Payment Technology23 July 20267 min read

Conversational AI Payments: How We Keep Cards Out of AI

We just launched Conversational & AI Payments. Here's what the category actually is — and how an AI agent takes a card payment without the card details ever reaching the AI.

Conversational AI Payments: How We Keep Cards Out of AI

On 15 July we launched something we'd been working towards for a long time: a way for an AI agent to take a card payment without the card details ever reaching the AI. The product is called Conversational & AI Payments, it's built on our Capture Assist API, and the full announcement is on our news page — Finextra covered the launch too. This post isn't the press release, though. It's the conversation we've been having with customers for the past year, written down: what conversational AI payments actually are, why the payment step has quietly become the riskiest part of every AI deployment, and how the isolation model that fixes it works.

What conversational AI payments actually are#

The term sounds grander than the thing it describes. A conversational AI payment is a payment taken inside a conversation that an AI agent is running — a voicebot answering the phone, a chatbot on your website, an assistant inside a messaging thread. The customer never leaves the conversation. They aren't transferred to a human, they aren't told to check their email for a link, and they don't get parked in an IVR queue at the exact moment they were ready to pay.

That last part matters more than it sounds. AI agents have got genuinely good at conversation. They book, they reschedule, they answer questions, they even sell. Then they reach the payment step and the experience collapses, because until now there were only two ways to finish the job: hand the customer off to something that isn't the bot, or let the bot take the card details itself. The first throws away the experience the AI was bought for. The second is the problem nobody had properly solved.

The problem nobody had solved#

If a customer reads a card number to a voicebot, or types it into a chat window, that number passes straight through the language model's context window. From there it can leak into the call recording, the chat transcript, the prompt-and-response logs that every AI platform accumulates by default, and potentially into training data. Businesses are putting AI agents on the phone and in chat faster than their compliance teams can keep up, and this is happening quietly inside a lot of those deployments right now. Nobody designed it that way. It's just where the data goes when nothing stops it.

PCI DSS doesn't make an exception for software that sounds friendly. If a system stores, processes, transmits or can affect the security of cardholder data, it's in scope — and an AI agent that hears or reads a card number does all of those things at once. The PCI Security Standards Council made the point itself in the AI principles it published in May 2025: AI systems in payment environments must comply with the standard like everything else. There's no AI carve-out, and there isn't going to be one.

So a team shipping an AI agent faced a choice between two bad options. Pull the AI into PCI scope and harden it — isolate the inference environment, audit every vendor in the stack, treat every model update as a compliance event. That works, but it's expensive, slow, and fragile under change, because AI stacks change constantly. Or break the conversation at the payment step and hand off, which is the thing conversational AI was supposed to end. The third option — keep the customer in the conversation and keep the card out of the AI — didn't exist. That's what we built.

How the isolation model works#

When the agent reaches the payment step, it calls Capture Assist. Think of it as the bot pressing pause on its own lane. The customer enters their card on our hosted form, or keys it on their telephone keypad if the conversation is a call, inside a capture zone that's fully isolated from the AI — separate infrastructure, separate network, separate logs. We process the payment on our PCI DSS Level 1 SecureFlow platform, then hand the bot back a token and a result. The conversation picks up exactly where it left off. No transfer, no email, no dead air while somebody finds a payment link.

The word doing the work in that paragraph is isolated. The card number never enters the model's context window, so it can't appear in the transcript, the logs or the recording, because it was never in the material those things are made from. The AI vendor never sees it. Neither does the business running the bot. We hold it, briefly, inside a platform we've kept at PCI DSS Level 1 — the highest tier of the standard — through every revision since 2016, with Cyber Essentials Plus alongside. We've processed more than £400 million this way since 2020.

The boundary is architectural rather than procedural, and that distinction is worth sitting with for a moment. A procedural control says the bot promises not to log the card. An architectural one says the card physically never reaches anything the bot could log. Swap the model, retrain it, change AI vendor entirely — the compliance posture doesn't move, because the boundary was never inside the AI stack to begin with. Our AI payment security page walks through the architecture in more detail, but the one-line version is that we draw a hard line around the card and the AI never crosses it.

Phone and chat work differently under the hood#

On a phone call, we connect over SIP in one of two ways. For total isolation, we sit in front of the bot, so every call passes through us and the capture zone is always in place. Or we conference in on demand: when a payment is due, a unique call ID in the SIP header triggers capture, we join the call, take the card by keypad, and drop back out. The mechanism doing the heavy lifting on voice is DTMF masking, the same technique we've run for human agents for years — the customer keys the card, the keypad tones are intercepted before they reach the agent side of the call, and the digits route straight to the payment platform. The AI hears nothing worth hearing.

In chat, capture runs through Advanced Payment Links. The bot hands the customer a secure capture step inside the conversation, the customer enters their card there rather than in the chat box, and the bot receives the token and result when it's done. Different transport, same line in the sand.

Either way, it works alongside the platforms teams are already building on. We're not asking anyone to rip out their AI stack or rebuild their agent around us — the bot calls an API at the payment step and carries on. And if you're already a Paytia customer, turning it on is a configuration change rather than a new contract.

Contact centre agent at a workstation wearing a headset, in the kind of environment where AI voice agents now handle the front of the call

It isn't only card numbers#

Cards are where the compliance pressure is sharpest, but they're not the only sensitive thing an AI agent gets asked to collect. The same isolation covers bank account details, passport numbers and national insurance numbers — any sensitive data the process needs to capture. A bot verifying identity before an account change has no more business holding a passport number in its logs than it has holding a card number, and the pattern that protects one protects the other. The Capture Assist page covers the wider sensitive-data side if that's the part of the problem you're staring at.

What this means for a compliance team#

The service is backed by a Data Protection Agreement. We act as the appointed data processor, with defined terms for how sensitive data is captured, retained and deleted. Card data is never logged and never used to train models — ours or anyone else's. When an assessor asks what the AI can see, the answer is short and architectural: nothing, and here's the diagram. That's a much better afternoon than walking a QSA through forty slides of compensating controls wrapped around a language model.

If you're weighing up where AI genuinely helps a payment operation and where the hype falls apart, our guide to AI in payments in 2026 covers the wider landscape — fraud scoring, routing, voice agents and the rest. This post is the deep cut on the one problem that guide flagged as the hard one. The human-agent baseline it all sits on is covered in our piece on PCI compliance for telephone payments, and if the transcript-and-recording angle is what worries you, our call recording compliance guide is the place to start — AI transcripts are the new call recordings, and the same logic applies. For the mechanics of keeping card data out of an audio path altogether, there's our explainer on DTMF masking and PCI compliance.

Where this goes next#

We think conversational AI payments stop being a category and just become how payments in conversations work. The direction of travel is obvious: more of the first contact a customer has with a business is going to be with an agent that isn't human, and money changes hands in a lot of those conversations. The businesses that get this right early won't be the ones with the cleverest bots. They'll be the ones whose bots never had to be trusted with a card number in the first place.

Conversational & AI Payments is available now — the product page has the detail, and if you'd rather see it take a payment mid-conversation than read about it, book a demo and we'll show you.

The Paytia solution

If you're reading this, here are the Paytia solutions that solve it.

Related Articles

Ready to take secure payments?

Book a demo with our team. We'll show you DTMF masking live, talk through PCI DSS scope reduction, and put together pricing based on your call volume.

PCI DSS Level 1
Cyber Essentials Plus

Trusted by law firms, insurers, healthcare providers and regulated businesses worldwide. Learn more about Paytia