TL;DR: PCI workloads can run on AWS S3, but compliance fails when organisations cannot continuously locate cardholder data across buckets, backups, logs, and AI-connected workflows, according to Strac. The practical shift is from infrastructure-only controls to DSPM and DLP that discover, classify, and remediate sensitive data before it spreads.
NHIMG editorial — based on content published by Strac: Is AWS S3 PCI Compliant? Compliance in Cloud Storage: Is AWS S3 Equipped for PCI DSS 4.0?
By the numbers:
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes and as quickly as 9 minutes in some cases.
- Only 13% of organisations feel extremely prepared for the reality of agentic AI despite the majority racing toward autonomous adoption.
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job.
Questions worth separating out
Q: How should security teams govern PCI data in AWS when S3 storage is only one part of the problem?
A: They should treat PCI governance as a data-location and data-movement issue, not only a storage configuration issue.
Q: Why do IAM controls fail when sensitive data spreads across cloud storage and AI workflows?
A: IAM can restrict access to a bucket, but it cannot tell you whether the bucket contains regulated data, whether copies exist elsewhere, or whether an agent can pull that data into another system.
Q: What breaks when organisations rely on encryption alone for PCI compliance in the cloud?
A: Encryption protects data in some exposure scenarios, but it does not solve misplaced storage, excessive retention, hidden copies, or delegated access through service accounts and AI agents.
Practitioner guidance
- Build a continuous PCI data discovery programme Scan S3, RDS, Redshift, DynamoDB, backups, logs, and file stores for PAN, PCI-related records, and related sensitive content on an ongoing basis, not just during audits.
- Tie bucket access to content-aware policy checks Use identity policies together with data classification so roles, service accounts, and AI connectors are evaluated against the sensitivity of the data they can reach.
- Set remediation paths for misplaced cardholder data Predefine actions such as masking, redaction, access blocking, alerting, and secure deletion for data discovered in buckets, backups, logs, or exports that should not contain PCI.
What's in the full article
Strac's full article covers the operational detail this post intentionally leaves for the source:
- How its AWS data discovery and classification workflow scans S3, RDS, Redshift, DynamoDB, and other stores for PCI and related sensitive data
- How remediation actions such as masking, redaction, access blocking, alerting, and secure deletion are applied after discovery
- How the article frames GenAI and MCP as part of the cloud data security boundary rather than a separate AI-only issue
- How its PCI guidance maps storage controls to real data movement patterns across exports, backups, browsers, and AI tools
👉 Read Strac's analysis of AWS S3 PCI compliance and cloud data discovery →
AWS S3 and PCI data: why discovery now matters more than buckets?
Explore further
Cloud compliance is now a data-location problem, not a bucket-security problem. Encryption and IAM are necessary controls, but they do not answer the question compliance teams now care about most: where cardholder data actually exists. That shifts PCI governance from static storage checks to continuous discovery, classification, and lifecycle control. Practitioners should treat data visibility as the foundation of any defensible cloud compliance programme.
A question worth separating out:
Q: Who is accountable when cardholder data is discovered in the wrong AWS location?
A: Accountability sits with the organisation, because cloud providers supply control options while customers decide configuration, retention, access scope, and operational monitoring. In practice, compliance and security owners must jointly prove that discovery, classification, access governance, and remediation are working across the full data lifecycle.
👉 Read our full editorial: AWS S3 PCI compliance depends on data discovery, not encryption alone