AIM Media House

Visa's AI Cybersecurity Tool Just Got an Upgrade

Visa's AI Cybersecurity Tool Just Got an Upgrade

"AI is compressing the time between vulnerability discovery and exploitation, which means defenders need a faster, more reliable path to action."

Visa's Vulnerability Agentic Harness has been finding vulnerabilities since its June 2026 release. The update announced on August 27, adds what comes after, remediation and validation, compressing some resolutions from weeks to hours within a single structured workflow.

Closed-loop remediation is the most operationally significant change. When a fix fails validation, the system provides structured feedback that allows teams to refine and resubmit, without restarting the entire discovery process from the beginning.

The update also adds flexible model choice, allowing organizations to deploy Anthropic models, OpenAI models, or any other AI model through configuration changes rather than code changes, a governance design that lets security teams work within their approved model stack without modifying the underlying framework.

"AI is compressing the time between vulnerability discovery and exploitation, which means defenders need a faster, more reliable path to action," said Rajat Taneja, President of Technology at Visa. "By advancing VVAH and expanding our cybersecurity advisory capabilities, we're helping organizations move from insight to validated remediation."

Alongside the VVAH update, Visa Consulting and Analytics launched three new advisory services designed to help clients apply the framework's capabilities to their own security operations. 

The AI Cyber Leadership Education service provides executive workshops, trainings, and Visa University certification courses drawing on Visa's experience with Project Glasswing, Anthropic's frontier AI cybersecurity initiative through which VVAH was originally developed. 

The VVAH-Informed Cybersecurity Maturity Assessment helps organizations apply the framework to identify and prioritize vulnerabilities across their environment, according to the press release. 

The VVAH Cyber Risk Prioritization and Roadmap service provides strategic guidance on evaluating findings and building a long-term cyber risk management plan.

CAIXA Cartões is cited as a named client that has used Visa's cybersecurity advisory services for a maturity assessment and risk prioritization initiative. VVAH has been downloaded by tens of thousands of developers since its open-source release in June 2026. 

Visa has joined NVIDIA's Open Secure AI Alliance, contributing VVAH as a model-agnostic framework, and is collaborating with IBM and Red Hat through Project Lightwell to help secure open-source software.

"Finding vulnerabilities is no longer the hardest part. Speed to remediation is the new battleground," said Carl Rutstein, global head of Visa Consulting and Analytics. "When AI-enabled attackers move faster and probe at scale, companies need AI-powered defenses."

Key Takeaways

  • Upgrade Visa's AI cybersecurity tool, VAH, now adds remediation and validation, drastically reducing resolution times.
  • Implement a new closed-loop remediation system for efficient vulnerability fixes and feedback without restarting discovery.
  • Utilize flexible model choice, allowing integration of various AI models (Anthropic, OpenAI) without code changes.