
Sofia / Trust
Hospitality Automation: What Sofia Can Handle and What Must Remain Human
A practical matrix based on repeatability, sources, risk and reviewability.
Ask the right question
Asking whether a task can be automated is too broad. Ask whether the input is reliable, the output verifiable, the error reversible and the owner identified.
A repetitive answer may be suitable. A rare decision with legal or safety impact is not, even when a model can produce a plausible sentence.
Four criteria
Repeatability: the process is stable. Source: approved knowledge exists. Risk: the cost of error is limited. Review: the result can be checked before action.
As criteria disappear, the system should move from execution to drafting, recommendation or blocking.
Green automation
Classifying language and intent, checking a link, creating a report, recording an opportunity and proposing a reply from approved content are lower-risk tasks.
Green still requires logs, a task identifier and the ability to correct the source.
Amber automation
Publishing a page, approving design, localising commercial copy, proposing price or sending a campaign requires an authorised person. The system prepares, validates and shows differences.
Approval must refer to a version. Changing content after approval invalidates the authorisation.
Red actions
Major refunds, legal threats, allergens, safety, non-integrated availability, undocumented products and promotional contact without a legal basis must be blocked or escalated.
A model does not replace a qualified professional when representation, signature, certification or reserved judgment is required.
The automation traffic-light matrix
| Level | Examples | Treatment |
|---|---|---|
| Green | Classify language and intent, reports, reminders, drafts from approved sources | Execution with logs and correction paths |
| Amber | Publishing pages, localising copy, proposing prices, sending campaigns | Draft + approval by an authorised person |
| Red | Major refunds, legal issues, allergens, safety, non-integrated availability | Block or immediate escalation to a person |
How to read this data
The more criteria are missing (repeatability, source, risk, review), the more the system shifts from execution to blocking.
Sofia in practice
Sofia recognises context, retrieves approved knowledge, collects missing data and moves the enquiry towards booking or an owner. Client-facing language focuses on what she does, not a list of models.
Quality depends more on knowledge, rules and exception handling than on the technical provider name.
Transparency
A person interacting with an automated system should be able to understand the nature of that interaction where required and reach a human route. Transparency should not be hidden in legal copy.
The EU AI Act introduces obligations on different timelines. Each launch needs a review against current guidance rather than memory of the regulation.
Approved knowledge
Each piece of information used in a response has an origin, owner, date, scope and state. An expired policy should not survive because it remains inside a prompt.
Prices, availability and operating conditions should come from one source or require confirmation.
The four-eyes principle
Producer, validator and approver are separate functions. A deterministic check verifies fields and rules; a critic assesses meaning and reputation; policy decides whether to execute or block.
No agent creates and approves the same delivery. Separation matters more than the number of named agents.

Data minimisation
Do not place more data in a model than the task requires. Identity, channel, consent, retention and access belong in the operating system.
Logs should support audit without becoming an indefinite copy of every conversation.
How to begin
Choose one repetitive flow, catalogue sources, define three risk levels and test normal and adversarial cases. Measure corrections, escalation and human time, not only response count.
Stop the pilot if the system cannot state uncertainty or exceptions do not reach an owner.
Recommendation
Automate classification, knowledge retrieval, recording and drafting first. Add execution only when source, control and rollback have been demonstrated.
The best automation does not eliminate judgment. It protects judgment from repetition and makes it available where it matters.
Official sources and notes
Sources were verified on the stated date. Scenarios and formulas remain explicitly disclosed.
- EUR-Lex, Artificial Intelligence Act2026-07-11
- Google Search Central, Helpful content2026-07-11