Adapt or die: payment security programmes for the age of Al
20th January 2027 • Park Plaza Victoria, London, UK
The payments ecosystem left credit card data behind long ago. Can PCI DSS compliance deliver true payment security?
Bridging the gap between attestation and risk management
PCI DSS v4.0.1 has been fully in force since March 2025, and the first full assessment cycle has taught hard lessons: scope was broader than expected, the customised approach was harder to operationalise, evidence demands grew, and third-party contracts proved the weakest control.
The Council has begun work on v5.O — with Al systems and modernised validation among its stated goals, but no publication date — and the PTS POI vs device deadline has slipped to April 2027. The standard is moving from a point-in-time audit to continuous assurance faster than most compliance teams can staff it.
Meanwhile, the payment environment has moved beyond a neat cardholder-data perimeter. Modern payment journeys rely on JavaScript, hosted fields and iframes, mobile SDKs, APls, cloud platforms, token vaults, fraud engines, digital wallets, orchestration layers and multiple third-party processors. Scope can be reduced, but dependency cannot. A merchant may outsource the checkout and remain exposed to compromised scripts, weak integrations or failures elsewhere in the payment chain.
Agentic commerce — Al agents authorised to shop and pay on a customer's behalf — is arriving and raises a question the standard has yet to answer: who is the cardholder when an agent pays? And the criminals have not gone away: browser-side skimming still harvests card data from checkout pages that passed their last scan, and the socialengineering playbooks that dismantled major retailers in 2025 bypassed every compliance control en route to payment systems.
That makes payment security a visibility problem as much as a compliance problem: what can touch a payment, who can change it, which systems and suppliers can influence authorisation, and how quickly will a control failure be detected?
The schemes and regulators add urgency. Enforcement of v4.0.1 is now real; reimbursement rules for authorised push-payment fraud have moved cost onto payment firms; and operationalresilience and third-party regimes on both sides of the Channel are pulling processors, cloud providers and managed service providers into the same conversation. But compliance is not security, and an attestation is not a control.
Compliance leaders face an external challenge (a payments ecosystem changing shape beneath the standard) and an internal problem: how to fund continuous assurance for one small dataset in organisations that believe the box is ticked — and how to get the same outcome for the small and medium-sized merchants making up most of the ecosystem.
Their case for action is not that PCI DSS has failed, but that the gap between attestation and exposure is widening: more suppliers, more channels, more automation, less human line of sight. Waiting for the next breach to reopen the budget conversation may be the mistake.
Where do PCI leaders see genuine assurance, where is a clean attestation masking hidden scope, and what practical steps should organisations take before v5.O makes them mandatory? Is PCI DSS keeping up with payments — and are compliance teams keeping up with PCI DSS?
PCI DSS is at a crossroads: payment security is moving from proving compliance once a year to demonstrating control every day, across systems, suppliers and agents the compliance team does not own. PCI London will look at how compliance must deliver real security.
Key Themes
From point-in-time to continuous assurance
v4.0.1 moved the standard from annual audits towards ongoing monitoring and evidence, and the first full cycle showed how much that costs. Compliance teams need tools and processes that prove security every day, not once a year, with implications from basic workflow to risk management. Can you help?
Third-party and service-provider risk
Processors, gateways, cloud providers and MSPs all carry PCI obligations, and weak contracts, unclear SLAs and limited audit rights create blind spots that v4.0.1 exposes. Operational-resilience and critical-third-party regimes are now asking the same questions. Any success stories in continuous supplier assurance?
Automation, Al and evidence at scale
Manual evidence gathering and fragmented monitoring do not scale. Al and automation can streamline assessments, monitor scope, detect anomalies and embed PCI DSS into daily operations — but the Council is clear that human accountability and traceability are non-negotiable. So, what is best practice here?
Reducing the cost of compliance
Most organisations have limited resources, and the ecosystem is mostly small and medium-sized merchants completing self-assessment questionnaires. They need automation, solutions that apply more widely, and pro-business answers. How do you derive PCI DSS compliance from the security processes you already run?
Agentic commerce: who is the cardholder when an agent pays?
Schemes are building rails for Al agents that shop and pay on a customer's behalf, with delegated credentials and tokens. Authentication, consent, liability and scope were all designed for humans. What does compliance look like when the customer is software, and can you help merchants prepare?
Dealing with regulations
Teams now must build a single coherent security program that simultaneously satisfies divergent regulatory demands; they must interpret vague legal standards into technical architectures, and they risk non-compliance if auditors, regulators, or courts interpret differently later; they face unrealistic expectations around incident reporting; and they face personal liability. Can RegTech help?
Aligning PCI with the wider security and resilience stack
Compliance chiefs are under pressure to show that PCI DSS maps into NIST, ISO, GDPR, operational resilience and regulatory expectations. Integrating PCI into the enterprise risk stack turns compliance from burden into advantage. But is PCI DSS really the right standard for this?
Preparing for PCI DSS v5.O
The Council has signalled work on v5.0, with Al systems and modernised validation documents among its goals and no date yet. The cryptographic inventory now required under v4.0.1 is also the starting point for post quantum migration. What should compliance teams do now that will still be right when v5.O lands?
Scope: finding the COE you did not know you had
Backup servers, monitoring tools, contact-centre recordings and data lakes have all turned out to be in scope. Discovery tooling, tokenisation and P2PE shrink the environment; late discovery is the most expensive remediation of all. How do you find, reduce and keep control of scope continuously?
Post-quantum readiness — really?
How do organisations improve cryptographic visibility and prepare for migration without creating operational risk? The new KMO standard provides a concrete development to examine: it addresses lifecycle key management and cloud-based or remote HSM use. But is post-quantum readiness a practical planning discussion or pie-in-the-sky?
Securing the contact centre and the human channel
The 2025 retail attacks went through help desks and identity, not zero-days. Voice deepfakes, pause-and-resume and phishing-resistant authentication for operators are now part of the payment perimeter. How do you keep agents, and their credentials, out of scope and out of reach?
Browser-side skimming
Securing e-commerce isn't just about payment card data or even pure payments. Script inventories, integrity checks and tamper detection are now mandatory, yet checkout pages that passed their last scan are still harvested through third-party and supply-chain scripts. Content security policies help; monitoring is what catches the change. What actually works at scale, and at what cost?