THREAT INTELLIGENCE | COMPLIANCE
13 min read

PCI DSS 4.0 Penetration Testing in the AI Era: What Changes When AI Finds the Bugs

AI tools like Claude Mythos are reshaping what QSAs expect from penetration testing programs. Here is what actually satisfies PCI DSS 4.0 Requirement 11.4 in 2026.

March 2025
PCI DSS 4.0 full enforcement date for new requirements
Req 11.4
PCI DSS requirement governing penetration testing
10,000+
High/critical findings discovered by Glasswing
CVSS 9.1
wolfSSL CVE-2026-5194, potentially in-scope for PCI environments

SponsoredRetool

Retool's new app builder is where AI-generated code ships safely

Building apps with AI is easy. Getting them to production safely is another story.

Start building for free today

PCI DSS 4.0, published by the PCI Security Standards Council in March 2022 and fully enforced since March 2025, significantly updated penetration testing requirements. Requirement 11.4 mandates annual penetration testing of cardholder data environment (CDE) systems and segmentation controls by qualified resources, with documentation that satisfies QSA review. At the same time, Project Glasswing, Anthropic's coordinated vulnerability disclosure program powered by Claude Mythos, is demonstrating that AI can identify complex vulnerabilities at scale and speed that far exceeds traditional manual pen testing. The collision of these two developments creates urgent questions for compliance teams: where does AI-powered testing fit in the PCI framework, what do QSAs currently accept, and how should a Glasswing CVE notification be handled within a PCI compliance program?

PCI DSS 4.0 Requirement 11.4: What It Actually Says

Requirement 11.4 of PCI DSS 4.0 requires penetration testing at least annually and after any significant infrastructure or application upgrade or modification. The standard requires testing of both external and internal network penetration, application-layer penetration testing for all in-scope applications, and testing of segmentation controls if segmentation is used to reduce the scope of the CDE.

The standard specifies that testing must be performed by a qualified internal resource or qualified external third party. A qualified resource is defined as someone with organizational independence from the systems being tested, specialized penetration testing expertise, and current knowledge of penetration testing techniques. The standard does not mandate specific credentials, but most QSAs look for certifications such as OSCP, GPEN, GXPN, or equivalent demonstrated competency.

PCI DSS 4.0 introduced new requirements in this area: Requirement 11.4.7 (added as a best practice in v4.0, now fully enforced) requires multi-tenant service providers to support their customers' external penetration testing by providing additional context about shared infrastructure. This matters for cloud-hosted cardholder environments where the penetration tester needs visibility into shared network architecture.

What a QSA Reviews in Penetration Test Evidence

When a QSA evaluates penetration testing evidence, they are looking for a defined scope that maps to the documented CDE boundary, a methodology that addresses both network and application layers, evidence that segmentation was actually tested (not just assumed), documentation of all findings including severity ratings and remediation status, and evidence that the tester had the qualifications required by PCI DSS.

The QSA's review of the pen test report typically focuses on whether the scope matches what was depicted in the network diagrams and data flow diagrams the company provided. A common finding is that the pen test scope was narrower than the actual CDE, either because the scoping exercise was inaccurate or because the tester was not given access to the full environment.

QSAs are also looking at the finding severity classifications. A penetration test that returns only low and medium findings for a complex environment is likely to prompt follow-up questions from a QSA, because an adversarial simulation of a real CDE typically identifies at least some high-severity issues if conducted thoroughly.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

Where AI Tools Fit Today

AI-powered security tools fit naturally into two phases of a PCI pen test program where human capacity constraints create gaps: the discovery phase and the vulnerability analysis phase.

In the discovery phase, AI tools like Claude Mythos can enumerate the attack surface far more comprehensively than a human tester working within a time-boxed engagement. An AI system can examine thousands of services, identify non-obvious dependency chains, and cross-reference discovered components against its knowledge of known and zero-day vulnerabilities in a fraction of the time a human team would require. For a large CDE with hundreds of systems, this breadth of coverage is operationally significant.

In the vulnerability analysis phase, AI systems excel at identifying complex vulnerability chains where individual CVEs combine with configuration weaknesses to create exploitable attack paths that neither a vulnerability scanner nor a single human analyst would identify in isolation. Project Glasswing's 10,000-plus high- and critical-severity findings demonstrate this capability at scale: these findings include not just known CVEs but novel vulnerability classes discovered through AI-driven analysis.

For PCI compliance programs, the practical application is using AI-powered tools in the reconnaissance and vulnerability identification phases, then having qualified human testers validate and exploit the most critical findings, with particular focus on the CDE boundary and segmentation controls.

Where Human Testers Remain Required for PCI Compliance

Current QSA practice requires human oversight and attestation for several elements of the PCI penetration test that AI tools cannot fully address. Scope confirmation requires a human to map the actual testing scope against the company's network diagrams and data flow diagrams and attest to their accuracy. This is a business and architectural judgment, not a technical scanning task.

Segmentation testing requires active validation that systems outside the CDE cannot reach cardholder data. This involves manually probing the segmentation controls from designated out-of-scope systems, attempting to traverse the segmentation boundary, and documenting the test methodology and results. QSAs scrutinize segmentation test documentation carefully because inadequate segmentation is one of the most common causes of PCI scope expansion.

Business logic testing for payment applications requires a human who understands payment workflows to attempt to manipulate the application logic in ways that could expose cardholder data or enable fraud. This type of testing requires contextual judgment about how the application is intended to work and creative identification of deviations from that intended behavior.

Finding attestation requires a human qualified tester to attest that the testing was conducted, that the methodology was appropriate, and that the findings represent their professional judgment. QSAs cannot accept an attestation from an automated system.

The Hybrid Model QSAs Accept

Based on current QSA practice, the penetration testing model that satisfies PCI DSS 4.0 while incorporating AI-powered tools follows a staged approach. The first stage uses AI-powered discovery tools to enumerate the attack surface comprehensively, identify all in-scope components, cross-reference against known and novel vulnerability databases, and generate a prioritized finding list. This stage produces output that is far more complete than a purely manual discovery phase.

The second stage involves human penetration testers who review the AI-generated finding list, validate the most critical findings through active exploitation, conduct business logic testing, and perform segmentation validation. The human testers focus their limited time on the highest-value targets identified by the AI discovery phase, which increases the efficiency and coverage of the human testing component.

The third stage produces the QSA-ready documentation: a pen test report authored by the qualified human tester, attesting to the methodology, scope, findings, and their professional judgment about remediation priority. The report may note that AI-assisted tools were used in the discovery phase, but the attestation is from the qualified human.

This hybrid model typically produces better coverage than a purely manual engagement of equivalent duration, at similar or lower cost, while satisfying QSA requirements for human qualification and attestation.

How a Glasswing CVE in Your CDE Changes Your Posture

When a Glasswing CVD notification identifies a critical vulnerability in software present in your CDE, the PCI compliance implications are immediate. The unpatched vulnerability is a finding that the QSA must document, and it will typically be categorized as a high-severity issue that must be remediated or mitigated before the ROC can be completed.

More consequentially, if the vulnerability enables exploitation of a pathway into the CDE that your pen test did not cover, the QSA may require supplemental penetration testing to validate that the vulnerability was not exploitable in your specific environment, or to confirm that compensating controls adequately mitigate the risk.

The wolfSSL CVE-2026-5194 (CVSS 9.1) illustrates this scenario. wolfSSL is an embedded TLS library used in payment terminals, industrial controllers, and network equipment. If wolfSSL is present in systems that connect to or are part of your CDE, CVE-2026-5194 is a potential in-scope finding. The QSA will expect to see either a documented patch (wolfSSL version that includes the fix, applied to all in-scope instances) or a compensating control with documented evidence that it adequately mitigates the CVSS 9.1 risk.

Compensating Controls While Patching

PCI DSS 4.0 permits the use of compensating controls when a required control cannot be met due to legitimate technical or documented business constraints. Compensating controls must provide a similar level of protection to the original requirement and must be documented, approved by a QSA, and re-assessed annually.

For a Glasswing CVE that cannot be immediately patched (because a patch is not yet available, because the affected system is a legacy component that cannot be updated, or because patch testing cycles prevent immediate deployment), a compensating control analysis is the appropriate response.

Effective compensating controls for a high-CVSS unpatched vulnerability in a CDE component might include: network segmentation that prevents exploitation of the vulnerability from external networks; application-layer firewall rules that block the specific attack vectors identified in the CVD notification; enhanced monitoring for indicators of compromise associated with the vulnerability; and accelerated patch testing and deployment timelines with documented approval.

The compensating control documentation must be specific: it must identify the specific vulnerability, explain why the primary control cannot be implemented immediately, describe the compensating control in detail, and attest that the compensating control provides equivalent protection. Generic compensating control language does not satisfy QSA requirements.

QSA Conversation Guide: Positioning AI-Augmented Testing

When briefing a QSA about your AI-augmented penetration testing program, the framing matters. QSAs are not opposed to AI tools; they are concerned about ensuring that required elements of PCI testing are actually performed by qualified humans. Lead with the human attestation, not the AI tooling.

Start with who conducted the testing: a qualified penetration tester with specific credentials who scoped, planned, and attested to the test. Then describe the methodology, including the use of AI-assisted discovery tools in the reconnaissance and vulnerability identification phases. Provide documentation of the AI tooling used and its output, not as the primary deliverable but as supporting evidence.

For segmentation testing specifically, document the human-led testing methodology in detail. QSAs scrutinize segmentation test documentation more carefully than almost any other element of the pen test report, because segmentation failures are a common audit finding.

If a Glasswing CVE was identified during the testing period, include it as a finding in the pen test report with remediation status and timeline. This demonstrates that your testing program captured the relevant vulnerability, which is evidence of testing thoroughness rather than a compliance gap.

PCI DSS AI Testing Framework and QSA Briefing Template

The Mythos Brief provides the practitioner toolkit for implementing a PCI DSS 4.0-compliant penetration testing program that leverages AI-powered discovery while satisfying QSA requirements.

Subscribe to unlock Remediation & Mitigation steps

Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.

The bottom line

PCI DSS 4.0 does not prohibit AI-powered penetration testing tools; it requires human qualification, attestation, and specific test coverage that AI tools alone cannot provide. The compliance-maximizing approach in 2026 is the hybrid model: AI-powered discovery for breadth and zero-day identification, human-led exploitation and segmentation validation for QSA acceptance. When a Glasswing CVE notification arrives for software in your CDE, treat it as a pen test finding that requires remediation or compensating control documentation before your next ROC. For the complete PCI DSS AI testing framework, QSA briefing templates, and Glasswing CVE impact assessment toolkit, visit decryptiondigest.com/mythos-brief.

Frequently asked questions

Does AI pentesting satisfy PCI DSS 4.0 requirements?

AI-powered vulnerability scanning tools, including systems like Claude Mythos, do not by themselves satisfy PCI DSS 4.0 Requirement 11.4. PCI DSS distinguishes between vulnerability scanning (automated, broad) and penetration testing (manual or hybrid, designed to exploit identified vulnerabilities to assess real-world impact). AI tools can substantially augment the penetration testing process by accelerating vulnerability discovery and enabling zero-day identification at scale, but QSAs currently require human oversight for scope confirmation, segmentation validation, and business logic testing. The hybrid model, where AI-powered discovery feeds human-led exploitation and validation, is what most QSAs accept.

What is a QSA and why do they matter?

A Qualified Security Assessor (QSA) is a company or individual certified by the PCI Security Standards Council to conduct PCI DSS assessments. For Level 1 merchants (processing more than 6 million Visa or Mastercard transactions annually), the annual Report on Compliance (ROC) must be completed by a QSA. For other merchants, QSAs conduct the penetration tests that satisfy Requirement 11.4. The QSA's judgment about whether a testing methodology satisfies PCI requirements is binding for assessment purposes, which is why understanding current QSA expectations about AI-augmented testing is operationally critical.

How does a Glasswing CVE affect my PCI scope?

If a Glasswing CVE affects software components within your cardholder data environment (CDE) or in systems that could provide a path into the CDE, it affects your PCI posture in two ways. First, the unpatched vulnerability may constitute a finding that a QSA must document and track to remediation before your ROC can be completed. Second, if the vulnerability enables a network path into the CDE that did not previously exist (or that your segmentation was not designed to block), it may expand your PCI scope by demonstrating that previously out-of-scope systems now have connectivity to the CDE.

Can I use Claude Security for PCI DSS pen testing?

Claude Security and similar AI-powered security tools can be used as part of a PCI DSS penetration testing program, but they cannot replace the human-led testing that QSAs require for full compliance. The appropriate use of AI tools in a PCI pen test program is in the discovery and vulnerability identification phases: AI excels at breadth, speed, and identifying complex vulnerability chains that manual testers might miss. Human testers are then required to validate scope, confirm segmentation controls, test business logic, and produce the attestation documentation that QSAs require.

What is the difference between vulnerability scanning and penetration testing under PCI?

PCI DSS treats vulnerability scanning (Requirement 11.3) and penetration testing (Requirement 11.4) as distinct and complementary requirements, not interchangeable. Vulnerability scanning is automated identification of known vulnerabilities using tools like Tenable, Qualys, or Rapid7. It must be performed quarterly and after any significant change. Penetration testing is active exploitation of identified vulnerabilities to confirm they are actually exploitable and to assess real-world impact. It must be performed at least annually, after significant infrastructure or application changes, and by a qualified internal or external resource. A scan identifies a CVE is present; a pen test confirms that CVE can be exploited to reach cardholder data.

How do QSAs evaluate segmentation testing evidence produced by AI-assisted tools, and what documentation format do they expect?

QSAs scrutinize segmentation testing evidence more carefully than almost any other penetration test component because inadequate segmentation is the most common cause of PCI scope expansion. For AI-assisted segmentation tests, QSAs expect documentation that covers four elements: the test methodology description, including which tools were used and what attack paths were attempted; a network topology map annotated with tested segmentation boundaries and their locations; a log or transcript of attempted segmentation traversal attempts showing the source system, destination system, protocol, port, and outcome (blocked or passed); and the qualified human tester's attestation that the segmentation testing was conducted under their supervision and that the documented results represent their professional judgment. The human attestation is the element AI tools cannot substitute. Organize the documentation with the human tester's signed cover sheet first so QSAs can locate the attestation without reading the full technical appendix. If AI-generated discovery identified a segmentation gap that the human tester then validated by exploiting a traversal path, document both the AI identification and the human validation as distinct steps to demonstrate the hybrid workflow clearly.

Sources & references

  1. PCI DSS v4.0 Standard Document
  2. PCI DSS v4.0 Requirement 11.4 Penetration Testing Guidance
  3. PCI SSC Information Supplement: Penetration Testing Guidance
  4. Anthropic Project Glasswing CVD Program
  5. PTES Technical Guidelines - Penetration Testing Execution Standard

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Black Hat Giveaway

Win a $2,495 Black Hat pass.

Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.

Joins Decryption Digest daily briefing. Unsubscribe anytime.

Giveaway: Black Hat USA 2026 Full-Access Pass ($2,495 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $2,495 Black Hat USA 2026 pass.