PCI Council Published New AI Security Guidance
The standards body issued protocols to help businesses secure AI within payment environments.
Updated on Oct. 8, 2026 in Artificial Intelligence

Live Poll
Do you trust that businesses are implementing AI securely in their payment systems?
The PCI Security Standards Council has released new guidance to assist organizations in securely integrating AI into their payment systems. This move comes as businesses work to mitigate risks posed by fraudsters using AI for phishing and large-scale security exploits.
Why it matters
As companies rapidly incorporate AI into their daily operations, they face increased threats from attackers leveraging automated tools. This guidance provides a framework for maintaining robust security controls while navigating the complexities of AI deployment.
The PCI Security Standards Council is marking 20 years of operation in 2026. The new AI security guidance serves as a non-mandatory framework intended to complement existing PCI standards.
The players
PCI Security Standards Council
This global organization manages and develops standards for the security of payment card data.
Global Executive Assessor Roundtable
This group consists of professional experts who collaborate with the council to ensure industry security standards remain practical and effective.
PCI SSC Board of Advisors
This body provides guidance and strategic input to the council to help maintain and evolve payment security protocols.
The details
Developed with the Global Executive Assessor Roundtable and the Board of Advisors, the guidance offers real-world use cases for managing access and integrating AI within compliance frameworks. Organizations are instructed that official PCI standards remain the governing authority in any instance of conflict.
Timeline
October 8, 2026: The PCI Security Standards Council published the AI security guidance.
October 20-22, 2026: The PCI SSC Europe Community Meeting will occur in Edinburgh.
The Big Picture
The new guidance bridges the gap between traditional transaction protocols and modern machine learning requirements. It extends the established framework of the PCI Data Security Standard to incorporate emerging artificial intelligence risks within the global financial sector.
While the guidance is not mandatory for all businesses, organizations adopting these practices may see more robust protection against AI-driven phishing attempts. For the user, this means that payment systems may become more resilient as companies better secure their AI integrations.
The takeaway
Adopting these new protocols can help companies prevent security vulnerabilities that arise from rapid AI integration. Businesses should prioritize reviewing their current security posture against this guidance to ensure AI usage does not create non-compliance risks.
What happens next
The industry will further address these risks during the PCI SSC Europe Community Meeting in Edinburgh, which will feature dedicated sessions on AI agents and emerging threat landscapes.
Further reading
Learn more about the latest innovations and security shifts in the Artificial Intelligence section.
More information
View the full PCI SSC event registration and agenda for upcoming sessions on AI security.
Live Poll
Do you trust that businesses are implementing AI securely in their payment systems?







