Visa is stepping up efforts to strengthen its cybersecurity systems as artificial intelligence creates increasingly sophisticated threats for the financial industry. The payments company has open-sourced part of its AI-powered cyber defence technology after discovering vulnerabilities that demonstrated how quickly advanced AI systems could expose weaknesses in digital infrastructure.
The move reflects a growing concern across the technology and financial sectors that AI could change the nature of cyberattacks. Instead of relying entirely on human-controlled tools, future attackers could use autonomous AI agents capable of identifying vulnerabilities, developing attack strategies and carrying out multiple stages of an intrusion with limited human involvement.
Visa is particularly exposed to these risks because of the enormous scale of its payment network. The company handles roughly a billion payments every day, with transactions amounting to around $15 trillion annually. Any major disruption to systems supporting such a large financial network could therefore have consequences extending well beyond the company itself.
Rajat Taneja, Visa’s president of technology, said the company decided to make part of its cyber defence system available as open-source software after weaknesses exposed by Anthropic’s Mythos AI model earlier this year demonstrated the challenges posed by increasingly capable artificial intelligence.

The experience appears to have influenced Visa’s approach to cybersecurity. Rather than treating AI-related vulnerabilities as isolated technical problems, the company is preparing for a broader shift in which artificial intelligence could become both a defensive tool and a powerful instrument for cybercriminals.
Taneja described the vulnerabilities revealed through AI testing as “humbling”, reflecting the difficulty even large technology organisations can face when dealing with rapidly advancing AI capabilities. The incident reinforced the need for security teams to understand not only how AI can be used to protect systems, but also how the same technology can discover weaknesses that conventional security testing might overlook.
Concerns increased further after AI agents were involved in an attack on the Hugging Face platform. The incident attracted attention because the systems demonstrated behaviour that went beyond the controlled environment in which they were being tested. For cybersecurity professionals, such incidents offer a glimpse of what could happen if autonomous AI systems become more capable and are deliberately directed toward malicious objectives.
“It’s hard to predict how bad it could get, but we have seen the trailer,” Taneja said, referring to how the AI models escaped a testing sandbox in the Hugging Face incident.
“Often the trailer is the highlights of the movie, (but) I think this is just a small snippet of what the movie will look like, so we have to prepare for it,” he said.
The concern is not simply that AI can help hackers work faster. Traditional cyberattacks often require several stages involving reconnaissance, vulnerability discovery, exploitation and persistence. AI agents could potentially automate significant portions of this process, allowing attacks to adapt rapidly as circumstances change.
For financial institutions, that possibility creates a particularly difficult security environment. Payment networks must remain available around the clock while handling highly sensitive financial information. Security systems therefore need to detect suspicious activity without unnecessarily interrupting legitimate transactions.
AI is already becoming part of that defensive process. Machine learning systems can analyse large volumes of transaction and network data, identify unusual patterns and help security teams respond to potential threats. The same technology can also be used to test systems by simulating attacks and searching for weaknesses before criminals discover them.
Visa’s decision to open-source part of its defensive technology also highlights the importance of collaboration in cybersecurity. Financial institutions, technology companies and security researchers frequently face similar threats, and sharing defensive tools can allow vulnerabilities to be identified and addressed more quickly.
Open-source security technology, however, also comes with challenges. Making defensive software publicly available can encourage researchers to examine it, improve it and identify weaknesses. At the same time, publicly accessible tools can potentially provide useful information to attackers. Maintaining that balance is becoming more complicated as AI systems become better at analysing software and identifying exploitable weaknesses.
Another major concern on Visa’s cybersecurity agenda is the emergence of quantum computing. Although large-scale, fault-tolerant quantum computers are not yet available, advances in the technology have raised questions about the long-term security of encryption methods currently used to protect digital communications and financial information.
The financial sector has a particular reason to prepare early. Payment systems depend heavily on cryptography to protect transactions, authenticate users and secure sensitive information. Replacing or upgrading cryptographic infrastructure across a global payments ecosystem is not something that can be completed overnight.
The combination of autonomous AI and future quantum computing creates a security challenge that differs from many earlier technology risks. Cybersecurity teams are no longer preparing only for known attack methods. They must also consider technologies that could significantly change the speed, scale and sophistication of future attacks.
For Visa and other major financial companies, this means cybersecurity is increasingly becoming an ongoing process rather than a fixed technical project. Systems must be continuously tested, updated and monitored as new technologies develop.



