How Amex GBT Reviews AI Risk and Governance
Amex GBT reviewed about 139 third-party AI tools or new use cases in the past year, up significantly from 13 the previous year.

Stock photo for illustration only, not from the actual event
- Amex GBT reviewed around 139 AI tools in the past year, up from 13 previously.
- Utilizes binding corporate rules for cross-border data transfers as a compliance foundation.
- Blocks personal and payment data completely from entering AI systems.
American Express Global Business Travel (Amex GBT) treats trust as a core product, establishing a formal review process for artificial intelligence under an internal company AI policy overseen by product and infrastructure teams.
Sheena Varma, chief privacy officer, VP and senior counsel at Amex GBT, detailed the travel management company's evaluation framework at the Skift Data and AI Summit Europe. She noted that the company reviewed approximately 139 third-party AI tools or new AI use cases over the past year, compared to just 13 the year before.
The internal committee initially convened weekly before scaling back its meeting frequency as the review process matured. The workflow now utilizes reusable checklists, funnels only flagged proposals into deeper reviews, and embeds AI assessments directly into product development cycles.

Stock photo for illustration only, not from the actual event
"Think about your company’s reputation, right? You don’t want to be that person who’s created something that suddenly gets them into the press headlines for all the wrong reasons. So that’s something that I think has to be put front an"
Sheena Varma
According to Varma, Amex GBT leveraged its existing legally binding, regulator-approved binding corporate rules for cross-border personal data transfers as a solid base to layer EU AI Act governance on top of—an approach she noted that industry peers have not necessarily replicated.
As corporate travel management companies navigate the intersection of rapid AI adoption and rigorous international regulations like the EU AI Act, establishing formalized and auditable internal governance is crucial for maintaining enterprise client trust and avoiding reputational fallout.
Furthermore, Amex GBT enforces strict non-negotiable boundaries: personal information and payment data are blocked from its AI tools, confidential input data is scrubbed, and travelers ready to complete a booking are always routed directly to a human agent.
Source: Skift
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment