TL;DR: Payment security is shifting toward browser-side control, AI governance, and post-quantum planning, according to Jscrambler’s report on the 2025 PCI SSC Europe Community Meeting, with Verizon cited on nearly 52,000 third- and fourth-party scripts across 7,000 merchant websites. The operational lesson is that trust in payments now depends on continuous authorisation, monitoring, and cryptographic readiness, not annual compliance cycles.
NHIMG editorial — based on content published by Jscrambler: analysis of the 2025 PCI SSC Europe Community Meeting and its security takeaways
By the numbers:
- That script count has surged by almost 50% in just two years.
Questions worth separating out
Q: How should payment teams govern third-party scripts in the browser?
A: Payment teams should treat every browser script as a controlled dependency, not just code delivered by the business.
Q: Why do AI-assisted fraud controls need human accountability?
A: AI-assisted fraud controls can improve speed and pattern detection, but they can also produce decisions that are difficult to explain after the fact.
Q: What signals show that browser-side payment controls are failing?
A: Warning signs include unexplained script additions, frequent third-party changes, missing approval records, and inconsistent behaviour between approved code and what runs in production.
Practitioner guidance
- Build a live client-side script inventory Track every first-party, third-party, and fourth-party script on payment pages, including owners, purpose, change history, and business approval status.
- Enforce script authorisation before execution Require pre-approved policy decisions for scripts that can read, write, or redirect payment data, and monitor for drift after deployment.
- Document AI decision boundaries Define where AI may assist fraud screening or script risk assessment, where humans must approve, and what evidence is required for auditability.
What's in the full article
Jscrambler's full article covers the operational detail this post intentionally leaves for the source:
- Specific PCI DSS 6.4.3 and 11.6.1 implications for client-side script governance and evidence collection
- Conference-level commentary on how merchant teams are using AI to support fraud screening and control authorisation
- Practical examples of how security teams are thinking about hybrid quantum-safe cryptography transitions
- Speaker perspectives from payment leaders on balancing compliance, browser integrity, and future cryptographic change
Browser-side payment risk: what payment teams need to govern now?
Explore further
Browser-side trust is now the real perimeter for payment flows. Merchants can no longer treat the checkout page as a thin presentation layer. Third-party scripts, embedded services, and dynamic code now sit inside the transaction path, which means authorisation and integrity controls must operate at runtime. The governance problem is not only code provenance, but continuous control over what is allowed to execute.
A question worth separating out:
Q: Who is accountable for post-quantum migration across partners and contractors?
A: Accountability sits with the organisation that owns the trust boundary, but the work spans vendors, contractors, and federated partners. Identity teams should define who approves changes, who validates compatibility, and who owns rollback if a cryptographic transition disrupts access. Cross-organisation trust is a governance issue, not just a technical one.
👉 Read our full editorial: Browser-side payment security now demands continuous script governance