MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-09 · via Help Net Security

PCI Council Issues Guidance on Securing AI in Payment Systems

Image via Help Net Security
Image via Help Net Security

The PCI Security Standards Council released Security Considerations for AI Systems, advisory guidance for protecting payment data used by AI and defending against AI-assisted attacks. It recommends defining an AI system's purpose, permissions, and data access before deployment, limiting its agency, and assigning human accountability for outputs. The guidance also calls for human approval of certain actions, independent access controls, testing, monitoring, and inventories to manage shadow AI.

Expanded Detail

The PCI Security Standards Council released advisory guidance titled Security Considerations for AI Systems. It focuses on payment environments, covering governance, deployment, access controls, testing, and PCI standard application. Existing PCI requirements override its recommendations. The council says parties must use AI responsibly as adoption grows.

The document urges organizations to define an AI system's purpose, permissions, and data access before deployment. It recommends limiting agency, assigning human accountability, requiring approval for some actions, using independent access controls, testing safeguards, monitoring behavior, and maintaining inventories to curb unapproved shadow AI.

Context

Payment providers, merchants, technology vendors, and consumers could feel this guidance's effects. Organizations may adopt stricter AI governance, access limits, and human oversight, potentially reducing risks to cardholder data and AI-assisted attacks. Security and development teams might face added testing, monitoring, and documentation duties, while smaller merchants could encounter higher compliance costs. Consumers may benefit from stronger safeguards, but the advisory nature means real-world impact may depend on how widely firms choose to follow it.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at Help Net Security →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “PCI SSC calls for human approval of AI agent actions involving cardholder data.” Browse more stories.