惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Jina AI
Jina AI
N
Netflix TechBlog - Medium
P
Proofpoint News Feed
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
D
DataBreaches.Net
人人都是产品经理
人人都是产品经理
aimingoo的专栏
aimingoo的专栏
Stack Overflow Blog
Stack Overflow Blog
Blog — PlanetScale
Blog — PlanetScale
月光博客
月光博客
阮一峰的网络日志
阮一峰的网络日志
I
InfoQ
F
Fortinet All Blogs
J
Java Code Geeks
Last Week in AI
Last Week in AI
美团技术团队
大猫的无限游戏
大猫的无限游戏
有赞技术团队
有赞技术团队
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园_首页
量子位
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Apple Machine Learning Research
Apple Machine Learning Research
小众软件
小众软件

PCI Perspectives

Just Published: Security Considerations for AI Systems Just Published: PCI Key Management and Operations (KMO)™ Standard v1.0 Coffee with the Council Podcast: Celebrating 20 Years of Securing Payment Data The Quantum Leap: Preparing for Post Quantum Cryptography Featuring Futurex 2026 Asia-Pacific Community Meeting Agenda Highlights The AI Exchange: Innovators in Payment Security Featuring GM Sectec Coffee with the Council Podcast: Meet This Year’s Europe Community Meeting Keynote Speaker, Ken Hughes Join Us at the Payment Industry Events of the Year Coffee with the Council Podcast: Meet This Year’s Asia-Pacific Community Meeting Keynote Speaker, CJ Meadows 2026 Europe Community Meeting Agenda Highlights The AI Exchange: Innovators in Payment Security Featuring atsec Mapping PCI DSS v4.0.1 to the NIST Cybersecurity Framework 2.0 2026 North America Community Meeting Agenda Highlights Meet the Council’s New Head of Business Operations and Risk Management The AI Exchange: Innovators in Payment Security Featuring PCA Cyber Security Enhance Your Community Meeting Experience with Interactive Workshops The AI Exchange: Innovators in Payment Security Featuring PROSA Bring PCI SSC Training to Your Organization with the New Training Venue Host Program The AI Exchange: Innovators in Payment Security Featuring Utimaco Coffee with the Council Podcast: Meet This Year’s North America Community Meeting Keynote Speaker, Sharon Gai Welcome Our Newest Associate Participating Organizations The AI Exchange: Innovators in Payment Security Featuring SecurityMetrics PCI SSC Publishes New Guidance on Compensating Controls and the Customized Approach Spotlight On: Dreamplug Technologies Private Limited (CRED), a New Principal Participating Organization Request for Comments: PCI Data Security Standard (PCI DSS) v4.0.1 The AI Exchange: Innovators in Payment Security Featuring In-Solutions Global Ltd Coffee with the Council Podcast: Nominate Now for the Global Executive Assessor Roundtable (GEAR) PCI SSC Publishes PCI PTS HSM v5.0 Request for Comments: PCI Secure Software Lifecycle Standard v2.0 Spotlight On: Worldline, a New Principal Participating Organization
The AI Exchange: Innovators in Payment Security Featuring...
Alicia Malone · 2026-09-12 · via PCI Perspectives

Welcome to the PCI Security Standards Council’s blog series, The AI Exchange: Innovators in Payment Security. This special, ongoing feature of our PCI Perspectives blog offers a resource for payment security industry stakeholders to exchange information about how they are adopting and implementing artificial intelligence (AI) into their organizations.  

In this edition of The AI Exchange, Integrity360 Group AI Practice Leader and Head of Payments Compliance, Alessandro Amalfitano, offers insight into how his company is using AI, and how this rapidly growing technology is shaping the future of payment security. 

How has your AI strategy evolved over the past 12–18 months? 

The most important shift has been treating AI governance as the starting point, not a retrofit. This is where I see many organizations struggle: they move quickly on capability and deal with governance afterwards, often realizing too late that they have gone in the wrong direction - at significant cost. We deliberately did the opposite. Before scaling anything, we invested in getting the governance model right and in structuring our adoption to stay compliant with applicable regulations, standards, and frameworks, including the EU AI Act. As a firm that assesses other organizations against industry standards and regulatory expectations - and through my role on the PCI SSC’s Global Executive Assessor Roundtable (GEAR), contributes to PCI guidance and industry discussion around assessment practices - operating AI internally without a defensible model was never an option; it had to be built in by design.  

From there, my thinking changed more fundamentally. AI stopped being a standalone initiative and became a layer of support running through our processes. I now hold two mandates at once: building AI capability for the firm and bringing AI into the assessment work itself. On the second, one principle is non-negotiable: the human stays at the center and validates every decision. AI is a powerful tool; it is never the final decision. 

What is one AI initiative that has already delivered a measurable impact, and what made it successful? 

Rather than a single tool, the initiative that has mattered most is embedding AI across our delivery processes - internal operations and, most significantly, the assessment lifecycle itself - from gap assessment through to reporting. The obvious benefit is removing repetitive, low-judgment steps. But the more meaningful impact is one we did not fully anticipate: consistency of diligence. Under deadline pressure, even an experienced assessor can be forced to move quickly through detail; an AI assistant does not. It brings the same rigor to the last control of the day as to the first, sustaining a uniform depth that improves the quality and completeness of our deliverables - with the assessor always reviewing, validating, and owning the final result.

Three things made it work. First, the human remains the final decision-maker; AI augments judgment; it never replaces it. Second, we treated this as a governance change, not just a tooling change - adapting our authorization processes and investing in training so the technology is used appropriately given the data it handles, the standards and frameworks it touches, and the European and national regulations of each market we operate in. Third, the wider industry is moving in the same direction: the PCI SSC is working toward a machine-readable reporting format, and that shared infrastructure is what will let AI integrate more deeply, and more safely, into assessment reporting over time. 

How are you approaching AI governance, particularly around data privacy and security? 

Our starting principle is that AI changes nothing about our data-protection obligations - it simply introduces new surfaces that must be brought into scope, never left outside it. We apply the same discipline to AI inputs that we demand of cardholder data: classify first, define what is categorically never permitted into an AI system and enforce minimization on everything else. As assessors, we also hold ourselves to the standard we hold clients to: how AI touches an assessment is logged, reviewable, and attributable, so the integrity of our opinion is never in question.

What makes this work in practice is that responsibility is not delegated to one function. We run a dedicated committee - CEO, CISO, IT, DPO, Legal, and the relevant stakeholders - so decisions are made collectively, with full visibility of compliance, security, and documentation implications before anything is adopted. The result is governance by design: every tool and process is designed to be compliant and under control from the outset, with its own permissions, restrictions, and controls. There is no path by which something reaches production outside that framework - the controls are the process, not a review applied afterwards. 

What challenges have become more apparent as AI capabilities have matured? 

The challenges that matter most are the ones that only surface once you are running AI at scale in a high-assurance environment - not the ones visible from a demo.

The first is a paradox inside our own human-in-the-loop principle: the better the AI gets, the harder it becomes to stay critical of it. When outputs are visibly rough, reviewers scrutinize them closely. When they become polished and usually correct, automation bias creeps in and vigilance quietly drops - at exactly the moment the stakes are unchanged. Keeping humans genuinely engaged, not just nominally in the loop, has become an active discipline rather than something we can assume. 

Closely related, the failure mode itself has shifted. As capability matured, the danger moved from “obviously wrong” to “plausible but wrong,” an output that looks right and is well-formed can pass review precisely because of how convincing it appears. In assessment work that carries real consequences, this raises the bar on reviewer expertise rather than lowering it.

The third challenge is one organizations underestimate: AI is not for everyone. It looks effortless in a chat window but applying it in a business context is a different matter entirely. Whether a given solution genuinely works can only be judged in capable hands - otherwise something fails because it was executed poorly, not because the idea was wrong. Distinguishing a flawed concept from a flawed implementation has become one of the most important judgments we make and getting it wrong means either abandoning good ideas or scaling bad ones. 

What advice would you provide for an organization moving from early AI adoption to broader implementation? 

My advice comes down to three convictions; each learned the hard way.

First, build the governance rails before you scale, not after. Governance is not the brake on broader adoption - it is the precondition for it. You can only scale safely on rails you laid early; retrofitting control onto a deployment that has already sprawled is exactly where the high costs and dead ends come from. I have watched organizations move fast on capability and pay for it later; doing the unglamorous work first is what makes everything that follows possible.

Second, put it in capable hands before you decide whether it works. Pilot with your strongest people, not as a broad rollout - otherwise you risk abandoning good ideas because they were executed poorly or scaling weak ones because they appeared to work for the wrong reasons. Until a capable person has implemented something properly, you are judging the execution, not the concept.

Third - and this is specific to regulated, high-assurance work - mind your data. Do not let the model rely on everything it was trained on, or everything available on the open web. In our field, the relevant data is controlled, and that controlled data must be the single source of truth. An AI system grounded in authoritative sources is an asset; one drawing freely on general knowledge is a liability, however convincing it sounds. 

What AI trend are you most excited about? 

What excites me most is not a single feature but the moment we are living through. This is an epochal shift, and the honest truth is that none of us really knows what this field will look like in two or three years - the pace of research and change is unlike anything I have seen in my career. I do not find that uncertainty unsettling; it is precisely what I find inspiring.  

If I had to name one frontier that captures it for our world specifically, it is agentic payments. AI agents that can initiate and complete transactions on a person’s behalf. This reshapes some of the most fundamental questions in payments security: how you authenticate an agent rather than a human, how sensitive data is protected when a machine transacts, where authorization and liability ultimately sit. For an industry built on trust and verification, it is at once an extraordinary opportunity and an entirely new surface to secure. 

And that is the thread running through everything: the very speed that makes this so exciting is what makes it so difficult to govern. We are watching capability grow faster than the frameworks meant to contain it, and harnessing that, without smothering it, is the real work ahead. After years in this field, I can say without hesitation that I have never seen a technology with such transformative potential and, at the same time, such an urgent need to be governed with discipline. 

View More Content on Artificial Intelligence

Learn More About Integrity360