PCI SSC wants human sign-off on AI agent card data actions
The PCI Security Standards Council (PCI SSC), the industry body behind the payment card security standards that merchants and processors must follow, has released new guidance on running AI systems in payment environments. One recommendation stands out: AI agents that can see cleartext cardholder data should get explicit human approval before taking any action involving that data.
The document, titled Security Considerations for AI Systems, was developed with industry stakeholders. It covers governance, deployment, access controls, testing and how PCI standards apply to AI. It also addresses defenses against attacks that use AI. The recommendations are advisory only, and existing PCI requirements take precedence.
