Visa warns AI is speeding up cyber threats. Its defense keeps humans in charge
The payments company’s September warning draws attention to an open-source security workflow released in June—and the checks needed before automated fixes reach production.
Visa is warning that increasingly capable artificial intelligence could compress the time available to defend major digital systems. But the security software it has made available to other organizations is built around a distinction that can disappear in the excitement over autonomous agents: identifying a possible vulnerability is different from proving and safely fixing it.
In a September 29 Reuters interview, Visa technology president Rajat Taneja described the risks posed by AI-powered attacks and the company’s decision to share defensive tooling after work involving Anthropic’s Mythos. The interview was a fresh warning, not the original launch of that software. Visa had publicly described its Vulnerability Agentic Harness in June.
The company’s own account says its testing produced findings initially marked critical even where existing controls would have prevented exploitation. Segmentation and zero-trust defenses, Visa said, changed the practical significance of those findings. That is an important qualification: a model identifying dangerous-looking code does not establish that an attacker can compromise the deployed system.
Visa describes people reviewing findings, severity and proposed remediation, with agents assisting validation. Its stated measure is the time required to reach a verified fix, rather than simply the speed at which software generates alerts. Those are company descriptions of its approach, not an independent audit of the effectiveness of its defenses.
The publicly available repository provides a more specific view of the workflow. It divides work into discovery and modeling, deeper verification, synthesis and reporting, and optional remediation and validation. The default sequence stops at the reporting stage. Automatic remediation is disabled unless it is explicitly enabled.
That default matters for organizations considering whether to place powerful models inside their development processes. A proposed code change can alter application behavior as well as remove a weakness. The repository warns that model-generated findings and fixes require human review, keeping responsibility with the organization operating the system.
The reference implementation can assign different models to different roles and supports multiple provider interfaces rather than requiring a single vendor. It is released under the Apache 2.0 license. Sending prompts to a selected provider also creates a data-handling decision: organizations must consider what information their chosen endpoint receives and use the tooling only on code they are authorized to assess.
Visa’s warning therefore connects two pressures often discussed separately. Attackers may gain faster ways to search for weaknesses, while defenders need reliable methods to distinguish exploitable problems from alarming but misleading output. Producing more findings is useful only when teams can verify them and act without damaging the systems they protect.
For teams examining the published implementation, the concrete starting point is its existing configuration: reporting enabled, remediation optional and human review still required. The September interview did not replace those documented controls with a promise of fully autonomous security.