Artificial intelligence is changing how payments are made — and increasingly, how they are attacked.
That tension will take center stage in Kuala Lumpur this November, when banks, payment service providers, retailers, technology companies and cybersecurity professionals gather for the PCI Security Standards Council’s (PCI SSC) Asia-Pacific Community Meeting 2026.
The two-day event, scheduled for November 11-12 at the Mandarin Oriental Kuala Lumpur, will mark the PCI SSC’s 20th anniversary while examining how payment security needs to evolve as AI becomes more deeply embedded in the financial ecosystem.
Held under the theme “Celebrating 20 Years of Progress – and Shaping the Future of Payment Security,” the event comes as payment fraud and cyber threats become increasingly sophisticated, with AI giving attackers new ways to automate, adapt and scale their operations.
For an industry built on trust, the challenge is no longer simply protecting payment data. It is keeping pace with technologies that can change the nature and speed of both transactions and attacks.
AI creates a new payment security challenge

Since its establishment in 2006, the PCI SSC has developed standards and programs aimed at helping organizations protect payment data and reduce the risk of cyberattacks and breaches.
Its 20th-anniversary meeting in Kuala Lumpur will look at how those security principles need to adapt to an increasingly automated payments environment.
Among the issues on the agenda is the rise of autonomous AI systems and AI agents, which can make decisions and execute tasks with limited human intervention.
One session, “AI Agents and Emerging Payment Threats in the Cardholder Data Environment,” will examine the new risks these systems could introduce and how businesses can balance rapid technological adoption with security.
Another session, “Trust, Scalability and the Future of Payments in an Autonomous World,” will explore how the industry can maintain trust and security as machines take on a greater role in payment processes.
The meeting will also examine how AI and automation can be used defensively, including through automated data collection, analysis and governance to provide organizations with more timely insights into their security and compliance posture.
From compliance to business resilience
The discussions will extend beyond AI.
The event will cover recurring payment vulnerabilities, security across the increasingly interconnected global payments ecosystem, regional cybersecurity approaches and emerging strategies for managing security risks.
A session on “Turning PCI Standards into Business Value” will also look at compliance from a broader business perspective, focusing on how security investments can support resilience and growth rather than being viewed solely as a regulatory or operational cost.
The program will feature regional case studies, including examples from India on developing a national approach to strengthening cyber resilience and defending against emerging threats.
Building trust beyond technology

The event’s keynote will be delivered by Dr. CJ Meadows, head of the Innovation and Entrepreneurship Center at S P Jain School of Global Management and a specialist in emerging technology, creativity, human behavior and the future of work.
Her keynote, “Thinking Beyond Technology to Build the Next 20 Years of Trust,” will explore the role of human behavior, creativity and responsible innovation in shaping the next phase of digital transformation.
The focus reflects a broader challenge facing the payments industry: technology alone cannot guarantee trust.
As payment systems become more automated and interconnected, organizations will need to consider not only whether new technologies work, but whether they can be deployed responsibly and securely.
PCI SSC looks ahead after two decades
For PCI SSC Executive Director Gina Gobeyn, the anniversary provides an opportunity to look back at the organization’s contribution to payment security while preparing for a fundamentally different threat environment.
“Security and trust are inseparable in payments,” Gobeyn said.
“For 20 years, the PCI SSC has helped the industry stay ahead of evolving threats to payment security. Artificial intelligence is now one of the defining challenges of this next chapter,” she added.
Gobeyn said AI presents opportunities for the payments industry but also creates potential vulnerabilities that will require new defenses.
“Bringing the industry together in Kuala Lumpur for our anniversary is the right way to confront challenges head-on and shape what comes next,” she said.
The Asia-Pacific Community Meeting will take place on November 11-12, 2026, at the Mandarin Oriental in Kuala Lumpur, Malaysia.
The event is expected to bring together stakeholders from across the payments ecosystem as the industry considers what the next 20 years of payment security could look like.
For organizations operating in a region where digital payments continue to expand, the conversation comes at a critical time: the faster payments evolve, the faster security must evolve with them.
Registration and the full event agenda are available through the PCI SSC event website.
About the PCI Security Standards Council
The PCI Security Standards Council (PCI SSC) leads a global, cross-industry effort to strengthen payment security through industry-driven, flexible and effective data security standards and programs designed to help businesses detect, mitigate and prevent cyberattacks and data breaches.
More information is available through the PCI Security Standards Council.
