White Paper · For Payments Leaders
Payments Set the Gold Standard for Security. AI Just Moved the Bar.
PCI, EMV, tokenization: payments built the strongest data-security architecture in commerce. It was designed for human attackers and human readers. Rogue AI agents are neither.
01The industry that taught everyone else how to protect data
No industry has done more for data security than payments. PCI DSS made cardholder data protection auditable. EMV killed counterfeit card fraud at the terminal. Network and vault tokenization got the PAN out of merchant systems entirely. When other industries want to explain data protection, they reach for your vocabulary.
It worked because the whole architecture was aimed at one thing: keep the card number safe from human attackers, in the systems built to carry it. The stakes have not gotten smaller.
Now the board wants AI in the operation, employees are already using it on their own, and the adversary is changing species. Everything the gold standard was built on deserves a re-evaluation, not because it failed, but because its assumptions were written before AI agents existed.
02What the gold standard assumed
03Hole 1 · Attackers now operate at AI speed, and you are a first-tier target
In late 2025, Anthropic disclosed that it had disrupted the first reported large-scale cyber-espionage campaign orchestrated by an AI agent. A state-sponsored group used an agentic AI to run 80–90% of the attack autonomously, from reconnaissance and exploit development through credential harvesting and exfiltration, against roughly thirty organizations including financial institutions, at thousands of requests per second.
Every SOC response loop assumes attacks unfold at the tempo of scarce human labor. That economics just inverted, and few targets are worth more to an automated attacker than a payments company. Hardening the perimeter does not change the arithmetic. Having less worth stealing on the other side does.
04Hole 2 · Your disputes queue is attacker-authored content
The lethal trifecta for agentic AI is private data, untrusted content, and the ability to communicate externally. Most industries have to imagine how untrusted content might reach their agents. In payments it arrives on schedule: chargeback evidence, dispute narratives, merchant applications, and support emails are written by outside parties and delivered straight into the workflows your teams process all day. Any AI that helps work those queues is reading attacker-reachable text next to sensitive data, with a send button nearby. Permissions do not help, because permissions assume the authorized session behaves. A prompt-injected agent makes authorized reads, through granted access, for someone else's purpose.
05Hole 3 · Shadow AI is already inside the operation
78% of AI users bring their own AI tools to work, and IBM now finds one in five data breaches involves shadow AI, adding roughly $670K to the average breach cost. In a payments company that looks like a support rep pasting a merchant's banking details into a free chatbot to draft a response, or an ops analyst uploading a settlement file to "just get it summarized." A ban moves this to personal phones and home computers, where nothing is logged. The fix is not a tighter ban. It is a sanctioned door that works better than the shadow tools.
06You already invented the answer
The defense that works against a persuadable reader already exists. Your industry built it twenty years ago: tokenization. The PAN never sits in merchant systems; a worthless stand-in does, and the real number resolves only inside a controlled vault at an authorized moment.
RedactSure applies that exact model to the age of AI, and to every field, not just the card number. Names, bank accounts, merchant financials, and KYC details are replaced with consistent stand-in tokens at the screen layer, before any model reads them. Real values resolve only on approved destinations, at the moment of action. A perfectly executed prompt-injection attack exfiltrates MERCHANT_001 and ACCT_001. Nothing to sell, nothing to report.
07Where sanctioned AI co-workers earn their keep
The reason to close these holes is not defense alone. The administrative middle of a payments company is work AI does well, once it can be trusted near the data:
- Merchant onboarding and underwriting prep. Assemble the application file: KYC documents, business verification, web presence, processing history. The underwriter makes the risk decision.
- Chargebacks and disputes. Pull the transaction record, gather the evidence, draft the representment in the format each network wants. A named person approves every submission. At 337 million chargebacks a year industry-wide, this queue alone justifies the pilot.
- Settlement and reconciliation exceptions. Match the break across processor reports, bank statements, and the ledger, then propose the entry for approval.
- Fraud-queue triage. Assemble the context an analyst needs: history, linked accounts, device data, prior cases. The analyst makes the call. Consistency here is fraud caught by default.
- Merchant support. Draft responses grounded in the merchant's actual account state, with every sensitive value masked from the model. Staff review and send.
- Residuals and partner commissions. Reconcile ISO and agent payouts across processor statements, the kind of monthly grind that eats an ops team.
- Regulatory and compliance reporting prep. Gather, cross-check, and draft. Compliance officers review and file.
Every workflow runs in one sanctioned environment with a complete audit trail: which user, which model, what was redacted, what was approved, exportable to your SIEM and holding tokens rather than merchant data. Employees get AI that actually works, so they stop routing around you. Corral first, automate second.
08Where to start
One queue, one team, one quarter. Disputes and reconciliation exceptions are the proven candidates: the volume is daily, the hours are measurable, and the approval stays with your people. Baseline in week one, then take three numbers to the board: hours returned, shadow-AI attempts redirected, and sensitive-data exposure events, which should read zero with the audit trail to prove it.
Bring your hardest questions.
A thirty-minute architecture conversation with the founders: threat model, token design, egress paths, audit schema. We come with diagrams, not a pitch deck.
Book the architecture review →Sources
- Nilson Report, "Card Fraud Losses Worldwide — 2024" — $33.41B in 2024; $407.6B projected cumulative losses 2024–2034.
- Mastercard chargeback volume estimate, via Chargebacks911 chargeback statistics — 337 million chargebacks projected globally in 2026.
- Microsoft & LinkedIn, Work Trend Index — 79% of leaders say AI adoption is critical to competitiveness; 78% of AI users bring their own tools.
- Anthropic, "Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign" (November 2025).
- IBM, "Cost of a Data Breach Report 2025" — shadow AI involvement in breaches and incremental cost.
- OWASP, "LLM01:2025 Prompt Injection".