Last month, the PCI Security Standards Council hosted their annual North America Community Meeting in Vancouver, Canada. Alongside Europe and Asia-Pacific events, these Community Meetings shed light on upcoming changes to PCI standards and provide a launchpad for new guidance to support organizations in their compliance efforts.

The Vancouver event saw the publication of a new Information Supplement, Security Considerations for AI. The guide explains how and where PCI DSS applies for organizations using AI.

In this article, we’ll break down the key takeaways from the guidelines and explain how data intelligence delivers key evidence for compliant use of AI.

Key takeaways

  1. PCI DSS requirements apply to AI tools in the same way as any other system or identity.
  2. AI tools must be considered when scoping for PCI DSS compliance, and must be included in periodic scope revalidation to ensure the boundaries and guardrails in place to limit scope remain effective.
  3. Non-human identities granted to AI systems should be applied following the same access principles as human individuals, subject to the same logging and monitoring.

Complying with PCI DSS when using AI

The compliance principles for AI are no different from other systems and applications for PCI DSS.

Much of the prevailing discourse surrounding AI overlooks that it is another application or service with a set of identities that needs managing like any other, lost in the noise of its vast potential as both opportunity and threat.

AI is a further evolution of the same technologies that the latest version of the standard was written to support.

The guidelines highlight that:

“In general, when AI is used, it should be considered no different from any other form of technology when scoping the PCI requirements that may apply.”

This also means that in scope AI technology is subject to the same requirements as any other system and identity.

Scoping considerations for AI

A system is in scope for PCI DSS if it:

  • Stores, processes or transmits cardholder data/sensitive authentication data (CHD/SAD), and/or
  • Is on the same network or has unrestricted connectivity to systems that store, process or transmit CHD.

Systems that are connected to the cardholder data environment (CDE) and those that impact the configuration or security of the CDE, or otherwise support PCI DSS requirements are also in scope.

These same scoping rules apply when those systems are AI tools or utilize AI components.

PCI DSS v4.0 introduced a periodic scope revalidation requirement that is particularly important when AI tools are introduced, to ensure that they are not enabling unauthorized transfer of cardholder data outside the CDE.

Where possible, cardholder data processed by AI systems should be modified so the system is not presented with full PAN data, instead using tokenized, truncated or encrypted data. The guidelines further state that access to sensitive authentication data - even if encrypted - should be prohibited to AI systems.

To prevent out-of-scope AI systems from being brought inadvertently into scope, the guidelines recommend using DLP on AI system egress. This means that cardholder data will be identified and blocked before leaving the system.

Agents, identities and PCI DSS

AI tools require access to vast quantities of information to function. This means they are often given broad access into company systems and the data they contain.

PCI DSS addresses non-human identities within the current standard. For AI tools that are able to take actions and make decisions without direct human involvement, the latest guidelines advise considering them as individual identities - similar to a human user. The access control principles - such as least privilege - that apply to individuals must also be applied to AI ‘users.’

The actions performed by these AI ‘users’ must be logged and regularly reviewed, just as they are for individuals accessing and processing cardholder data and in-scope systems.

The main difference between AI ‘users’ and individual human users in the new guide applies to the use of multi-factor authentication. While individuals are able to present “something you have” and “something you are” factors, AI systems and other applications should rely instead on unique, device-bound cryptographic credentials.

Data intelligence for evidence-based compliance

Data intelligence is the starting point for safe AI deployments, knowing what data resides in the systems and platforms it will access to ensure the right safeguards are in place to prevent unauthorized access, use or disclosure.

“Effective AI governance starts with the data rather than the tooling.” (PCI SSC, Security Considerations for AI Systems)