PCI Council Issues Guidance on Securing AI in Payment Systems

The PCI Security Standards Council released Security Considerations for AI Systems, advisory guidance for protecting payment data used by AI and defending against AI-assisted attacks. It recommends defining an AI system's purpose, permissions, and data access before deployment, limiting its agency, and assigning human accountability for outputs. The guidance also calls for human approval of certain actions, independent access controls, testing, monitoring, and inventories to manage shadow AI.
The PCI Security Standards Council released advisory guidance titled Security Considerations for AI Systems. It focuses on payment environments, covering governance, deployment, access controls, testing, and PCI standard application. Existing PCI requirements override its recommendations. The council says parties must use AI responsibly as adoption grows.
The document urges organizations to define an AI system's purpose, permissions, and data access before deployment. It recommends limiting agency, assigning human accountability, requiring approval for some actions, using independent access controls, testing safeguards, monitoring behavior, and maintaining inventories to curb unapproved shadow AI.
Payment providers, merchants, technology vendors, and consumers could feel this guidance's effects. Organizations may adopt stricter AI governance, access limits, and human oversight, potentially reducing risks to cardholder data and AI-assisted attacks. Security and development teams might face added testing, monitoring, and documentation duties, while smaller merchants could encounter higher compliance costs. Consumers may benefit from stronger safeguards, but the advisory nature means real-world impact may depend on how widely firms choose to follow it.