The Month Restaurant Tech Grew Up
July 2025 was the month restaurant and hotel AI stopped being a press release and became a business model. Olo went private, a hiring bot leaked 64 million records, the EU posted the rulebook, and Marriott began wiring an agent into rooms. A first attempt to read the shape.
It is Friday, July 25, a little after four. The light in the office has gone that particular color it goes in late July — gold on the floorboards, no edge to it — and I have spent the last hour trying to write the same paragraph six different ways. The week has been busy in the way that only mid-summer weeks are busy in hospitality tech: nothing on fire, nothing closed, nothing announced loud enough to dominate the trade press, and yet the inbox has been full of things that, taken together, will not let me alone.
I keep coming back to a sentence I scribbled on a notepad on Tuesday and have circled three times since. July 2025 was the month restaurant and hotel AI stopped being a press release and became a business model.
I think that is true. I am less sure how to prove it, which is the position from which most of the better Mise columns get written, so I am going to try.
The argument, in its rawest form, is this. Over twenty-two business days we watched four things happen in sequence — a private-equity take-private of the largest restaurant ordering middleware in North America, a security breach at a hiring bot that exposed every applicant who has ever clicked “apply” at McDonald’s, a regulator publishing the operating rules for the model providers, and a global hotel brand beginning to roll an agent into its room experience. And a fifth thing, the Toast Go 3, is anticipated by month-end as the punctuation mark. None of these on its own is a category-defining event. Taken together they describe a structural change in who owns the operating system of hospitality, who is liable when it breaks, and where the margin actually lives.
I want to be honest about what this essay is and is not. It is not a framework. I have been trying for weeks to write a framework piece — something that names the dimensions of operator margin in an AI-rewritten kitchen and room — and I keep failing to get it tight enough to publish. There is a framework May refinement that this essay anticipates, and there are pieces of it I can already feel pressing against the page, but it is not ready, and I am not going to fake it. This is a narrative synthesis. It is a first attempt to read the shape of July, not an attempt to file the shape away. The framework, if it comes, will come in August, when I have had more time to sit with the earnings transcripts and watch what the second half of the year does to the thesis.
So: six headings, one Friday afternoon, no claim to be tidy.
The Olo take-private is the canary
Start with the deal that nobody on the operator side wanted to talk about on the record. On July 3, Bloomberg reported that Thoma Bravo had agreed to take Olo private at roughly $2 billion. Olo is — was — the publicly listed ordering and delivery middleware that sits between the restaurant POS and every consumer-facing ordering channel a multi-unit operator might use. If you have ever ordered a salad on a chain’s mobile app and not been certain whether it was the chain’s app or DoorDash’s checkout, you have used Olo. It is plumbing.
The take-private was greeted in the trade press as a routine private-equity event, which it is, and as a vote of confidence in restaurant tech, which it sort of is. Both readings miss what the deal is actually about. Olo is being taken off the public markets because the public markets cannot underwrite what is about to happen to ordering middleware, and Thoma Bravo can.
What is about to happen, in my reading, is that the ordering layer is going to fold into the agent layer. The right place to take an order in 2027 is not a mobile app and not a checkout page; it is a voice agent, a chat surface, a kiosk that recognizes the customer, a drive-thru lane that has decoded the loyalty profile from the license plate. Olo’s existing position — the integrator that already speaks every POS and every brand’s loyalty stack — is the most defensible distribution wedge for that next layer. But getting from here to there is a multi-year capital cycle of platform rebuilds, agent deployments, channel rationalization, possibly hardware partnerships, and certainly some painful margin compression in the interim. None of that is something a public-market story can tolerate quarter by quarter. So the public market gets out, the private capital comes in, and the rebuild happens behind closed doors.
This is the canary not because Olo is special but because Olo is structural. When the integration layer goes private to rebuild, every brand on top of it is buying into a roadmap they cannot see and a pricing model they did not negotiate. The pricing model is the part operators will feel first. The roadmap is the part they will feel last and worst.
I have been on the phone this week with two CTOs of mid-size casual-dining brands. Neither will go on the record. Both said the same thing in different language: the moment Olo went private was the moment they started writing down what it would take to get out. Neither thinks they can. That is what makes the deal a canary. Not the price; the lock-in.
McHire and the end of “it’s just a vendor”
Six days later, on July 9, TechCrunch reported what may turn out to be the most consequential single hospitality-AI story of the year. McHire — the McDonald’s hiring chatbot, built and operated by Paradox.ai — exposed an estimated 64 million applicant records to two researchers who logged in with the password 123456. The default credentials on a test admin account had never been rotated. The dataset included names, contact details, transcripts of the chatbot’s conversations with applicants, and in many cases the personality-test results McHire uses to triage applicants for franchise interviews.
I want to be careful here, because the temptation is to make this a security story, and a security story is not the interesting story. The interesting story is liability. McHire is a Paradox product. McDonald’s licensed it. The applicants thought they were applying to McDonald’s. The breach was on Paradox’s infrastructure, but the brand at the top of every news headline is the golden arches.
For most of the last decade the hospitality industry’s working assumption about vendor risk has been that there is a contractual moat between the operator and the vendor — that data processing addenda, breach notification clauses, and indemnities together construct a wall over which liability does not climb. That assumption was already showing cracks before July. It has now, I think, been formally retired. The applicants who are right now talking to the class action plaintiffs’ bar are not going to be especially interested in whether McHire is hosted on Paradox or AWS or anyone else. They applied at McDonald’s. They will sue McDonald’s. McDonald’s will then sue Paradox. The market will price the chain of indemnity inside two quarters.
What this means for operators is something I have been trying to put my finger on all week, and the closest I have come is this: the vendor-operator distinction in AI is collapsing in exactly the way the franchisor-franchisee distinction collapsed in the joint-employer cases ten years ago. If you put the brand on the chatbot, you own the chatbot. If you let the chatbot collect data, you own the data. If the chatbot makes a hiring decision, you own the hiring decision. The contracts are not going to save you, because the courts are not going to read them the way the GCs hoped they would, and the regulators — see below — have just told the courts how to read them.
McHire is the moment hospitality stopped being able to outsource AI risk to its tech stack. The brands that understand this will start hiring AI-specific risk officers in Q3. The brands that do not understand it will hire them after their first breach.
The EU posts the rulebook
On July 18, the European Commission’s Directorate-General for Communications Networks, Content and Technology published its guidelines for providers of general-purpose AI models. This is the implementing guidance for the GPAI provisions of the AI Act, and it is the first time we have a regulator’s working definition of what a “provider” is, what a “general-purpose AI model” is, what counts as systemic risk, and what the documentation, copyright, and transparency obligations look like in practice. For an upcoming May piece I have been trying to map the operator-side consequences of the Act more carefully; the GPAI guidelines are the first piece of that puzzle that has any real edge.
Three things about the guidelines matter for hospitality, and the trade press has so far covered none of them well.
First, the definition of “provider” is broad. If you fine-tune a general-purpose model on your own data — and many of the larger restaurant and hotel groups are now doing exactly that on the OpenAI, Anthropic, and Google platforms — you may, depending on the modification, become a provider in your own right with respect to the modified model. That brings documentation and copyright obligations with it. Most chains’ legal departments have spent the year reading the Act as something that applies to OpenAI and Mistral. They are going to spend the rest of the year discovering that it may apply to them.
Second, the transparency template — the model documentation that providers must make available to downstream deployers — is going to leak laterally into procurement. Once OpenAI publishes the GPAI documentation for its frontier model, every operator that buys a Paradox or a SoundHound or a Presto deployment built on top of that model has the right and arguably the obligation to demand the same kind of documentation from the deployer. The transparency obligation is theoretically only on the upstream provider. In practice it is going to push down the stack, because no operator’s GC is going to want to be the one who did not ask.
Third — and this is the part I keep going back to — the systemic-risk classification is going to bite a small number of providers very hard, and through them a small number of operators. The 10^25 FLOPs presumption is not going to catch most restaurant-AI vendors, but the chat agents that the QSR majors are deploying are running on models that are squarely inside that envelope. The systemic-risk obligations are real: model evaluations, adversarial testing, incident reporting, serious-incident notification within prescribed windows. Operators who have deployed a customer-facing voice agent in the EU now have a regulator on the other end of the phone whether they realize it or not.
July 18 is the day the model providers and, transitively, the operators who deploy on top of them stopped having room to argue about whether the rules existed. The rules exist. They are written down. The next twelve months are about who reads them first.
Marriott begins to wire an agent into the room
While the regulator was finishing its guidance, a hotel brand was quietly starting to ship something that I think will turn out to be the most-copied operator move of the second half of 2025. Marriott’s AI Concierge Unit — the program various trade outlets are calling ACU — began its rollout in July. Klover’s analysis is the cleanest public read I have seen on what Marriott is actually doing, and it is worth reading slowly. The headline is not the chatbot. The headline is that Marriott is wiring an agent across the length of the guest stay — from booking through pre-arrival, in-room, in-property, and post-stay — rather than dropping it into a single touchpoint.
This is the choice that distinguishes the brands that are going to win the next phase from the brands that are going to find themselves overpaying for point solutions. The hotel industry’s first wave of AI deployments was almost entirely point: a chatbot on the booking site, a sentiment classifier on review platforms, a price-optimization module bolted onto the revenue management stack. Marriott’s bet, as best I read it from the public commentary, is that the agent has to be coherent across the guest’s whole interaction with the brand or it is not really an agent — it is just a chat surface with branding.
The reason this matters for the larger July thesis is that Marriott is the first hospitality operator to publicly declare that it is going to own the agent layer rather than license it. The ACU is being built with partners, but Marriott is the integrator. The brand is the operating system. Compare that with the McHire structure — McDonald’s licensing Paradox, McDonald’s letting Paradox stand between the brand and the applicant — and the contrast is sharp. The operators who decide the agent is part of the product will build it. The operators who decide the agent is a vendor relationship will license it and inherit the McHire risk profile.
I do not yet know whether Marriott will execute. The ACU rollout is in process; it is not done. Public-facing deployments are spotty and the early guest reactions, as best I can tell from the corner of Reddit where hotel obsessives gather, are mixed. But the strategic posture is the right one. The brands that read this correctly will spend Q3 reorganizing their AI programs around the agent as a product line, not a vendor relationship. The brands that read it incorrectly will spend Q3 issuing RFPs.
There is a piece of this I want to dwell on for a moment because I think it is the central operator question of the second half. Where does the agent sit in the org chart? For most chains today it sits inside IT, sometimes inside digital, occasionally inside marketing. None of those are right. The agent is going to be the dominant guest interface within thirty-six months. It belongs to whoever owns the guest experience, which in a well-run hotel group is the COO or a chief commercial officer, and in a well-run restaurant group is the chief operating officer with the brand president dotted in. The reason the McHire breach happened on a test admin account with 123456 is that nobody senior enough was watching, and nobody senior enough was watching because the agent was in the HR-tech budget line. That has to change. Marriott’s ACU is, among other things, the first organizational signal I have seen that one of the majors has changed it.
The Toast Go 3 is the punctuation, not the headline
Toast is expected to unveil the Toast Go 3 next Thursday, July 31. I do not yet know exactly what the device will be — the spec sheets in circulation are unreliable and I am not going to publish unreliable spec sheets — but the strategic shape of the announcement is forecastable from what Toast has already said about Toast IQ in a forthcoming May piece and from the broader Toast Expands Toast IQ Smart AI Assistant materials that came out earlier in the summer. Toast is moving from a POS company to an AI-assisted operations platform, and the next handheld device is the wedge that gets the AI into the hands of every front-of-house employee in every Toast restaurant.
I am writing this six days before the announcement, so I want to be careful. What I can say with reasonable confidence is that the Go 3 is going to matter less for what it does than for what it represents. Toast has roughly 140,000 restaurants on the platform. Whatever runs on the next handheld will be, by sheer install base, the dominant restaurant-AI deployment in North America within a year of launch. It will probably not be the most sophisticated agent on the market; it will be the one that ships.
This is the part of the July story that, more than the others, foreshadows the framework I keep trying to write. There is a piece of the Voice Agent Maturity framework that I have been working on for an upcoming May framework piece that says the right question to ask of any deployed agent is not how clever it is but how many shifts have been worked on it. By that metric, the Go 3 — assuming it ships and assuming Toast IQ rides it — is going to be the most-mature deployment in the category within twelve months, whether or not it is the best one technically.
The Toast Go 3 is anticipated, not announced. I will not be surprised if the device is delayed, or if the AI features that show up on July 31 are narrower than the leaks suggest. But the existence of the device, and the timing of its anticipated announcement at the back end of this month, are the right punctuation mark for the rest of the July story. Olo goes private to rebuild the ordering layer. McHire defines the liability boundary. The EU writes the rulebook. Marriott shows the operator playbook. Toast, six days from now, puts the AI in the apron pocket of the line cook.
What the earnings calls were really saying
I have spent most of the last two weeks reading transcripts from the earnings calls that landed inside the July window — Domino’s, Chipotle, Hilton, Wyndham, Las Vegas Sands among others. The transcripts are interesting less for what was said than for the structural shift in how it was said.
Three years ago, when AI came up on a hospitality earnings call, it came up because an analyst asked. Two years ago it came up because the CFO mentioned a pilot. One year ago it came up because the CEO had a talking point about a partnership. This quarter, in nearly every transcript I have read, AI is coming up in the guidance. It is being cited as a driver of labor productivity, of marketing efficiency, of average ticket, of guest satisfaction scores. It is being baked into the numbers.
This is the change that I think makes July the month the thing grew up. When AI is in the guidance, it is no longer an investment thesis; it is a business model. The CFO has committed numbers to it. The audit committee will ask about it. The board will see it on the dashboard. The risk officer, post-McHire, is going to be told to map it. The compliance lead, post-EU GPAI guidelines, is going to be told to document it. The COO, watching Marriott, is going to be told to own it.
I want to be careful not to overstate this. Many of the AI numbers in the earnings calls this quarter are soft — labor-hours-saved estimates, conversion-lift estimates, satisfaction-score deltas that are inside the noise of the measurement. The disciplined operators are the ones being most cautious about the numbers they put in print. But “cautious about the numbers” is itself the tell. You do not have to be cautious about the numbers if the numbers are not in the model. The numbers are in the model now.
A second pattern in the transcripts is worth flagging because I think it will turn out to be the most-cited operator move of the back half. Several of the chains have started splitting AI investment into two budget lines: an “operator AI” line that captures the labor, kitchen, and inventory deployments, and a “guest AI” line that captures the agent, recommendation, and personalization deployments. The split is not universal yet, but it is showing up in enough places to be a pattern. The brands that are splitting are the brands that have figured out that the unit economics of operator AI and guest AI are different, the risk profiles are different, and the organizational owners are different. The brands that are not splitting are running both budgets out of IT and will discover in Q4 that they are paying for the same model twice.
What this Mise is not yet ready to say
I said at the top that this is not a framework essay, and I want to come back to that before I sign off, because I have been writing around the framework for the entire piece and I owe the reader the honesty of saying so.
There is a doctrine I keep trying to write that names the dimensions along which an AI-rewritten hospitality operator captures, defends, or loses margin. I think there are four of them. I am not yet ready to publish the list. The reason is not that I do not have candidates — I have candidates, and I have been arguing about them with three or four people I trust for most of the month. The reason is that I am not yet confident the four are the right four, that they are independent of each other, and that the framework predicts as well as it describes. A framework that describes is a framework that gets out of date by Christmas. A framework that predicts is a framework you can run a business off. I want the second kind, and I need August to know whether I have it.
So consider this Mise the scaffolding. The Olo take-private is about the integration margin — who owns the layer that sits between the brand and the consumer. McHire is about the liability margin — who is on the hook when the agent gets it wrong. The EU guidelines are about the compliance margin — who has to document, evaluate, and report. The Marriott ACU is about the experience margin — who owns the agent that sits across the length of the guest stay. The Toast Go 3, if it ships as expected, is about all four at once, which is why I think it is going to turn out to be the punctuation rather than the headline.
Whether those four — integration, liability, compliance, experience — survive the next month of reporting as the actual axes of the framework or whether they collapse into two or expand into five, I do not yet know. I have a private bet with myself that one of them does not make it through August. I am not going to say which.
What I am willing to say, on July 25, with the gold light getting longer on the floorboards, is that something changed this month, and the change is not going to be undone by the August news cycle. The integration layer has been bought out of public view to be rebuilt. The liability boundary has been redrawn around the operator. The regulator has arrived in writing. The first operator has declared it will own the agent. And the largest restaurant POS in North America is six days away from putting the model in the hands of the line.
July 2025 was the month restaurant and hotel AI stopped being a press release and became a business model. I am going to spend August trying to write the doctrine. I am going to spend September watching whether it survives the back-to-school traffic at the QSRs and the run-up to the holiday booking window at the hotels. If the doctrine survives, the next Mise will be a framework. If it does not, I will be in this office on a Friday afternoon in late September writing another scaffolding piece, and I will tell you that too.
For now, the canary is out of the cage, the rulebook is on the table, and there is one announcement left to come. I will see you on the other side of the Go 3.
— Eitan is editor-in-chief of TableTransfers. Tips: eitan@tabletransfers.com.
The Voice Agent Maturity Curve
mise
·12 min read
The Four Margins of a Restaurant
mise
·14 min read
The AI Premium in Hospitality M&A: Broker Story or Real Number?
the bottom line
·9 min read
What the DoorDash/SevenRooms Deal Actually Buys
the bottom line
·11 min read
Related posts
mise
·20 min read
The Voice Agent Maturity Curve
mise
·26 min read
The Four Tables: Why the reservation system is the most contested square foot in hospitality
mise
·22 min read