Visa has expanded the Visa Vulnerability Agentic Harness, the open-source framework it released in June 2026, so that it no longer stops at finding security flaws. The version announced on August 27, 2026, also writes the fix and validates it, and it can run on models from Anthropic, OpenAI, or other AI providers.
The pitch is speed. The gap between the discovery of a software vulnerability, a flaw in code that an attacker can exploit, and its fix is the window during which a system stays exposed. At large organizations, that window is often measured in weeks. “AI is compressing the time between vulnerability discovery and exploitation, which means defenders need a faster, more reliable path to action,” said Rajat Taneja, Visa’s president of technology.
An agentic harness is an execution pipeline that splits a task into stages and hands each one to a language model equipped with tools, passing context from one stage to the next. Visa’s framework has 11 stages. The first ones scan the code repository, rank the flaws they find, and map them against the asset inventory, threat models, and business risk. That is what separates it from a plain vulnerability scanner.
The harness now goes from detection to a validated fix
The original version stopped at discovery. The update adds remediation and validation. At stage 10, the system writes the fix into a working copy of the repository. Stage 11 sends it to an adversarial validation panel whose job is to find what the fix breaks or lets through. When a fix fails, the framework returns structured feedback to the earlier stages instead of a bare error signal. Visa presents that loop as the main functional addition. The process has three human checkpoints:
- a check before the pipeline runs, to decide what the system is allowed to touch
- a check when the generated fix is reviewed
- a check before the fix is merged into the main branch
Teams can assign a different AI model to each stage
The second change is model agnosticism. Organizations can now deploy the models they have approved, whether from Anthropic, OpenAI, or others, through configuration rather than code changes. The choice can be made stage by stage, so a team can use a high-precision model where a false positive is costly and a high-recall model where a missed flaw costs more. Progress on scans and fixes can be tracked in real time.
Visa pitches “mean time to adapt” as the metric to watch
Visa is promoting a metric it calls Mean Time to Adapt (MTTA), the average time between the discovery of a flaw and its actual resolution. The company says some resolutions have shrunk from weeks to hours. The figure comes from the vendor, covers cases it has not detailed, and has no published methodology. For now, it reads as a stated goal rather than a result anyone can verify.
A card network’s exposure spans the whole acceptance chain
A card network’s risk does not stop at its own systems. It covers the entire acceptance chain, from issuers and acquirers to processors and merchants, where security failures turn into fraud on the network’s cards. The networks jointly fund the PCI Security Standards Council, which publishes the security requirements for that chain. Those requirements describe the state to reach, not the means of reaching it.
The harness works differently: it hands clients a technical tool for their own code, with no obligation or oversight attached. There is still a commercial angle. Visa Consulting & Analytics is pairing the launch with three paid services: AI Cyber Leadership Education, a VVAH-Informed Cybersecurity Maturity Assessment, and VVAH Cyber Risk Prioritization and Roadmap.
The framework also feeds into several industry efforts. Visa is contributing it to NVIDIA’s Open Secure AI Alliance and working with IBM and Red Hat on Project Lightwell, which focuses on securing open-source software. Visa built the original version after taking part in Project Glasswing, Anthropic’s cybersecurity initiative.
For the payments industry, the real test is narrow: the share of machine-written fixes that pass human review without rework. A framework that writes fixes quickly but incorrectly shifts the burden from engineering to code review, without cutting the delay it claims to measure.