IAG’s 3-question AI automation test any operator can steal

a laptop computer sitting on top of a white table

Most AI governance content is vague. IAG’s is not. Speaking at the Skift Data + AI Summit in London, Ben Dias, chief AI scientist at British Airways parent IAG, shared a concrete three-question test the group runs before automating anything with AI.

The 3-question test

Before automating a task, IAG asks:

  1. How critical is it? If it fails, what is the cost in revenue, safety, customers, and reputation?
  2. What’s the blast radius? Is a failure self-contained, or does it cascade across other systems?
  3. What’s the fallback? If the AI fails (and Dias noted plainly that AI does fail), what happens next?

Dias said plenty can be automated if the system recovers quickly. If it can’t, the decision goes through risk assessment. The default posture is to augment humans first and automate only when the risk level justifies it.

How IAG structures AI governance

IAG operates a federal model. The group focuses on domain-level transformation, including maintenance, repair, and overhaul. Each airline in the group runs its own AI team and handles its own use cases. Risk committees sit inside each carrier for faster, more context-aware assessments.

The group also has a 10-principle AI policy. It covers elements including no bias and discrimination, human oversight, and what Dias described as wanting AI initiatives to be “adequately accurate.” Every solution gets mapped against these principles. A failed mapping doesn’t kill the project: the team asks what mitigations can be put in place instead.

What hotel groups are doing differently

Two hotel executives at the same event offered contrasting takes on AI governance.

Nicolas Maynard, SVP of data and AI at Accor, described a more centralized approach. The concern: developers who assume that because something works on a laptop it will work everywhere. Accor keeps initiatives central to protect customer data and IP, reduce shadow AI, and ensure compliance with regulations including the EU Artificial Intelligence Act. The goal, Maynard said, is not to slow teams down but to make sure they understand the risks before scaling to production.

Kari Anna Fiskvik, chief digital and technology officer at Norway-based hotel group Strawberry, took a looser line. Her view: if you don’t let people experiment, they won’t surface the ideas worth scaling. Strawberry monitors costs and compliance issues but tries not to shut teams down while they’re learning.

The takeaway for operators

IAG’s three questions work at any scale. Before you automate a customer-facing workflow, a billing process, or a data pipeline, run the blast radius check. A quick-recovery failure is a different risk category than a cascading one.

Stay on top of AI & Automation with BizStack Newsletter
BizStack  —  Entrepreneur’s Business Stack
Logo