惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
B
Blog
博客园 - Franky
H
Help Net Security
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
月光博客
月光博客
云风的 BLOG
云风的 BLOG
小众软件
小众软件
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 聂微东
G
Google Developers Blog
大猫的无限游戏
大猫的无限游戏
M
MIT News - Artificial intelligence
罗磊的独立博客
H
Hackread – Cybersecurity News, Data Breaches, AI and More
宝玉的分享
宝玉的分享
L
LangChain Blog
阮一峰的网络日志
阮一峰的网络日志
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Vercel News
Vercel News
V
V2EX
Martin Fowler
Martin Fowler
T
Tailwind CSS Blog
有赞技术团队
有赞技术团队

PCI Perspectives

Just Published: Security Considerations for AI Systems Just Published: PCI Key Management and Operations (KMO)™ Standard v1.0 The AI Exchange: Innovators in Payment Security Featuring Integrity360 Coffee with the Council Podcast: Celebrating 20 Years of Securing Payment Data The Quantum Leap: Preparing for Post Quantum Cryptography Featuring Futurex 2026 Asia-Pacific Community Meeting Agenda Highlights Coffee with the Council Podcast: Meet This Year’s Europe Community Meeting Keynote Speaker, Ken Hughes Join Us at the Payment Industry Events of the Year Coffee with the Council Podcast: Meet This Year’s Asia-Pacific Community Meeting Keynote Speaker, CJ Meadows 2026 Europe Community Meeting Agenda Highlights The AI Exchange: Innovators in Payment Security Featuring atsec Mapping PCI DSS v4.0.1 to the NIST Cybersecurity Framework 2.0 2026 North America Community Meeting Agenda Highlights Meet the Council’s New Head of Business Operations and Risk Management The AI Exchange: Innovators in Payment Security Featuring PCA Cyber Security Enhance Your Community Meeting Experience with Interactive Workshops The AI Exchange: Innovators in Payment Security Featuring PROSA Bring PCI SSC Training to Your Organization with the New Training Venue Host Program The AI Exchange: Innovators in Payment Security Featuring Utimaco Coffee with the Council Podcast: Meet This Year’s North America Community Meeting Keynote Speaker, Sharon Gai Welcome Our Newest Associate Participating Organizations The AI Exchange: Innovators in Payment Security Featuring SecurityMetrics PCI SSC Publishes New Guidance on Compensating Controls and the Customized Approach Spotlight On: Dreamplug Technologies Private Limited (CRED), a New Principal Participating Organization Request for Comments: PCI Data Security Standard (PCI DSS) v4.0.1 The AI Exchange: Innovators in Payment Security Featuring In-Solutions Global Ltd Coffee with the Council Podcast: Nominate Now for the Global Executive Assessor Roundtable (GEAR) PCI SSC Publishes PCI PTS HSM v5.0 Request for Comments: PCI Secure Software Lifecycle Standard v2.0 Spotlight On: Worldline, a New Principal Participating Organization
The AI Exchange: Innovators in Payment Security Featuring...
Alicia Malone · 2026-08-17 · via PCI Perspectives

Welcome to the PCI Security Standards Council’s blog series, The AI Exchange: Innovators in Payment Security. This special, ongoing feature of our PCI Perspectives blog offers a resource for payment security industry stakeholders to exchange information about how they are adopting and implementing artificial intelligence (AI) into their organizations.  

In this edition of The AI Exchange, GM Sectec President, Héctor Guillermo Martínez, offers insight into how his company is using AI, and how this rapidly growing technology is shaping the future of payment security. 

These responses reflect GM Sectec’s practical experience securing AI adoption in regulated payment environments through tokenization, continuous vulnerability validation, and AI-specific architectural controls. 

How has your AI strategy evolved over the past 12–18 months? 

Over the past 18 months, GM Sectec has moved from closely monitoring AI developments to deliberately building a “Secure AI Adoption” framework designed for payment ecosystems. We recognized that agentic AI and large language models would dramatically expand attack surfaces through Non-Human Identities (NHIs), dynamic “ghost” or shadow APIs, and the risk of sensitive data exposure. Our strategy evolved around three integrated pillars: protecting data at the source with tokenization, maintaining continuous visibility and validation of our attack surface, and implementing AI-specific technical controls for visibility, containment, and behavioral protection. This allows us — and our clients — to embrace AI innovation while strengthening, rather than weakening, PCI DSS compliance. 

What is one AI initiative that has already delivered a measurable impact, and what made it successful? 

A high-impact initiative has been the integration of DataBye by FirsToken tokenization with AI governance controls in client payment environments. By tokenizing cardholder data and other sensitive information before it can be accessed or processed by AI agents or LLMs, we enabled organizations to safely pilot agentic AI for fraud detection and customer service while reducing PCI audit scope by 60–70% in targeted environments. The key to success was treating tokenization not just as a traditional compliance tool, but as the foundational “data firewall” for the AI era — combined with strict access controls and real-time behavioral monitoring. Clients shifted from viewing AI as “too risky” to “we can now innovate with confidence and measurable compliance benefit”. 

How are you approaching AI governance, particularly around data privacy and security? 

We govern AI through a “Zero Trust for AI” model fully aligned with PCI DSS v4.0.1 principles. The cornerstone is DataBye by FirsToken, ensuring that LLMs, AI agents, and NHIs never interact with raw sensitive data — only with tokens. Through our partnership with Akamai, we extend this foundation with zero-trust micro segmentation to contain the blast radius of compromised autonomous agents and continuous API discovery and behavioral governance to eliminate shadow and ghost APIs created by agentic workflows. Privacy is protected by design: data minimization, strong encryption, and treating AI entities with the same (or greater) rigor as human identities under access control, authentication, and monitoring requirements. 

What challenges have become more apparent as AI capabilities have matured? 

As AI capabilities have matured, two challenges have become especially clear: first, the explosion of Non-Human Identities combined with the “ghost API” problem — where AI agents dynamically create undocumented API calls that reach into cardholder data environments, bypassing traditional inventory and review processes; second, the speed of AI adoption has outpaced governance in many organizations, resulting in sensitive data being fed directly into LLMs without adequate protection. Traditional static access reviews and periodic vulnerability assessments are no longer sufficient. The clear lesson is that “bolt-on” security fails in agentic environments; security and compliance must be architected into AI systems from the very beginning. 

What advice would you provide for an organization moving from early AI adoption to broader implementation? 

Start with data protection as the non-negotiable foundation — implement robust tokenization (such as DataBye by FirsToken), so sensitive information is never exposed to AI systems in the first place. Next, establish comprehensive visibility and containment: discover and govern all APIs (including those dynamically created by agents), apply micro-segmentation to limit blast radius, and deploy behavioral runtime protection that distinguishes normal from anomalous AI activity. Treat AI agents and NHIs as first-class identities under your PCI program — unique credentials, least privilege, continuous monitoring, and regular access reviews. Finally, replace periodic assessments with continuous validation programs, such as ongoing vulnerability scanning and attack surface management with platforms like FirstFire. Organizations that embed security into their AI architecture from day one will turn AI into a competitive advantage rather than a compliance and risk burden. 

What AI trend are you most excited about? 

I am most excited about the emergence of self-protecting, AI-native security architectures — where advanced behavioral analysis, micro-segmentation, continuous API governance, and intelligent data protection work together to make agentic AI systems secure and compliant by default. In the payment industry, this means we can finally move beyond “AI is powerful but dangerous” to “AI is powerful, trustworthy, and a strategic enabler” within highly regulated environments. The convergence of tokenization for data minimization, real-time visibility into agentic workflows, and intelligent containment is transforming the autonomous digital workforce from a liability into one of our most powerful tools for fraud prevention, operational efficiency, and customer experience. 

View More Content on Artificial Intelligence

Learn More About GM Sectec