Visa deployed Anthropic’s Claude Mythos AI to rigorously test its vast payment network that processes billions of daily transactions across over 200 countries and handles nearly 5 billion payment credentials. This AI-driven approach uncovered deep, complex vulnerabilities by linking minor system weaknesses into exploit chains typically found only late in penetration testing. Visa’s president of technology, Rajat Taneja, highlighted how the company open-sourced the Visa Vulnerability Agentic Harness—an AI governance pipeline that runs multi-phase, multi-model security evaluations with human oversight. This tool helps ensure fixes are effective and measurable through a new metric, Mean Time to Adapt (MTTA), which tracks how quickly vulnerabilities are verified, fixed, and validated in production. Beyond security, Visa is preparing for an AI-driven future where agents transact autonomously, emphasizing the need for stringent identity and trust frameworks. Their work also extends to supply chain security through initiatives like Project Lightwell—partnering with IBM, Red Hat, and major banks to strengthen open-source components using AI. Visa’s strategy focuses on proactive security, rapid adaptation to threats, and autonomous defenses at scale, with the AI harness and best practices available openly to help other security teams.
Back