“The new PRD serves as an evaluator,” said Xavi Amatrian, the inaugural Chief AI and Data Officer at Expedia Group. During the VB Transform 2026 conference in Menlo Park last week, he stated, “Essentially, you encode your desired product functionalities through evaluations, which may include red team assessments and other evaluations that inherently include numerous security requirements. Thus, before initiating coding, you’re already embedding security considerations into your PRD and product design documents.”
He further elaborated, “With AI-assisted or AI-generated code, the future is all about the thought process embedded in the evaluations.”
Before joining Expedia in December 2025, Mr. Amatrian was the Vice President of AI and Compute Enablement at Google, overseeing Gemini and the infrastructure behind Google Search. He has also mentored individuals who went on to establish Perplexity and Scale AI.
VentureBeat’s VB Pulse study on valuation gaps enhances this perspective. Of the 157 companies surveyed, 66% have permitted some production deployments absent of human review, or are progressing toward this within the next year. However, only 5% express complete trust in automated assessments for decision-making. Alarmingly, half of those who deployed agents that excelled in internal evaluations found them lacking when interacting with actual customers.
Minimizing Guardrails to Enhance Feedback
“Excessive guardrails and artificial business rules diminish system efficacy,” warned Amatrian. “Not only do they make the system brittle, but they also disrupt the feedback loop, biasing user interactions and leading to misguided learning.” He described guardrails as a “necessary evil,” emphasizing the importance of mitigating long-term negative impacts.
However, not all participants at Transform concurred. Other speakers cautioned that the most hazardous behaviors still demand robust guardrails.
Expedia’s approach to AI governance operates on three foundational layers. First, principles are clearly articulated and widely disseminated. “I prefer to define decision-making expectations at a high level due to the extensive number of distributed decisions in large organizations,” asserts Amatrian. “If fortunate, these principles become part of the organizational culture; yet, often, that’s not the case.” The subsequent layers consist of processes and tools designed to reinforce these principles. “While principles may appear appealing on inspirational posters, practical implementation is crucial,” he noted. Automation is layered atop these structures.
This governance is manifest in risk-specific checkpoints, branded as Agent Release Tollbooths by Expedia. “Governance should correlate with risk levels,” Amatrian explained. “For low-risk scenarios, minimal governance suffices, while high-risk situations demand comprehensive oversight.” The Tollbooth mechanism aligns evaluation cycles, red team activities, and security reviews according to each agent’s risk profile, transitioning from recommended to mandatory as risk escalates.
Embracing Specialized Agents for Diverse Intelligence
“During my tenure at Google, I maintained that AGI isn’t a singular entity, but rather a composition of specialized agents excelling at specific tasks,” Amatrian expressed to the audience. “This approach embraces the integration of skilled agents into a cohesive system.”
Expedia’s architecture begins at the elemental level. Tools are categorized into skills, integrated into subagents, and combined into full-fledged agent systems. “A coherent set of principles dictating tone, user interaction, and context management is vital,” he noted. “The design must be thorough and systematic.” He framed this as a systematic design challenge, emphasizing that it revolves around system engineering rather than model selection.
Amatrian argued that refining the scope of each agent ultimately enhances system security, as teams can closely evaluate and secure each agent individually prior to broader integration.
Ensuring User Involvement in Decision-Making
Travel costs fluctuate in real time, flight availability changes minute-to-minute, and hotel reviews frequently contradict supplier claims. Amatrian outlined a system that fuses search extension generation with direct API tool interactions, selecting an approach based on response time. “When a user inquires about what a four-star hotel in Chicago costs in July,” he explained, “it’s unreasonable to anticipate a two-minute response.” “While immediate answers are unrealistic for some queries, a four-star hotel with pet-friendly amenities by Lake Michigan can yield a decision in 30 seconds.”
“Suppliers may assert they provide top-tier amenities, but our reviews may reveal otherwise—like two reports highlighting the pool’s unavailability,” Amatrian stated. While typical chatbots rely solely on supplier self-reports, Expedia cross-references data with an extensive repository of actual reviews.
“We don’t want agents booking hotels or purchasing flights on users’ behalf,” Amatrian stressed. “That action is reserved for the user to initiate. The agency can recommend, suggest, and engage, but the user must make the final click—this process is non-negotiable.” He also posited that this limitation is a security measure. “Once these design principles are firmly in place, guardrails become superfluous; otherwise, you’d have to retroactively implement them.”
The New Threat: AI Systems
“Security must be ingrained as early as possible in the design process,” Amatrian emphasized in response to an audience query. “Typically, the need for guardrails signals a failure to prioritize security during initial development.”
When prompted about production insights, Amatrian illustrated a feedback loop enabling monitoring signals to inform the evaluation suite. “The entire cycle can be significantly automated,” he remarked, “but it is imperative to sustain this process to ensure real-time feedback from operational AI systems.”
The Amatrian tollbooth represents a commitment to maintaining risk-informed governance ahead of feedback cycles. VentureBeat’s June Pulse survey of agent security from 107 firms highlights the urgency: over half, 54%, reported an agent security incident, and 59% plan to enhance their security tools within the coming year, with 29% aiming for immediate migration. The incidence of security breaches rises with company size, affecting 63% of organizations with over 1,000 employees and 49% of those with between 101 to 1,000 employees. Moreover, the adoption of sandbox isolation measures, which limit damage following breaches, drops significantly from 35% among small businesses to just 20% among large enterprises.
Amatriain cautioned that evolving threats often originate from other AI systems. “Threats emerge not solely from human actors but also from other potentially powerful agent systems; they will test every facet of your operations. Identification is just the beginning; addressing these threats promptly is crucial.”
Source: venturebeat.com


