The PCI Security Standards Council (PCI SSC) issued additional guidance on securing AI in payment environments on 8 October 2026, according to its announcement. The council says the guidance covers the deployment of AI, the risk of misuse, its place within existing PCI standards and examples drawn from payment operations. It also says the guidance is not mandatory: where it differs from an official PCI standard, the standard takes precedence.
Key points
- The council developed the guidance with the Global Executive Assessor Roundtable and its Board of Advisors.
- It addresses AI deployment, misuse and the application of existing payment-security controls.
- The council says the advice creates no mandatory requirements and cannot override official PCI standards.
PCI standards retain precedence over AI guidance
PCI SSC says it produced the additional guidance with industry stakeholders, including the Global Executive Assessor Roundtable and the council’s Board of Advisors. The work concerns securing AI systems within payment environments while continuing to use controls already in place. Its stated subjects range from how organisations deploy AI to how they reduce the risk that it will be misused. The council also includes examples of payment-related uses, rather than presenting the advice solely as general principles.
The distinction between advice and a PCI standard matters to organisations using the council’s materials. PCI SSC explicitly says the additional guidance must not be treated as mandatory requirements. It gives official PCI standards priority if their provisions differ from the advice. An organisation considering the new material therefore has the council’s account of how AI fits alongside its existing standards, without a new requirement created by this publication.
Gina Gobeyn, PCI SSC’s executive director, called the guidance a “practical starting point for secure AI implementation”. She said parties using AI in payment environments have an obligation to use it responsibly. Those are the council’s reasons for offering the advice, rather than a change to the status it assigns to the advice itself: its announcement separately states that official standards prevail when the two differ.
PCI SSC addresses AI access and misuse
The council describes AI as part of both payment protection and attempts to defeat it. It says fraudsters use the technology to make phishing more persuasive and to search for weaknesses at scale, while businesses are adding AI to their operations. Its guidance consequently addresses two related activities: securing the systems an organisation chooses to use and reducing the risk of misuse. Both sit within the council’s stated aim of keeping existing payment-security controls in view.
PCI SSC also identifies access and responsibility as questions for systems that can operate with limited human involvement. In the council’s account, people may be targets of AI-assisted social engineering as well as safeguards against it. It says organisations must consider how access is managed and how their controls hold up as AI changes. The examples in the additional guidance are intended to place those questions in the circumstances of payment operations.
The October publication follows earlier work on AI in payments. PCI SSC introduced guidance on using artificial intelligence in payment environments, including principles for its use in PCI assessments, FinTech BizNews reported in February. The new guidance deals specifically with securing AI systems and reducing the risk of misuse, according to the council’s October announcement.
India-South Asia has a place in PCI SSC’s work
PCI SSC is the global body that sets payment card security standards. Its Board of Advisors has 64 members for the 2025–2027 term, FinTech BizNews reported. The council also launched an India-South Asia Regional Engagement Board in August 2025. That regional board advises PCI SSC on risks, implementation difficulties and changing fraud patterns in India and South Asia.
The regional board includes organisations from banking, financial technology, payments processing and technology, among them NPCI, HDFC Bank, Google, Cred and Zeta. FinTech BizNews reported that it gives firms in the region a channel into the drafting and revision of future PCI standards. For the October AI publication, the council names its global Board of Advisors and the Global Executive Assessor Roundtable as collaborators.
Edinburgh meeting turns to AI in payments
PCI SSC says banks, retailers, payment service providers and security professionals will attend its Europe Community Meeting in Edinburgh. The programme includes a session on AI agents and emerging risks in the cardholder data environment, alongside one on security, compliance and accountability between people and machines. Those subjects reflect the council’s stated concern with AI systems that act with limited human involvement and the controls around their use.
PCI SSC says AI-related payment security issues will be discussed at its Europe Community Meeting in Edinburgh from 20 to 22 October 2026.