you are contracting with; this trap has caught vendors in several adjacent markets.
    • A pricing page that returns 404, or a trust page that does not exist. Both happened in this roster. A missing page is not neutral — it tells you how the vendor expects the sale to go.
    • A price quoted to you from a software directory rather than from the vendor. Aggregator figures circulate for most vendors here and none of them is a vendor-published price.
    • Silence on the EU AI Act while selling you a guest-facing agent. The transparency obligations applied on 2 August 2026. Three vendors here have published a position; ask the rest for theirs in writing.
    • An upsell flow that pre-selects the add-on, or discloses the charge after the total. That is the Hopper fact pattern in a conversational channel, and the Fees Rule count in that case was pleaded on short-term lodging.
    • Any suggestion that the agent can take a card number in chat to make it easier for the guest. That single convenience pulls your entire messaging archive into cardholder-data scope.
    • A promise that prompt injection is handled. It is not handled anywhere by anyone. The correct answer describes blast-radius controls, tool allowlists and approval gates.
    • A roster or a case study that lists an acquired product under its old independent name. If a vendor's competitive deck still says Quicktext, OpenKey, Easyway, Whistle or NAVIS, the rest of that deck is the same vintage.
    • Reluctance to run a limited pilot with your instrumentation rather than their dashboard. The measurement should be yours, on your property, or it is not a measurement.

    Limitations and What We Could Not Verify

    This section is part of the product, not a disclaimer at the end of it. Everything below is something we tried to check on 23 August 2026 and could not, or could only check through a secondary source. Naming it is the difference between a ranking and a sales page.

    • No independent benchmark of any hotel AI product exists. No head-to-head evaluation of any vendor in this table has been published by a party not selling one of them. The Intouch Insight drive-thru study we cite measures restaurants, not hotels, and identifies brands rather than vendors.
    • Compliance posture is unverified for seven of the fourteen vendors we checked. Asksuite, Akia, Visito, HiJiffy, Quinta, Operto and Revinate had no trust page located or checked in this pass.
    • Three vendor pages failed on the day we checked: HiJiffy's security page returned HTTP 404, Asksuite's pricing page returned HTTP 404, and the Cloudbeds PCI support article returned HTTP 403 to automated fetch. All three need a browser check before anyone relies on them.
    • The Official Journal would not serve the AI Act text to any automated request in this pass. The Article 50 duty described here is a paraphrase, deliberately not presented as a quotation of the regulation, and the 2 August 2026 applicability date should be confirmed against Article 113 of the regulation itself.
    • Legal entity names are not disclosed on the websites of Quinta, Akia, Operto, Visito and Asksuite. Country of incorporation is widely reported for several of them and we did not print any of it as fact.
    • Akia's 2026 trading is inferred from a live site with current customer logos and a working demo booker, not proven by a dated 2026 item. That is why it does not rank higher.
    • Data residency and retention commitments were not found for any vendor except Mews, which publishes hosting and a named subprocessor list, and chatlyn, which asserts EU hosting without an audit. That is a real gap: it is a standard procurement question nobody in this market answers publicly.
    • No vendor publishes a human-in-the-loop authority boundary except Alliants, and Alliants does so by disclaiming autonomy entirely rather than by defining a limit.
    • Resort-fee attorney-general settlements involving large chains were not verified to primary consent orders, so this article prints nothing specific about them. An assurance of voluntary compliance, a consent decree and a judgment are three different instruments and we could not confirm which applied.
    • The PCI DSS requirement numbering for payment-page script inventory, tamper detection and third-party management is taken from secondary summaries. Confirm the exact wording and numbering against the PCI Security Standards Council document library before it enters a policy document.
    • The DOJ interim final rule extending ADA Title II web compliance dates is described from secondary sources; we did not obtain the Federal Register citation, so no compliance dates for it appear in the body of this article. The report that the Title III rulemaking is paused indefinitely is likewise secondary.
    • Reports that OHIP API usage is billed per call, and that partner certification can run long, came from a third-party API review rather than Oracle's own documentation. Both would be commercially significant for an independent, and neither is asserted here.
    • The July 2026 BLS accommodation employment figure is preliminary and CES revises for two months, so treat it as provisional. Accommodation employment has been flat to slightly down across 2026 — it does not support a claim that hotels are shedding staff to AI, and we make no such claim.
    • Vendor employee counts, customer counts, funding totals and valuations are as published by the vendor or reported in trade press, and we audited none of them. Where sources contradicted each other — HiJiffy's funding and deployment counts, Canary's valuation, the month of the Dack acquisition — we printed nothing.
    • Cloudbeds and Revinate pricing was not verified on the vendors' own sites in this pass and is recorded as not publicly disclosed rather than as confirmed gated.
    How to keep this ranking current. Re-check four things each quarter and you will stay ahead of every competing listicle: whether each vendor still exists and under whose ownership; whether the pricing page still publishes the same numbers; whether the trust page has appeared, moved or disappeared; and whether the named integration list has quietly lost a logo. Those four checks take about an hour, and they are the only maintenance this method needs — because nothing in it depends on a number only the vendor can see.

    Want an Honest Read on Your Hotel AI Shortlist?

    Book a free 60-minute discovery call. You leave with a channel volume baseline from your own data, a fee-disclosure and consent map for the states and countries you sell into, and a fixed-price phased proposal within 5 business days.

    1517 S Bentley Ave Unit 204, Los Angeles CA 90025

    Frequently Asked Questions

    Sources & References

    1. 1eCFR — 16 CFR Part 464, Trade Regulation Rule on Unfair or Deceptive Fees (current text)
    2. 2Federal Register — Trade Regulation Rule on Unfair or Deceptive Fees, 90 FR 2166 (10 January 2025)
    3. 3FTC — “FTC Rule on Unfair or Deceptive Fees to Take Effect on May 12, 2025”
    4. 4FTC — case page, FTC v. Hopper (USA) Inc., D. Mass. No. 1:26-cv-13058, File No. 232 3086 (last updated 20 August 2026)
    5. 5FTC — Complaint for Permanent Injunction, Monetary Judgment and Other Relief, FTC v. Hopper (filed 2 July 2026)
    6. 6FTC — “Travel app Hopper to pay $35 million to settle FTC allegations” (2 July 2026)
    7. 7California Legislative Information — Bus. & Prof. Code §17568.6, hotel and motel advertised rates (AB 537)
    8. 8California Legislative Information — Penal Code §632, confidential communications
    9. 9California Legislative Information — Penal Code §632.7, recording of cellular and cordless calls
    10. 10California Legislative Information — Penal Code §637.2, private right of action, $5,000 per violation
    11. 11California Legislative Information — SB 690 (CIPA reform) bill status, 2025–2026 session
    12. 12European Commission — “AI Omnibus enters into force” (27 July 2026), with the deferred high-risk dates
    13. 13FCC — Declaratory Ruling FCC 24-17, AI-generated voices are “artificial” under the TCPA (released 8 February 2024)
    14. 14FCC — Order DA 26-12, CG Docket No. 02-278, waiver of one sub-part of §64.1200(a)(10) to 31 January 2027 (6 January 2026)
    15. 15PCI Security Standards Council — adopting the future-dated requirements of PCI DSS v4.x
    16. 16Oracle — “New AI capabilities in Oracle OPERA Cloud supercharge hotel operations” (16 June 2026)
    17. 17Oracle — OPERA Cloud Hospitality Integration Platform, documented limits and throttling thresholds
    18. 18Mews — trust centre (SOC 2 Type 2, ISO/IEC 27001:2022, PCI DSS v4.0.1, named subprocessors, shared responsibility matrix)
    19. 19Mews — public Connector API documentation, no login required
    20. 20Mews — “Mews secures $300 million investment” (January 2026, EQT Growth, $2.5B valuation)
    21. 21Canary Technologies — security and trust centre (SOC 2 Type 2, PCI DSS, RoPA, EU AI Act transparency statement)
    22. 22Canary Technologies — acquisition of OpenKey, finalised January 2026
    23. 23Duve — security page (ISO/IEC 27001, ISO/IEC 27701, SOC 2 Type II)
    24. 24Skift — Duve raises a $60 million Series B led by Susquehanna Growth Equity (9 December 2025)
    25. 25HiJiffy — published pricing tiers and setup fees
    26. 26Visito — published credit-metered pricing
    27. 27Alliants — Allin AI product page, stating that no message reaches a guest without a human decision
    28. 28chatlyn — “chatlyn secures €8M Series A” (Smedvig Ventures, with an FFG innovation grant)
    29. 29Cloudbeds — public developer documentation, REST and GraphQL, with a machine-readable llms.txt index
    30. 30Apaleo — public developer platform and Swagger surfaces for core, payment, identity, webhooks and distribution APIs
    31. 31Revinate — Revinate and NAVIS join forces (July 2021)
    32. 32SEC — In the Matter of Presto Automation Inc., Securities Act Release No. 11352, Admin. Proc. File No. 3-22413 (14 January 2025)
    33. 33US Bureau of Labor Statistics — Occupational Employment and Wage Statistics, hotel, motel and resort desk clerks (SOC 43-4081), May 2025
    34. 34US Bureau of Labor Statistics — Current Employment Statistics, accommodation employment (CES7072100001)
    35. 35US Bureau of Labor Statistics — JOLTS quits rate, accommodation and food services (JTS720000000000000QUR)
    36. 36Ipsos Loyalty — “Loyalty Myth #8: It Costs Five Times More to Acquire a Customer than to Retain a Customer,” excerpt from Loyalty Myths (2005)
    Chris Machetto - CEO & Founder of Frenchy Digital

    Chris Machetto

    CEO & Founder of Frenchy Digital. Building apps and digital products since 2019 for startups and enterprises across LA, San Francisco, Paris, Geneva, and more globally.