Abstract illustration: PCI Council Issues AI Guidance, Stops Short of a Mandate

PCI Council Publishes AI Security Guidance — Non-Binding, for Now

The PCI Security Standards Council has published its first full information supplement on securing AI systems, its most detailed AI guidance to date for organizations subject to PCI assessments.

On Sept. 15, the PCI Security Standards Council published an information supplement titled “Security Considerations for AI Systems,” developed with input from the Global Executive Assessor Roundtable (GEAR) and the Council’s Board of Advisors. The document is guidance, not a standard. The Council states that it “serves as guidance and is not to be considered as mandatory requirements,” and that where it conflicts with an official PCI standard, the standard wins.

The supplement covers two directions: securing AI used inside payment environments, and defending traditional systems against AI-enabled attacks. It addresses four high-level topics: AI Deployment and Use, Defending Against Malicious Use of AI, PCI Standards and AI Use, and AI use-case examples. The announcement describes those areas at a high level; the supplement itself is where the detail lives.

The most useful line for compliance planners is the scoping position. The Council says AI “should be considered no different from any other form of technology when scoping the PCI requirements that may apply.” In practice, that means no new AI-specific mandatory controls, but existing scoping and segmentation obligations explicitly reach AI systems, a position the Council first signaled in its 2025 AI Principles.

For security leaders in regulated payment environments, the document indicates future audit priorities. Guidance developed with assessor input tends to become a reference point QSAs cite, and information supplements often precede later normative requirements. This one carries no audit weight today, but it is an early marker worth tracking.

Source: PCI Security Standards Council Blog


Leave a Reply

Discover more from Digerati One (Di1) | AI Integration & Multi-Cloud Architecture

Subscribe now to keep reading and get access to the full archive.

Continue reading