Realtime AI News
PCI SSC publishes AI security guidance, calls for human approval of agent actions on cardholder data
The PCI Security Standards Council has published a new information supplement on securing AI systems, covering both the security of using AI in payment environments and defenses against AI-enabled attacks on traditional systems. Reporting on the guidance, Help Net Security highlighted its call for human approval of AI agent actions involving cardholder data.

The PCI Security Standards Council (PCI SSC) has published a new information supplement addressing the security of artificial intelligence systems. The document covers both the security aspects of using AI in payment environments and the considerations for securing traditional systems against attacks that leverage AI.
Reporting on the guidance, Help Net Security highlighted that it calls for human approval of AI agent actions involving cardholder data. That framing puts a governance question squarely on the table: how much autonomy AI agents should have over payment data.
PCI SSC said it developed the document in collaboration with industry stakeholders including the Global Executive Assessor Roundtable (GEAR) and the Board of Advisors. The guidance provides a high-level summary of AI guidelines alongside a description of key areas, according to the council.
Importantly, PCI SSC stresses that the information supplement serves as guidance and is not to be considered mandatory requirements. Where the guidance and official PCI standards differ, the PCI standard always takes precedence. In practice, that makes the document a reference for understanding risk rather than a new set of compliance obligations.
The release reflects PCI SSC's recent focus on AI. The council has already been discussing AI's role in payment security through its "The AI Exchange" interview series and topic articles, and packaging the material into a dedicated information supplement marks a step from exchanging views toward structured guidance.
For the payments industry, AI agents are moving into customer service, reconciliation and risk workflows, while cardholder data remains at the center of compliance. Requiring human approval for agent actions that touch cardholder data draws a line between automation and accountability: which decisions a system may take on its own, and which need a person to sign off.
What to watch next is how payment organizations interpret and implement the guidance as they bring agents into live systems, and whether it shapes the direction of future revisions to the PCI standards.
Why it matters
By folding AI security into the payments compliance conversation and asking for human approval of agent actions on cardholder data, PCI SSC gives financial institutions a reference for where accountability should sit when deploying payment agents.
Nearby Updates
All10/09, 13:00
Descartes launches Agent Control Plane for logistics AI agents
Descartes Systems Group has introduced the Descartes Agent Control Plane, an AI agent coordination platform that automates complex logistics workflows across applications, supply chain partners and business systems. Built on the Descartes Global Logistics Network, the platform lets AI agents coordinate tasks within customer-defined permissions and approval processes to cut manual work on shipment updates and operational coordination.
10/09, 12:55
NineData debuts at Singapore Tech Week 2026 with a data-management AI Agent
NineData has appeared at Singapore Tech Week 2026, showcasing an AI Agent for data management as it moves to expand its global footprint. Data management is emerging as one of the more practical landing grounds for AI agents.
10/09, 11:52
Tsinghua embodied model tops global ranking without external modules or extra data
A Tsinghua embodied AI model has taken the top spot in a global ranking, breaking through against GPT-6 and NVIDIA-based approaches, according to QbitAI. Its key move is to train video prediction and action learning in separate stages, decoupling and re-ordering the two.
10/09, 11:40
Microsoft Sets Rules for Agents as Windows Takes Charge of Managing AI
Microsoft is reportedly drawing up rules for AI agents that run on Windows, positioning the operating system as the manager of AI on the PC. The move signals that platform vendors are pulling agent permissions and behavior constraints down into the system layer to address the security and control risks of autonomous software.