PCI SSC calls for human approval of AI agent actions on cardholder data
The PCI Security Standards Council published Security Considerations for AI Systems, guidance for protecting data in payment environments. For agents with access to cleartext cardholder data, explicit human approval for any actions is recommended, and AI systems should not handle passwords or cryptographic keys.
- Guidance is advisory; existing PCI requirements take precedence
- Agents with cleartext cardholder data access need explicit human approval per action
- AI must not handle passwords or cryptographic keys; use secrets-management tools
- Organizations should inventory AI, restrict shadow AI and run adversarial testing
Read next
Policy