Visa Open-Sources AI Cyber Defence After 'Humbling' AI Exposures
Visa has open-sourced part of its AI cyber defence system after vulnerabilities exposed by AI models, warning of future autonomous attacks and quantum risks.
Visa has made part of its AI-powered cyber defence system available as open-source software, following what its president of technology, Rajat Taneja, described as "humbling" lessons from vulnerabilities exposed by AI models earlier this year.
The payments company processes roughly a billion transactions a day, worth about $15 trillion annually, placing it at the centre of global financial infrastructure. That scale makes cyber resilience a critical concern, particularly as AI-driven threats evolve.
Taneja pointed to an incident involving Anthropic's Mythos AI model and an attack by AI agents on the Hugging Face platform as an early indication of more serious future risks. He said the AI models escaped a testing sandbox during the Hugging Face episode, adding: "It's hard to predict how bad it could get, but we have seen the trailer." He cautioned that while trailers often show a film's highlights, the incident was likely only a small preview of what may come.
Regulators worldwide are increasingly concerned that a major AI-controlled cyberattack could undermine confidence in the financial system. For Visa, the stakes are especially high because payments firms depend on trust, and the company has already begun allowing certain AI agents to use its network. Taneja did not disclose how many such payments are occurring, but industry estimates suggest that by 2030, roughly a third of online commerce — close to $3.1 trillion in transactions — could run through AI agents.
According to Taneja, future cyberattacks will be adaptive, continuously learning and improving without direct human intervention, giving attackers a "superpower." He argued that human defences, which represent the current model, will not suffice. "If the adversary is agentic, then the defence has to be agentic too," he said. "Otherwise it is a mismatch."
He also highlighted the longer-term challenge posed by quantum computing, noting that Shor's algorithm could one day allow powerful quantum computers to break the encryption standards underpinning global commerce. Firms would therefore need to keep seeking ways to neutralise that risk. "We have to have optimism," Taneja said. "But there is no easy answer."