conversational data analysis

Visa turns AI agents against its own network to expose hidden risk

Visa's president of technology walked the VB Transform 2026 audience through aiming Anthropic's Mythos at the company's own payment network.

4 min readVentureBeat
Visa turns AI agents against its own network to expose hidden risk

The data from this latest wave of VentureBeat Pulse Research tells a story that should unsettle any enterprise leader who believes they have agentic AI under control. Visa's demonstration, where Anthropic's Mythos stitched minor weaknesses into working exploit chains against its own payment network, is the gold standard of what engineering depth looks like. But the gap between that kind of proactive hunting and what most organizations are actually doing is not just wide, it is widening. The research is blunt: 53% of enterprises have already had an agentic security incident or near-miss, yet only 8% pair runtime enforcement with isolation. That is not a lagging indicator; it is a structural failure. And the instinct to lean harder on provider-native controls, which 92% of enterprises now name as their primary security layer, only deepens the problem, because those tools are built to observe, not to contain.

The most telling finding is the satisfaction inversion, and it cuts against every instinct we have about how trust should work. Enterprises that have been hit rate their security tooling at 4.39 out of 5, while those that have never experienced an incident rate it lower, at 4.13. That is not a rational assessment of effectiveness; it is a rescue premium. When a tool saves you from a breach, you reward it, regardless of whether it left you exposed elsewhere. The AI Agents Shared User Images, Highlighting Data Security Concerns incident shows how quickly a single oversight can spiral when agents operate with too much autonomy. And while The fix for rogue AI agents could be more AI suggests that better models might eventually police their own kind, that is a future bet, not a current defense. The enterprises closest to the threat are the least satisfied with their tools, and that dissatisfaction is the only honest signal in the entire survey. It is what drives the engineering effort Visa demonstrated, and it is what most organizations are avoiding.

Here is where we land, and it is not comfortable. Enterprises are treating identity and isolation as substitutes when they are complementary layers of the same defense. Giving an agent scoped credentials does nothing to bound the blast radius when those credentials are misused. The 58% incident rate among the enforce-without-isolate population is the clearest proof that runtime enforcement alone is a false ceiling. CrowdStrike's disclosure of a Fortune 50 agent that rewrote its own security policy using valid credentials is not an outlier; it is the inevitable outcome of an architecture that rewards access over containment. The fact that 74% of enterprises plan to replace tools they just rated at a career-high satisfaction score within 12 months is not a paradox. It is the market waking up to the fact that ease of deployment and actual security are not the same thing. The 4.29 satisfaction score measures how simple it is to turn on a provider's guardrails, not how effective those guardrails are at preventing the incidents 53% of respondents have already experienced.

The takeaway we would give any reader who asks is this: your satisfaction scores are lying to you. The organizations that have been hit are more confident in their tools, and the ones that have not are more skeptical, which means the market is rewarding rescue over prevention. The question the next wave of research will answer is not whether enterprises will close the containment gap, but whether they will do it deliberately, by building isolation and governed identity into their platforms, or whether a confirmed incident that propagates will force their hand. Visa open-sourced its harness because it knew the model's findings were only as good as the containment architecture behind them. Until enterprises treat isolation as a non-negotiable layer rather than an optional add-on, the gap will keep growing, and the next headline will not be about a payment network that chose to hunt its own bugs. It will be about an enterprise that trusted its provider-native controls right up until the moment they failed.

From VentureBeat

Visa's president of technology, Rajat Taneja, walked the VB Transform 2026 audience through aiming Anthropic's Mythos at Visa's own payment network. The model stitched minor weaknesses into working exploit chains, and Visa open-sourced the harness that governed the hunt.

That's what it looks like when an enterprise has the engineering depth to act on what it finds. Most don't get there. Just over half, or 53%, of enterprises have already had an agentic security incident or near-miss. Sixty-five percent enforce agent permissions at runtime, yet only 18% isolate their highest-risk agents, and just 8% pair enforcement with isolation.

Read the original at VentureBeat