In short
“AI chatbot,” “conversational AI,” “generative AI,” “agentic AI.” The words get used loosely, usually by someone selling something. Underneath them sit three genuinely different kinds of system, and the difference that decides everything is not how clever each one sounds. It is how much control you have over what it says and does to your guests.
This article sorts them into three: scripted bots, generative AI, and agentic systems. For talking to guests, scripted bots are now obsolete. Unconstrained generative AI is a liability wearing a friendly face. A controlled agentic system, one that knows only your hotel and behaves like a good concierge, is the only kind you can safely leave alone with a guest.
Take-home: you’ll be able to place any product a vendor shows you on that scale, and know which questions expose what it really is.
Why the words matter more than usual here
In most technology categories, terminology is a distraction. A general manager doesn’t need to know how a channel manager transmits inventory to buy one well.
This category is different. The words are used to blur rather than clarify. A rigid system from 2015 and a system that reasons across your live inventory are both sold as “AI-powered,” and the label hides a chasm. The deeper reason to get this straight is that the thing separating these three is not age or cleverness. It is control: over whether the system can say something you never approved, invent something untrue, or act in ways you didn’t intend. For a business where a wrong word to a guest becomes a disappointment at your front desk and then a review, that is the axis that matters.
We’ll be blunt about the technology, because you’re owed a clear answer rather than the usual “it depends.” We won’t name or knock any vendor doing its best in a hard market. The judgement here is about the technology, not the people selling it. And every hard verdict comes with proof you can check.
The three kinds, on the axis that matters
The three in comparison, side by side
| (a) Rule-based | (b) Intent-based | (c) Generative | (d) Agentic | |
| Understands free text | No — buttons/keywords | Within a fixed topic list | Yes | Yes |
| Handles a compound question | No | Usually drops half | Yes | Yes |
| Remembers earlier in the conversation | No | Limited | Within the session | Within the session, and can persist |
| Can check live availability | No | Only if integrated, rigidly | No | Yes |
| Can complete a booking | No | Rarely, and rigidly | No | Yes |
| Can invent a wrong answer | Never | Rarely | Yes — grounding reduces it | Yes — grounding reduces it |
| Cost & effort | Low | Moderate | Moderate | Highest |
| Best used for | Fixed FAQs | Bounded, repetitive requests | Answering questions well | Discovery and booking |
1. Scripted bots: obsolete for talking to guests
A human decided the answers in advance. A guest’s message gets matched to a pre-written answer, either by clicking through a menu or by software sorting the message into one of a fixed list of topics, and the matching block of text comes back.
(Technically there are two versions. One is the rule-based chatbot, a decision tree with no learning. The other is the intent-based, or NLU, chatbot, which uses language classification to guess which topic you mean and copes with paraphrase a little better. To you as the buyer the difference barely registers. They fail the same way where it counts, and you can’t tell them apart from the outside, so we treat them as one kind.)
At a glance:
- What it does well: answers a small set of fixed facts, like the Wi-Fi password, check-in time, or the exact wording of a policy.
- Where it fails: anything phrased in a way the script didn’t anticipate, which is most of what real guests ask.
- Guest experience: poor, and it fails invisibly, so you rarely see the guests it costs you.
The pitch has always been safety and simplicity. A scripted bot can only ever say what a human wrote, so it can’t invent anything, and it’s cheap. That was a reasonable trade when it was the only affordable option. It isn’t anymore. Here is why, in a conversation that happens on hotel websites every day.
EXAMPLES
A guest types: “Can I get in with my auto-camper? It’s 3.1 metres tall.”
The bot replies with its parking block: “Parking is available for hotel guests at [address]. To reserve a space, please…”
The bot did not process “3.1 meters.” It did not process “auto-camper.” It saw the one word its parking answer is filed under and returned the file. The guest asked a specific, answerable question, whether the vehicle physically fits, and got a generic paragraph that ignored it. They leave irritated, because the bot visibly didn’t listen, which is a worse impression of your hotel than no bot at all.
A scripted bot doesn’t understand questions. It matches words to pre-written answers. “Parking” triggers the parking answer whether the guest asked where to park, what it costs, or whether a tall camper clears the entrance.
There’s a second failure. When the bot serves that parking block, your system records a parking question, answered. A success. It has no idea the guest rolled their eyes and closed the tab. So when you review how the bot is performing, parking looks handled, and you never see the guest you lost. Did a bad parking answer just cost you a booking? You can’t find out, because the instrument that failed is the same instrument reporting the results.
So the verdict, plainly. Now that agentic systems built for hotels exist, scripted bots are obsolete for talking to guests. The odds that a real guest asks something the script didn’t anticipate are not small. They are most of the time. And there is no “simple FAQ” safe harbour to retreat to, because the auto-camper question started life as a parking FAQ. The follow-up the script never saw coming is always one message away.
The tell: it offers buttons, or it answers a narrow question and then serves the same block no matter how you rephrase.
2. Generative AI: capable, uncontrolled, and not actually about your hotel
This is the technology behind ChatGPT, and what most people mean by “AI” today. Instead of returning a pre-written answer it composes a new one, word by word, handling nuance, mixed topics and follow-up questions with a fluency the scripted generation can’t approach. Next to a scripted bot it feels like magic.
Here is what the fluency hides, and it’s the most important thing in this article. Being fluent is not the same as being right, and on its own, generative AI cannot be controlled. Left to itself it produces a confident, well-written, wrong answer whenever it doesn’t actually know, and it has no way of knowing that it doesn’t know. This isn’t an occasional glitch. It’s how the technology works: it generates the most plausible next words, true or not.
At a glance:
- What it does well: work behind the front line, with a human checking it, like drafting replies, summarising, first-draft content, and helping staff find information.
- Where it fails: talking to guests unsupervised, where it invents things about your hotel and can’t be reined in.
- Guest experience: impressive until it’s wrong, and neither you nor the guest can tell which is which.
Start with the damage that matters most, because it’s also the one nobody measures.
The risk that matters most: a broken guest experience
Picture the failure that never reaches a courtroom. Your bot, trying to be helpful, tells a guest the room has a sea-view balcony, or that early check-in is fine, or that the spa can fit them in on the Sunday. None of it is true. The bot didn’t know, so it produced the most pleasing plausible answer. The guest books on the strength of it. They arrive, for the anniversary or the birthday they’ve been looking forward to, and at your reception desk a member of your team has to say the words: “I’m sorry, our system got that wrong.” You’ve disappointed an arriving guest before they’ve set their bag down. That becomes the review.
A generative model knows an enormous amount about the world and almost nothing specifically, reliably true about your hotel. When a guest asks something your hotel never told it, the model doesn’t stop. It fills the gap with the most plausible-sounding answer, because filling gaps with plausible language is the mechanism. A system that knows the whole world is the wrong thing to put in charge of the specific truth about your property.
The only defense is a system whose knowledge is closed: bounded to your hotel, and built to say “let me check” rather than guess when it reaches the edge of what it knows. It should NOT even know the current Pope of the Vatican, the current president of United States, who won the FIFA World Cup 2026, or who Pele, Maradonna, or Michel Platini is.
Which raises a hard question this article won’t pretend to answer here, because it deserves its own: a controlled system has to know everything about your hotel, and most hotels don’t have anything close to everything about themselves written down in a form a machine can use. (We take that up separately in “An AI Is Only as Good as What Your Hotel Has Written Down.”)
When it goes wrong
A generative bot will follow a guest into any topic, and it can be deliberately steered off course. Deliberate manipulation has a name, prompt injection, which OWASP ranks the number-one risk for these systems, and the usual fixes don’t fully close it. It doesn’t take a hacker, and even the most capable models aren’t immune. A few documented cases:
- DPD, UK (2024). A customer talked the parcel firm’s chatbot into swearing and calling DPD “the worst delivery firm in the world,” despite its instruction not to curse.
- Claude Code (2025). Attackers bypassed the safeguards on a frontier AI tool to run most of a cyber-espionage operation, and even then it hallucinated, fabricating credentials its operators had to correct.
- Air Canada (2024). The airline’s chatbot invented a refund policy that didn’t exist, and a tribunal held the airline liable for it.
The tell: it answers anything, beautifully, which is exactly why you can’t trust it. It answers just as beautifully when it’s wrong.
3. Agentic systems: capable, and controlled
An agentic system is a generative model placed inside a structure: a defined task, explicit boundaries, guardrails about what it may and may not say, and real connections to your systems so it works from fact instead of guesswork. The mechanism that lets it reach those systems and act is called function calling.
At a glance:
- What it does well: the guest-facing discovery and booking conversation, unsupervised and around the clock.
- What it needs: a live connection to your systems, current hotel knowledge, and a human checkpoint for anything irreversible.
- Guest experience: concierge-level, when it’s properly built and connected.
What makes it different: accountability
The difference from raw generative AI isn’t eloquence. It’s accountability. It looks up real availability instead of imagining it. It works within rules you set, so it doesn’t wander off your property or invent a policy. When it reaches the edge of what it knows, it’s built to say so or hand to a person rather than guess. And because it can reach your systems, it can do things (check a date, hold a room, complete a booking) instead of only talking about them. This is the only one of the three you can safely put in front of a guest unsupervised, and the only one that can take a direct booking.
It mimics a concierge, it isn’t smarter than one
One correction, because the marketing errs in the opposite direction here. An agentic system is not smarter than your best concierge, and you should distrust anyone who says it is. It has no superhuman intelligence. What it has is a good concierge’s reach and reliability at a scale a person can’t cover, every guest, every channel, every hour, working only from what your hotel actually knows. The goal is to mimic a great concierge consistently, so guests get the experience that turns into a direct booking and your staff are freed to be present with the people in front of them. Held to that standard, your best concierge rather than a science-fiction one, it is achievable. Sold as something cleverer than any human, it’s the same hype the rest of this article exists to puncture.
The honest limits: least agency
It is not magic, so here is the honest part. Giving a system the power to act means a mistake is no longer only a wrong answer. It can be a wrong action, and in connected systems one wrong action can set off others. The researchers who study this recommend a principle worth borrowing, least agency: give the system the minimum freedom the job needs, not the maximum, and put a human checkpoint in front of anything irreversible, like a refund or a cancellation. Its guardrails are only ever as good as the people who built them and the knowledge you feed it. Which is why the question to press a vendor hardest on is not how clever the thing is. It’s what stops it from saying or doing the wrong thing.
The tell: ask it to do something, not just explain something, then ask what keeps it from doing the wrong thing.
What you can actually buy
The consequence follows directly, and almost no vendor states it plainly. You cannot simply “add generative AI” to your hotel website and expect it to be safe. Raw generative AI is a component, not a product. Pointed at your guests without a control layer, it’s a liability: fluent and unaccountable. What a responsible vendor actually sells is the third thing, a generative model wrapped in the workflow, boundaries, guardrails and system access that make it trustworthy. That wrapping is the hard part, and it’s the whole distance between an impressive demo and something you can leave alone with a guest at eleven at night.
So the first question in any vendor conversation isn’t “is this AI?” It’s two questions. 1. Can it act on my real data? And 2. what stops it from saying or doing something wrong? A vendor who answers the second clearly is selling the controlled kind. A vendor who only wants to show you how fluent it is may be handing you the dangerous middle with a nicer interface.
Why it has to be your hotel’s own system
There’s a second reason a general-purpose generative chatbot can’t run your bookings, and it has nothing to do with how clever it is. The regulated parts of a booking can only be handled by a system wired into your hotel and operating under your rules.
For Availability, Booking, and Payment – Integration to PMS or Booking System is necessary
A general chatbot sitting on your website isn’t connected to your property management system or booking engine, so it can’t see real availability, real rates, or a real reservation. It can’t complete a booking at all, whatever the demo suggests. The moment a booking has to be real, the system has to be connected to the one that holds your inventory.
Data Protection
Then data protection. Every guest conversation carries personal data: names, contact details, sometimes payment and preferences. Under the GDPR, your hotel is the data controller, and you stay accountable for that data even when a vendor’s tool is what mishandles it.
Local Compliance
Then local law on payment and invoicing, where “a bot that takes payments” meets reality. In Italy, an invoice is not valid unless it’s issued electronically through the government’s Sistema di Interscambio in the required format. An agentic hotel specific solution should be integrated to your PMS and Booking System, so that ALL invoicing, payment, and bookkeeping is handled by your dedicated and compliant system, and NOT by an Agentic AI agent. A receipt a bot emails straight to the guest is not, in law, an invoice at all. Europe’s payment rules add strong customer authentication on the transaction itself. None of that can be improvised by a general chatbot. It has to run through your booking and payment systems, which are built to do it correctly.
Put those together and the answer is not to avoid AI. It is to make sure the AI that handles your guests is your hotel’s own: integrated with your systems, operating under your data agreements, issuing invoices through the right channel, taking payment through your processor. That can ONLY be an Agentic AI solution.
Here’s the part hotels sometimes miss. Having “your own” agentic system does not mean building one yourself to the tune of tens or hundreds of thousands EURO. You didn’t build your property management system. You bought it from a PMS provider, and it runs as yours, holding your rates and your reservations under your control. An agentic AI is the same kind of purchase. You get it from an agentic-solution provider, deployed for your hotel, preferably built and made for hotels specifically, connected to your systems, operating under your compliance obligations. This was never a build-versus-buy decision. It’s a question of whose control the system runs under, and for anything that touches a guest, a booking, a payment or an invoice, that has to be you.
Generative AI is already booking hotels. Just not yours.
Here is where the terminology stops being academic.
While the industry debates whether hotels should adopt AI, generative AI has quietly become a booking channel. In late 2025 OpenAI opened ChatGPT to third-party applications, and its first travel partners were Expedia and Booking.com. A guest can now describe what they want in ordinary language, inside ChatGPT, and get live prices, photographs and availability from those platforms without opening a browser tab. The booking itself completes on the travel brand’s own site.
Read that sequence again from your side of the desk. The guest never reached your website. They never saw your rooms described in your words. They never had the conversation in which you might have answered the one question standing between them and booking direct. And the reservation, when it happens, arrives with a commission attached.
Expedia and Booking.com are NOT interested in your hotel, they just want your inventory, and sell it as they please. Your brand differentiation is entirely “in the way” of what they want, they prefer bland and “grey” hotels, great room pictures.
This is not a distant prospect. Adobe’s data indicates that around 29% of US consumers already use AI services to plan travel, with generative-AI referral traffic to US travel sites growing rapidly since mid-2024.
Notice the asymmetry, because it is the whole point. Generative AI can transact — for Booking.com and Expedia, because they connected their live inventory to it. It cannot transact for you, because your inventory is not connected to it. The technology is not the constraint. The connection is.
There is a fair counterweight worth stating. Practitioners testing these travel integrations early on found them slow, thinner on detail than the OTA sites themselves, and capable of confusing one destination with a similarly-named one elsewhere. This is a first generation, not a finished one. But the direction of travel is not really in doubt, and the strategic consequence for an independent hotel is the same either way: a new intermediary is forming between your guest and your rooms, and the tier of technology that makes it possible is precisely the tier you cannot deploy on your own site.
The honest limits of the newest tier
Agentic systems are the most capable of the four and the most demanding to run. In fairness:
They depend completely on integration. An agentic system without live, two-way access to your property management system is just generative AI that you can control, your knowledge only, guardrails, and little risk of running “wild”. Getting that access is genuinely harder than vendors imply — the hotel systems market is fragmented across dozens of platforms, many older systems were never designed to be connected to, and “we integrate” sometimes means a one-way read rather than the ability to write a booking back.
They depend on your knowledge being accurate. Stale policies and half-correct room descriptions get repeated confidently.
They still carry a residual risk of a wrong answer, which is why the right behavior when uncertain is to say so and bring in a human rather than to guess.
And they cost more per conversation than a rule-based bot, which is a reason to point them at the conversations that pay for them.
How to tell what you’re being shown
Five questions. They take a minute in any demo, and they place a product in the table above.
- Show me it checking live availability for a specific date. If it cannot, it is not agentic.
- Ask it something two-part — a room question and a policy question in one sentence. Does it answer both?
- Ask it something nobody would have scripted. Does it reason, or fall back?
- Ask what it does when it doesn’t know. Does it say so and hand over, or produce a confident guess?
- Ask which of your systems it writes back to — and whether that is a real two-way connection.
Summary
Three kinds of technology, one label. What separates them is control.
- Scripted bots match keywords, not questions. The auto-camper gets the parking answer, the guest leaves, and your system logs it as a success, so you never see the loss. Obsolete for talking to guests.
- Generative AI is fluent and uncontrolled. It invents past the edge of what it knows, and being general, it knows the world rather than your hotel. Its everyday damage isn’t a lawsuit. It’s a guest disappointed at your desk over something the bot promised.
- Agentic systems put that capability inside boundaries, guardrails and real connections, working only from your hotel’s facts. The only kind safe to leave with a guest, and it should behave like your best concierge, not claim to be smarter than one.
One question this article doesn’t try to answer: a controlled system has to know everything about your hotel, and your hotel almost certainly hasn’t written everything down. That’s next, in “An AI Is Only as Good as What Your Hotel Has Written Down.”
The one question to take into any demo: forget “is it AI?” Ask what stops it from telling your guest something that isn’t true.
FAQ – AI for Hotels
A rule-based chatbot answers using predefined logic: decision trees, if/then rules, keyword or pattern matching, and button menus, with no machine learning and no language model generating the reply. Every answer is written by a human in advance, so the bot can only respond to inputs it was explicitly built for, and it returns the same pre-written text whenever a keyword matches. It’s cheap, predictable, auditable, and incapable of inventing anything, and it collapses the moment a guest phrases something it wasn’t programmed for. It’s the oldest and simplest kind of chatbot.
An intent-based chatbot uses Natural Language Understanding (NLU), a machine-learning technique, to sort a guest’s message into one of a fixed set of predefined “intents” (what the guest wants) and to pull out “entities” (specific details such as dates, room types, or number of guests). It copes with paraphrase, typos and varied wording far better than keyword matching, but it can still only handle the intents it was trained on, and it typically stumbles when a guest asks two things at once, because it maps each message to a single intent. This is the generation of technology behind platforms such as Dialogflow, Rasa and IBM Watson Assistant, and it’s very often marketed simply as “an AI chatbot.” From a hotel’s point of view it behaves like a more flexible rule-based bot, which is why this article groups the two together as “scripted.”
Generative AI is built on a Large Language Model (LLM), a model pre-trained on vast amounts of text, that composes a new response word by word rather than retrieving a pre-written one. It handles open-ended, nuanced, multi-topic conversation with a fluency the scripted kinds can’t match, and follows context within a conversation. In its raw form it works in a simple request-and-response pattern: it generates language, but doesn’t take actions in other systems or check live data, and because it produces the most plausible-sounding words rather than verified facts, it can state falsehoods with complete confidence (a “hallucination”). The term “conversational AI” is usually applied to this kind or the intent-based kind.
Agentic AI is an LLM-based system that can reason about a task, plan, use tools by connecting to external systems through function calling, keep track of context, and carry out multi-step actions toward a goal. In other words, it can do things, not just talk about them: in a hotel it can check real availability in your systems, hold a room, and complete a booking, rather than only describing them. The ability to take bounded, real-world actions within rules you set is what separates an agentic system from a generative chatbot, and it’s the only one of the four that can safely complete a direct booking.
Only an agentic system, and only for the things it’s connected to. An agentic bot works from two separate things: the knowledge you give it, which lets it describe your rooms, spa or restaurant, and the live connections to your systems, which let it check availability, reserve, and take payment. With a connection to the system that holds that inventory (your PMS or booking engine for rooms, your scheduling system for the spa) it can see what’s free, book it, and confirm. Without one it can talk about the treatment but can’t see the 4pm Saturday slot, and can only point the guest to where the booking is made. Payment is a third connection: some systems let the bot take it in the chat, others hand the guest a payment link for the last step. So a scripted bot can only ever hand over a link, raw generative AI can describe your rooms but may invent their availability, and an agentic system is the only kind that genuinely checks and books, per service, wherever it’s connected.
Sources
- IBM, “What Is Agentic AI?” — https://www.ibm.com/think/topics/agentic-ai
- IBM, “What Is Generative AI?” — https://www.ibm.com/think/topics/generative-ai
- IBM, “What Are AI Agents?” (rule-based / nonagentic chatbots) — https://www.ibm.com/think/topics/ai-agents
- IBM, “What Is Tool Calling?” (function calling) — https://www.ibm.com/think/topics/tool-calling
- Rasa, “Dialogue Understanding” (intents / NLU and their limits) — https://learning.rasa.com/rasa-pro/dialogue-understanding/
- OWASP, “LLM01: Prompt Injection,” Top 10 for LLM Applications 2025 — https://genai.owasp.org/llmrisk/llm01-prompt-injection/
- OWASP, “Top 10 for LLM Applications 2025” (Excessive Agency / least agency) — https://genai.owasp.org/llm-top-10/
- CBC News, “Air Canada found liable for chatbot’s bad advice on plane tickets” (Feb 2024) — https://www.cbc.ca/amp/1.7116416
- TIME, “DPD AI chatbot swears and criticises the company” (UK, Jan 2024) — https://time.com/6564726/ai-chatbot-dpd-curses-criticizes-company/
- European Data Protection Board, “Italian SA fines the company behind chatbot Replika €5 million” (2025) — https://www.edpb.europa.eu/news/national-news/2025/ai-italian-supervisory-authority-fines-company-behind-chatbot-replika_en
- European Commission, “eInvoicing in Italy” (Sistema di Interscambio / FatturaPA) — https://ec.europa.eu/digital-building-blocks/sites/spaces/DIGITAL/pages/467108890/eInvoicing+in+Italy
- Anthropic, “Disrupting the first reported AI-orchestrated cyber espionage campaign” (Nov 2025) — https://www.anthropic.com/news/disrupting-AI-espionage


