The safest card payment is one the AI never touches
PCI scope follows card data. So the right design is not an AI that guards card numbers carefully - it is one that never receives them, while still doing everything either side of the payment.
The instinct when a voice agent needs to take money is to ask whether the platform is certified. The more useful question is where the card number goes. If it reaches the agent, it reaches the audio, and probably the recording and the transcript, and now the whole platform is inside your cardholder data environment. If it never reaches the agent, none of that is true and there is nothing to secure, prove or delete.
Four ways to take the money
All four keep the card outside the voice platform. Which one fits depends on your payment provider and your callers.
Payment link during the call
The agent confirms the amount, sends a link by SMS or email while the caller is still on the line, and waits for the confirmation to come back. The card details go straight to your payment provider. The simplest option, and the right default for most businesses.
Masked keypad entry
The caller types the card number on their keypad. The tones are suppressed before they reach the agent and before they reach any recording, so the digits exist only between the caller and the payment provider. Nothing to redact afterwards, because nothing was captured.
Pause and resume recording
Recording stops automatically before the payment step and restarts after it, driven by where the conversation is rather than by anyone remembering. The audit trail shows the pause, which is what a reviewer wants to see.
Handoff to a hosted payment step
For higher-value or regulated flows, the call is passed to your payment provider's secure step and control returns to the agent once the result is known. The agent never sits in the path the card data travels.
Nothing lands in the transcript
Card numbers, expiry and security codes are never written to the transcript, the summary, the CRM note or the logs. The transcript records that a payment was taken and what for, which is the part your team actually needs.
The agent still does the work around it
Verifying who is calling, finding the invoice, confirming the amount, taking the payment result, sending the receipt and updating the record. The payment step is a few seconds in the middle of a call that is otherwise entirely automated.
What a payment call actually looks like
Before the payment
The agent identifies the caller, finds the invoice or the booking, states the amount and what it is for, and confirms the caller agrees to pay it now.
The payment step
A link goes out, or the caller types on the keypad with the tones masked, or the call passes to the secure step. Recording pauses automatically for the duration.
After the payment
The agent takes the result, says whether it went through, sends the receipt, updates the record, and carries on with the rest of the call.
Where this earns its keep
Payment on the call matters most where the alternative is a callback that never happens. An overdue balance, a deposit that holds an appointment, a renewal that lapses next week: each of those is a call where the money is collected in the same minute the customer agrees to pay, or it is not collected at all.
This connects directly to the recovery work on AI payment reminder calls and accounts receivable calling. A reminder that ends in a payment is a different economic object from one that ends in a promise.
Frequently Asked Questions
Is your AI voice agent PCI compliant?
The honest answer is that the question is usually the wrong one. PCI scope follows card data, so the safest design is one where card data never reaches the voice platform at all. With a payment link, masked keypad entry or a handoff to your payment provider, the agent is never in the path the card travels, which is a stronger position than any assurance about how well it is guarded.
Can the caller read the card number out loud to the AI?
They can, and we advise against building for it. Spoken card details land in the audio, in the recording and potentially in a transcript, which pulls the whole platform into scope and creates an obligation to redact reliably. Every method on this page exists to avoid that.
What is DTMF masking?
When the caller types on their keypad, each key sends a tone. Masking suppresses those tones so they never reach the agent or the recording, while the payment provider still receives the digits. The caller experiences it as typing their card in normally.
Does pausing the recording break our audit trail?
No, and reviewers generally prefer it. The recording shows a deliberate gap at the payment step with the reason logged, rather than a continuous recording that contains card data somebody now has to prove was destroyed.
Can the AI take a payment and then keep going with the call?
Yes. The payment is a short step in the middle. The agent confirms the amount before it, takes the result after it, sends the receipt, updates the record and carries on with whatever the call was about, including booking the next appointment.
Which payment providers can you work with?
We connect to the provider you already use rather than asking you to move, because the compliance position you have already established with them is worth more than any convenience of switching. What the provider needs to support is a hosted payment step, a link that can be issued mid-call, or masked digit collection.
Founder & CEO, AInora
Building AI digital administrators that replace front-desk overhead for service businesses across Europe. Previously built voice AI systems for dental clinics, hotels, and restaurants.
View all articlesCollect it on the call, not on a callback
Tell us who your payment provider is and what the calls are for. We will tell you which of the four methods fits and what your team has to do, which is usually nothing.
Book a free consultation