Wednesday, 02 September 2026 Login

Virtual Tech. Real Impact.

BREAKING
Remote Workflows

Visa deploys AI to fix code flaws

Visa deploys AI to fix code flaws - ai security
Visa deploys AI to fix code flaws

Visa has released a security AI that can patch production code before any human reviews it. The company’s open-source security harness, Visa Vulnerability Agentic Harness (VVAH), finds vulnerabilities, writes fixes, and tests them using an adversarial panel, all without human intervention.

The harness automates the entire process, from discovery to remediation, using a combination of AI models and a governance architecture. Rajat Taneja, Visa’s president of technology, says the bottleneck in security has moved from finding vulnerabilities to fixing them, and AI is now finding vulnerabilities faster than humans can.

Taneja argues that the new bottleneck is fixing and proving that things have been fixed, and that’s where VVAH comes in. It uses a model-agnostic approach, allowing users to choose from multiple AI models, including Mythos, depending on the stage of the process, such as AI workloads.

Some experts, such as Steve Wilson, Chief AI and Product Officer at Exabeam, have raised concerns about the security implications of automated patching. Wilson argues that security rules written inside prompts may shape the model’s behavior, but they are still suggestions, not enforceable security controls.

Visa has addressed these concerns by implementing a governance architecture that includes human gates at three stages: before running the tool, when reviewing patches, and before merging code. They say that the final call on any fix stays with the security and engineering teams.

The harness also includes an adversarial validation panel that scores each fix and returns one of three verdicts: validated, validation failed, or needs review. This panel ensures that the fix is thoroughly tested before it is merged into production code.

Related: AI agents hit limits of messy business data

Visa has introduced a new metric, Mean Time to Adapt (MTTA), which measures the time between discovery and resolution of attack paths. Taneja ranks MTTA as the most strategically important metric.

It shifts the focus from scanning to how fast an enterprise adapts. They argue that it’s not the finding that matters, but the fixing, and that’s where VVAH comes in.

Visa has made VVAH available on GitHub, and the repository has gained significant traction, with over 2,300 stars and 300 forks.

Visa is also expanding its Consulting & Analytics advisory practice to help companies implement VVAH and improve their security posture. The practice will offer executive workshops, a VVAH-informed maturity assessment, and a cyber risk prioritization roadmap.

Visa’s consulting practice aims to help companies implement VVAH to improve their security and reduce the mean time to adapt.

Tags:

Leave a Reply

Your email address will not be published. Required fields are marked *