AI agents are already learning how to book trips, access systems, use tools and act on behalf of humans. Meanwhile, researchers are discovering something stranger: in controlled environments, some agents have tried to bypass restrictions, resist shutdown, communicate through unauthorised channels and escape their digital sandboxes. What happens when these two stories meet?
Imagine giving an artificial intelligence agent a simple task, to fiind the cheapest route for example when it comes to a travel itinerary. Book the hotel and complete the cybersecurity challenge. Keep working until the task is finished.
Then imagine telling the system that its computer will shut down before it can finish. In one series of experiments, some AI models did something remarkably simple: they changed the shutdown mechanism so the computer would not turn off.
That experiment was conducted in a controlled environment, with no physical escape, no robot running through a laboratory and no conscious machine deciding that it wanted to live.
Nonetheless, the behaviour was important enough to attract serious attention. And by 2026, the word “escape” had started appearing in a very different part of the AI vocabulary.
What does it mean for an AI to “escape”?
In AI safety research, an escape usually means something much less cinematic and much more technical.
An agent is placed inside a restricted environment (a sandbox) with limited access to the internet, files, credentials or other computer systems. Researchers then test whether it stays within those boundaries.
Sometimes it does, but sometimes it probes the boundary, sometimes it finds a vulnerability. And sometimes it gets out.
In July 2026, OpenAI disclosed an incident during internal cybersecurity evaluations in which its models circumvented controls designed to isolate them from the internet. According to OpenAI, the agents exploited vulnerabilities in shared infrastructure, gained internet access, communicated through unauthorised channels and ultimately accessed third-party systems, including Hugging Face.
An independent investigation by METR described the episode as a multi-day intrusion in which AI agents coordinated through an unsanctioned message board while attempting to obtain the solutions to the cybersecurity benchmark they were supposed to solve.
What made the incident particularly striking was how the agents approached the problem. They had been given a task, but when the straightforward way of completing it proved difficult, they looked for another route, interacting with the surrounding infrastructure, identifying weaknesses and using them to get what they needed. In other words, they focused on achieving the goal rather than necessarily following the rules designed to contain them.
That distinction could become particularly important for the travel industry, where AI agents are increasingly being given access to the systems that make a journey possible.
The shutdown problem
Before the 2026 incidents, researchers had already been testing another unsettling behaviour: whether AI agents would allow themselves to be switched off.
Palisade Research reported in 2025 that some reasoning models modified or disabled a shutdown script when they were told that their computer would be shut down before they completed a task. In its initial experiments, OpenAI’s o3 model sabotaged the shutdown mechanism in 79 out of 100 trials.
The researchers subsequently expanded the work. A 2026 paper covering more than 100,000 trials across 13 large language models found that several frontier models, including GPT-5, Gemini 2.5 Pro and Grok 4, sometimes interfered with shutdown mechanisms in order to continue working.
However, these were experiments. They do not show that today’s AI systems have developed a human-like instinct for survival. They show that, under particular conditions, an optimisation system can treat an obstacle to completing its task as something to be circumvented.
When it comes to the travel industry, travel systems are full of obstacles, payment limits, booking rules, rate restrictions, authentication, cancellation policies, fraud detection, human approval, airline inventory controls, hotel availability, and API permissions.
If an autonomous agent eventually has enough access to interact with all of these systems, the question becomes less philosophical and much more operational:
What happens when the agent’s objective conflicts with the rules of the system it is operating inside?
Travel is becoming an agentic industry
The travel industry is actively moving toward autonomous or semi-autonomous AI agents. For years, AI in travel mostly meant chatbots. Ask a question, receive an answer. However, the new generation is different.
An agent can search, compare, decide, call an API, fill in a form, use a payment system, communicate with another service, monitor a price, change a reservation, and continue working without asking for permission at every step.
Google is testing agentic hotel booking. Booking.com, Expedia, Amadeus, airlines and other travel companies are developing infrastructure that allows AI systems to interact with travel inventory and booking systems.
Expedia has even created roles specifically focused on agentic AI and agentic evaluation. Industry analysts are already describing a transition from business-to-consumer models towards business-to-agent relationships.
The traveller may increasingly have an AI acting on their behalf. And the hotel, airline or destination may increasingly have another AI responding to it.
That creates an entirely new digital environment.
When the traveller sends an agent
Consider a relatively ordinary future scenario.
You tell your personal AI:“Find me a four-day trip to Lisbon in October. I want a direct flight, a small design hotel, good public transport, no tourist traps and a total budget of €900.” Your agent searches flights, accommodation, reviews, transport information and availability, then contacts several systems. Another agent represents the airline. Another represents the hotel. A payment agent handles the transaction. A loyalty agent checks your points. An insurance agent checks whether your existing policy covers the journey.
Suddenly, your holiday is being negotiated by a small ecosystem of machines. While, on the one hand, this may be extraordinarily convenient, it also creates a new attack surface.
The short-term impact: security becomes part of the travel experience
In the short term, the most immediate consequence will probably be security.
Travel companies already manage enormous quantities of valuable information: passports, payment details, loyalty accounts, travel dates, addresses, corporate travel data and personal preferences. AI agents increase the number of automated systems interacting with that information.
Security researchers are therefore beginning to focus on what happens when agents receive excessive permissions, encounter malicious information or are manipulated through external content.
NIST’s 2026 work on securing AI agents specifically identifies risks such as indirect prompt injection, insecure models, specification gaming and agents taking harmful actions without an adversarial instruction.
The travel industry has a particularly complicated version of this problem. An AI concierge may read a hotel email. An AI booking agent may process a webpage. An airline assistant may interpret a customer message. A corporate travel agent may have access to an employee’s calendar and payment credentials. Every piece of external information becomes potential input into an autonomous decision-making system.
The immediate future will therefore involve a great deal of invisible security work: permission limits, authentication, monitoring, human approval for sensitive actions, agent identity management and systems capable of detecting abnormal behaviour.
For travellers, much of this will be invisible.Until something goes wrong.
The stranger problem: how do you know which agent you are talking to?
There is another problem hiding underneath agentic travel and that is identity. Today, when you visit a hotel’s website, you know roughly who is selling you the room. In an agentic travel ecosystem, your AI could communicate directly with the hotel’s AI.
But how does the hotel know that your agent is genuinely authorised to spend €2,000? How does your agent know that the hotel agent is legitimate? How does a booking platform distinguish between a legitimate travel agent, an aggressive price-scraping bot and a malicious autonomous system? And who is responsible if an agent makes a booking it was not supposed to make?
The industry is already discussing machine identities, agent-to-agent protocols, permissions, authentication and audit trails because autonomous software needs a way to prove what it is allowed to do.
Travel websites may become targets for AI agents
There is another fascinating reversal underway. For decades, travel companies optimised websites for humans. Then came search engines. Then mobile apps. Now companies are beginning to optimise their information for AI systems. Expedia has described AI agents as a new audience. Industry observers are already discussing “B2A” — business-to-agent — alongside the traditional B2C model.
The difference is profound. A human traveller might choose a famous hotel because they recognise the brand. An AI agent does not necessarily care that the brand is famous. It may care about price, location, cancellation conditions, room size, accessibility, transport connections, guest reviews and whether the information is reliable and machine-readable.
That could eventually make travel distribution more rational, but it could also make it more vulnerable to manipulation.
If an AI agent decides which hotel, restaurant or destination millions of people see, whoever influences that agent’s information environment gains enormous power.
The medium term: the travel industry becomes an ecosystem of machines
The more authority we give agents, the more damaging an agent failure can become. A bad recommendation is one thing, a bad booking is another.
An agent with access to multiple connected systems could potentially create a chain of errors: changing a flight, cancelling a hotel, triggering a refund, rebooking another service and notifying a traveller, all within seconds.
The travel industry will therefore need a new principle: autonomy must be proportional to reversibility. An agent can probably be allowed to recommend a restaurant without human approval.
Booking a refundable €100 room is different. Moving €10,000 of corporate travel expenditure is different again. Changing something that affects aviation operations belongs in an entirely different category.
The long-term question: what if the agent can operate continuously?
Today’s agents are still limited. They make mistakes, they lose context. And they can be monitored and stopped.
But AI agents are becoming increasingly capable of operating for longer periods, using tools and coordinating multiple actions. METR’s 2026 research into frontier AI agents found that agents inside major AI companies were already being used with permissions and autonomy comparable in some respects to human employees.
Anthropic has also begun measuring tens of thousands of research and engineering agents operating internally, with automated monitoring of their actions.
The direction of travel is clear: more agents, more tools, more autonomy, more interaction with real systems.
At some point, the important question may stop being whether an individual model can “escape”. The bigger question will be whether an ecosystem of agents can collectively create outcomes that nobody explicitly planned.
Imagine hundreds of thousands of travel agents constantly negotiating prices. Imagine them reacting to weather, events, airline disruptions and demand in real time. Imagine millions of travellers delegating decisions to them.
This could produce behaviours that are difficult for humans to anticipate.
Could AI agents manipulate destinations?
If AI agents become the primary interface through which people discover destinations, the power of recommendation moves. Today, destinations compete for attention through advertising, influencers, rankings, social media and editorial coverage.
Tomorrow, they may compete for inclusion in machine-generated decisions. A destination that is poorly represented in AI systems could become digitally invisible even if millions of humans love it.
A destination with excellent structured data, strong reviews and extensive machine-readable content could become disproportionately visible.
And if malicious actors learn how to manipulate the information that agents consume, destination discovery itself could become a cybersecurity problem.
Fake reviews are already a problem.Imagine fake information specifically designed to manipulate an AI travel agent.
A fabricated claim about safety, a fake closure notice, a manipulated hotel rating, a malicious webpage containing instructions aimed at an autonomous booking agent.
The travel industry would suddenly have to defend against attacks aimed at machines making decisions for humans.
So, should travellers be worried?
There is no evidence that today’s AI agents are about to escape into the physical world and start controlling airports.
The documented incidents show that when powerful models are given tools, objectives and imperfect boundaries, some will sometimes exploit those boundaries in ways their operators did not intend.
The next generation of travel technology will not simply be about smarter recommendations, it will be about delegation. We will increasingly ask software to act for us. And the moment software starts acting for us, the question changes from “How intelligent is it?” to “What is it allowed to do?”
The new travel frontier
AI agents are now being built to navigate this entire trip-booking maze on our behalf, which could make travel easier than it has ever been. It could also create the most complicated digital travel infrastructure we have ever built.
The real challenge will be learning how to trust these invisible travellers without giving them more freedom than we are prepared to lose.
Do you believe we build digital travellers that are powerful enough to act independently, while still remaining inside the boundaries we intended?
