When Formula 1 made the halo device mandatory in 2018, drivers hated it. Nobody wanted a piece of hardware standing between them and the sport they knew. Agentic AI payments are running into the same resistance right now. The hardware this time isn't titanium. It's PCI DSS, and most Australian businesses haven't noticed it's already standing guard.
AI Agents Are Already at Checkout
You've probably typed something like “book me a flight under $400” into an AI assistant. What used to end with you clicking through five checkout screens is starting to end with the AI completing the purchase on its own, without you touching a card number or a form.
This isn't hypothetical for Australian shoppers. In April 2026, Visa launched its Agentic Ready program in Australia, with ANZ, NAB, Bank of Melbourne, BankSA, St. George, Cuscal, ING Australia, Latitude Financial, and Zip signed on as early partners. That's most of the country's major card issuers and several of its biggest buy-now-pay-later players, all building toward the same thing: AI agents initiating payments on a customer's behalf, inside infrastructure Australians already bank with every day.
In the US, Visa reported a 4,700% surge in AI-driven traffic hitting retail sites, and has said 2025 is expected to be the last year people shop and check out entirely alone. Mastercard's answer, Agent Pay, launched around the same time as Visa's Trusted Agent Protocol, both designed to let a merchant tell a legitimate AI agent apart from a fraudulent bot before a transaction completes.
Those protocols solve the identity problem. They don't solve the compliance problem sitting underneath it, and every bank on that Agentic Ready list already answers to one: PCI DSS.
PCI DSS Didn't Wait for Agentic AI to Show Up
The Payment Card Industry Data Security Standard is maintained by the PCI Security Standards Council. Visa, Mastercard, American Express, Discover, and JCB jointly run the body. It is structured around 12 core requirements and applies to any business that stores, processes, or transmits cardholder data. It isn't Australian law, but it doesn't need to be. It's a contractual obligation your acquiring bank and the card networks impose, and every bank named above, ANZ, NAB, and the rest, still requires the merchants it works with to meet it. Visa's Agentic Ready program doesn't replace that requirement. It sits directly on top of it.
The current version, PCI DSS v4.0.1, became fully mandatory on March 31, 2025, after the standard's 51 future-dated requirements moved from “recommended” to “required.” Two of those requirements read almost like they were written with AI agents in mind, years before anyone used that phrase.
Requirement 6.4.3 governs scripts running on a payment page. Requirement 11.6.1 requires detecting unauthorized changes to that page and its security-related headers. Both were written to catch a specific attack: a third-party script quietly skimming card data off a checkout page. An AI agent completing a purchase on a customer's behalf is, from the payment page's point of view, exactly that: a third-party script interacting with checkout in real time. The standard already assumes something other than a human is touching that page. It just didn't know yet, that the something would be a shopping assistant your customer trusts.
Requirement 8.4.2 pushes the same logic on identity, mandating phishing-resistant authentication for remote and privileged access to the cardholder data environment. That's the compliance-side mirror of what Trusted Agent Protocol and Agent Pay are trying to solve on the network side: proving that whoever, or whatever, is at the door is actually who they claim to be.
None of this changes because the transaction happens to originate in Sydney instead of San Francisco. PCI DSS is a global standard, and Australian merchants are held to the exact same 12 requirements as anyone else on the network.
The Scope Question Nobody Has a Clean Answer To Yet
Even before AI agents entered the picture, scope was where most PCI DSS programs quietly failed, and Australian businesses were already feeling the heat of getting the basics wrong. Businesses reported an average loss of $80,850 per cybercrime incident to ASD's Australian Cyber Security Centre last financial year, a 50% jump on the year before, and online shopping fraud was already one of the three most reported cybercrime types among individuals, before a single AI agent ever touched a checkout page.
Add an AI agent to the flow and the questions multiply fast. Does the agent's runtime environment now sit inside your cardholder data environment? Who owns the compliance burden when a token is issued to an agent that a merchant never directly connected to? If an agent's consent policy or spending scope gets misconfigured, whose assessment does that show up in, yours or the AI platform's?
Nobody in the industry has a fully settled answer to any of that yet. So how does a business find out where its own scope sits?
Finding Your Own Halo
This is exactly the kind of ambiguity PCI DSS is designed to force businesses to resolve before an incident does it for them. It's also exactly what StickmanCyber's Compliance & GRC team, based in Sydney and working with Australian and New Zealand businesses since 2006, is built to help with. StickmanCyber is certified by the PCI Security Standards Council as a Qualified Security Assessor, so its assessors can formally validate and certify your compliance against PCI DSS rather than only advise from the sidelines. StickmanCyber is also CREST accredited for Penetration Testing, which matters here specifically: scoping an agentic checkout flow correctly on paper means little if nobody has tried to attack it the way a real adversary would. The same banks now piloting Agentic Ready still expect the merchants behind them to hold a clean PCI DSS assessment, signed off by a QSA, not a generic advisor.
The engagement follows StickmanCyber's Continuous Cybersecurity Resilience Framework: Assess, where the business context, risk landscape, and existing controls are reviewed to establish a baseline. Plan, where findings are translated into a prioritised roadmap aligned to business objectives and resources. Execute, where agreed security improvements are implemented and validated by specialist teams. Maintain, where controls are continuously monitored, tested, and refined as the environment evolves; and Optimise, where outcomes are measured, evidence is gathered, and learnings are fed into the next cycle of improvement.
Rather than treating security as a yearly exercise, the framework creates an ongoing process of assessment, remediation, and continuous improvement
Agentic commerce will keep changing shape as Visa, Mastercard, and the AI platforms iterate on their protocols. A PCI DSS program treated as a one-time certification will fall behind that pace. StickmanCyber's own positioning is built on the same idea driving this whole shift: compliance delivered by humans, backed by AI, not replaced by it.
Know Where Your Scope Actually Stands
- Map exactly where AI agents touch your cardholder data environment
- Gap analysis against PCI DSS v4.0.1's newest requirements
- QSA-backed certification, not just advice
- No hard sell, ever
Book a free consultation and get a clear read of where your PCI DSS scope sits, before an assessor, or an attacker, finds it for you.
