CFOtech Asia - Technology news for CFOs & financial decision-makers
Asia
PCI council marks 20 years with AI focus in Kuala Lumpur

PCI council marks 20 years with AI focus in Kuala Lumpur

Wed, 19th Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

The PCI Security Standards Council will hold its Asia-Pacific Community Meeting in Kuala Lumpur, marking the organisation's 20th anniversary.

The event will bring together banks, retailers, payment service providers, assessors, technology providers and security professionals from across the region. It will focus on how artificial intelligence is reshaping payments and changing the risks facing cardholder data and payment systems.

The return to Kuala Lumpur comes three years after the city last hosted the event. The agenda comes amid rising concern over fraud and cybercrime in payments, as AI tools give attackers new ways to adapt faster than traditional security controls.

Founded in 2006, the PCI Security Standards Council has become a central body in setting rules for protecting cardholder data. Its standards are widely used across the payments industry, making its regional meetings a forum for discussions that can influence how banks, merchants and service providers approach compliance and security operations.

AI focus

Several sessions will examine the effect of more autonomous systems on payment security. Topics include trust and scalability in an environment where machines make more decisions, and the emergence of AI agents as a new source of threats within the cardholder data environment.

Another part of the programme will look at automated governance tools designed to reduce the burden of collecting and analysing compliance data. A regional case study focused on India will explore how national approaches can strengthen resilience against cyber threats.

The agenda also includes a session on turning PCI standards into business value, reflecting a wider industry debate over whether compliance should be treated solely as a regulatory and operational cost. Other discussions will cover cross-border payments, recurring vulnerabilities, ecosystem security and security management strategies.

Keynote speaker

The keynote speaker will be Dr CJ Meadows, who leads the Innovation & Entrepreneurship Centre at S P Jain School of Global Management. Her work has focused on the intersection of emerging technology, creativity, human behaviour and the future of work.

Her keynote, titled "Thinking Beyond Technology to Build the Next 20 Years of Trust", will address responsible decision-making in a digital environment that is changing quickly. The session places trust at the centre of the meeting's wider discussions about automation in payments.

The emphasis on trust reflects a basic challenge for the payments sector. As more processes are delegated to software, firms face pressure to preserve consumer confidence while responding to new forms of attack and keeping pace with operational change.

Industry stakes

The issue has become more pressing as payment systems grow more interconnected across borders and service providers. Security lapses in one part of the ecosystem can affect merchants, financial institutions and consumers far beyond a single market, which is one reason common standards remain important to the industry.

In Asia-Pacific, the discussion carries added weight because of the region's mix of payment markets, from large card networks and digital wallets to rapidly expanding online commerce platforms. The spread of AI into fraud detection, customer interaction, transaction screening and back-office processes has created both efficiency gains and new operational questions.

Industry groups and businesses are increasingly trying to determine where AI can improve oversight and where it may create blind spots. Autonomous systems can process large amounts of information quickly, but they can also widen the attack surface if organisations fail to manage access, decision rights and data flows properly.

Gina Gobeyn, executive director of PCI SSC, said the anniversary meeting would address those competing pressures directly. "Security and trust are inseparable in payments," Gobeyn said. "For 20 years, the PCI SSC has helped the industry stay ahead of evolving threats to payment security. Artificial intelligence is now one of the defining challenges of this next chapter. New technology creates real opportunities for the industry but also introduces the potential for new vulnerabilities that will demand new defences. Bringing the industry together in Kuala Lumpur for our anniversary is the right way to confront challenges head-on and shape what comes next."