The PCI Security Standards Council has published Security Considerations for AI Systems, advisory guidance for organizations using AI in payment environments. Developed with industry stakeholders, it covers governance, deployment, access controls, testing, and how PCI standards apply to AI. The recommendations are not mandatory; existing PCI requirements remain the primary compliance baseline.
The guidance urges organizations to define an AI system's purpose, permissions, and data access before deployment, applying a "least agency" approach that limits each system to only what its task requires. A suitable human individual should formally accept responsibility for AI output, and organizations should specify which actions require human approval. For agents with access to cleartext cardholder data, the Council explicitly recommends human approval for any actions involving that data. It also warns against combining sensitive data access, external communications, and unrestricted input from untrusted sources in a single system.
Beyond access controls, the guidance calls for adversarial testing before functional testing, ongoing monitoring for behavioral changes, and safeguards against excessive trust in AI output. For monitored autonomy, organizations should define permitted actions, approval requirements, shutdown triggers, and rollback procedures. High-impact secrets such as passwords and cryptographic keys should not be handled or generated by AI systems; credentials should be kept out of prompts, logs, and outputs, and encrypted or tokenized payment data should be used where possible.
The Council also addresses AI-assisted attacks, recommending ongoing vulnerability monitoring, phishing-resistant authentication, and security testing of AI-generated code. External AI providers with access to sensitive data should be assessed under third-party service provider requirements, with agreements that prohibit using organizational data for training and set clear breach notification terms. Incident response plans should cover prompt injection, model poisoning, and unauthorized AI tools accessing sensitive data.