Just Published: Security Considerations for AI Systems

The PCI Security Standards Council (PCI SSC) has published a new information supplement addressing the security of artificial intelligence (AI) systems. This document covers both security aspects of using AI in payment environments and considerations when securing traditional systems against attacks that utilize AI systems. PCI SSC developed this document in collaboration with industry stakeholders including the Global Executive Assessor Roundtable (GEAR) and the Board of Advisors.
The guidance provides a high-level summary of AI guidelines and a description of the following key areas:
- AI Deployment and Use
- Details are provided on how entities may approach the deployment of AI systems. Methodologies and framework examples for how to assess the potential scope and impact of such deployments are discussed.
- Defending Against Malicious Use of AI
- When considering defending systems in the age of AI-powered vulnerability discovery, emphasis is placed on the importance of frequent, if not continual, monitoring and management of vulnerabilities.
- PCI Standards and AI Use
- In general, when AI is used, it should be considered no different from any other form of technology when scoping the PCI requirements that may apply.
- AI Use-case examples
- Examples of how AI may be deployed and assessed in payment environments are provided.
It is important to note that this information supplement serves as guidance and is not to be considered as mandatory requirements. When there are differences between the guidance and official PCI standards, the PCI standard always takes precedence.
This guidance, along with PCI SSC’s previously published guidance document, Integrating Artificial Intelligence in PCI Assessments – Guidelines, Version 1.0, is now available in the PCI Document Library. The Council has also published a blog post on AI Principles: Securing the Use of AI in Payment Environments as well as its ongoing blog series, The AI Exchange: Innovators in Payment Security featuring payment security industry stakeholders. These resources represent PCI SSC’s commitment to helping organizations maintain strong security practices as AI technologies continue to evolve.

