What happened
On 7 October 2026 (Edinburgh; json-ld datePublished=2026-10-07, confirmed by fetching the primary press release), the PCI Security Standards Council published additional guidance, 'Security Considerations for AI Systems', developed with the Global Executive Assessor Roundtable (GEAR) and the PCI SSC Board of Advisors. It sets out how organisations can secure AI systems in the cardholder data environment — how AI is deployed, reducing risk of misuse, how AI fits within existing PCI standards, and real-world use cases — and explicitly covers AI agents acting with limited human involvement (two agent-behaviour models including explicit human approval for high-impact actions involving cardholder data). The press release states the guidance is not mandatory: PCI standards take precedence.
Why it matters
This is the first dedicated AI-security guidance from the global payments standards body, targeting one of the most sensitive AI-managed environments. It signals how the PCI ecosystem expects merchants, acquirers, PSPs and QSAs to treat AI systems and AI agents inside the cardholder data environment — closing the gap between AI capability and accountability, and likely to be referenced in upcoming PCI DSS/assessment practice and the PCI SSC Europe Community Meeting (20-22 Oct).
Action needed
Map the guidance's considerations to existing PCI DSS 4.x controls; review AI/agent deployments in payment environments against the human-approval and accountability models; brief compliance and security teams ahead of PCI SSC Europe Community Meeting.