---
title: Do We Need to Embed AI Policies Within the PCI DSS Framework?
description: Explore the crucial steps in cybersecurity penetration testing. From setting goals to discussing findings, ensure success with expert guidance from 1 Cyber Valley.
image: https://www.onecybervalley.com/hubfs/igor-omilaev-FHgWFzDDAOs-unsplash-1.jpg
---

[![dark-logo-cyber](https://www.onecybervalley.com/hs-fs/hubfs/CyberValley_2023/Images/dark-logo-cyber.png?width=228&height=96&name=dark-logo-cyber.png "dark-logo-cyber")](https://www.onecybervalley.com/)

[![Logo](https://www.onecybervalley.com/hs-fs/hubfs/CyberValley_2023/Images/Logo.png?width=228&height=96&name=Logo.png "Logo")](https://www.onecybervalley.com/)

- [Home](https://www.onecybervalley.com)
- [About Us](https://www.onecybervalley.com/about-us) 
    - [Career](https://www.onecybervalley.com/careers)
    - [Blog](https://www.onecybervalley.com/blog)
    - [FAQ](https://www.onecybervalley.com/faq)
- [How we help](https://www.onecybervalley.com/how-we-help) 
    - [PCI DSS](https://www.onecybervalley.com/how-we-help/pci-dss) 
          - [QSA Assessment Services](https://www.onecybervalley.com/how-we-help/pci-dss/assessment-services)
          - [PCI DSS Managed Service](https://www.onecybervalley.com/how-we-help/pci-dss/pci-dss-managed-service)
    - [PCI PIN](https://www.onecybervalley.com/how-we-help/pci-pin/pci-pin-advisory-services) 
          - [PCI PIN Advisory Services](https://www.onecybervalley.com/how-we-help/pci-pin/pci-pin-advisory-services)
    - [Managed Security Services](https://www.onecybervalley.com/how-we-help/managed-security-services) 
          - [Vulnerability Magagement](https://www.onecybervalley.com/how-we-help/management-services/vulnerability-management)
          - [Managed Detection & Response](https://www.onecybervalley.com/how-we-help/management-services/managed-detection-response)
          - [Penetration Testing](https://www.onecybervalley.com/management-services/penetration-testing)
          - [Security Awareness & Training](https://www.onecybervalley.com/management-services/security-awareness-training)
          - [Managed Phishing Services](https://www.onecybervalley.com/management-services/managed-phishing-service)
          - [Third Party Assurance](https://www.onecybervalley.com/how-we-help/management-services/third-party-assurance)
    - [Consultancy](https://www.onecybervalley.com/how-we-help/consultancy) 
          - [Cyber Security Consultancy](https://www.onecybervalley.com/how-we-help/cyber-security-consultancy)
          - [Virtual CISO](https://www.onecybervalley.com/how-we-help/virtual-ciso)
          - [Security Strategy & Transformation](https://www.onecybervalley.com/how-we-help/security-strategy-transformation)
- [Contact Us](https://www.onecybervalley.com/contact-us)

- [Home](https://www.onecybervalley.com)
- [About Us](https://www.onecybervalley.com/about-us) 
    - [Career](https://www.onecybervalley.com/careers)
    - [Blog](https://www.onecybervalley.com/blog)
    - [FAQ](https://www.onecybervalley.com/faq)
- [How we help](https://www.onecybervalley.com/how-we-help) 
    - [PCI DSS](https://www.onecybervalley.com/how-we-help/pci-dss) 
          - [QSA Assessment Services](https://www.onecybervalley.com/how-we-help/pci-dss/assessment-services)
          - [PCI DSS Managed Service](https://www.onecybervalley.com/how-we-help/pci-dss/pci-dss-managed-service)
    - [PCI PIN](https://www.onecybervalley.com/how-we-help/pci-pin/pci-pin-advisory-services) 
          - [PCI PIN Advisory Services](https://www.onecybervalley.com/how-we-help/pci-pin/pci-pin-advisory-services)
    - [Managed Security Services](https://www.onecybervalley.com/how-we-help/managed-security-services) 
          - [Vulnerability Magagement](https://www.onecybervalley.com/how-we-help/management-services/vulnerability-management)
          - [Managed Detection & Response](https://www.onecybervalley.com/how-we-help/management-services/managed-detection-response)
          - [Penetration Testing](https://www.onecybervalley.com/management-services/penetration-testing)
          - [Security Awareness & Training](https://www.onecybervalley.com/management-services/security-awareness-training)
          - [Managed Phishing Services](https://www.onecybervalley.com/management-services/managed-phishing-service)
          - [Third Party Assurance](https://www.onecybervalley.com/how-we-help/management-services/third-party-assurance)
    - [Consultancy](https://www.onecybervalley.com/how-we-help/consultancy) 
          - [Cyber Security Consultancy](https://www.onecybervalley.com/how-we-help/cyber-security-consultancy)
          - [Virtual CISO](https://www.onecybervalley.com/how-we-help/virtual-ciso)
          - [Security Strategy & Transformation](https://www.onecybervalley.com/how-we-help/security-strategy-transformation)
- [Contact Us](https://www.onecybervalley.com/contact-us)

- [Talk to an Expert](https://calendly.com/hello-onecybervalley)

- [Talk to an Expert](https://calendly.com/hello-onecybervalley)

![waves](https://www.onecybervalley.com/hubfs/CyberValley_2023/Images/bg%20(2).png)

![ball1](https://www.onecybervalley.com/hubfs/CyberValley_2023/Images/ball1.png) ![ball2](https://www.onecybervalley.com/hubfs/CyberValley_2023/Images/ball2.png) ![ball3](https://www.onecybervalley.com/hubfs/CyberValley_2023/Images/ball3.png) ![ball4](https://www.onecybervalley.com/hubfs/CyberValley_2023/Images/ball4.svg)

# Do We Need to Embed AI Policies Within the PCI DSS Framework?

In the UK, there is currently no direct legal requirement for companies to adopt a dedicated Artificial Intelligence (AI) policy. Yet, with AI now being rapidly integrated into business operations - particularly within payments - the question arises: should organisations start embedding AI governance into established compliance and security frameworks such as PCI DSS?

The PCI Security Standards Council has already recognised this shift. In a recent publication, the Council highlighted that AI is increasingly being used in the design, management, and operation of payment systems. It also acknowledged the unique challenges AI poses: its ability to adapt and “learn” makes it difficult to fully understand the risks or anticipate how such systems may behave over time. To respond, the Council has introduced a set of guiding principles for the responsible use of AI in payment environments.

This is significant. PCI DSS has always been the cornerstone for securing payment data, but AI introduces new layers of complexity that extend beyond traditional risks. Should it therefore now be considered best practice for companies not only to implement AI policies but to align them directly with PCI DSS frameworks?

An AI-specific policy framework could provide organisations with several advantages:

- **Risk awareness**: Educating employees on the risks AI presents, from bias to misuse, helps reduce the chance of legal, financial, or reputational harm.
- **Access control**: Clear rules on how much access AI systems receive (least privilege principle) minimise unnecessary exposure.
- **System approval**: Defining which AI tools are permitted, particularly on company-owned devices, helps prevent shadow AI usage.
- **Security vigilance**: Acknowledging that AI systems themselves may become targets for malicious attacks, including data theft or manipulation, ensures these risks are considered upfront.

These considerations feel particularly relevant as PCI DSS already mandates Incident Response Plans and Security Awareness Programmes. But are these measures sufficient in the age of AI? Perhaps not. As we see training methods evolve - such as the growing popularity of “AI Escape Rooms” that simulate AI-related cyber incidents - it seems the industry is beginning to recognise the need for AI-specific awareness and preparedness.

There is also a wider regulatory backdrop. GDPR already covers aspects of AI through provisions on automated decision-making and data handling. While not AI-exclusive, these clauses remind organisations that processing personal data with AI requires special care, transparency, and strong safeguards. A company-wide AI policy could bridge this gap by ensuring responsible data use, reinforcing human oversight, and embedding governance across the entire lifecycle of AI systems.

Looking ahead, the EU AI Act - formally adopted on 21 May 2024 and due to enter into force on 1 August 2024 - marks a landmark step in regulating AI. It sets obligations based on the risk category of AI systems, ranging from transparency to outright restrictions on high-risk use cases. Organisations that begin integrating AI governance into their PCI DSS and wider compliance frameworks now will be far better positioned to adapt to this evolving landscape.

**So, is it time to embed AI policies into PCI DSS frameworks?**

The evidence suggests yes. By proactively creating structured AI governance policies, aligned with both PCI DSS and emerging regulations, organisations can increase resilience, protect customer trust, and remain agile in a rapidly changing environment. Crucially, employee education must be at the centre of this effort - because while AI is powerful, it is not accountable. Responsibility remains firmly with humans.

**Three Things Companies Should Do Now:**

**1.) Develop an AI governance policy** aligned with PCI DSS and covering risk, access, and permitted use.

**2.) Update security awareness training** to include AI-related risks and scenarios, ensuring staff are prepared.

**3.) Monitor regulatory developments** (such as the EU AI Act) and proactively adjust compliance practices.

To see how the PCI Security Standards Council is approaching this challenge, read their AI Principles for Securing the Use of AI in Payment Environments [here](https://blog.pcisecuritystandards.org/ai-principles-securing-the-use-of-ai-in-payment-environments).

If you would like to get in touch with us to discuss how we can support your cybersecurity needs - please reach out to us: [hello@onecybervalley.com](mailto:hello@onecybervalley.com)

**By 1 Cyber Valley | October 1st, 2025 | Sara Higgins**

### Latest Posts

[![Top Cybersecurity Open-Source Tools to Combat Cyber Threats - 2026](https://www.onecybervalley.com/hubfs/sasun-bughdaryan-KdCJ1nIkgOU-unsplash.jpg)](https://www.onecybervalley.com/blog/top-cybersecurity-open-source-tools-to-combat-cyber-threats-june-2026)

[Top Cybersecurity Open-Source Tools to Combat Cyber Threats - 2026](https://www.onecybervalley.com/blog/top-cybersecurity-open-source-tools-to-combat-cyber-threats-june-2026)

September 22,2026

[![AI-Driven Cyber Threats: Rising Risks for Healthcare Information Security](https://www.onecybervalley.com/hubfs/nappy-Q0qcTWEb7AI-unsplash-1.jpg)](https://www.onecybervalley.com/blog/ai-driven-cyber-threats-rising-risks-for-healthcare-information-security)

[AI-Driven Cyber Threats: Rising Risks for Healthcare Information Security](https://www.onecybervalley.com/blog/ai-driven-cyber-threats-rising-risks-for-healthcare-information-security)

September 15,2026

[![Decades-Old Bash Tricks Fuel AI Supply Chain Cybersecurity Risks](https://www.onecybervalley.com/hubfs/fotis-fotopoulos-DuHKoV44prg-unsplash-1.jpg)](https://www.onecybervalley.com/blog/decades-old-bash-tricks-fuel-ai-supply-chain-cybersecurity-risks)

[Decades-Old Bash Tricks Fuel AI Supply Chain Cybersecurity Risks](https://www.onecybervalley.com/blog/decades-old-bash-tricks-fuel-ai-supply-chain-cybersecurity-risks)

September 08,2026

[![AI-Driven Social Engineering Scams: A Growing Cybersecurity Threat](https://www.onecybervalley.com/hubfs/markus-winkler-FjyseC7iV3k-unsplash-1.jpg)](https://www.onecybervalley.com/blog/ai-driven-social-engineering-scams-a-growing-cybersecurity-threat)

[AI-Driven Social Engineering Scams: A Growing Cybersecurity Threat](https://www.onecybervalley.com/blog/ai-driven-social-engineering-scams-a-growing-cybersecurity-threat)

September 02,2026

[![2026 Payment Gateway Build Cost: Cybersecurity Requirements](https://www.onecybervalley.com/hubfs/vagaro-Iingrw2ZVYs-unsplash-1.jpg)](https://www.onecybervalley.com/blog/2026-payment-gateway-build-cost-cybersecurity-requirements)

[2026 Payment Gateway Build Cost: Cybersecurity Requirements](https://www.onecybervalley.com/blog/2026-payment-gateway-build-cost-cybersecurity-requirements)

August 31,2026

## Related Articles

[![](https://www.onecybervalley.com/hs-fs/hubfs/nathana-reboucas-KAuBwnUzJvg-unsplash-1.jpg?width=352&name=nathana-reboucas-KAuBwnUzJvg-unsplash-1.jpg)](https://www.onecybervalley.com/blog/pci-compliance-for-merchants-how-to-simplify-scope-saqs-and-assessments)

#### [PCI Compliance for Merchants: How to Simplify Scope, SAQs, and Assessments](https://www.onecybervalley.com/blog/pci-compliance-for-merchants-how-to-simplify-scope-saqs-and-assessments)

 When people think about PCI DSS, the focus is usually on security requirements and compliance...

[Read More](https://www.onecybervalley.com/blog/pci-compliance-for-merchants-how-to-simplify-scope-saqs-and-assessments)

[![](https://www.onecybervalley.com/hs-fs/hubfs/PCI-DSS-4.jpg?width=352&name=PCI-DSS-4.jpg)](https://www.onecybervalley.com/blog/pci-dss-version-4-new-requirements)

#### [PCI DSS 4.0: New Requirements](https://www.onecybervalley.com/blog/pci-dss-version-4-new-requirements)

 Payment Card Industry Data Security Standard (PCI DSS) v4.0 is the exclusive version that brings...

[Read More](https://www.onecybervalley.com/blog/pci-dss-version-4-new-requirements)

[![](https://www.onecybervalley.com/hs-fs/hubfs/franz26-fork-in-the-road-8116713_1920-1.jpg?width=352&name=franz26-fork-in-the-road-8116713_1920-1.jpg)](https://www.onecybervalley.com/blog/a-qsas-guide-to-choosing-the-right-path-customized-approach-vs-compensating-controls)

#### [A QSA's Guide to Choosing the Right Path: Customized Approach vs Compensating Controls](https://www.onecybervalley.com/blog/a-qsas-guide-to-choosing-the-right-path-customized-approach-vs-compensating-controls)

 The rollout of PCI DSS v4.x kinda marked one of the biggest shifts in payment security compliance...

[Read More](https://www.onecybervalley.com/blog/a-qsas-guide-to-choosing-the-right-path-customized-approach-vs-compensating-controls)

[![footer-logo-1](https://www.onecybervalley.com/hs-fs/hubfs/CyberValley_2023/Images/footer-logo-1.png?width=270&height=78&name=footer-logo-1.png "footer-logo-1")](https://www.onecybervalley.com/)

Cybersecurity today, tomorrow, together…

- Useful Links 
    - [PCI DSS QSA Compliance Services](https://www.onecybervalley.com/how-we-help/pci-dss)
    - [Cyber Security Consultancy Services](https://www.onecybervalley.com/how-we-help/consultancy)
    - [Managed Security Services](https://www.onecybervalley.com/how-we-help/managed-security-services)
- Community 
    - [About Us](https://www.onecybervalley.com/about-us)
    - [Blog](https://www.onecybervalley.com/blog)
- More Info 
    - [Contact Us](https://www.onecybervalley.com/contact-us)
    - [Career](https://www.onecybervalley.com/careers)

All Rights Reserved © 1 Cyber Valley. 2026

- [Privacy](https://www.onecybervalley.com/privacy-policy)
- [Terms & Conditions](https://www.onecybervalley.com/terms-and-conditions)

```json
{
  "@context" : "https://schema.org",
  "@id" : "https://www.onecybervalley.com/",
  "@type" : "Organization",
  "description" : "PCI DSS Qualified Security Assessor and cybersecurity consulting firm operating in 120+ countries, serving 150+ enterprise clients.",
  "logo" : {
    "@type" : "ImageObject",
    "url" : "https://www.onecybervalley.com/hs-fs/hubfs/CyberValley_2023/Images/Logo.png"
  },
  "name" : "One Cyber Valley",
  "sameAs" : [ "https://uk.linkedin.com/company/1-cyber-valley" ],
  "url" : "https://www.onecybervalley.com/"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Admin",
    "url" : "https://www.onecybervalley.com/blog/author/admin"
  },
  "dateModified" : "2026-07-16T18:56:35.040Z",
  "datePublished" : "2025-10-01T09:00:00.000Z",
  "headline" : "Do We Need to Embed AI Policies Within the PCI DSS Framework?",
  "image" : [ "https://www.onecybervalley.com/hubfs/igor-omilaev-FHgWFzDDAOs-unsplash-1.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.onecybervalley.com/blog/ai-policies-within-the-pci-dss-framework",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.onecybervalley.com/hubfs/Picture%201-1.png"
    },
    "name" : "1 Cyber Valley"
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "Article",
  "author" : {
    "@type" : "Person",
    "name" : "Admin"
  },
  "dateModified" : "2026-07-16T18:56:35+0000",
  "datePublished" : "2025-10-01T09:00:00+0000",
  "description" : "Explore the crucial steps in cybersecurity penetration testing. From setting goals to discussing findings, ensure success with expert guidance from 1 Cyber Valley.",
  "headline" : "<span id=\"hs_cos_wrapper_name\" class=\"hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text\" style=\"\" data-hs-cos-general-type=\"meta_field\" data-hs-cos-type=\"text\" >Do We Need to Embed AI Policies Within the PCI DSS Framework?</span>",
  "image" : [ "https://9302146.fs1.hubspotusercontent-na1.net/hubfs/9302146/igor-omilaev-FHgWFzDDAOs-unsplash-1.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.onecybervalley.com/blog/ai-policies-within-the-pci-dss-framework",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.onecybervalley.com/hs-fs/hubfs/CyberValley_2023/Images/Logo.png"
    },
    "name" : "One Cyber Valley"
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BreadcrumbList",
  "itemListElement" : [ {
    "@type" : "ListItem",
    "item" : "https://www.onecybervalley.com",
    "name" : "Home",
    "position" : 1
  }, {
    "@type" : "ListItem",
    "item" : "https://www.onecybervalley.com/blog",
    "name" : "Blog",
    "position" : 2
  }, {
    "@type" : "ListItem",
    "item" : "https://www.onecybervalley.com/blog/ai-policies-within-the-pci-dss-framework",
    "name" : "<span id=\"hs_cos_wrapper_name\" class=\"hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text\" style=\"\" data-hs-cos-general-type=\"meta_field\" data-hs-cos-type=\"text\" >Do We Need to Embed AI Policies Within the PCI DSS Framework?</span>",
    "position" : 3
  } ]
}
```