
Key Points
- Amex GBT reviewed about 139 third-party AI tools or new AI use cases in the past year, compared with 13 the year before, through an internal committee operating under a company AI policy.
- Existing binding corporate rules for cross-border data transfers gave the company a compliance base it then layered EU AI Act governance onto, Varma said — something she said peers have not necessarily done.
- Personal and payment data are blocked from Amex GBT’s AI tools, confidential inputs are scrubbed, and travelers ready to book are routed to a human. Varma called these non-negotiables.
Summary
Amex GBT has built a formal review process for AI tools, and the volume of requests is climbing fast. Speaking at the Skift Data and AI Summit Europe, Chief Privacy Officer Sheena Varma said the travel management company reviewed about 139 third-party AI tools or new AI use cases in the past year, up from 13 the year before. An internal committee, governed by a company AI policy overseen by product and infrastructure teams, takes in employee proposals and assesses the tool, the data involved, potential risks, and whether another team is already building something similar. The committee initially met weekly and now meets less often as the process has scaled, using reusable checklists, routing only flagged proposals to deeper review, and embedding AI review inside product development. Amex GBT also uses binding corporate rules — legally binding, regulator-approved data protection rules for cross-border personal data transfers — which Varma said gave it a base to layer on EU AI Act governance, and which she said peers have not necessarily adopted. Personal information and payment data are blocked from its AI tools, confidential data is scrubbed on input, and travelers ready to book are directed to a human. Varma called those “non-negotiables,” and said customers ask for transparency in how AI decisions are made.
