As AI reshapes payments, security needs the industry in the room
11 min read
Artificial intelligence is rapidly finding its way into payments, just as cloud computing, digital payments and mobile acceptance have done before it. But unlike a traditional technology rollout, AI is changing fast enough to raise a more fundamental question for the payments industry – how do you keep security standards relevant when the technology itself is constantly moving?
The challenge is not unique to AI. Across payments, new technologies are being layered onto an ecosystem where older systems and payment methods continue to operate. That makes it increasingly difficult for security standards to simply anticipate what comes next.
For the Payment Card Industry Security Standards Council (PCI SSC), the answer is less about predicting every innovation and more about keeping the industry involved in the process.
That is putting greater importance on the standards council's community meetings, where payment companies, technology providers, merchants, assessors and other stakeholders come together to discuss what is changing, where the risks are emerging and what security needs to address next.
"Payment security is everyone's responsibility," says Diana Greenhaw, head of education and engagement at PCI SSC. "No single entity has the responsibility to secure the whole system."
There is another complication in payments. Unlike many technology industries, the old does not disappear when the new arrives. “As fast as the new technology is coming in, all of the traditional methods are still there,” Greenhaw says. “So we don't get to just move to the next thing.”
The payments industry therefore has to secure the entire ecosystem simultaneously – from traditional point-of-sale terminals to mobile payments and increasingly AI-enabled environments. “It’s really about adding on and not taking away as we move forward,” Greenhaw said in an interaction with The Head and Tale.
Conversations matter
PCI SSC, which is marking its 20th anniversary this year, has spent the past two decades developing standards around payment security. But the technology landscape it was created for looks very different today, with emerging technologies reshaping how payments are accepted, processed and secured.
For Greenhaw, there is one lesson from the council’s two-decade journey that stands above everything else, “Change is the only constant.” She says this adaptability is critical to the way payment security standards are designed.
“The ability to adapt and build products, services, security standards, that are based on sound, objective security principles, while retaining the flexibility to respond to quickly changing technology is the key to our long-term success,” she quips.
The community meetings are an important part of that engagement. PCI SSC holds three large-scale meetings globally each year, alongside workshops and other forums where participants can exchange views.
The meetings are not, however, the only point at which that feedback is gathered. Greenhaw notes that the conversations can continue through workshops, working groups and other forms of engagement, creating a feedback loop between those developing security requirements and those dealing with their implementation.
Ahead of its community meetings, PCI SSC holds information-sharing workshops on topics proposed and selected by its board of advisors. At one such workshop in 2025, participants discussed vulnerability management and penetration testing. The discussions subsequently helped the council compile best-practice guidance for the wider community.
It is a simple example of the feedback loop – first understand what companies are seeing in the real world and use that experience to make security guidance more practical.
That becomes particularly important when the technology in question is changing faster than any formal standards process can reasonably keep up with.
"No standard that you ever write and produce can change at the pace of innovation," Greenhaw says.
AI brings a new layer of uncertainty
Artificial intelligence is now at the centre of PCI SSC’s engagement with the payments industry, with the council looking at how organisations are deploying AI and what that means for payment security.
The council has been using its network of payment and technology companies to share how organisations are adopting AI and what that means from a security perspective. PCI SSC published its AI principles for securing the use of AI in payment environments in late 2025.
Greenhaw said the principles are designed around four broad categories covering what AI systems must be, should not be, should be and may be. But the starting point is straightforward: introducing AI does not remove existing security obligations.
"AI systems must be deployed and managed in compliance with the applicable PCI SSC requirements," she adds. In other words, the use of AI does not change the applicability of an existing PCI standard or remove the need to implement the controls required in an environment.
At the same time, the council needs to understand how AI is actually being used, rather than considering it only as a theoretical technology risk.
PCI SSC is also relying heavily on its community to understand how AI is actually being deployed. The council has been running an ongoing blog series, “The AI Exchange: Innovators in Payments Security”, which allows companies to share their experiences with the wider payment industry.
"The response has been much stronger than expected. The council is also looking at what comes next. Its work now includes AI as well as technologies such as post-quantum cryptography," Greenhaw says.
That could become increasingly important as AI moves from being a back-end tool to playing a more active role in how consumers discover, choose and pay for products.
The approach reflects a broader reality that security requirements may provide the baseline, but the industry has to keep feeding information about new technologies and new implementation challenges back into the standards process.
Mobile payments offer a real-world example
AI is not the only area where payment security standards are having to evolve. Mobile and in-app payments are among the fastest-growing payment methods globally, and the shift is particularly visible in India, where softPOS and tap-to-phone acceptance are gaining traction.
PCI SSC developed its mobile payment standard, MPoC, to address security in these environments. PCI SSC has also been refining the guidance around MPoC based on industry feedback. Late last year, it published supplemental guidance aimed at helping stakeholders interpret the requirements consistently and improve assessment readiness for vendors submitting solutions for laboratory review.
That process, Diana says, reflects the way PCI SSC increasingly develops its standards – with industry participation rather than in isolation.
The council has a mobile working group, a technology guidance group involving subject matter experts from its principal participating organisations, as well as engagement with solution providers, laboratories, payment brands and acquirers.
"We didn't do this in a vacuum," Diana shares. "Feedback from the solution providers, the labs, the payment brands, and acquirers really helped shape the content, to ensure that it is addressing real-world implementation challenges."
The council also does not necessarily wait for the next formal version of a standard to address an emerging issue, she further notes.
That distinction matters because payments technology can change between formal standards updates. Industry feedback can therefore help identify where additional guidance or clarification is needed before a completely new standard is developed.
The consumer doesn't see any of this
While standards bodies and payment companies are dealing with increasingly complex technology underneath the transaction, consumers are moving in the opposite direction.
Ken Hughes, a consumer behaviour and digital experience expert, describes today's consumer mindset as one shaped by immediate gratification: one click, one tap and the expectation that the desired outcome follows instantly.
"Younger generations generally don't question what happens behind the payment," he believes. "There is an inherent belief that everything will work as it should, and that it will work immediately."
For younger consumers, trust in digital payments is therefore less a conscious consideration than an assumption. "Payments should work first time, every time. They should be inherently trustworthy and secure," Hughes notes.
That creates an interesting paradox for the payments industry. The more successful it becomes at making security invisible, the less consumers may think about the systems protecting them.
"They are not the ‘buffering generations’," he adds, while also arguing that consumers now expect digital experiences to be fast and effortless while organisations simultaneously handle the necessary security controls.
The problem is that speed and security can sometimes pull in opposite directions.
"If you deliver immediacy without security, you obviously have an unhappy customer. But equally, if you have a lagging system where security checks are taking too much time, you also have a customer you’re failing to satisfy," Hughes notes.
The challenge, he feels, is not to choose between security and convenience – but to find a way to deliver both.
And then there is agentic AI
The balance could become even harder to achieve as AI moves beyond assisting consumers to acting on their behalf.
Hughes believes agentic AI could fundamentally change how consumers make purchasing decisions. Instead of searching for products, comparing options and deciding what to buy themselves, consumers could increasingly give an AI agent permission to do that work for them.
The agent could learn their preferences, evaluate products and prices and eventually make purchases on their behalf.
That could move commerce towards what Hughes calls a “B2M" -- Business to Machine -- model, where businesses increasingly have to persuade the machine acting on behalf of the consumer.
For payments, the implications are significant. As consumers become further removed from the transaction, more responsibility shifts to the automated systems behind it.
There is also a question around trust. Today, consumers can easily see and compare price, convenience and experience. Security is different because much of the work happens invisibly.
Hughes believes the industry will eventually need to "physicalize trust" by making some of the technology and human effort behind secure transactions more visible to consumers.
That could become particularly important as the same AI technologies making payments more efficient can also be used to create more sophisticated fraud.
"If we want to build brands that have trust as a core value, we need to make trust something consumers can actually see, understand and feel," he said.
As more of the payment and purchasing experience becomes machine-driven, the human side of trust could become more important rather than less. Hughes argues that as AI, automation and other technologies become more prevalent, human empathy, emotion and interaction become scarcer – and therefore more valuable.
In other words, the more invisible the payment process becomes, the more important it may be for the industry to ensure that the underlying security inspires trust – even when consumers never see the systems doing the work.
Community meetings as a feedback loop
This is where the role of industry community meetings becomes more significant. They are not substitutes for formal standards development, nor can they make the standards process move at the same speed as technology. Their value is in keeping the conversation going between standards bodies and the organisations dealing with new technologies in the real world.
The broader philosophy behind this approach is that payment security is a collective responsibility. Every organisation that stores, processes or transmits cardholder data has a role to play, Greenhaw feels, particularly as threats evolve rapidly.
This is also why PCI SSC places significant emphasis on bringing different parts of the payments ecosystem into the standards-development process. The council – which currently has 64 organisations on its board of advisors – has seen its principal participating organisation membership double over the past few years.
"The willingness of some of the largest companies in the payments and broader business ecosystem to participate is evidence of the importance they attach to payment security." But participation is not limited to membership.
One of the most direct ways organisations can influence PCI SSC standards is through its formal Request for Comment (RFC) process. The process applies to new standards under development as well as existing standards being revised. Organisations can submit feedback during designated RFC periods, with PCI SSC subsequently providing information on how that feedback was considered and incorporated.
Greenhaw urges companies to make greater use of this process. "If you're having a challenge with a specific requirement, speak up during those RFCs," she says. "That's the opportunity to really shape what those look like going forward."
PCI SSC has already conducted five RFCs in 2026, including one for the next version of PCI DSS, with more expected in 2027.
The larger point is that standards development increasingly has to be informed by what is happening in the market, rather than anticipating it from a distance.
For an industry dealing simultaneously with legacy payment infrastructure, mobile acceptance, AI and eventually autonomous purchasing, there may be no single point at which the security question is settled. The standards have to evolve as the technology does – and that requires the people building and implementing the technology to remain part of the conversation.
The community meeting, in that sense, is less about a room full of presentations and more about keeping that conversation alive between the people writing the rules, the companies implementing them and the consumers who ultimately have to trust the system.
The PCI SSC’s community meetings this year is taking place in Vancouver this month, Edinburgh in October and Kuala Lumpur in November.