American Express Global Business Travel has started letting an AI agent spend its clients' money. On July 27, 2026, Amex GBT launched an "Egencia AI connector" inside Anthropic's Claude, backed by a new agent-to-agent (A2A) infrastructure layer. A traveler, or an enterprise AI agent acting on their behalf, can ask Claude to check a calendar, propose an itinerary, and then buy the flight and hotel, inside company travel policy, using the traveler's own profile and negotiated corporate rates. Amex GBT calls it one of the industry's first agentic integrations that completes a real transaction, not just information retrieval.
That distinction is the news. Most enterprise "agentic AI" in 2026 still stops at the draft: it recommends, summarizes, drafts something for a human to send. Amex GBT built something that reaches further. Claude can call Egencia AI as a tool and finish the purchase. It also isn't betting this on one AI vendor: alongside Claude, it's rolling Egencia's conversational AI into Google Chat (early adopters from August 2026, general availability by year-end) and piloting a Microsoft Teams assistant for Neo customers. That's three ecosystems, not one exclusive bet.
Recommending and transacting are different problems
A chatbot suggesting three flight options is a UX feature. A system that charges the corporate card is a financial control. Amex GBT bridges that gap with what it calls an "agentic thinking layer": it interprets the traveler's request, breaks it into tasks, and routes each to a specialized agent (one for flight shopping, one for hotel search, one for booking) via Anthropic's Model Context Protocol. That layer, already live inside Egencia AI, hits better than 80% accuracy on multi-step task sequencing, Amex GBT says, with response times under 25 seconds. That's vendor-reported, not independently benchmarked, but specific enough to check.
That's not a small engineering step. Most travel-and-expense tools marketed as "agentic" in 2026 still route the purchase through a human clicking confirm, because liability makes that the safer default. Amex GBT crossing that line is the notable move, not the underlying model. What changed isn't Claude's capability; it's that a company holding corporate card data and negotiated airline contracts decided its own orchestration was trustworthy enough to remove that step.
"Within policy" is doing a lot of work in that sentence
Here's what's actually described, and what isn't. Policy enforcement, as Amex GBT explains it, isn't a separate approval step. It's baked into the routing. Traveler profiles, negotiated corporate agreements, and configured policy rules sit inside the orchestration layer itself, and bookings are constrained to Amex GBT's own marketplace, so the agent can't reach outside pre-vetted inventory. Every transaction runs under the traveler's own credentials, tying it to an accountable person, and results flow into standard reporting afterward.
What's conspicuously absent from the coverage we reviewed, including Amex GBT's own materials, is any human-in-the-loop checkpoint for exceptions: an out-of-policy request, an unusual fare, a spend threshold that should trigger a second look. That may exist without being publicized, or it may not exist yet. Either way, it's the right question, not a gotcha. Amex GBT's own commissioned Forrester research, released alongside the launch, found 78% of enterprise decision-makers cite governance and auditability as the barrier to approving autonomous AI purchasing. That's the vendor's own data naming what the market hasn't resolved.
The multi-platform bet is itself the signal
Shipping into Claude, Google Chat, and Microsoft Teams at once is unusual discipline: it means Amex GBT's policy engine, marketplace, and reporting have to behave identically no matter which model is holding the conversation, which is a harder integration problem than picking a favorite. For buyers, it's a hedge against platform lock-in. For Amex GBT, it's a bet that the value sits in the orchestration layer, not the chat interface on top of it.
How True Horizon does it
When we wire transactional authority into an agent for a client, we treat "policy compliance" as a property to test, not a feature to trust. That means building the audit trail and exception path before the agent gets a live credential, simulating out-of-policy requests and ambiguous instructions against the actual routing logic rather than the marketing description of it, so the client can show an auditor exactly how a boundary is enforced instead of just asserting it.
What to do now
If you're evaluating a connector like this, Amex GBT's or anyone's, ask the vendor to walk through what happens on an out-of-policy request, in writing, before you pilot it. Ask for the audit log format, not just the existence of "reporting." Pilot with a hard spend ceiling and a narrow traveler group before it touches your full travel budget. The architecture may be sound, but "sound" is what you verify, not assume.
If you want a clearer picture of what your own AI agents are actually authorized to do, versus what you assume they're authorized to do, take our AI assessment and we'll show you where the gap is.

Written by
Milan Tahliani
Co-Founder & CEO
I'm Milan, an AI enthusiast and entrepreneur passionate about making cutting-edge technologies accessible and efficient for businesses.









