Visa announced on 1 September 2026 an enhanced version of A2A Protect, its fraud prevention service for account-to-account transfers. The main addition is a single risk score, presented as the first commercial integration of Featurespace technology, a company the network acquired. The score is computed in real time, before the funds leave the payer's account.
Where it applies: before the debit
An account-to-account transfer settles in central bank or commercial bank money, without the chargeback machinery that comes with cards. Once the order has been executed, recovering the funds depends on cooperation between banks rather than on a payer's right. That is what moves the question to the moment just before the debit: the service returns a signal before execution, while the payment can still be held.
What a single score changes
A bank fighting transfer fraud usually combines several signals from separate tools, each with its own scale and threshold. The announced score folds those signals into one value, reachable through a single programming interface. Visa adds a plain-language explanation of why a payment was flagged, aimed at the teams that work the alerts.
- One score, computed across the network and returned in real time
- A single interface into existing systems
- A plain-language reason for each flag
- Intelligence shared between institutions, to spot coordinated fraud and emerging scam hotspots
Transfer learning, and its limit
The service rests on transfer learning, which reuses a model trained on one dataset for a neighbouring purpose. Applied to fraud, it lets a bank benefit from patterns seen elsewhere on the network without holding the matching history itself. Its limit is representativeness: a pattern that is common in one market can be rare in another, and the transfer is worth what the resemblance between the two populations is worth.
What Visa does not quantify
The release names no client institution, no deployment market, and gives no date for general availability. The 75% detection increase covers “the first six months of deployment”, without stating the baseline or which institutions were in scope. A detection rate is also read alongside its false alert rate, since the two move together.
James Mirfin, head of risk and security solutions at Visa, frames the problem in terms of speed: “Fraudsters move fast across payment types, and financial institutions need risk insights just as quickly, without slowing down legitimate payments.” The wording points at the constraint specific to this kind of tool, which has to return its verdict within the execution time of an instant transfer.