October 9, 2026 · 7 min read · pcidss.ae

PCI DSS Scope for Agentic Commerce: Agent Tokens, Delegated Credentials and Your CDE

How AI agents, agent tokens and delegated credentials affect PCI DSS scope. A reasoned scoping model for UAE merchants and PSPs while PCI SSC guidance catches up.

PCI DSS Scope for Agentic Commerce: Agent Tokens, Delegated Credentials and Your CDE

PCI SSC has not published guidance specific to AI agents making card payments, so PCI DSS scope for agentic commerce still follows the old rule. Any system that stores, processes or transmits cardholder data, or can affect its security, is in scope. The practical question is whether your agent ever sees a raw PAN. If it only carries network or agentic tokens, scope can stay small.

Everything below is our reasoned reading of PCI DSS v4.0.1 applied to new payment flows. It is not official Council guidance, because there isn’t any yet on this topic. Treat it as a starting point for the conversation with your QSA and acquirer, not a substitute for it.

Has PCI SSC published anything on AI agents and payments?

Some AI guidance, yes. Agentic payment guidance, not yet.

  • September 2026: the Council published an information supplement, Security Considerations for AI Systems. It covers how organisations deploy AI, defending against malicious use of AI, and how AI fits PCI scoping. The headline line for scoping: AI should be considered no different from any other form of technology when scoping PCI requirements.
  • 8 October 2026: the Council announced additional guidance on securing AI in payment environments, developed with its Global Executive Assessor Roundtable and Board of Advisors. It is explicitly not a mandatory requirement, and the standard takes precedence where they differ.
  • 20-22 October 2026: the PCI SSC Europe Community Meeting in Edinburgh lists sessions including “AI Agents and Emerging Risks in the Cardholder Data Environment” and “Human vs. Machine: Rethinking Security, Compliance, and Accountability”.

None of these, as far as we can find, tells you how to scope an agent holding a delegated card credential. That gap is what this post is about.

What are agent tokens and delegated credentials?

The card networks have converged on a similar idea: the agent never holds your card number. It holds a token tied to that agent, created with the cardholder’s consent.

  • Visa describes AI agents setting up a new payment token on the cardholder’s behalf, with Visa Payment Passkeys used to authenticate the cardholder at that moment. Its Agentic Ready programme is built on this.
  • Mastercard issues Agentic Tokens through Agent Pay, again tokenized credentials registered for a specific agent.
  • Checkout protocols such as ACP and AP2 pass a scoped payment credential or a signed mandate rather than a PAN. Our sister practice covers the mechanics in its AP2 protocol guide and agentic payment protocols comparison.

Then there’s the messy reality: plenty of “agents” today are just browser automation filling in a checkout form with a stored card number. Those are a completely different scoping story.

How does each agentic payment pattern affect your CDE?

Here’s the scoping model we use. Read “in scope” as “likely in scope, confirm with your QSA”.

PatternDoes the agent stack touch PAN?Likely scope impact
Agent fills a merchant checkout form with a raw card numberYesAgent runtime, browser automation, logs, and possibly the model provider all handle PAN. Large scope expansion.
Agent holds a network or agentic token from a card network TSPNoAgent platform usually outside the CDE. Token store and payment API credentials need strong controls.
Merchant receives a scoped payment credential via a checkout protocol and charges it through its PSPNo (merchant side)Similar to accepting any tokenized payment. Merchant payment pages and integrations stay in normal scope.
Agent calls a tool that charges a stored card on fileNot directlyTool, its API keys and its authorization logic can affect CDE security. Treat as security-impacting.
Users paste card numbers into a chat agentYes, unintentionallyChat logs, traces, vector stores and LLM provider become in scope unless you detect and block PAN at input.

The last row catches more teams than any other. A support or shopping agent that never “handles payments” by design can still end up with card numbers in its conversation history, observability traces and fine-tuning datasets. Once that happens, every system those records flow through is handling cardholder data, whether or not anyone designed it to. The cheapest fix is at the front door: detect PAN-shaped input and redact it before it reaches the model or the logs.

Do agent tokens actually take you out of scope?

Mostly, with one caveat that matters. A network token is not a PAN, so holding one is not storing cardholder data. That’s the same logic that makes payment tokenization the strongest scope-reduction tool most UAE merchants have.

The caveat: PCI SSC’s long-standing tokenization guidance distinguishes high-value tokens, ones that can be used like a PAN to generate transactions, and warns they may remain in PCI DSS scope even though they can’t be reversed into card data. Agentic tokens are built to initiate payments. Network-side controls (agent binding, spend limits, cardholder authentication) reduce the damage a stolen one can do, but we’d still treat the token vault and the credentials that can spend from it as high-value assets with access control, logging and change management.

Which PCI DSS requirements bite hardest for agentic checkouts?

If you only have time to look at a handful, start here.

  1. Requirement 3, stored account data. Make sure PAN and sensitive authentication data never land in prompts, model context, traces, evaluation datasets or embeddings. Add PAN detection and redaction at the input layer.
  2. Requirement 8.6, system and application accounts. Agents act through service accounts and API keys. Inventory them, restrict interactive use, and rotate credentials as v4.0.1 expects.
  3. Requirement 10, logging. Log what the agent did, which token it used, and the cardholder consent or mandate it acted on. You’ll want this for disputes as much as for the QSA.
  4. Requirement 12.8, third-party service providers. Your LLM provider and agent platform are TPSPs if they can touch card data or affect its security. Know which, and get the responsibility split in writing.
  5. Requirements 6.4.3 and 11.6.1. If agents interact with your payment pages, the script inventory and tamper detection still apply. Agent traffic doesn’t change who is responsible for the page.
  6. Requirement 12.5.2, scope confirmation. Adding an agentic checkout is a significant change. Re-confirm and document scope, rather than waiting for the annual cycle.

How should you document agentic scope until guidance arrives?

Write it down, then get agreement from the people who accept your compliance. Concretely:

  • A data flow diagram showing exactly where PAN, tokens, mandates and consent records travel, including the model provider and observability tools.
  • A short scoping rationale per component: in scope, connected-to, security-impacting or out of scope, and why.
  • Acquirer agreement. The August 2026 revision of FAQ 1331 made the point clearly in a related context: applicability decisions belong with your compliance accepting entity, not just you and your QSA. We cover that change in PCI FAQ 1331 Revised.
  • A review trigger for when PCI SSC publishes agentic-specific guidance, so your rationale gets checked against it rather than silently going stale.

For UAE banks and PSPs, add a column for CBUAE expectations. The Central Bank’s client-side and consumer protection rules don’t pause because a purchase was agent-initiated.

Book an agentic payment-flow PCI scoping workshop

If you’re building or accepting agent-initiated payments, the cheapest time to get scope right is before the first transaction. Our agentic payment-flow PCI scoping workshop is fixed-scope: we map your agent, token and checkout flows end to end, classify every component against PCI DSS v4.0.1, flag where PAN can leak into prompts or logs, and hand you a written scoping rationale you can take to your QSA and acquirer.

It pairs naturally with our payment tokenization advisory and PCI DSS gap analysis. Get in touch to set up a session, ideally before the Community Meeting news cycle turns this into everyone’s urgent question.

Frequently Asked Questions

Has PCI SSC published guidance on AI agents making payments?

Not specifically, as of 9 October 2026. The Council published an information supplement on security considerations for AI systems in September 2026 and announced additional AI guidance on 8 October 2026. Both treat AI as technology to be scoped like any other. Neither, as far as we can find, addresses agent-initiated card payments or agent tokens directly.

Is an AI shopping agent in PCI DSS scope?

It depends on the data flow. If the agent, its tools, its logs or its model provider ever store, process or transmit a full PAN or sensitive authentication data, those components are in scope. If the agent only handles a network token or agentic token that cannot be turned back into a PAN, it is usually outside the CDE, though it may still be connected-to or security-impacting.

Do agent tokens like Mastercard Agentic Tokens remove PCI DSS scope?

They reduce it, they don't erase it. A network token is not a PAN, so an agent holding one is not storing cardholder data. But a token that can initiate payments is valuable to an attacker, and PCI SSC's tokenization guidance notes that high-value tokens may remain in scope. Treat token storage and use with strong access control and logging.

What PCI DSS requirements matter most for agentic checkouts?

Requirement 3 (never let PAN land in prompts, traces or vector stores), Requirement 8.6 (manage the system and application accounts your agents use), Requirement 10 (log what agents did and on whose authority), Requirement 12.8 (manage the AI and agent platforms as third-party service providers), and 6.4.3 and 11.6.1 if agents interact with your payment pages.

When will PCI SSC issue agentic commerce guidance?

There is no announced date. The PCI SSC Europe Community Meeting in Edinburgh on 20-22 October 2026 includes a session titled 'AI Agents and Emerging Risks in the Cardholder Data Environment', which is a signal the topic is on the Council's agenda. Until something is published, scoping is your reasoned analysis plus your acquirer's agreement.

Start Your PCI DSS Journey

Book a free 30-minute compliance discovery call with our PCI DSS specialists in Dubai. We assess your current posture and identify the fastest path to compliance - actionable findings in days.

Every engagement is scoped by our principal architect, Adrian Vale: 20+ years in production engineering, 40+ professional certifications. Meet Adrian

Talk to an Expert