New guidance responds to a payments environment where AI increasingly shapes safeguards
Edinburgh, Scotland, 7 October 2026 — AI is changing both how payments are protected and how they are exploited. Fraudsters are using it to make phishing more convincing and to find weaknesses at scale, while businesses are introducing AI into their own operations. To help organisations navigate that shift, the PCI Security Standards Council (PCI SSC) has published additional guidance on securing AI in payment environments.
Developed in collaboration with industry stakeholders including the Global Executive Assessor Roundtable (GEAR) and the PCI SSC Board of Advisors, the guidance sets out how organisations can secure AI systems without losing sight of the controls already in place – covering how AI is deployed, to reduce the risk of its misuse, how it fits within existing PCI standards, and real-world use-case examples.
The additional guidance is available to download here.
Closing the Gap Between Capability and Accountability
Much of the public discussion around AI in payments still centres on the technology itself, what it can do and where it might go next. But people remain part of the equation on both sides – as much a target for AI-driven social engineering as they are a safeguard against it. The more pressing issue is what happens once AI systems can act with limited human involvement: how access is managed, how existing controls hold up as the technology changes, and where responsibility – and ultimately trust – sits as AI takes on greater independence within payment systems.
“As AI is increasingly used in payment environments, there is an obligation for all parties to ensure the technology is used responsibly.” said Gina Gobeyn, Executive Director, PCI SSC. “This additional guidance provides a practical starting point for secure AI implementation.”
With AI playing a growing part in payment decisions, clear accountability is what allows confidence in the system to hold. Across the industry, the focus is shifting from preparing for AI’s arrival to governing it securely in day-to-day operations.
PCI SSC Europe Community Meeting 2026
These issues will also shape discussion at the PCI SSC Europe Community Meeting in Edinburgh (20–22 October), where banks, retailers, payment service providers and security professionals will come together at a significant moment for the industry, as AI continues to transform the payments landscape. The meeting, held in PCI SSC’s 20th anniversary year, marks its first return to the city since 2016. Sessions including AI Agents and Emerging Risks in the Cardholder Data Environment and Human vs. Machine: Rethinking Security, Compliance and Accountability will examine how organisations can keep AI secure within the controls they already have.
Registration and full agenda details are available at https://www.pcisscevents.org/event/2026-edinburgh/summary
___
It is important to note that the additional guidance is not to be considered as mandatory requirements. When there are differences between the guidance and official PCI standards, the PCI standard always takes precedence.
About the PCI Security Standards Council
The PCI Security Standards Council (PCI SSC) leads a global, cross-industry effort to increase payment security by providing industry-driven, flexible and effective data security standards and programs that help businesses detect, mitigate and prevent cyberattacks and breaches. Connect with the PCI SSC on LinkedIn. Join the conversation on X (formerly Twitter) @PCISSC. Follow us on Instagram. Subscribe to the PCI Perspectives Blog. Listen to the Coffee with the Council podcast.