惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
Engineering at Meta
Engineering at Meta
博客园 - 聂微东
博客园 - Franky
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
雷峰网
雷峰网
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
L
LangChain Blog
WordPress大学
WordPress大学
H
Help Net Security
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Y
Y Combinator Blog
Blog — PlanetScale
Blog — PlanetScale
MyScale Blog
MyScale Blog
IT之家
IT之家
酷 壳 – CoolShell
酷 壳 – CoolShell
罗磊的独立博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
有赞技术团队
有赞技术团队
Apple Machine Learning Research
Apple Machine Learning Research
云风的 BLOG
云风的 BLOG
博客园 - 【当耐特】
P
Proofpoint News Feed
D
DataBreaches.Net

PCI Perspectives

Just Published: PCI Key Management and Operations (KMO)™ Standard v1.0 The AI Exchange: Innovators in Payment Security Featuring Integrity360 Coffee with the Council Podcast: Celebrating 20 Years of Securing Payment Data The Quantum Leap: Preparing for Post Quantum Cryptography Featuring Futurex 2026 Asia-Pacific Community Meeting Agenda Highlights The AI Exchange: Innovators in Payment Security Featuring GM Sectec Coffee with the Council Podcast: Meet This Year’s Europe Community Meeting Keynote Speaker, Ken Hughes Join Us at the Payment Industry Events of the Year Coffee with the Council Podcast: Meet This Year’s Asia-Pacific Community Meeting Keynote Speaker, CJ Meadows 2026 Europe Community Meeting Agenda Highlights The AI Exchange: Innovators in Payment Security Featuring atsec Mapping PCI DSS v4.0.1 to the NIST Cybersecurity Framework 2.0 2026 North America Community Meeting Agenda Highlights Meet the Council’s New Head of Business Operations and Risk Management The AI Exchange: Innovators in Payment Security Featuring PCA Cyber Security Enhance Your Community Meeting Experience with Interactive Workshops The AI Exchange: Innovators in Payment Security Featuring PROSA Bring PCI SSC Training to Your Organization with the New Training Venue Host Program The AI Exchange: Innovators in Payment Security Featuring Utimaco Coffee with the Council Podcast: Meet This Year’s North America Community Meeting Keynote Speaker, Sharon Gai Welcome Our Newest Associate Participating Organizations The AI Exchange: Innovators in Payment Security Featuring SecurityMetrics PCI SSC Publishes New Guidance on Compensating Controls and the Customized Approach Spotlight On: Dreamplug Technologies Private Limited (CRED), a New Principal Participating Organization Request for Comments: PCI Data Security Standard (PCI DSS) v4.0.1 The AI Exchange: Innovators in Payment Security Featuring In-Solutions Global Ltd Coffee with the Council Podcast: Nominate Now for the Global Executive Assessor Roundtable (GEAR) PCI SSC Publishes PCI PTS HSM v5.0 Request for Comments: PCI Secure Software Lifecycle Standard v2.0 Spotlight On: Worldline, a New Principal Participating Organization
The AI Exchange: Innovators in Payment Security Featuring...
Alicia Malone · 2026-04-03 · via PCI Perspectives

Welcome to the PCI Security Standards Council’s blog series, The AI Exchange: Innovators in Payment Security. This special, ongoing feature of our PCI Perspectives blog offers a resource for payment security industry stakeholders to exchange information about how they are adopting and implementing artificial intelligence (AI) into their organizations.  

In this edition of The AI Exchange, Toast, Inc. Senior Director, Technical Compliance, Mahmoud Sultan, offers insight into how his company is using AI, and how this rapidly growing technology is shaping the future of payment security. All opinions expressed are his own and do not represent the opinions of Toast, Inc. 

How have you most recently incorporated artificial intelligence within your organization? 

At Toast, we’re incorporating AI in a variety of ways, including two complementary ways: customer-facing capabilities for restaurants and retailers, and internal productivity enablement.

On the product side, Toast IQ has expanded from a set of “smart features” into a more conversational, task-oriented AI assistant built directly into the Toast ecosystem—helping answer operators’ questions and surface insights. Toast IQ can flag top-selling items by daypart, add a menu item with a single prompt, automatically update menus across every service channel, and quickly answer questions like, “Who’s working Friday night?"

Internally, we’re applying and exploring many AI use cases including to accelerate the engineering lifecycle. We’re also exploring AI-enabled approaches to support GRC operations—such as summarizing evidence, highlighting exceptions, and generating first-pass narratives that assist (not replace) human review at this time. 

What is the most significant change you’ve seen in your organization since AI-use has become so much more prevalent? 

The biggest change is that AI has shifted from being “a tool” to becoming a workflow layer—compressing the time between question → insight → action. For our customers, this can potentially mean faster decisions inside a system that spans orders, operations, and payments. For internal teams, it can mean moving faster while still meeting a high bar for assurance, audit readiness, and control discipline.

How do you see AI evolving or impacting payment security in the future? 

AI will likely be a force multiplier for payment security in a variety of ways including: 

  1. Detection at machine speed: AI-driven anomaly detection and behavioral analytics can help identify fraud patterns, account takeover attempts, and operational signals that humans would struggle to catch—especially as attackers automate and scale.
  2. Adaptive controls: We’ll likely see more dynamic risk-based decisioning (e.g., step-up verification, transaction friction, or routing decisions) based on contextual signals rather than static rules—improving both protection and user experience.
  3. Continuous assurance: AI can help shift compliance from periodic snapshots to more continuous monitoring by triaging evidence, flagging exceptions, and accelerating remediation cycles—while preserving strong human oversight and traceability. 

For payments ecosystems, the goal is higher confidence with less friction: security that’s not only strong, but also more scalable and more integrated into how teams build and operate. 

What potential risks should organizations consider as AI becomes more integrated into payment security? 

In the future, as AI becomes embedded into payment security, organizations should plan for risks across security, integrity, privacy, and governance, including: 

  • Adversarial use of AI: automated phishing/social engineering, synthetic identities, and accelerated vulnerability exploitation.
  • Model risk: data poisoning, prompt injection (for LLM-based workflows), and evasion techniques that can reduce detection effectiveness.
  • Data governance: ensuring payment-related and other sensitive data is properly scoped, minimized, protected, and not inappropriately exposed to third parties—especially when using external models/services.
  • Explainability and accountability: if AI influences security outcomes (e.g., blocking, routing, step-up actions), organizations must be able to justify decisions, monitor quality and bias, and maintain human override paths.
  • Over-reliance: At least for now AI should augment—not replace—core security fundamentals and expert judgment, particularly for high-impact determinations, realizing that this pendulum will likely swing further over time.

What advice would you provide for an organization just starting their journey into using AI? 

Start with high-value, low-risk use cases, and build the governance foundations early: 

  • Pick the right first use cases: prioritize productivity and decision support before automated enforcement (e.g., summarization, triage, investigation acceleration, policy mapping).
  • Define guardrails upfront: data classification, acceptable use, human-in-the-loop requirements, auditability, and retention boundaries.
  • Threat model AI features: treat AI like any other production capability—secure SDLC, abuse cases, logging/monitoring, and red-team approaches where appropriate.
  • Measure outcomes: track accuracy, false positives/negatives, drift, and operational impact—not just novelty.
  • Don’t skip vendor diligence: understand model boundaries, data handling/retention, training usage, and security controls when using third-party AI.

This approach helps organizations move quickly while keeping trust, safety, and compliance as first-order requirements. 

What AI trend (not limited to payments) are you most excited about? 

I’m most excited about AI that reduces operational toil while increasing assurance—especially agentic workflows that can gather context, propose actions, and prepare evidence packages, while keeping humans in control for approval and final judgment (for now).

In practical terms, that includes AI-assisted engineering workflows, AI-augmented investigations, and AI-enabled compliance operations (e.g., evidence summarization, exception detection, and control effectiveness signals). Done well, these capabilities can help make security and compliance more seamless and integrated into day-to-day operations—less of a late-stage blocker, and more of an enabling mechanism for trusted innovation. 

View More Content on Artificial Intelligence

Learn More About Toast, Inc.