How do artificial intelligence systems fit into the scope of PCI DSS? It depends on how AI is implemented and what it can access.
Here’s what you need to know:
Let’s dive deeper.
According to the PCI Security Standards Council (PCI SSC), if an AI system is part of an environment that is in-scope for PCI DSS, it must be implemented and managed in accordance with applicable PCI DSS requirements.
In other words, AI doesn’t create an exception to PCI DSS requirements for securing payment card data.
“Use of AI does not remove or bypass the need to meet the requirements of any applicable PCI SSC standard,” the PCI SSC explained in a September 2025 article. “This can sometimes be complex, and AI systems can often operate in ways that are not easily decomposed and understood. However, this complexity does not remove the need to meet any applicable requirement.”
AI systems may be used to detect fraud, manage payment risk, interact with users, analyze logs, or even facilitate payments. The key question isn’t simply whether your organization uses AI. Instead, organizations should consider how each AI system is implemented and what it can access or do within the CDE.
Depending on how an AI system is implemented, a number of PCI DSS requirements may apply. This includes securing cardholder data at rest and during transmission, as well as requirements related to logging and monitoring, software development, change management, incident response, and least privilege. For example, AI systems should only have access to the systems and information necessary to perform their functions.
In some cases, AI systems may need access to payment data to perform their intended function. The PCI SSC notes that organizations can consider approaches such as payment tokens, single-use PANs, or truncated PANs to limit the scope and potential impact of that access.
As part of developing an effective AI governance program, organizations should also consider whether AI systems can be monitored and whether their actions can be traced back to a responsible human individual.
The PCI SSC says AI systems should be “deployed so that the actions performed by the AI can be logged and monitored, and a (human) individual held responsible for those actions.”
In sum, AI does not change the requirements of PCI DSS. Instead, organizations need to understand where AI fits within their existing payment environment and ensure that the system is appropriately secured based on its role, access, and capabilities.
AI isn’t only changing how organizations approach compliance. It’s also changing how auditors conduct assessments.
In spring 2025, the PCI SSC published guidance outlining how AI should be used during PCI DSS assessments. While they acknowledged the benefits of using AI to improve efficiency and minimize errors, they also emphasized the importance of human oversight.
AI can assist assessors with a variety of time-consuming tasks, such as helping review large volumes of documentation, creating work papers, and transcribing and summarizing interviews. These capabilities can reduce the level of manual effort involved in an assessment and allow auditors to spend more time on higher-value analysis. But there is an important limitation: AI cannot replace the assessor.
The PCI SSC emphasizes that the lead QSA remains responsible for overseeing the assessment, making critical judgments, and ensuring the accuracy and completeness of the final report.
AI can produce false positives, incorrect assumptions, and biased results. For that reason, human expertise and oversight remain essential throughout the assessment process.
Organizations should avoid thinking of AI as a separate category that sits outside their PCI DSS obligations.
If an AI system is implemented within an environment that is subject to PCI DSS, the system must be managed in accordance with applicable PCI DSS requirements. Organizations should carefully consider what data and systems AI can access, what actions it can perform, how those actions are monitored, and who is ultimately responsible for them.
At the same time, AI can be a valuable tool during a PCI DSS assessment. The key is finding the right balance between technology and human expertise.
BARR is one of only a few U.S. auditing firms that is qualified to perform audits against all of the highest-regarded security compliance standards, including PCI DSS, CMMC, HITRUST, ISO 27001, and SOC 2. If you’re looking for a QSA firm to help you grow your compliance program, contact us today for a free consultation.