generative AI for data analysis

Visa turns AI on itself to find hidden flaws in global payments

Visa aimed Anthropic's Claude Mythos at the infrastructure behind billions of daily transactions, and the model stitched minor weaknesses deep in the stack into working exploit chains that would traditionally surface…

4 min readVentureBeat
Visa turns AI on itself to find hidden flaws in global payments

Visa pointed an AI at its own payment network and let it try to break things. The result was a series of exploit chains that would normally have taken human penetration testers weeks to assemble, stitched together from minor weaknesses scattered across the stack. That is the headline. But the story that matters more is what Visa did next, because the company did not just fix the bugs and move on. It open-sourced the harness that made the hunt possible, abandoned its old remediation metrics, and started measuring something its own team had to invent. If you are responsible for securing anything critical, this is the most practical thing you will read this quarter.

The decision to release the Visa Vulnerability Agentic Harness on GitHub is not charity, and it is not marketing. It is an acknowledgment that the bottleneck in security has moved. Anthropic's own conclusion from Project Glasswing, the initiative that invited Visa and others to test Mythos, was that discovery is no longer the hard part. The hard part is verification, disclosure, and patching speed. Visa's team found this firsthand when the model surfaced critical findings cleanly enough for engineers to act on without wading through noise. But the epiphany, as Rajat Taneja put it, was that defense also has to be agentic. Traditional SAST tools still have a place as a first pass, but pattern matching cannot follow an adversary who reasons through logic and data flow. The harness is not another scanner. It is a governed pipeline that forces frontier models through structured tasks with deterministic controls and human oversight at every stage, and it runs hot by default, editing source files in fix mode unless an operator stops it.

Here is what we would tell a reader who asks whether this matters for their team. Yes, and not because you operate a network that moves money in 160 currencies. The lesson is in the metric. Visa abandoned mean time to detect and raw CVE closure counts because those numbers can look fine while actual exposure grows underneath them. The company now tracks Mean Time to Adapt, measuring inventory freshness, exploitable paths per release, and validation cycle time. That is a genuinely different way to think about security, and it is one any organization can adopt with a dashboard rather than a procurement cycle. The white paper's 12 non-negotiable practices map onto architecture reviews most security teams already run. You do not need Visa's budget to start. You need to stop measuring whether you closed findings and start measuring whether you closed attack paths.

The other thread worth pulling is the identity problem, because Visa is already looking past its own perimeter. The company is building the trust framework and agent readiness scoring for a future where AI agents transact on behalf of consumers, and it is doing so because the research is sobering. A related piece from our coverage notes that 69% of enterprises already run credential sharing in their agent deployments, and those organizations report security incidents at a 63.5% rate versus 40.9% where every agent has its own scoped identity. Visa's white paper now lists "AI agents are identities" as a non-negotiable practice, requiring least privilege enforcement and full audit trails for every agent that touches an API. Meanwhile, the company has joined Project Lightwell, the $5 billion IBM and Red Hat initiative to harden open-source components, alongside Bank of America, JPMorganChase, and Mastercard. The logic is simple: the MTTA clock does not pause at any single company's perimeter.

The takeaway to quote is this: Visa is treating the opening to get ahead of machine-speed attackers as a deadline, not an opportunity. The harness sits on GitHub with 595 stars, MTTA needs a dashboard rather than a procurement cycle, and the white paper is candid that the models behind attacks are only going to improve. The question worth watching is whether other critical infrastructure firms follow Visa's lead on supplier due diligence, specifically the demand for continuous vulnerability validation and MTTA baselines from every vendor in the stack. Because if a payment network with five billion credentials says it cannot afford to wait for patches, your supply chain should probably start listening.

From VentureBeat

Visa aimed Anthropic's Claude Mythos at the infrastructure behind billions of daily transactions, a network that spans more than 200 countries and territories, moves money in roughly 160 currencies, and connects nearly 5 billion payment credentials to more than 175 million merchant locations.

Read the original at VentureBeat