What happened
The PCI Security Standards Council published 'Security Considerations for AI Systems', an advisory that recommends defining AI purpose, permissions, and data access, enforcing least‑agency principles, and requiring explicit human approval for any AI‑initiated actions involving clear‑text cardholder data. It also calls for an AI inventory, adversarial testing, ongoing monitoring, and clear accountability for AI outputs.
Why it matters for trust and compliance
- This guidance highlights the need for a documented AI governance framework that provides continuous evidence of human oversight, access restrictions, and testing—key elements of a control‑assurance program.
- Map AI governance requirements to your existing control framework to demonstrate due diligence during PCI assessments.
- Collect and retain evidence of human approval processes and AI testing for audit readiness.
Who is affected
Financial services organizations handling payment card data
Recommended actions
- Create an AI inventory and define purpose, permissions, and data access for each model.
- Implement formal human‑approval workflows for AI actions that touch clear‑text cardholder data.
- Integrate adversarial testing and continuous monitoring into your AI lifecycle.