**Our Take: The Bottleneck Has Moved, and So Must the Human Gate**
If you're feeling constrained by the old rhythm of security, scan, triage, assign, wait, it's time to look closely at what Visa shipped last week. The Visa Vulnerability Agentic Harness doesn't just find flaws; it patches them, attacks its own patch, and iterates until the exploit dies, all before a human looks at the diff. This is a profound shift in who does the heavy lifting. As Rajat Taneja, Visa's president of technology, put it, the bottleneck has moved from discovery to remediation. For our readers, this means the conversation is no longer about whether AI can secure your code, but whether your architecture can survive the speed of the fix. We would tell you this: the harness is a legitimate step function, but it demands a clear-eyed understanding of where the human sits in the loop.
The tension here is not about capability; it is about sequence. Wilson, the OWASP co-lead, argues for an authorization gate *outside* the model, approval before action. Visa's default places human gates before the run and after the patch is written, with the adversarial panel at stage eleven acting as the automated referee. On paper, this lands close to Wilson's boundary. But the practical reality is that the "attack" is the autonomous part. Visa's own documentation is explicit: the tool runs with elevated privilege, and the README warns about egress to third-party endpoints. If you are considering this, do not let the marketing gloss obscure the operational mandate. Visa's written response to VentureBeat is the most important line: "VVAH is a harness, not a merge tool." Your build, test, and code review flow remains non-negotiable. The human gates are real, but they are strategic, not tactical. You are not approving every keystroke; you are approving the boundaries of the sandbox and the final merge.
The deeper insight for practitioners is the multi-model orchestration and the metric shift. Visa is moving away from "finding" as the win condition. The release refactors scanning around an abstract syntax tree call graph to cut token counts, and it routes stages to different models based on precision or recall needs, Claude for semantic reasoning, others for precision, all configurable. This is the death of the single-model monoculture. But with that flexibility comes a burden: Visa admits precision and recall figures are not published for the harness's fix stages. So, our advice is to measure your own outcomes. Pair this with the Building A UX ROI Case That Survives The Boardroom thinking, because adopting this tool is a UX decision for your security team, not just a tech swap. Meanwhile, the Death Of The Button trend toward intent-driven interfaces mirrors what Visa is doing: removing the friction of manual triage, but only if you trust the system's judgment.
We would tell a reader this: do not run the default on your production repo tomorrow. Run `--stop-after s9` first. Read the SARIF output. Map the three human gates Visa mentions, before the run, at patch review, and at merge, and name who holds each. The GhostJacking attack, demonstrated 18 days before this release, was an agent reading a payload from a log file and rewriting DNS. That is the exposure class. If you let this harness touch production code, treat it as a privileged identity with a scope limit, not a script. Visa says it is client zero, and that is good. But your job is to ensure you are client one-hundred-and-one, with a fence around your repos and a clear answer to the question: who reviews the reviewer? The bottleneck has moved, but the gate must move with it.
