AI is spreading quickly through the contact center, from summaries to transcriptions, quality assurance, coaching, analytics, agent assist, bots and customer intent modelling. These tools depend on customer conversation data, but it is crucial that payment data does not drift into AI systems. Once sensitive data enters those environments, compliance becomes harder to control.
As Dan Bloy, Regional Director at SequenceShift, told CX Today, AI might be easy to switch on, but organizations may not fully understand what they are exposing when they do.
“AI has become such a simple technology to enable, but difficult to get value out of. Turning on AI is now just a tick box.”
This simplicity creates a governance problem, because if contact centers add AI without first understanding where payment data sits, they may inadvertently bring systems into the scope of Payment Card Industry Data Security Standard (PCI DSS) regulation, Bloy warned.
Where Payment Data Can Enter AI Systems
There are two clear points in the customer journey where payment data can end up in AI systems. The first is a live customer interaction. For instance, if a bot or AI-enabled service journey is not properly controlled, the customer may enter or disclose payment data inside that interaction.
The second is historical data, as AI tools may be applied to recordings, transcripts and conversation archives for analytics, summarization, agent coaching or customer intent modeling.
“You can turn on AI and just ask the customer, and it can have a conversation, and then inadvertently start to collect PCI data, and therefore it's in all of the debug logs for the AI system, which is vast amounts of data they generate,” Bloy said. “Or it could be in legacy core recordings that the system is now going through and transcribing and pulling them into the model, and then trying to understand customer intent and propensity to buy.”
The concern is where that data goes next.
AI systems can generate logs, create summaries, connect to analytics tools and feed workflows that are not owned by the same team that manages payment compliance, making data mapping essential.
“It's really making sure that you understand what is already in your data and what's going to be added to that dataset as well,” Bloy said.
“Turning it on is simple, but doing it in a compliant fashion needs some thought.”
Governance Cannot Stop After the Proof of Concept
Many AI projects begin with a limited use case, perhaps starting with one customer journey and a small team. But once the AI tool is in place, other teams may start using it, adding new use cases and data sources that create scope creep.
This is where organizations can lose control, Bloy said. “Making sure that there's governance not just at the start of the project, but throughout the lifecycle of the AI is really important.”
This is particularly importance as AI governance becomes more visible, with the EU AI Act pushing more organizations to look at transparency, data use, oversight and risk management.
Contact centers need to know what data AI can access, what it can retain and where human review is required. They also need to know whether payment data is being kept out of the AI environment entirely.
De-Scoping Is the Simplest Control
For Bloy, the most direct question is whether the organization has de-scoped payment data in the first place. If payment data does not enter the organization’s systems, it cannot contaminate downstream AI workflows.
Bloy describes it as a prevention strategy rather than a remediation strategy.




