Visa is opening more of its cybersecurity tooling to outside developers as the payments company prepares for a future in which cyberattacks could increasingly be carried out by autonomous AI systems rather than human operators following fixed scripts.
Reuters reported that Visa has open-sourced part of its AI-powered cyber defense system after experiments with advanced models revealed weaknesses that company technology president Rajat Taneja described as “humbling.” Visa processes roughly $15 trillion in payments annually, making failures in the underlying infrastructure potentially significant well beyond the company itself.
The system is known as the Visa Vulnerability Agentic Harness, or VVAH.
Visa built an AI system to hunt attack paths
Visa originally developed VVAH while participating in Anthropic’s Project Glasswing.
The company describes the software as an open-source reference implementation for AI-powered vulnerability management that security teams can inspect, adapt and extend for their own environments.
Rather than acting like a conventional vulnerability scanner, the system can use AI models to examine how several weaknesses might connect into a workable attack path.
VentureBeat reported that Visa used Anthropic’s Mythos model against its own infrastructure and built VVAH as a governed pipeline spanning threat modeling, verification, attack-chain synthesis and remediation.
Cyber defense is shifting from discovery to adaptation
Visa expanded the framework in August.
The company said the newer release moves AI-powered risk management from simply finding vulnerabilities toward validated remediation of attack paths. Visa says some remediation cycles that previously required weeks can now be reduced to hours.
That changes the metric security teams need to optimize.
Finding a vulnerability quickly matters less if an attacker can exploit it before defenders can deploy and verify a fix.
Visa calls the interval between discovery and resolution Mean Time to Adapt, or MTTA, arguing that cybersecurity increasingly needs to measure how quickly a system responds rather than simply how fast a flaw is detected.
Autonomous attacks change the defensive model
Reuters reported that Taneja sees recent incidents as early signals of attacks that could become adaptive and increasingly independent of direct human control.
That possibility creates an asymmetry for defenders.
Human security teams work through alerts, tickets, meetings and remediation queues. Autonomous systems can potentially discover vulnerabilities, test combinations and change tactics at machine speed.
Visa’s response is effectively to automate more of the defensive loop as well.
The company says VVAH is model-agnostic and combines AI reasoning with deterministic controls and human oversight rather than giving models unrestricted control over production systems.
Payment infrastructure is becoming a cybersecurity laboratory
Visa’s decision to publish part of the framework matters beyond payments.
Financial networks operate under unusually strict reliability requirements and are among the most attractive targets for cybercriminals. Techniques proven there can influence how other large enterprises approach automated defense.
For developers and security teams, the broader shift is becoming clear.
The cybersecurity industry spent years improving how quickly software could detect suspicious activity.
The next competition may be about how quickly systems can understand an attack, generate a fix, validate that fix and deploy a response before an autonomous attacker changes tactics again.
Visa is betting that part of the answer should be open source.