← Back to News
Innovation

Visa’s AI security harness now writes and validates fixes

Visa has extended its open-source Vulnerability Agentic Harness from finding flaws to writing and validating fixes, and opened it to other AI models. It edits code by default, and Visa’s claim that some fixes now take hours is unverified.

Networks mentioned

Visa has expanded the Visa Vulnerability Agentic Harness, the open-source framework it released in June 2026, so that it no longer stops at finding security flaws. The version announced on August 27, 2026, also writes the fix and validates it, and it can run on models from Anthropic, OpenAI, or other AI providers.

The pitch is speed. The gap between the discovery of a software vulnerability, a flaw in code that an attacker can exploit, and its fix is the window during which a system stays exposed. At large organizations, that window is often measured in weeks. “AI is compressing the time between vulnerability discovery and exploitation, which means defenders need a faster, more reliable path to action,” said Rajat Taneja, Visa’s president of technology.

An agentic harness is an execution pipeline that splits a task into stages and hands each one to a language model equipped with tools, passing context from one stage to the next. Visa’s framework has 11 stages. The first ones scan the code repository, rank the flaws they find, and map them against the asset inventory, threat models, and business risk. That is what separates it from a plain vulnerability scanner.

The harness now goes from detection to a validated fix

The original version stopped at discovery. The update adds remediation and validation. At stage 10, the system writes the fix into a working copy of the repository. Stage 11 sends it to an adversarial validation panel whose job is to find what the fix breaks or lets through. When a fix fails, the framework returns structured feedback to the earlier stages instead of a bare error signal. Visa presents that loop as the main functional addition. The process has three human checkpoints:

  • a check before the pipeline runs, to decide what the system is allowed to touch
  • a check when the generated fix is reviewed
  • a check before the fix is merged into the main branch
⚠️
Source files are edited by default
The framework modifies source files by default unless the operator limits it to detection only. Whether it touches code depends on how the deploying organization configures it, not on the software itself. Visa says the final decision on a fix rests with security and engineering teams, a position that holds only if the three human checkpoints are actually enforced.
Server racks in a data center
Automated remediation shifts human work from writing the fix to reviewing it.

Teams can assign a different AI model to each stage

The second change is model agnosticism. Organizations can now deploy the models they have approved, whether from Anthropic, OpenAI, or others, through configuration rather than code changes. The choice can be made stage by stage, so a team can use a high-precision model where a false positive is costly and a high-recall model where a missed flaw costs more. Progress on scans and fixes can be tracked in real time.

Visa pitches “mean time to adapt” as the metric to watch

Visa is promoting a metric it calls Mean Time to Adapt (MTTA), the average time between the discovery of a flaw and its actual resolution. The company says some resolutions have shrunk from weeks to hours. The figure comes from the vendor, covers cases it has not detailed, and has no published methodology. For now, it reads as a stated goal rather than a result anyone can verify.

11
stages in the framework’s execution pipeline
VentureBeat
June 2026
initial open-source release of the framework
Visa
2,300
stars on the GitHub repository as of August 25, 2026, with more than 300 forks
VentureBeat
3
new cybersecurity advisory services at Visa Consulting & Analytics
Visa

A card network’s exposure spans the whole acceptance chain

A card network’s risk does not stop at its own systems. It covers the entire acceptance chain, from issuers and acquirers to processors and merchants, where security failures turn into fraud on the network’s cards. The networks jointly fund the PCI Security Standards Council, which publishes the security requirements for that chain. Those requirements describe the state to reach, not the means of reaching it.

The harness works differently: it hands clients a technical tool for their own code, with no obligation or oversight attached. There is still a commercial angle. Visa Consulting & Analytics is pairing the launch with three paid services: AI Cyber Leadership Education, a VVAH-Informed Cybersecurity Maturity Assessment, and VVAH Cyber Risk Prioritization and Roadmap.

The framework also feeds into several industry efforts. Visa is contributing it to NVIDIA’s Open Secure AI Alliance and working with IBM and Red Hat on Project Lightwell, which focuses on securing open-source software. Visa built the original version after taking part in Project Glasswing, Anthropic’s cybersecurity initiative.

June 2026
Open-source release
The framework is published on GitHub, limited to finding vulnerabilities.
August 25, 2026
Adoption milestone
The repository passes 2,300 stars and 300 forks.
August 27, 2026
Expansion
Remediation, adversarial validation, model choice through configuration, and three related advisory services.
ℹ️
Where these details come from
The features and the advisory services come from Visa’s August 27, 2026, press release. The 11-stage breakdown, the framework’s default behavior, and the GitHub adoption figures come from VentureBeat’s analysis published the same day. The time savings Visa cites have not been independently verified.

For the payments industry, the real test is narrow: the share of machine-written fixes that pass human review without rework. A framework that writes fixes quickly but incorrectly shifts the burden from engineering to code review, without cutting the delay it claims to measure.

Provenance

Published August 27, 2026

4 sources, 4 distinct domains

↗ Visa, “Open-source Vulnerability Agentic Harness expanded,” August 27, 2026 · corporate.visa.com↗ PYMNTS, “Visa Rolls Out AI-Powered Cyber Vulnerability Patching for Clients,” August 27, 2026 · pymnts.com↗ VentureBeat, “Visa ships a security AI that patches production code before any human reviews it,” August 27, 2026 · venturebeat.com↗ Digital Transactions, “Visa Updates VVAH Fraud Service and other news briefs from 8/27/26” · digitaltransactions.net
← All news