














Welcome to the PCI Security Standards Council’s blog series, The AI Exchange: Innovators in Payment Security. This special, ongoing feature of our PCI Perspectives blog offers a resource for payment security industry stakeholders to exchange information about how they are adopting and implementing artificial intelligence (AI) into their organizations.
In this edition of The AI Exchange, atsec Principal Consultant, QSA, Yan Liu, offers insight into how his company is using AI, and how this rapidly growing technology is shaping the future of payment security.
How has your AI strategy evolved over the past 12–18 months?
Within atsec, we have established guidelines for the secure and responsible use of Artificial Intelligence (AI) services within the organization. Given our responsibility to handle sensitive information from both customers and internal sources, alongside the high standards required by stakeholders, it is essential that AI tools are utilized in a manner that minimizes security risks.
Our principles include:
Our focus with AI/Automation tools is on commercial management, project management, general testing methodology, and the reporting tools (e.g. PCI DSS ROC).
What is one AI initiative that has already delivered a measurable impact, and what made it successful?
In different atsec global offices, we are developing in-house AI solutions on systems that are physically located in our offices, ensuring that all data remains on premises. atsec team has successfully implemented this using open-source models, for example: Llama, working with OpenSSL library code.
Through our current usage, we have improved efficiency and quality in aspects including test preparation, project management, and reporting. For vulnerability discovery, AI provides valuable references and facilitates the development of auxiliary scripts.
Regarding the cryptography testing area, we are currently in the process of incorporating specific retrieval-augmented generation (RAG) and fine-tuning the model with standard requirements (e.g., FIPS 140) to improve accuracy.
How are you approaching AI governance, particularly around data privacy and security?
atsec's general principles for information security are also applicable for AI. As such, AI services, especially those hosted externally, must never process any non-public data or information, classified as either atsec internal or atsec confidential. This also extends to customer data and all personally identifiable information. Any data used with AI services must always be anonymized and/or masked to reduce risk and note that even public information may pose a risk.
AI tools are subject to the same rules and requirements of other tools and software as delineated in this policy regarding the employ of internal and confidential information. It has become common that many software applications and tools provide AI features, such as AI Assistant in Adobe Acrobat, CoPilot features in Microsoft 365, AI in Webex, AI in Feishu, and others.
As a rule of thumb, the models and databases related to these AI tools are maintained by the providers and vendors, are property of them, and are not maintained locally in employee devices. In addition, usually the usage agreement for those tools gives the providers the right to use and store the information given to the tools, which will then be used to further train their models. Thus, when prompts contain some internal or confidential information, that information will be transferred to the provider of the tool, violating atsec NDAs with customers.
As such, using AI tools with atsec internal and confidential information is forbidden unless the specific AI tool is explicitly allowed for use for specific projects/situations. atsec has established the internal policy “Use of AI within atsec” since 2023, and the policy is well-maintained internally. All colleagues need to be aware of and follow the requirements.
What challenges have become more apparent as AI capabilities have matured?
Quality and Accuracy of AI-Generated Output.
AI may be leveraged to improve efficiency and streamline repetitive or time-consuming tasks. However, it is not intended to replace human critical thinking, decision-making, or judgment. All AI-generated content must be carefully reviewed and validated by employees to ensure accuracy and alignment with company standards. The author is always responsible for all content produced with any AI service.
AI tools are tools. They shall not be used for authorship or produce work on behalf of the human. We do NOT allow the public AI tools to process any customer confidential data, even with commercial licenses that atsec has purchased from trusted AI suppliers.
While AI may be employed to generate output, it is critical to maintain the high standards expected by the organization and its stakeholders. To ensure this, all AI-generated content, whether it involves code, documentation, reports, or any other deliverable, is expected to undergo verification and quality assurance by the responsible employee. Therefore, atsec colleagues are required to:
What advice would you provide for an organization moving from early AI adoption to broader implementation?
The most suitable use of AI is customer and product agnostic tasks handling non-sensitive information. It is acceptable to use the service to generate a description or a script and then have the tool to change/improve it. Rather, a more restrictive approach should be selected where the service is used to improve isolated parts of the work.
Note that even publicly available information should be used only with caution. Consider operations of security! All input provided to an AI service relating to any project must be considered not only by itself, but in the context of other related input. For example: if an AI service is used to assist with installing and configuring a specific product, and that same service is then used to develop scripts to execute a specific attack. Regardless of whether all information was public, the potential result is data leakage.
Examples of appropriate usage:
What AI trend are you most excited about?
The trend I look forward to most is accessible, human-centric AI. First, AI is moving from large cloud models to lightweight local applications, which better protects user privacy and security.
Second, AI is deeply integrated into our industry, from payment functions to cybersecurity implementation and test/verification. Most importantly, it focuses on human-AI collaboration — AI takes over repetitive tasks, while people focus on creativity, thinking, and decision-making.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。