Visa Explains Why It Made Its AI Cyber Defence Tool Public

The Visa AI cyber defence system is now partly open to the public, and the payments company’s technology chief says the decision grew out of what AI models turned up when they were pointed at Visa’s own code. Rajat Taneja, the company’s president of technology, told Reuters in an interview published on September 29 that the findings were a sobering lesson. He said defending against machine-driven attacks will take machine-driven defences.

The code itself is not new. Visa first published the tool, called the Visa Vulnerability Agentic Harness (VVAH), on GitHub in June 2026, and the company says it has since been downloaded by tens of thousands of developers worldwide. What the Reuters interview adds is Visa’s own account of why it chose to share the system, and how its leadership now reads the threat.

How the Visa AI cyber defence tool works

According to Visa’s own write-up, the harness maps a company’s codebase, sends AI agents through its environment to look for weaknesses, then sorts and ranks what they find and writes reports for developers and remediation agents. It is described as model-agnostic, meaning it is not tied to one AI provider’s product, and Visa says security teams can inspect the code, adapt it and contribute changes.

Since the first release, Visa says it has extended the tool beyond detection. Newer versions add steps for remediation and validation, with patch-validation agents checking fixes, while Visa’s own security and engineering staff review findings, confirm severity and decide how to fix them before changes move forward. Visa says some resolutions that once took weeks now take hours, a figure that comes from the company and that HCN could not independently verify.

What Anthropic’s Mythos model found inside Visa

Visa joined Anthropic’s Project Glasswing, a defensive cybersecurity programme in which selected organisations test Anthropic’s Mythos model against their own systems. In its June write-up, Visa said the model was strong at whole-system analysis and at spotting flaws deep in the software stack, including ones that become more serious when linked together.

Visa’s published account was more reassuring than its chief’s tone. It said its defences held: some findings were flagged as critical, but its zero-trust controls and network segmentation would have prevented exploitation. That is Visa’s assessment of its own systems, and HCN could not independently check it. Taneja’s remarks to Reuters struck a more cautious note, saying the weaknesses exposed by Mythos showed how large the challenge is.

Why fixing flaws now matters more than finding them

A central idea in Visa’s write-up is what it calls Mean Time to Adapt: the gap between discovering a flaw and proving that the attack path it opened is closed. Visa argues that finding vulnerabilities is no longer the hard part, because AI can do it at scale, and that the real test is confirming a flaw is exploitable, fixing it and showing the fix works in production.

The same point appears in Visa’s write-up, which cites Anthropic’s May 22 update on Project Glasswing. According to Visa’s summary of that update, participants found more than 10,000 high- or critical-severity vulnerabilities in widely used software in the first month. That figure covers all participants across the industry, not Visa alone, a distinction some secondary reports have not made.

Agentic attacks and the fear for financial stability

Visa processes roughly a billion payments a day, worth around $15 trillion a year, according to Reuters, which describes it as a key piece of the world’s financial plumbing. Reuters noted that regulators around the world fear a major AI-controlled cyberattack could shake confidence in the financial system, and that payments companies depend on trust in a way few other businesses do.

Taneja’s argument is that defence built around human analysts responding to alerts will not hold up. “If the adversary is agentic, then the defence has to be agentic too,” he told Reuters. He also pointed to an attack by AI agents on the Hugging Face platform as a possible early glimpse of a more serious threat; HCN has not independently confirmed the details of that incident.

Visa has also tied the project to wider industry efforts. Its August announcement said it is contributing VVAH to NVIDIA’s Open Secure AI Alliance and collaborating with others through Project Lightwell, an initiative from IBM and Red Hat aimed at securing open-source software. Separately, Reuters reported that Visa has begun letting certain AI agents use its network, and is preparing for the longer-term risk from quantum computing.

Visa is not the only company facing questions about autonomous AI. HCN has separately reported on OpenAI’s always-on AI agents launch and the safety questions around it, which touch the same concern of software acting with less direct human oversight.

What is still unresolved

Several questions remain open. HCN could not find an independent assessment of how well the tool performs outside Visa’s own environment, and its speed and download figures are company claims. Anthropic’s Mythos model is available only to a limited group of organisations under Project Glasswing, so it is unclear how widely other firms can reproduce Visa’s results.

Visa itself says Mythos is not an outlier, that rival frontier models are closing the gap, and that attackers are already using such AI tools. The practical test for the Visa AI cyber defence project now is whether other organisations adopt the harness and whether faster fixing shortens the window attackers have. HCN will update this story as further details emerge.

Stay informed. Stay human.

Get the latest global crisis updates, breaking news, and in-depth reports delivered directly to your inbox.

No spam. Unsubscribe anytime. Your privacy is respected.

Leave a Reply

Your email address will not be published. Required fields are marked *

HumanCrisisNews — Footer
Toggle Dark Mode