
Artificial intelligence (AI) is playing an increasingly prominent role within companies. You may be using AI for customer service, fraud analysis, software development, or process automation. However, as soon as AI becomes part of an environment where you process payment data, you will also encounter new security considerations.
Therefore, the PCI Security Standards Council (PCI SSC) regularly publishes new guidance: Security Considerations for AI Systems. The guidance describes key considerations for securely deploying AI within payment environments and for protecting traditional systems against attacks that leverage AI.
AI changes your perspective on security
AI can help you work faster and analyze large amounts of information. At the same time, an AI system can gain access to data, applications, and processes that are critical to your business.
Attackers use AI too. For example, they can employ AI to discover vulnerabilities faster or execute attacks more efficiently. PCI SSC therefore emphasizes that you must continue to apply existing security principles, while also assessing how AI alters your risk profile.
Are you using AI within an environment governed by PCI DSS? If so, the relevant PCI DSS requirements continue to apply as usual. Using AI does not remove these obligations.
1. Know where you use AI
A first step is gaining insight into where and for what purpose you deploy AI. Are you using AI for customer service, software development, or transaction analysis? Or can an AI system autonomously perform actions within other systems? The more responsibilities and access privileges you give an AI system, the more important it becomes to evaluate potential risks beforehand.
Therefore, map out the following:
- Where you are using AI
- What data the system processes
- Which systems it has access to
- Which actions it is allowed to execute
- Who within your organization is responsible
2. Grant AI access only to what is necessary
PCI SSC emphasizes the principle of least privilege: grant a system access only to the information and systems it actually needs. This principle applies to AI as well. It might seem convenient to give an AI system access to as much information as possible. However, if something goes wrong, that broad access can significantly increase the impact.
Therefore, ask yourself beforehand:
- Which data does the AI system truly need?
- Which systems must it be able to access?
- Which information can you keep out of reach?
- Which actions may the system execute autonomously?
Caution is especially important when your AI system works with payment data or other sensitive information.
3. Protect sensitive data
AI systems can process large volumes of information. Therefore, think carefully before entering or exposing data. PCI SSC highlights account data, credentials, API keys, and cryptographic keys as examples of sensitive information that you should not carelessly entrust to AI systems or datasets.
A simple question can help: What information am I feeding into AI, and does the system actually need that information? The less sensitive information you make available, the smaller the potential risk in the event of unauthorized use or an incident.
4. Maintain visibility over what AI does
Some AI systems can execute actions or make recommendations autonomously. Therefore, you must be able to track what the system is doing. Logging and monitoring help you gain insight into activities. Additionally, it must be clear who within your organization bears responsibility for using the AI system.
AI does not take over your responsibility. Especially when a system can execute actions independently, human oversight remains essential. PCI SSC also recommends validating AI systems both beforehand and during deployment. This allows you to verify that the system continues to function as expected.
5. Regularly audit AI
An AI system can respond differently to the exact same input. Furthermore, systems can evolve over time as they process new information and input. PCI SSC therefore points to continuous validation throughout the lifecycle of an AI system as a crucial consideration. A one-time check does not automatically grant you lasting insight.
Regularly verify:
- Whether the system is still functioning as intended
- Whether the access privileges are still appropriate
- Whether the system is still processing the same data
- Whether new risks have emerged
- Whether you can shut down the system if necessary
AI can also be used by attackers
You do not need to use AI yourself to feel its impact. Attackers can leverage AI to identify vulnerabilities faster, automate attacks, and execute them on a larger scale. PCI SSC therefore emphasizes the importance of frequent—and where possible, continuous—vulnerability management and monitoring. That makes visibility into your own digital environment all the more vital.
Do you know which systems are publicly accessible? What software is running on them? Are there known vulnerabilities present? And do you actually follow up on discovered vulnerabilities?
AI does not change the basics of cybersecurity
While AI brings new capabilities and risks, many core principles of cybersecurity remain unchanged.
You need to know:
- Which systems you use
- What data is stored in them
- Who has access
- Which systems are reachable from the internet
- Which vulnerabilities are present
- Whether identified issues are being addressed
Monitoring, logging, access control, and regular testing therefore remain essential.
PCI SSC emphasizes that you should not view AI as a reason to bypass existing security controls. The new guidance offers practical support, but it does not replace the official PCI Security Standards. Should the guidance and an official PCI standard differ, the official standard prevails.
What does this mean for you?
Are you using AI within your business? Then incorporate AI into your existing security and risk processes.
You can start with a few simple questions:
- Where are we currently using AI?
- Which systems and data can AI access?
- Which access privileges are truly necessary?
- Can we see and monitor what AI is doing?
- Are our systems regularly scanned for vulnerabilities?
- What do we do if an AI system exhibits unexpected behavior?
- Can we quickly shut down the system if necessary?
AI thus requires not just new technology, but above all visibility, control, and ongoing attention to security.
Continue monitoring your digital environment
The PCI SSC identifies frequent or continuous vulnerability monitoring as a key focus area in an environment where AI plays a role. After all, an AI system itself may be secure, while the website, server, application, or other systems connected to it still harbor vulnerabilities.
Through regular external vulnerability scans, you maintain visibility into vulnerabilities within your publicly accessible environment. This allows you to detect changes faster and address identified points of concern.
Trust Guard supports you in this by regularly scanning websites, web applications, and IP addresses for vulnerabilities. This ensures you maintain an up-to-date overview of your security posture and gain insight into areas that require further follow-up.
More information from the PCI Security Standards Council
Would you like to know more about the security of AI within payment environments?
Then check out the full guidance Security Considerations for AI Systems from the PCI Security Standards Council via https://blog.pcisecuritystandards.org/just-published-security-considerations-for-ai-systems