Visa Launches Autonomous AI Security Harness for Auto-Patching Code
- Visa introduced VVAH, an open-source harness that automates the full vulnerability lifecycle from discovery to patching.
- The system employs an 11-stage loop, including an adversarial panel that attacks its own patches to ensure stability.
- By default, the AI can edit source files in target repositories before any human intervention occurs.
- The move shifts the security bottleneck from finding vulnerabilities to proving they are fixed.

The speed of software vulnerability discovery has officially outpaced the human capacity to respond. In a decisive move to address this gap, Visa has released an update to its open-source Visa Vulnerability Agentic Harness (VVAH), a system capable of identifying security flaws, writing the necessary code to fix them, and deploying those patches into production without a human ever reviewing the lines of code.
This autonomous loop represents a fundamental shift in DevSecOps. While traditional security pipelines rely on a human-in-the-loop to approve changes, VVAH ships with a default setting that allows the AI to edit source files in the target repository. This capability is designed to shrink remediation timelines from weeks to mere hours, providing a defense mechanism that operates at the same velocity as the AI-driven threats it seeks to neutralize.
The 11-stage autonomous remediation loop
The VVAH framework does not simply suggest a fix; it executes a rigorous, multi-stage process to ensure the integrity of the production environment. The system runs through 11 distinct stages, moving from the initial scan to the final commit. The most critical component of this process is the adversarial panel.
Once the AI generates a patch, it does not immediately deploy it. Instead, the harness pits the proposed fix against a suite of tests designed specifically to break the patch. This self-harming approach ensures that the AI is not merely masking a symptom but is solving the underlying vulnerability without introducing new security holes. If the patch fails this gauntlet, the closed-loop remediation allows the system to refine the fix and try again without requiring a manual restart of the process.
From Project Glasswing to open source
The origins of VVAH lie in Visa's collaboration with Anthropic through Project Glasswing. During this initiative, Visa utilized the Claude Mythos model to analyze the complex network supporting billions of daily transactions. The results were sobering: the model was able to chain minor, seemingly insignificant weaknesses into fully working exploits.
Rajat Taneja, Visa's president of technology, noted that this experience revealed the power of semantic reasoning in modern AI models. The realization that AI could find vulnerabilities faster than any human in the history of the industry led to the creation of the harness. Since its initial GitHub release in June 2026, the project has seen significant traction, growing to over 2,300 stars and 300 forks, with a clone-to-visitor ratio of approximately 9%.
The debate over authorization gates
The decision to make autonomous patching the default setting has sparked a divide among cybersecurity experts. The timing of the release is particularly pointed, coming just 18 days after Tenet Security demonstrated GhostJacking at DEF CON 34. That specific attack showed how an agent could read a payload from a log file and rewrite DNS settings using valid credentials.
Critics argue that the lack of a human gate is a dangerous precedent. Steve Wilson, Chief AI and Product Officer at Exabeam and a co-lead for the OWASP Top 10 for LLM Applications, suggested that an authorization gate should always exist outside the model. In Wilson's view, an agent should be able to propose a change, but it should never possess the authority to grant itself the permission to execute that change.
The bottleneck has moved. AI is finding vulnerabilities faster than humans can in the history of our technology industry. The new bottleneck is fixing and proving we have fixed things.
Taneja rejects the idea that the default setting is a risk-based decision, arguing instead that the autonomy is the product. For Visa, the risk of a delayed human response to a zero-day threat outweighs the risk of an AI-generated patch that has already passed an adversarial gauntlet.
Expanding the ecosystem and advisory services
Visa is not positioning VVAH as a standalone tool but as part of a broader strategic pivot toward AI-driven security. The company has integrated itself into the wider AI safety and security community by joining NVIDIA's Open Secure AI Alliance and the billion Project Lightwell, a joint effort between IBM and Red Hat.
To help other enterprises operationalize these autonomous insights, Visa is expanding its Consulting & Analytics Cybersecurity Advisory Practice. This expansion includes three new services:
- AI leadership education to prepare executives for autonomous security shifts.
- Risk prioritization roadmaps to identify which systems should be patched autonomously.
- Operational frameworks for integrating agentic security into existing workflows.
A new era for DevSecOps
The deployment of VVAH signals a transition where the role of the security engineer shifts from hands-on coding to high-level policy management and exception handling. By supporting diverse AI models, the harness aims to reduce the Mean Time to Adapt, ensuring that as new attack vectors emerge, the defense mechanism can evolve without waiting for a human developer to write a new script.
As more high-profile companies adopt this harness, the industry is moving toward a reality where production code is in a state of constant, autonomous flux. The focus is no longer on preventing all bugs, but on creating a system that can heal itself faster than an attacker can exploit it. For more details on the technical implementation, the AIStart analysis provides further context on the patch loop.
Global implications for US and UK enterprises
For businesses operating in the US and UK, Visa's move toward autonomous patching introduces a complex intersection of efficiency and liability. In the US, where the regulatory environment for AI is currently fragmented and largely driven by executive orders and sector-specific guidelines, the primary concern for CEOs will be legal accountability. If an autonomous agent patches a system in a way that causes a massive service outage or inadvertently creates a new vulnerability that leads to a data breach, the question of whether the liability rests with the software vendor, the AI model provider, or the enterprise operator remains unanswered.
In the UK, the approach to AI regulation has historically been more pro-innovation and less prescriptive than in the EU. However, UK firms in highly regulated sectors—such as fintech and healthcare—must reconcile the use of tools like VVAH with strict operational resilience requirements. The ability to deploy code without human review may clash with existing audit trails required by financial regulators, who typically demand a documented chain of approval for any change to critical infrastructure.
Ultimately, for the global entrepreneur, the lesson from Visa is that the Mean Time to Remediation (MTTR) is becoming the most critical metric in cybersecurity. Companies that cling to manual review processes may find themselves unable to keep pace with AI-powered exploits. The challenge for international firms will be implementing these autonomous tools while building a new layer of meta-governance—monitoring the AI that monitors the code.
FAQ
What is the Visa Vulnerability Agentic Harness (VVAH)?
VVAH is an open-source AI security framework that automates the entire process of finding, fixing, and validating security vulnerabilities in production code.
Does VVAH require a human to approve patches?
By default, no. The system is designed to edit source files and deploy patches autonomously after they pass an internal adversarial testing panel.
How does the AI ensure the patch doesn't break the system?
It uses an 11-stage loop that includes an adversarial panel, which acts as a suite of tests designed to attack and break the proposed patch before it is finalized.
Why did Visa make this tool open-source?
Visa aims to address the industry-wide bottleneck where AI finds vulnerabilities faster than humans can fix them, sharing the tool to help the broader ecosystem improve security response times.
Sources: Venturebeat, Aistart, Ground ·
Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.
Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.
oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email
