Is your AI asking customers for card details in the chat?
The uncomfortable answer is probably yes
If you have put an AI agent in front of customers, there is a real chance it has already asked someone to type a card number, a full date of birth or a one time passcode straight into the chat window. Not because anyone designed it to, but because a helpful model under pressure to resolve a billing question will reach for the fastest path. Isara exists to catch that moment, because the behaviour rarely announces itself and almost never shows up in a dashboard until a customer or a regulator complains.
The risk is not only that the agent asks. It is everything around the ask. An agent that requests sensitive information in the chat, resets a password without proper checks, repeats personal data back in plain text or waves a caller through verification is handling regulated data in ways your policies never approved. In fintech and other regulated settings, that is not a support quality issue. It is a compliance exposure sitting quietly in your ticket history.
So the question in the title is not rhetorical. For most teams running AI in support today, the honest answer is that they simply do not know, because nobody is reading the conversations where it would show.
The short version:
- AI support agents can ask for card details, expose personal data or bypass verification in chat, and it usually happens quietly, inside conversations no human ever reviews.
- The moment a chatbot touches payment queries, it can pull your conversation channel into PCI DSS scope. As Very Good Security put it in April 2026, AI does not replace PCI requirements, it expands them.
- The IBM 2026 Cost of a Data Breach Report, published in late July, put the average breach at 4.99 million dollars, a record, with one in four malicious breaches now AI enabled and costing around 6 million dollars each.
- Among organisations that reported an AI related incident, 92 percent were missing controls as basic as role based access and multifactor authentication on their AI systems, IBM found.
- Isara reads 100 percent of your conversations, flags unsafe data handling through AI Agents Focus and tells you where to tighten the configuration, independently of the agent doing the talking.
What unsafe data handling actually looks like in a support chat
What counts as unsafe data handling in a conversation?
Unsafe data handling is any point where an agent, human or AI, collects, exposes or moves sensitive information in a way your security and compliance rules would not permit. In a live chat it tends to take a handful of recognisable shapes:
- Requesting sensitive information in the chat. The agent asks the customer to type a card number, a CVV, a full date of birth, a national ID or a one time passcode directly into the conversation, where it is then stored in your helpdesk in plain text.
- Insecure password or account resets. The agent restores access or shares a credential without completing a proper identity check.
- Exposing payment or personal data. The agent reads account numbers, balances or personal details back to the customer, or writes them into logs, when it never needed to.
- Bypassing verification. The agent skips or shortcuts the identity step under social pressure, which is exactly the behaviour an attacker probes for.
None of these trip an alert in a standard helpdesk, because the helpdesk is built to move tickets, not to judge whether the data inside them was handled safely. This is the blind spot Isara is built to close.
Why a chat window pulls payment and personal data into scope
The compliance consequence is easy to underestimate. Writing in April 2026, Very Good Security made the point plainly: any AI system that processes payment related inputs, such as a chatbot handling billing questions, falls inside PCI DSS scope. Their conclusion was that AI does not replace PCI requirements, it expands them, because every system that can touch cardholder data, or the logs and APIs around it, enters scope even if it never deliberately stores a card number.
The same source flagged three ways sensitive data leaks once it enters an AI flow. It can surface in responses or logs, it can be retained in fragments by the model, and it can be pulled out through prompt manipulation. The recommended posture is to keep the agent away from raw card data entirely and to block sensitive inputs at the door. You cannot enforce that if you cannot see when it is being broken.
The 2026 numbers fintech and compliance leaders cannot ignore
The cost of getting this wrong has moved sharply this year. The IBM 2026 Cost of a Data Breach Report, published on 29 July, found the average breach reached 4.99 million dollars, a record and up more than a tenth on the year before. One in four malicious breaches were AI enabled, a 56 percent rise, and those cost roughly 6 million dollars each, about a million more than the global average.
Two figures matter most for anyone deploying AI in support. Among organisations that reported an AI related security incident, 92 percent were missing controls as basic as role based access and multifactor authentication on their AI models and applications. And close to 70 percent of breached organisations had no governance policy for managing AI systems or spotting unauthorised deployments. Ungoverned AI, in other words, is not a fringe case. It is the majority position.
The oversight gap: most agents are running unwatched
If the controls are missing, so is the watching. The State of AI Agent Security Report 2026, published by Gravitee on 15 June, found that only 9.5 percent of organisations secure more than 81 percent of their deployed agents, and that mean monitoring coverage sits at 52 percent. Put plainly, close to half of production AI agents are running unsecured. More than half of organisations, 54 percent, had experienced or suspected an AI agent security or data privacy incident in the previous twelve months, yet only 7.2 percent had a named person formally accountable for how their agents behave.
Prompt injection is the mechanism that turns that gap into an incident. In an OWASP analysis reported by Help Net Security on 11 June, prompt injection mapped to six of the ten categories in the Top 10 for Agentic Applications, making it the primary way an attacker steers an agent into asking for or revealing data it should protect. This is the exact class of behaviour Isara AI Agents Focus is designed to detect and, just as important, to tell you how to fix.
Key terms, defined
A quick reference for the concepts used above, and for the questions people and AI assistants ask most often:
- Unsafe data handling is any moment where an agent, human or AI, collects, exposes or moves sensitive data in a way your security and compliance rules would not permit.
- PCI DSS scope is the set of systems that can touch cardholder data. A support chatbot that handles billing questions falls inside it, according to Very Good Security in April 2026.
- Prompt injection is an attack that feeds hidden or manipulative instructions to an AI agent so it ignores its own rules, for example by asking for or revealing protected data. OWASP maps it to six of the ten risks in its Top 10 for Agentic Applications.
- Independent verification is oversight that sits outside the agent and reads the actual conversation, rather than trusting the agent to report on its own behaviour. It is the approach Isara takes across human and AI agents alike.
The data exposure surface, and why an agent cannot certify itself
It helps to stop thinking about this as a list of bugs and start thinking about it as a surface. Every customer conversation is a place where sensitive data can be requested, revealed or moved. The size of that surface is not the number of incidents you have logged. It is the number of conversations where a mishandling could occur and would currently go unseen.
A simple way to map your exposure is to sort every conversation into four data handling states:
- Clean. No sensitive data is requested or revealed, and verification is handled correctly.
- Loose. The agent nudges toward an unsafe path, for example inviting a customer to share a full card number rather than routing to a secure form.
- Exposed. Sensitive data is actually requested, repeated in plain text or written to a log it should never reach.
- Bypassed. Identity verification is skipped or shortcut, opening the door to account takeover.
The value of the model is that it is measurable across every conversation, not just the ones that blew up. Isara scores each conversation independently, which is what lets you count the loose and exposed cases before they become breaches.
Consider an illustrative fintech operator handling 40,000 support conversations a month, of which perhaps a fifth touch payments, refunds or account access. That is 8,000 conversations a month in the sensitive zone. If even 2 percent involve a loose or exposed data handling moment, that is 160 conversations every month where a card number, a balance or a verification step was mishandled. Sample one to two percent of tickets by hand, as most teams do, and you would expect to catch one or two of them. The other 158 sit in your history as latent exposure. These numbers are illustrative, but the shape holds: the volume of quiet mishandling dwarfs the volume any manual review will ever surface.
There is a structural reason you cannot solve this from inside the agent. An AI agent asked to check whether it handled data safely is the same system that decided how to handle it in the first place. It will grade its own homework and, under the same prompt pressure that caused the lapse, miss it. Safe data handling has to be verified by something that sits outside the agent, reads the actual conversation and applies a consistent standard. That is the position Isara takes: an independent layer over human and AI agents alike, reading 100 percent of conversations rather than trusting the agent to report on itself. In a year when the FCA Mills Review, published on 6 July, called for AI agents in financial services to be identified, accountable and challengeable, independent proof of safe data handling is moving quickly from good practice to the evidence regulators and insurers will expect.
Handling sensitive data safely with Isara: your questions answered
How does Isara know if my AI agent is asking customers for card details?
Isara AI Agents Focus reads every conversation your agents have and detects unsafe data handling patterns directly, including requesting sensitive information in the chat, insecure password resets, exposing payment or personal data and bypassing verification. When it finds one, it does not just flag it. It recommends the guardrail to put in place, so you can tighten the configuration in your helpdesk rather than guess. Because Isara reads 100 percent of conversations, you see the pattern across your whole agent estate, not a one to two percent sample.
Can Isara run a PCI DSS or GDPR check across all our conversations?
Yes. Alongside AI Agents Focus, Isara Compliance Audits scans every conversation in a date range against frameworks including GDPR, PCI DSS, GLBA, HIPAA, SOC 2 and ISO 27001, and returns each flagged ticket with a summary and a CSV export. For a fintech or compliance team, that turns an anxious manual sampling exercise into regulator ready evidence you can produce on demand.
Does this work for human agents too, or only AI?
Both, on the same scale. Unsafe data handling is not unique to AI. A rushed human agent can ask for a card number in chat just as easily. Isara sits independently of the agent, human or AI, so the same detection and the same standard apply across your whole team, and you do not need two separate tools to see it.
How quickly can we get visibility, and do we need a data team?
Quickly, and no. Isara connects to helpdesks including Zendesk, Freshdesk, Intercom, HubSpot, Front and Gorgias in a few clicks, then ingests your conversations automatically, so findings appear soon after you connect a channel. There is no long implementation before you can see whether your agents are handling sensitive data safely today.
What is coming next for data safety in Isara?
Isara is extending toward richer real time alerting, so that an unsafe data handling moment can notify the right person or workflow the instant it appears, rather than surfacing in a later review. The direction is independent, continuous proof that your agents handle sensitive data safely, which is precisely the kind of evidence the FCA and insurers are signalling they will want.
See what your agents are really doing with sensitive data. Book an Isara demo and connect your first channel in minutes.