A man’s grandmother died. He went to an airline’s website, asked the chatbot about bereavement fares, and was told he could book at full price and apply for the reduced fare retroactively within ninety days. He did exactly that. The airline then refused, because its actual policy — published elsewhere on the same website — says bereavement fares cannot be claimed after travel.
When the case reached the British Columbia Civil Resolution Tribunal in February 2024, Air Canada argued, among other things, that the chatbot was “a separate legal entity that is responsible for its own actions.”
The tribunal was unimpressed. Its response has been quoted in every AI governance deck since: the chatbot “is still just a part of Air Canada’s website. It should be obvious to Air Canada that it is responsible for all the information on its website.”
Air Canada was ordered to pay C$650.88 in damages, plus interest and fees. Financially, nothing. As a precedent, one of the most useful few hundred dollars ever spent, because it settled a question a great many organisations were quietly hoping would stay open: you own what your automation says.
That is the context in which ITIL Version 5 describes itself as AI-native. Let us look at what that actually means.
What “AI-native” contains
Four concrete things, and it is worth separating them from the marketing.
The ITIL AI Capability Model — the six Cs. A taxonomy of what AI actually does in a service context:
- Creation — generating new content, code or documentation.
- Curation — improving the quality and relevance of existing data, including identifying redundancies.
- Clarification — helping people navigate and understand complex content, such as summarising an incident ticket.
- Cognition — identifying patterns and hidden insights, for proactive problem detection.
- Communication — natural interfaces such as chatbots and virtual assistants.
- Coordination — autonomous execution and orchestration of actions across systems.
I like this model more than I expected to, for one reason: the six are in ascending order of consequence, and most organisations are deploying them in the wrong order. Creation and Communication are the visible, demo-friendly ones — write me a knowledge article, answer the user’s question. Curation and Cognition are where the actual operational value sits, and they are boring. Coordination is where the risk lives, because Coordination means the system does things.
If your AI programme consists of a chatbot on the portal and nothing else, you have taken the highest-exposure, lowest-value option first. That is not a framework observation, it is an observation from watching organisations do it.
A new subsection on organisations, people and AI inside the four dimensions. Modest, but it puts the workforce question inside the model rather than beside it.
A dedicated ITIL AI Governance publication and certification. No prerequisites, so anyone can take it. It covers AI fundamentals and governance, benefits and risks, AI in organisational contexts, good AI governance, the AI Capability Model and an AI Governance Improvement Model, and how regulation shapes governance. Its stated purpose is to help organisations “adopt and scale AI responsibly” while building “oversight, accountability, transparency, and ethical safeguards.”
AI threaded through the advanced modules — ITIL Product covers AI-enabled ways of working, ITIL Service covers AI-enabled service delivery, and the Managing Professional Transition covers AI-enabled operating models.
What “AI-native” does not yet contain
Be careful here, because the gap matters if you are buying training.
The AI content lives in Foundation, in the advanced modules and in the separate AI Governance publication. It does not yet live inside the thirty-four practice guides. Those are still the ITIL 4 documents. PeopleCert has scheduled their update for the second half of 2026, and one of the three stated changes is the “addition of established AI use” in selected practices — which practices has not been announced.
So if you are hoping to open the incident management practice guide and find guidance on validating an AI triage suggestion before it reaches a customer, that guidance is not there yet. Plan accordingly.
The governance question the framework is actually pointing at
Strip away the vocabulary and ITIL 5’s AI material is asking one question: who is accountable for what the system decides?
Air Canada answered it accidentally and expensively. Most organisations have not answered it at all, and the reason is structural. An AI capability in a service desk typically arrives through the tooling. The ITSM platform ships an assistant. Somebody turns it on. It is configured by an administrator, trained on the knowledge base, and measured on deflection rate. At no point does it pass through a design authority, a risk assessment, or a change advisory board, because it is a feature of a product you already own, not a new system.
Then it tells a customer something that is not true.
I would put three questions to any organisation running AI in a service context, and I would want written answers.
What is it allowed to say, and what must it escalate? Not as a principle — as a list. Refunds, entitlements, safety, medical, legal, financial, anything with a deadline attached. If the boundary is not written down, it is being set by whatever the model happens to produce.
What did it say, and can we reconstruct it? Air Canada could be held to what its chatbot said because the customer had a screenshot. Can you produce the transcript of a conversation from four months ago, with the version of the model and the knowledge source it used? If not, you cannot investigate a complaint, and you certainly cannot defend one.
Who reviews the ground truth? Curation, in the six Cs, is the unglamorous practice of keeping the underlying data accurate. Every AI failure I have looked at in a service context traces back to content that was wrong, stale or contradictory — Air Canada’s own website contained the correct policy and the chatbot contradicted it. The model was not hallucinating a fact from nowhere; it was reconciling a poorly curated knowledge estate and getting it wrong. That is a knowledge management failure wearing an AI costume.
Where ITIL 5 meets the standards and the regulators
ITIL is not a certifiable management system. If you need to demonstrate AI governance to a customer, an auditor or a regulator, you need something that is.
ISO/IEC 42001 is the AI management system standard, and it will feel immediately familiar to anyone who has been through ISO/IEC 27001: context, leadership, planning, support, operation, evaluation, improvement. What changes is the subject matter — the standard is concerned with the impact of AI systems on the people affected by them, not only on the organisation deploying them. It is certifiable, and it is the practical vehicle for turning ITIL 5’s AI framing into evidence. I qualified as a lead auditor for it precisely because clients started asking the question and there was nothing else to point at.
The EU AI Act entered into force on 1 August 2024 and applies in phases. Prohibitions and AI literacy obligations have applied since 2 February 2025. Obligations for general-purpose AI model providers began on 2 August 2025. Transparency requirements and enforcement across prohibitions, transparency and AI literacy apply from 2 August 2026. The rules for high-risk systems listed in Annex III now apply from 2 December 2027, and for high-risk AI embedded in regulated products from 2 August 2028 — dates that were amended by the Digital Omnibus, so if you are planning against them, check the current position rather than a 2024 slide.
For Indian organisations the relevance is indirect but real. If you provide IT or business services to a European financial entity or manufacturer, their compliance obligation becomes a contractual obligation on you, in exactly the way GDPR did.
The Indian position is more fragmented. The Digital Personal Data Protection Act, 2023 governs personal data used to train or prompt a system. CERT-In’s April 2022 directions require reporting of specified cyber incidents within six hours of noticing them. RBI’s Master Direction on IT Governance, Risk, Controls and Assurance Practices, effective 1 April 2024, sets board-level IT governance obligations for regulated financial entities and does not carve out anything for being AI. There is no single Indian AI statute, which means the governance burden currently falls on existing IT governance, risk and data protection obligations — and those already apply.
A practical sequence
If I were asked to start an AI-in-service-management programme tomorrow, this is the order I would work in.
1. Inventory before anything else. List every AI capability already running in your service estate, including the ones that arrived as vendor features and were switched on by an administrator. In most organisations this list is longer than the CIO expects, and nobody has ever written it down. You cannot govern what you have not enumerated — a point I make at greater length elsewhere about configuration and asset management, and which applies identically here.
2. Classify by the six Cs. For each item, is it Creation, Curation, Clarification, Cognition, Communication or Coordination? Then apply proportionate control. A tool that drafts a knowledge article for human review needs light governance. A tool that closes tickets, grants access, or tells a customer what they are entitled to needs the full apparatus.
3. Write the escalation boundary. The list of things the system must not answer, and what it does instead. Test it adversarially, the way you would test a control.
4. Fix the ground truth. Before you scale Communication, invest in Curation. Stale and contradictory knowledge is the raw material of every embarrassing answer.
5. Make it auditable. Retain transcripts, model versions and knowledge sources. Decide the retention period deliberately, against DPDP Act and CERT-In log retention obligations, rather than accepting the vendor default.
6. Then take the certification, if you want the vocabulary. ITIL AI Governance has no prerequisites and gives your team a common language. If you need to demonstrate governance externally, ISO/IEC 42001 is the instrument that produces evidence.
The unglamorous conclusion
ITIL 5’s AI material is better than I expected and less complete than the launch suggests. The six Cs are a genuinely useful classification. The separate governance publication is real new content with no ITIL 4 equivalent. And the practice guides, where the operational detail would have to live, have not been written yet.
Meanwhile the accountability question is already settled, and it was settled by a small claims tribunal in British Columbia over a bereavement fare. If your system says it, you said it.
Everything else is implementation.
What good looks like in a service desk deployment
Most organisations meet AI in service management through the same door: an assistant in the ITSM tool, aimed at users. Since that is where the exposure concentrates, it is worth being specific about what a controlled deployment looks like — mapped to the six Cs, so it connects back to the framework.
Start with Curation, not Communication. Before anything is customer-facing, run the model over your knowledge base to find contradictions, duplicates and stale articles. You will find them — every organisation does — and fixing them improves outcomes for human agents immediately, with no external risk at all. This is the highest-value, lowest-exposure work available, and almost nobody does it first because it does not demo well.
Then Clarification, internally. Summarising long incident tickets, drafting handover notes, pulling the relevant history for a major incident bridge. The audience is your own staff, who can spot a wrong answer, and the productivity gain is real.
Then Cognition, offline. Pattern detection across incident and change records to surface candidate problems. Output goes to a human problem manager, not to an automated action. This is the single most useful thing AI does in service management and it never appears in a vendor demo.
Then Communication, bounded. Only now put an assistant in front of users, and only with a written boundary: what it may answer, what it must escalate, and what it must never assert. Anything touching entitlement, money, safety, health, legal rights or a deadline goes to a human. Log every conversation with the model version and the knowledge sources used.
Coordination last, and narrowly. Autonomous execution — resetting a password, provisioning access, closing a ticket, restarting a service — needs the full change apparatus: an approved catalogue of permitted actions, rate limits, an audit trail, and an immediate kill switch. If you cannot answer “what is the worst thing this is allowed to do, and how fast can we stop it?”, it should not be running.
Creation with review. Generated knowledge articles, code and documentation are useful, but a generated article that enters the knowledge base unreviewed becomes tomorrow’s Curation problem — and, eventually, the source of a wrong answer to a customer.
Two measures I would insist on from day one. First, containment quality, not containment rate: of the conversations the assistant handled without escalation, what proportion were actually resolved, measured by whether the user came back within seven days? A high deflection rate with a high repeat-contact rate is not automation, it is a queue with extra steps. Second, escalation-boundary violations: how many times did the assistant answer something on the forbidden list? That number should be reported to the same forum that sees your change failure rate, and it should be zero.
Sources
- PeopleCert, ITIL AI Governance (Version 5) (syllabus, AI Capability Model, no prerequisites) — peoplecert.org
- ITIL.com, ITIL Foundation (Version 5): what’s new (“AI-native” and “complexity-native”) — itil.com
- ITSM.tools, ITIL (Version 5) explained: key changes, lifecycle, AI governance (practice guide updates scheduled H2 2026) — itsm.tools
- Moffatt v. Air Canada, 2024 BCCRT 149 — commentary at McCarthy Tétrault and the American Bar Association
- European Commission, AI Act implementation timeline — ai-act-service-desk.ec.europa.eu
- ISO/IEC 42001:2023, Artificial intelligence — Management system
- Reserve Bank of India, Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices, RBI/2023-24/107, 7 November 2023
- CERT-In, Directions under sub-section (6) of section 70B of the Information Technology Act, 2000, 28 April 2022