the voice of customer experience technology
Front pagesponsored · SequenceShift
CRM & Data40m · 10:31 BST · 6 min read

As Contact Center AI Grows, Payment Data Needs Boundaries

AI is changing contact center operations, from summaries and analytics to bots and agent assist, but payment data needs firm boundaries before it reaches those workflows. De-scoping PCI data early is the simplest way to keep compliance firmly under control

Close-up of red and white striped barrier tape stretched across a sandy field, with a second line of tape and green shrubs blurred in the background. The SequenceShift logo sits in the lower right corner.

AI is spreading quickly through the contact center, from summaries to transcriptions, quality assurance, coaching, analytics, agent assist, bots and customer intent modelling. These tools depend on customer conversation data, but it is crucial that payment data does not drift into AI systems. Once sensitive data enters those environments, compliance becomes harder to control. 

As Dan Bloy, Regional Director at SequenceShift, told CX Today, AI might be easy to switch on, but organizations may not fully understand what they are exposing when they do. 

“AI has become such a simple technology to enable, but difficult to get value out of. Turning on AI is now just a tick box.” 

This simplicity creates a governance problem, because if contact centers add AI without first understanding where payment data sits, they may inadvertently bring systems into the scope of Payment Card Industry Data Security Standard (PCI DSS) regulation, Bloy warned. 

Where Payment Data Can Enter AI Systems 

There are two clear points in the customer journey where payment data can end up in AI systems. The first is a live customer interaction. For instance, if a bot or AI-enabled service journey is not properly controlled, the customer may enter or disclose payment data inside that interaction. 

The second is historical data, as AI tools may be applied to recordings, transcripts and conversation archives for analytics, summarization, agent coaching or customer intent modeling. 

“You can turn on AI and just ask the customer, and it can have a conversation, and then inadvertently start to collect PCI data, and therefore it's in all of the debug logs for the AI system, which is vast amounts of data they generate,” Bloy said. “Or it could be in legacy core recordings that the system is now going through and transcribing and pulling them into the model, and then trying to understand customer intent and propensity to buy.” 

The concern is where that data goes next. 

AI systems can generate logs, create summaries, connect to analytics tools and feed workflows that are not owned by the same team that manages payment compliance, making data mapping essential. 

“It's really making sure that you understand what is already in your data and what's going to be added to that dataset as well,” Bloy said.  

“Turning it on is simple, but doing it in a compliant fashion needs some thought.” 

Governance Cannot Stop After the Proof of Concept 

Many AI projects begin with a limited use case, perhaps starting with one customer journey and a small team. But once the AI tool is in place, other teams may start using it, adding new use cases and data sources that create scope creep. 

This is where organizations can lose control, Bloy said. “Making sure that there's governance not just at the start of the project, but throughout the lifecycle of the AI is really important.” 

This is particularly importance as AI governance becomes more visible, with the EU AI Act pushing more organizations to look at transparency, data use, oversight and risk management. 

Contact centers need to know what data AI can access, what it can retain and where human review is required. They also need to know whether payment data is being kept out of the AI environment entirely. 

De-Scoping Is the Simplest Control 

For Bloy, the most direct question is whether the organization has de-scoped payment data in the first place. If payment data does not enter the organization’s systems, it cannot contaminate downstream AI workflows. 

Bloy describes it as a prevention strategy rather than a remediation strategy. 

“The best strategy is one not to cure the problem, but to not even have the problem in the first place.” 

CX, IT and compliance leaders do not want to retrofit governance controls every time a new AI tool is deployed; they need boundaries that reduce the risk before data flows into the wrong place. 

“If you're not having to collect PCI data, then all your downstream systems and processes are never going to be polluted, so they don't have to be considered for PCI.” 

Some contact centers still rely on pause and resume, where the recording pauses when the customer enters payment data, then resumes when the payment step is complete. While this can reduce exposure, it can also remove useful context from the interaction. 

Bloy explained the trade-off: “If you're employing a strategy of pause and resume, you're pausing at the point of entering the payment journey, and then resuming the call recording at the end of that payment journey. But there could be conversations during that journey that the AI agent needs context for. If you're doing that, then you're losing the benefit of AI.” 

There are tools that can detect sensitive information in text or audio, but they are not 100 percent accurate and still require manual review before data is used for AI training or analytics. 

This is why the first audit question should be practical. Where is payment data today? Is it in datasets now being considered for AI? If the answer is unclear, the business has work to do before expanding AI further. 

Bloy warned that historical data with potential PCI exposure makes large-scale analytics much harder. 

“It's going to be much more difficult to do big data analytics on a set of your data that has got potentially PCI data in there, without different processes to make sure you're not exposing the AI tool to the PCI scope.” 

The first step is to understand the data foundation before AI scales too far. 

“Understand the data that you're collecting today, and have a strategy for that,” Bloy explained. “If you are collecting personal information in a business process, or you are collecting payment data in a business process, have you employed the strategies to securely collect that data, using the tools and the processes that are available in the industry, like outsourcing of PCI data processing.” 

Bloy warned that a large, complex AI system will likely stop delivering the value the business expects. “Otherwise, your AI system is going to grow and grow and grow and become a big monolith platform to manage [it will] get bogged down with governance and compliance, and not really drive the business value you're looking for.” 

The alternative is to keep the context of the conversation available while outsourcing the PCI-sensitive payment processing. 

“Not needing the ability to pause and resume, and outsourcing the PCI compliance means that AI's got the full context without exposure,” Bloy explained. 

Dmitri Muntean, Managing Director at SequenceShift, noted that outsourcing specialist compliance processes where appropriate has been a long-standing approach for organizations that want to reduce exposure. 

By using SequenceShift to process payments, organizations can minimize the amount of sensitive data they hold and the number of systems that can access it. 

For contact centers adopting AI, the safest approach is to understand what data already exists, stop sensitive payment data entering AI workflows in the first place and build governance that lasts beyond the first proof of concept.

The discussion0 takes · attributed & checked

Does this reflect your experience?

opening the room…
Read nextordered by techtelligence · every pick explained
more from SequenceShift · sponsored

Five Signs Your Payment Journey Is Losing Customers

22 Sept 2026
same beat · CRM & DataWhy Claudeforce Indicates CRM Complexity Is Breaking Customer Experience23 Sept 2026same beat · CRM & DataOptimove AI Is Betting Big on Agentic Marketing. Most CRM Teams Aren’t Ready22 Sept 2026