CallataGuides

Keeping Card Numbers and SSNs Off AI Calls

Why AI phone agents shouldn't collect card numbers, Social Security numbers or passwords, how to instruct them to refuse, and safer ways to take payments.

AI phone agents should never collect payment card numbers, Social Security numbers, bank account numbers, passwords or one-time codes. Everything said on an AI call ends up in a transcript, and often a recording, stored by your phone system and processed by AI providers. Instruct the agent to refuse these details and offer a secure alternative, like a payment link or a callback from a person.

This article covers what to keep off AI calls, how to instruct the agent, and what to do instead.

Why AI calls are a bad place for sensitive data

A human receptionist taking a card number writes it down once. An AI call creates copies:

  • The live audio stream, processed by speech recognition.
  • A word-for-word transcript stored with the call.
  • An AI summary that might repeat the number.
  • An audio recording, if recording is on.
  • Messages the agent saves for your team.

Each copy is something you have to protect. The PCI Security Standards Council's guidance on telephone-based payment card data explains that call recordings and transcripts containing card data bring those systems into scope for PCI DSS, which is far more than most small businesses want to manage.

Data to keep off AI calls

Data Why it's risky Safer alternative
Full card number, CVV, expiration PCI DSS scope; fraud risk Secure payment link by text or email
Social Security number Identity theft Collect in person or via a secure portal
Bank account and routing numbers Fraud Secure portal or in person
Passwords, PINs, one-time codes Account takeover Never collect; direct to self-service reset
Driver's license number Identity theft Collect at the visit
Detailed medical information HIPAA (for covered entities); sensitivity Brief reason for visit only
Full date of birth plus name and address Identity theft combination Collect only if truly needed

Instructions that keep it out

Put this in your agent's instructions, near the top:

Never ask for or accept: credit or debit card numbers, security
codes, bank account numbers, Social Security numbers, passwords,
PINs or verification codes.
If the caller starts to share any of these, stop them politely:
"Please don't share that on this call. I can text you a secure
link, or have someone from our team help you."
Never repeat back numbers like these.
For payments, offer to text our payment link.

Then test it. Call the agent and say, "Let me give you my card number, it's 4111..." The agent should stop you before you finish. See testing an AI receptionist before launch.

An example of the behavior you want:

Caller: "I want to pay my invoice. My card is 4–1–1–" Agent: "Sorry to interrupt. Please don't read your card number on this call. I can text you our secure payment link right now. Is this the best number?" Caller: "Sure." Agent: "Sent. It goes to our payment page, and you can pay there in a minute or two. Anything else I can help with?"

Taking payments without card numbers on the call

The usual approach is a payment link:

  1. The caller wants to pay a bill or a deposit.
  2. The agent offers: "I can text you a secure payment link. Is this number OK?"
  3. The agent texts the link to the page your payment processor hosts.
  4. The caller pays on their phone. Card data goes to the processor, not your phone system.

Use a link you control on your payment processor's hosted page. Don't let the agent invent URLs; put the exact link in the business facts. See when an AI agent should text callers a link.

For businesses that must take card payments by voice, use a staff member with a PCI-compliant process (such as pausing recording during card entry), not an AI agent.

Identity verification without sensitive data

Some businesses need to confirm who's calling before discussing an account. Options that avoid sensitive data on the AI call:

  • Caller ID match: the call comes from the number on file. Not proof, but a reasonable first signal for low-risk questions.
  • Callback to the number on file: the safest option for anything account-specific.
  • Non-sensitive identifiers: an order number or appointment date.

If verification really matters (account changes, releasing information), route to a person.

Watch for social engineering

Scammers call businesses too, sometimes pretending to be customers, vendors or officials. The FTC's guide to scams targeting small businesses lists common patterns: fake invoices, impersonated suppliers, and urgent requests to change payment details. An AI agent should never:

  • Change a customer's contact or payment details based on a call.
  • Confirm whether a specific person is a customer to an unknown caller.
  • Read back account information.

Instruct it to take a message for anything like this. See how an AI receptionist handles spam and sales calls.

Healthcare and other regulated data

Medical offices covered by HIPAA can only share protected health information with vendors under a business associate agreement. If your AI vendor hasn't signed one, keep patient calls away from the agent or limit what it collects. See AI receptionists in medical and dental offices.

If sensitive data gets through

Callers will sometimes blurt out a card number before the agent can stop them. When you spot it in a transcript:

  • Delete or redact the transcript, summary and any recording for that call.
  • Check whether the data was repeated in a message or text.
  • Note the date and what was removed.
  • Review the instructions and test again.
  • If it's a pattern, add a line to the greeting or website ("we never take card numbers by phone").

A short policy for your team

  1. AI agents don't collect payment, banking, government ID, password or detailed medical data.
  2. Payments by phone go through a hosted payment link.
  3. Account changes require a callback to the number on file.
  4. Anyone who finds sensitive data in a transcript deletes it and reports it.
  5. Instructions are tested quarterly against these rules.

How Callata fits

Callata AI agents work from the instructions and business facts you write, so a "never collect" rule goes in the instructions. Agents can text a link during a call when the caller agrees (once business texting is registered) and can email information the caller asks for. Callata doesn't process card payments through AI agents. Recordings are stored privately, AI conversations are transcribed for your review, and you can delete call data. Contacts the agent can look up include notes and past call summaries, so don't store sensitive numbers in contact notes.

Callata Office is $99 per month with five users included; AI agents use prepaid minutes at $0.25 per minute. Set up Callata.

Frequently asked questions

Can an AI receptionist take credit card payments?

It shouldn't take card numbers by voice. Spoken card numbers end up in transcripts and recordings, which creates PCI DSS obligations most small businesses can't meet. Send a secure payment link instead.

What should the AI do if a caller starts reading their card number?

Interrupt politely, tell them not to share it on this call, and offer a secure link or a callback from the team.

Is it OK for an AI agent to ask for date of birth?

Only if you have a clear need and a plan to protect it. For most small businesses, name and callback number are enough on the first call.

What if sensitive data ends up in a transcript anyway?

Delete or redact the transcript and any recording, note what happened, and fix the instructions so it doesn't recur.