The PCI Security Standards Council has published additional guidance on securing AI in payment environments, according to its Oct. 7 press release. The document, developed with the Global Executive Assessor Roundtable and the PCI SSC Board of Advisors, covers how AI is deployed, how to reduce the risk of its misuse, how it fits within existing PCI standards, and use-case examples. PCI’s blog post lists the information supplement, titled Security Considerations for AI Systems, as published Sept. 15.

The Council states the guidance is not a set of mandatory requirements, and that where it differs from official PCI standards, the standard takes precedence.

On scoping, the blog post says that when AI is used, “it should be considered no different from any other form of technology when scoping the PCI requirements that may apply.” An AI agent that touches cardholder data brings the same requirements as any other system that does. On the attacker side, the blog says that in the age of AI-powered vulnerability discovery, the guidance emphasises frequent, if not continual, monitoring and management of vulnerabilities.

The release frames the problem as accountability. Gina Gobeyn, Executive Director of PCI SSC, said: “there is an obligation for all parties to ensure the technology is used responsibly.” The release adds that the pressing issue is what happens once AI systems can act with limited human involvement, including how access is managed and where responsibility sits.

In our reading, the practical effect lands in scoping. Teams adding AI assistants or agents near payment data should map them into the cardholder data environment before the next assessment, rather than treating them as a separate category. For related reading, see why a scope prompt is not an AI agent control and how AI coding agents posted internal screenshots publicly.

Source: PCI Security Standards Council, press release