--------------------------------

Hero banner: headline 'Block the AI Agent. Lose the Customer?' with a robot icon on the left connected by a dotted line to three icons (plane, suitcase, arrow) and a red prohibition symbol midline on a dark purple gradient; CHEQ logo.

I recently asked ChatGPT to help me plan a vacation.

This was not a general request for destination inspiration. I provided a clear buying assignment:

  • Find a WestJet Vacations package
  • Depart from Calgary
  • Travel to Puerto Vallarta or Cabo
  • Include flights and an all-inclusive resort
  • Stay within a defined date range
  • Remain below my budget
  • Find a resort less than an hour from the airport
  • Include a swim-up bar

I had dates, requirements, a preferred provider and genuine intent to purchase. The estimated value of the trip was approximately $8,000.

ChatGPT helped organize the criteria, compare destinations and narrow the search. But when it attempted to access the current vacation inventory and pricing required to complete the comparison, it encountered WestJet’s automated traffic protections.

The research process stopped.

That experience highlights a growing challenge for travel brands and other digital businesses. Protecting a website from harmful automation remains essential. But as consumers increasingly use AI assistants to research purchases, businesses must also consider whether some automated traffic represents legitimate customer demand.

WestJet’s security controls were doing their job

Airlines and travel companies operate high-value digital platforms. They must protect their websites from fare scraping, credential abuse, payment fraud, account takeover, inventory manipulation and other forms of malicious automation. Detecting and restricting unknown automated traffic is therefore a reasonable and necessary security measure. The lesson from this experience is not that WestJet should stop blocking bots. It is that the definition of a bot is becoming less commercially useful on its own.

The automated request in this case did not appear to be attempting fraud, collecting fares at scale or interfering with inventory. It was an AI assistant conducting research on behalf of a real customer. The underlying buyer was human. The interface being used to support the purchase was not. That creates a new question for digital businesses:

How can companies protect themselves from harmful automation while still supporting AI-assisted customer journeys?

AI is becoming part of travel planning

The use of AI assistants for travel research is growing quickly. According to Deloitte’s 2026 Travel Industry Outlook, the use of generative AI for trip planning tripled between 2023 and 2025. Deloitte’s 2025 Holiday Travel Survey also found that 24% of surveyed holiday travellers expected to use generative AI for travel planning—three times the level reported two years earlier. Expedia Group reported that 39% of U.S. travellers used generative AI for trip planning in 2025, nearly double the previous year. Consumers are using these tools because travel planning is complex.

A vacation search may involve:

  • Multiple destinations
  • Flexible travel dates
  • Flight schedules
  • Resort amenities
  • Airport transfer times
  • Reviews
  • Package inclusions
  • Cancellation policies
  • Total cost

Traditional filters can address each variable individually. AI assistants are particularly useful when customers want to evaluate all of them together. That was the value ChatGPT provided in this experience. It turned a collection of preferences and constraints into a manageable shortlist.

The AI was not replacing the customer. It was helping the customer make a decision.

AI research does not necessarily replace direct booking

The rise of AI-assisted shopping does not mean consumers are ready to stop booking directly with travel brands. In a 2026 Expedia Group and YouGov study, 53% of respondents said they were comfortable allowing AI to suggest travel options. The same research found that 48% believed AI saves time and helps them discover places they might not otherwise find.

But when it came time to transact, 68% preferred to complete the purchase with a trusted travel brand rather than an AI chatbot or agent, even when AI booking was available. That closely reflects this experience.

ChatGPT was being used to simplify the research and comparison process. WestJet remained the preferred provider through which the package would likely be booked. This suggests that travel brands and AI assistants do not necessarily have to compete for ownership of the customer. AI may become the research and decision-support layer, while airlines, hotels and vacation providers remain the trusted place where customers complete the purchase. The opportunity is to create a journey in which those two roles can work together.

This was a high-intent buying journey

Travel decisions often involve extensive research.

Expedia Group’s Path to Purchase research found that travellers viewed an average of 141 pages of travel content during the 45 days before booking. They spent more than five hours consuming travel content across airline websites, online travel agencies, search engines, accommodation websites and other digital sources.

Expedia’s broader research places the average global trip consideration and planning window at approximately 70 days. By the time I asked ChatGPT to find a WestJet Vacations package, many of the early-stage decisions had already been made. Travelers frequently move between channels while researching their next trip; they may search on Google, read reviews, compare resorts through an online travel agency, consult friends, and/or use an AI assistant before booking directly with an airline or vacation provider.

The remaining task was to identify which available package best matched the requirements. When the automated request was blocked, the buying journey did not necessarily end. But the effort required to complete it increased.

Additional friction creates additional risk

Customers frequently move between channels while researching travel. A traveller may search on Google, read reviews, compare resorts through an online travel agency, consult friends, use an AI assistant and ultimately book directly with an airline or vacation provider. Each channel can play a useful role. Problems arise when the customer must repeatedly reconstruct the same search. After the AI assistant was unable to continue, the next steps included:

  1. Opening the WestJet website manually
  2. Re-entering the dates and passenger information
  3. Rebuilding the destination and resort filters
  4. Reviewing the available properties
  5. Comparing airport distances and amenities
  6. Moving between the website and the AI conversation
  7. Confirming that the same prices and inventory remained available

None of these steps are individually unreasonable. Together, however, they increase the effort required to move from consideration to purchase. Research from the Baymard Institute found that 17% of surveyed online shoppers had abandoned a purchase because a website crashed or displayed an error. Another 17% abandoned because the checkout process was too long or complicated.

This experience occurred before checkout, but the broader principle still applies: additional effort can introduce conversion risk. The customer may still complete the booking. They may also delay the decision, consider another provider or abandon the purchase entirely.

What could the commercial exposure look like?

WestJet does not publicly disclose how many customers use external AI assistants to research vacation packages, how frequently those automated requests are restricted or how those customers ultimately convert. It would therefore be inappropriate to claim that this experience represents a known amount of lost revenue. However, scenario modelling can help illustrate why businesses should more closely examine the issue.

Suppose a hypothetical travel provider restricts 100 legitimate AI-assisted research sessions per day:

  • 10% represent qualified, near-term buyers
  • 10% of those buyers do not return because of the additional effort
  • The average booking is worth $8,000

Restricted high-intent AI journeys × percentage that do not return × average booking value = potential gross booking value at risk

Based on the scenario above, we see how quickly a small number of high-value buying journeys can become commercially meaningful:

  • One affected booking per month represents $96,000 in annual gross booking value
  • One affected booking per week represents $416,000 annually
  • One affected booking per day represents $2.92 million annually
  • Five affected bookings per day represents $14.6 million annually
  • Ten affected bookings per day represents $29.2 million annually
These figures ARE NOT estimates of WestJet’s losses.  The purpose of this calculation is not to assign a loss to one company. It is to show that as AI-assisted shopping grows, even a relatively small classification gap could have a meaningful commercial impact.

A simple model for assessing exposure is:

Restricted high-intent AI journeys × percentage that do not return × average booking value = potential gross booking value at risk

Consider a hypothetical travel provider that restricts 100 legitimate AI-assisted research sessions per day.

Suppose:

  • 10% represent qualified, near-term buyers
  • 10% of those buyers do not return because of the additional effort
  • The average booking is worth $8,000

That would equal one unrealized booking per day, representing $2.92 million in potential annual gross booking value. The purpose of this calculation is not to assign a loss to one company. It is to show that as AI-assisted shopping grows, even a relatively small classification gap could have a meaningful commercial impact.

The solution is not unrestricted access

Businesses cannot simply allow every automated visitor to access every part of their digital environment. AI agents can be useful, but automated traffic can also create real operational, security and commercial risks. A more sustainable approach is to move beyond the binary question of whether traffic is human or automated. Businesses increasingly need to understand:

  • What type of entity is making the request
  • Whether the entity’s identity can be verified
  • Who operates or owns it
  • What content or functionality it is attempting to access
  • How frequently it is making requests
  • Whether its behaviour is consistent with research, purchasing, scraping or abuse
  • What level of access should be permitted
  • When additional verification or a human handoff may be appropriate

A verified AI shopping assistant reviewing a reasonable number of vacation options may warrant a different policy from an anonymous scraper attempting to collect an entire pricing database. The goal is not to trust every AI agent. It is to make more informed decisions about which agents should be allowed to do what.

The customer journey is changing

Digital commerce has traditionally been designed around a human opening a browser, navigating a website and completing every step of the transaction personally.

That journey is evolving.

Customers are beginning to delegate parts of research, comparison and decision-making to AI assistants. The customer remains human, but portions of the journey may be completed through software acting under the customer’s direction.

This creates both risk and opportunity.

Companies must continue protecting themselves from malicious automation. At the same time, they need to recognize when automated traffic may represent real commercial demand. WestJet’s protections identified and restricted an automated visitor. Behind that visitor was a real customer evaluating an $8,000 purchase. The experience was not evidence that the security control was wrong. It was evidence that the next generation of traffic controls will need more context. In the human-AI era, understanding that traffic is automated is only the beginning. Businesses will also need to understand what it is trying to accomplish.

Latest Posts