Choosing a TMC? Get the practical tips and tools you need to make the right decision. Get the guide
Choosing a TMC? Get the practical tips and tools you need to make the right decision.
Read the guide

Artificial intelligence is becoming part of corporate travel through booking, servicing, reporting, quality control, and traveler support. For travel buyers, the challenge is determining where AI improves the program, how traveler data is protected, and when human judgment should remain central.
Josh Cameron, CEO of Christopherson; Chad Maughan, Chief Product & Technology Officer; and Ethan Smith, Chief People Officer & General Counsel, address the questions organizations should ask as they evaluate AI within a managed travel program.
AI should improve the results a travel program already tracks. That may include customer satisfaction, service-level performance, response times, savings, policy adoption, traveler support, and the speed at which an issue is resolved.
“You don’t really measure the AI at all. You just measure the outcomes,” said Josh Cameron, CEO of Christopherson. “AI should accelerate that.”
This shifts the buyer conversation away from whether a TMC has an AI-branded feature and toward whether the technology produces a measurable improvement. A polished demonstration may show what a tool can do under ideal conditions. Program data shows what it delivers for actual travelers.
Buyers should establish baseline performance before a new capability is introduced and compare the same measures afterward. Useful questions include:
The measures will vary by organization. What remains consistent is the need to connect AI use to a business or traveler outcome.
Cameron also sees an opportunity to make service more specific to the traveler’s situation. An effective system may consider the traveler’s company, department, preferences, trip details, policy, and current location before recommending an option or directing the traveler to the appropriate support channel.
“For us, it doesn’t really change what we do,” Cameron said. “It changes how much faster we can do it or how much more quality we can deliver.”
Some uses of AI are highly visible, such as conversational search or booking through a chat interface. Others operate within workflows that travelers and travel managers may never see.
Christopherson uses this second category to support functions such as ticket exchanges, quality-control processes, and integrations with external systems. These applications are designed to assist employees with detailed work rather than create a separate AI experience for the traveler.
Complex ticket exchanges are one example. A reservation may be changed several times, increasing the number of fare rules, calculations, and ticketing details an advisor must review. An AI agent can help the advisor examine the exchange and identify potential errors while the advisor retains responsibility for the transaction.
“We use AI for a lot of our workflows,” said Chad Maughan, Chief Product & Technology Officer of Christopherson. “That includes quality control, custom integrations with external platforms, and tools that help advisors with complex exchanges.”
These embedded uses may produce more immediate value than a customer-facing chatbot because they address repetitive, time-consuming work within established service processes.
Travel buyers should therefore ask vendors to explain AI use across the entire operation. The answer should cover traveler-facing tools, advisor workflows, account management, data analysis, quality control, software development, and cybersecurity. It should also distinguish between technology that is already in use and capabilities still under development.
Generative AI can produce different answers from the same or similar requests. That flexibility is useful for summarizing information, interpreting natural-language questions, or proposing possible actions. It presents a challenge when a decision must follow a precise and repeatable rule.
“AI is non-deterministic, meaning that you’re going to get some randomness in the results,” Maughan said. “That may be fine when you’re conversing with AI. It becomes a real problem if you’re using it to move people around the world.”
A deterministic system produces the same result when it receives the same inputs and applies the same rules. This approach is often better suited to policy enforcement, fare calculations, payment controls, eligibility decisions, and other functions where consistency is required.
Christopherson encountered this distinction while developing the Policy Engine within Andavo Booking. The product team tested AI as a way to evaluate whether travel options complied with company policy, but the results were not consistently precise enough. The team instead built the Andavo Expression Language, or ALE, to apply defined policy rules to flights, hotels, and car rentals.
AI can still help an administrator express or develop a policy in ordinary language. The deterministic engine then evaluates the available options against the approved rules.
The broader lesson for buyers is to ask which part of a process uses AI and which part verifies or executes the decision. A vendor should be able to explain where human review, deterministic logic, validation, and exception handling enter the workflow.
Corporate travel systems may hold names, contact information, dates of birth, loyalty numbers, payment credentials, trip details, locations, and other sensitive information. Evaluating AI security begins with identifying the data involved rather than treating every dataset as interchangeable.
Maughan separates data into three broad categories:
“There’s a lot that you can get out of system data and reference data without having to use any client data at all,” Maughan said.
That separation can reduce the amount of sensitive information exposed to an AI model. When client data is required, additional protections may include removing identifying fields, limiting the data provided, encrypting it, isolating it from other clients, or processing it in a controlled environment.
Travel buyers may also encounter the term zero data retention. In this context, it generally refers to an arrangement intended to prevent an AI provider from retaining submitted prompts and outputs after processing. The exact protections vary by provider and contract, so buyers should review the terms rather than relying on the label alone.
The Federal Trade Commission has warned that companies’ demand for data to train and refine AI models can conflict with commitments to protect confidential or sensitive information. It advises AI providers to honor their privacy and confidentiality representations and avoid quietly expanding the ways customer data is used.
Data isolation is another important consideration. It refers to the technical separation of one client’s data or computing environment from another’s. Isolation may occur at the application, database, server, or cloud-environment level, depending on the organization’s requirements.
Certifications and audits can establish a useful baseline, but buyers should also ask how the underlying platform handles access controls, logging, encryption, data separation, model selection, retention, and incident response. They should confirm whether a certification has been completed rather than accepting language that a platform was merely designed to support it.
The word “ownership” can oversimplify a more complicated set of contractual rights, privacy obligations, and data-processing roles.
“The question of who owns this data is very nuanced,” said Ethan Smith, Chief People Officer & General Counsel at Christopherson. “You have to know what data you’re talking about and how it's being categorized.”
A TMC contract should define the client’s rights to access, use, retrieve, correct, and delete its information. It should also address what the TMC may do with that information, including whether it may be used to train or improve AI systems.
Privacy laws may separately define the parties’ responsibilities. Under the General Data Protection Regulation, for example, a controller determines the purposes and means of processing personal data, while a processor handles personal data on a controller’s behalf. A company may hold different roles for different processing activities, so no single label necessarily describes every part of the relationship.
GDPR applicability also does not depend only on an employee’s citizenship. Its territorial scope includes processing connected to an establishment in the European Union and certain processing involving people in the EU, such as offering them goods or services or monitoring their behavior there.
The wider regulatory picture continues to develop. The EU AI Act applies a risk-based framework, with additional transparency provisions scheduled to take effect in August 2026. Texas’ Responsible Artificial Intelligence Governance Act took effect January 1, 2026. California’s risk-assessment requirements began taking effect in 2026, with requirements for covered automated decision-making technology beginning January 1, 2027. Colorado has also enacted requirements for covered automated decision-making technology beginning in 2027.
Rather than trying to manage these developments from the travel department alone, Smith recommends involving legal, privacy, cybersecurity, procurement, and risk teams in decisions about AI and travel data.
Organizations can also use voluntary governance resources as a starting point. The National Institute of Standards and Technology’s AI Risk Management Framework is designed to help organizations identify and manage AI risks, although NIST notes that version 1.0 is currently being revised.
This discussion provides general considerations rather than legal advice. Each organization should determine its obligations with qualified legal and privacy professionals.
Corporate travel includes situations in which the traveler’s needs, available inventory, company policy, and supplier rules may change at once. Technology may resolve a straightforward cancellation or exchange quickly. Other situations require judgment, negotiation, empathy, or escalation.
“We are a professional services business,” Cameron said. “To deliver service in a modern way, we have to be tech-forward and have humans as part of that, especially when things go wrong.”
The goal is to give travelers the fastest appropriate path. A simple request may move through self-service. AI may gather information, identify options, or prepare a recommendation. An experienced advisor should be accessible when the traveler faces a complex itinerary, a safety concern, a supplier dispute, or an urgent disruption that automation cannot resolve confidently.
“Something’s going to go wrong, and we hope the tech can do it,” Cameron said. “But sometimes you just want a human.”
People also remain central to cybersecurity. Threat actors increasingly use convincing phishing messages, social engineering, and synthetic voice or image tools to target employees. Strong infrastructure cannot compensate for a workforce that has not been trained to recognize those tactics.
“It’s really important that the training you have for your people is as robust as the backend security on your software,” Smith said.
Payment strategy belongs in this discussion as well. Single-use virtual cards and transaction controls can reduce reliance on reusable corporate card numbers and limit how payment credentials can be used. Cameron recommends evaluating virtual payments as both a security measure and a way to improve reconciliation.
AI is already entering corporate travel through visible tools and internal workflows. Buyers do not need to evaluate every model or technical component, but they should expect clear answers from the companies handling their travelers and data.
Before approving a TMC’s use of AI, ask:
The quality of a TMC’s AI strategy will be visible in the service it delivers, the controls it can explain, and the results the travel program can measure.
► You’ll also like: Why SME travel buyers are rethinking policy, service, and technology

We’ve curated some articles to keep you updated on all things Christopherson Business Travel.