Visa's Security AI Now Patches Production Code Before Any Human Reviews It
Visa's open-source VVAH harness now discovers, patches, and adversarially validates vulnerabilities in one autonomous loop — with human review pushed to the edges of the pipeline.
Visa has shipped the most aggressive answer yet to a question the security industry keeps dodging: when an AI agent finds a vulnerability, who writes the fix — the human, or the agent? With this week’s update to its open-source Visa Vulnerability Agentic Harness (VVAH), the answer is the agent. The harness now finds the vulnerability, writes the fix, and turns an adversarial panel loose on its own patch before any human reviews it. The full loop ships on by default.
The timing is deliberate. The release lands 18 days after Tenet Security demonstrated “GhostJacking” on the DEF CON 34 main stage — an attack chain in which a hijacked agent read an attacker’s payload out of a log file and rewrote DNS using a valid credential. Visa’s bet is the opposite of the industry’s instinct: instead of gating the agent at every step, give it the whole pipeline and put humans at the edges, where judgment actually matters.
The bottleneck moved, so Visa moved the pipeline
Rajat Taneja, Visa’s president of technology, rejects the framing that autonomous patching is a risk decision. It’s the product. “The bottleneck has moved,” he told VentureBeat in an exclusive interview. “AI is finding vulnerabilities faster than humans can in the history of our technology industry. The new bottleneck is fixing and proving we have fixed things.”
VVAH grew out of Visa’s participation in Anthropic’s Project Glasswing, where the company aimed Claude Mythos at the payment network behind billions of daily transactions and watched the model chain minor weaknesses into working exploits. The harness went to GitHub in June 2026 and has since climbed from 595 stars on July 20 to more than 2,300 stars and 300 forks as of August 25 — a clone-to-visitor ratio Taneja put near 9%. “We have got some very high-profile companies that have started using this harness,” he said.
The earlier release stopped at discovery: find a bug, verify it, file a structured report. Thursday’s update extends the pipeline across the full lifecycle. In Taneja’s words: “We’re going from discover, verify, and report, and then fix it, to discover it, verify it, remediate it, validate it, and iterate it. If a fix doesn’t negate the exploit, then there should be a structured, automated feedback that preserves the learnings from the first run and then enhances it.”
Underneath that loop, the release refactors scanning around an abstract syntax tree call graph that maps subroutine calls and the traversal paths an attacker could reach — a change Taneja argued cuts token counts while delivering better exploitability analysis. On top sits MTTA observability across all stages, plus real-time progress views for long-running scans.
The default, and the gate
What makes the release contentious is the default. A plain scan of the repo runs all 11 stages and edits source files in the target repository unless the operator explicitly caps it at detection. There is no approval step between patch and written file.
Steve Wilson — Chief AI and Product Officer at Exabeam and project co-lead for the OWASP Top 10 for LLM Applications — had made the case for the opposite default in VentureBeat days earlier: “The first thing I’d do is put an authorization gate outside the model. The agent can propose the exact DNS change, but it cannot grant itself the authority to make it.” Prompt-level security rules, he noted, “are still suggestions to the model, not enforceable security controls.”
Visa’s answer, delivered in written responses, is that the gates exist — just not where critics expected. “VVAH is a harness, not a merge tool,” the company wrote. “Stage 10 writes candidate fixes to a working copy of the repo. Stage 11 then runs an adversarial validation panel that scores each fix and returns one of three verdicts: validated, validation failed, or needs review. None of these bypasses your normal build, test, and code review flow.”
Humans, per Visa, are “the gate in three places: before running the tool, when reviewing the patches, and before anything gets merged.” The final call on any fix stays with security and engineering teams. What the harness automates is the adversarial step — before a fix counts as validated, the panel scores whether the patch actually negates the exploit, and failed fixes feed the next attempt. Stage 11 itself runs read-only; VVAH does not compile, build, or run tests against the patched tree.
Set beside Wilson’s standard, the architecture lands close to his line, but the sequence does not. His gate clears an action before it happens. VVAH’s human gates open before the run and after the write. The fully automated segment — discovery through patching through adversarial validation — sits entirely between them.
One metric, three definitions
Mean Time to Adapt (MTTA), the metric Visa invented alongside the harness, gets star billing. The short form: the time between discovery and resolution of attack paths, with some remediation cycles shrinking from weeks to hours. The Project Glasswing white paper tracks MTTA along three dimensions, including inventory freshness, exploitable paths per release, and validation cycle time. The repo carries a third definition — elapsed time from AI-discovered exploitability to a validated fix in production.
Taneja ranks MTTA as “the most strategically important metric” in security today, because it shifts focus from scanning output to how fast an enterprise actually adapts. His shorthand is blunt: “It’s not the finding. It’s the fixing that matters.” The nuance worth watching: board slides will quote the shortest of the three intervals. A resolution count that skips validation is exactly what MTTA was invented to replace — ask for all three numbers.
Model choice becomes a per-stage decision
The other substantive change is multi-model orchestration. “Mythos has a very high recall, but the Opus model has very high precision,” Taneja said, describing a per-stage routing philosophy: “On stage one I want to use this model. On stage two I want to use this model” — with newer GPT releases in the ensemble and open-weight models where pricing stings, all switchable through configuration rather than code.
One boundary quietly moved: in June, applying a fix required Anthropic backends, with OpenAI-compatible backends limited to report-only mode. The current README extends remediation and validation to OpenAI-compatible and open-weight models through a shared model-agnostic runtime — no single provider is a hard dependency, though default routing for both stages stays Anthropic.
Visa is also contributing VVAH to Nvidia’s Open Secure AI Alliance as a model-agnostic framework, and collaborating in Project Lightwell, the $5 billion IBM/Red Hat effort to harden open-source components. On the consulting side, Visa Consulting & Analytics added three advisory offerings built on the harness: AI Cyber Leadership Education, VVAH-Informed Cybersecurity Maturity Assessments, and VVAH Cyber Risk Prioritization and Roadmaps. Since its June open-source release, VVAH has been downloaded by tens of thousands of developers.
The road from here
Taneja pointed to the recent Hugging Face incident and frontier models “escaping sandboxes to do things more autonomously” as the preview of what’s coming. “We have seen the trailer of this movie,” he said, and “every company in the world should prepare and rethink their architecture.” Traditional security tooling — “signal providers” that hand telemetry to human SOC teams — cannot work at the scale AI-enabled attack and defense now demand.
Whether VVAH’s edge-gated autonomy becomes the enterprise default or a cautionary tale depends on adoption discipline. The safest on-ramp is explicit: start with --stop-after s9 and read the SARIF output before any run that can write source files, and map Visa’s three human gates onto your existing pipeline before turning fix mode on.
What’s not in dispute is the direction. Vulnerability discovery has become cheap; remediation capacity has not. Visa — as its own client zero — has now productionized the argument that the only defense that operates at AI speed is one that fixes at AI speed too.
Sources
- [1] https://venturebeat.com/security/visa-agentic-security-harness-autonomous-fix
- [2] https://www.itcpeacademy.org/blog/news-visa-unveils-major-cybersecurity-upgrades-as-ai-accelerates-vulnerability-exploitation
- [3] https://github.com/visa/visa-vulnerability-agentic-harness
- [4] https://corporate.visa.com/en/sites/visa-perspectives/security-trust/visa-cybersecurity-mythos-project-glasswing.html