The AI Exchange: Innovators in Payment Security Featuring GM Sectec

Welcome to the PCI Security Standards Council’s blog series, The AI Exchange: Innovators in Payment Security. This special, ongoing feature of our PCI Perspectives blog offers a resource for payment security industry stakeholders to exchange information about how they are adopting and implementing artificial intelligence (AI) into their organizations.
In this edition of The AI Exchange, GM Sectec President, Héctor Guillermo Martínez, offers insight into how his company is using AI, and how this rapidly growing technology is shaping the future of payment security.
These responses reflect GM Sectec’s practical experience securing AI adoption in regulated payment environments through tokenization, continuous vulnerability validation, and AI-specific architectural controls.
How has your AI strategy evolved over the past 12–18 months?
Over the past 18 months, GM Sectec has moved from closely monitoring AI developments to deliberately building a “Secure AI Adoption” framework designed for payment ecosystems. We recognized that agentic AI and large language models would dramatically expand attack surfaces through Non-Human Identities (NHIs), dynamic “ghost” or shadow APIs, and the risk of sensitive data exposure. Our strategy evolved around three integrated pillars: protecting data at the source with tokenization, maintaining continuous visibility and validation of our attack surface, and implementing AI-specific technical controls for visibility, containment, and behavioral protection. This allows us — and our clients — to embrace AI innovation while strengthening, rather than weakening, PCI DSS compliance.
What is one AI initiative that has already delivered a measurable impact, and what made it successful?
A high-impact initiative has been the integration of DataBye by FirsToken tokenization with AI governance controls in client payment environments. By tokenizing cardholder data and other sensitive information before it can be accessed or processed by AI agents or LLMs, we enabled organizations to safely pilot agentic AI for fraud detection and customer service while reducing PCI audit scope by 60–70% in targeted environments. The key to success was treating tokenization not just as a traditional compliance tool, but as the foundational “data firewall” for the AI era — combined with strict access controls and real-time behavioral monitoring. Clients shifted from viewing AI as “too risky” to “we can now innovate with confidence and measurable compliance benefit”.
How are you approaching AI governance, particularly around data privacy and security?
We govern AI through a “Zero Trust for AI” model fully aligned with PCI DSS v4.0.1 principles. The cornerstone is DataBye by FirsToken, ensuring that LLMs, AI agents, and NHIs never interact with raw sensitive data — only with tokens. Through our partnership with Akamai, we extend this foundation with zero-trust micro segmentation to contain the blast radius of compromised autonomous agents and continuous API discovery and behavioral governance to eliminate shadow and ghost APIs created by agentic workflows. Privacy is protected by design: data minimization, strong encryption, and treating AI entities with the same (or greater) rigor as human identities under access control, authentication, and monitoring requirements.
What challenges have become more apparent as AI capabilities have matured?
As AI capabilities have matured, two challenges have become especially clear: first, the explosion of Non-Human Identities combined with the “ghost API” problem — where AI agents dynamically create undocumented API calls that reach into cardholder data environments, bypassing traditional inventory and review processes; second, the speed of AI adoption has outpaced governance in many organizations, resulting in sensitive data being fed directly into LLMs without adequate protection. Traditional static access reviews and periodic vulnerability assessments are no longer sufficient. The clear lesson is that “bolt-on” security fails in agentic environments; security and compliance must be architected into AI systems from the very beginning.
What advice would you provide for an organization moving from early AI adoption to broader implementation?
Start with data protection as the non-negotiable foundation — implement robust tokenization (such as DataBye by FirsToken), so sensitive information is never exposed to AI systems in the first place. Next, establish comprehensive visibility and containment: discover and govern all APIs (including those dynamically created by agents), apply micro-segmentation to limit blast radius, and deploy behavioral runtime protection that distinguishes normal from anomalous AI activity. Treat AI agents and NHIs as first-class identities under your PCI program — unique credentials, least privilege, continuous monitoring, and regular access reviews. Finally, replace periodic assessments with continuous validation programs, such as ongoing vulnerability scanning and attack surface management with platforms like FirstFire. Organizations that embed security into their AI architecture from day one will turn AI into a competitive advantage rather than a compliance and risk burden.
What AI trend are you most excited about?
I am most excited about the emergence of self-protecting, AI-native security architectures — where advanced behavioral analysis, micro-segmentation, continuous API governance, and intelligent data protection work together to make agentic AI systems secure and compliant by default. In the payment industry, this means we can finally move beyond “AI is powerful but dangerous” to “AI is powerful, trustworthy, and a strategic enabler” within highly regulated environments. The convergence of tokenization for data minimization, real-time visibility into agentic workflows, and intelligent containment is transforming the autonomous digital workforce from a liability into one of our most powerful tools for fraud prevention, operational efficiency, and customer experience.

