Visa Expands AI Cybersecurity Tools and Advisory to Accelerate Threat Remediation
1 September 2026

Visa has expanded its cybersecurity suite to combat AI-driven threats by updating its open-source Vulnerability Agentic Harness and launching new advisory services. For fintech professionals, this move addresses the shrinking window between vulnerability discovery and exploitation, aiming to reduce remediation times from weeks to hours through automated, model-agnostic workflows.
What was announced
Visa introduced the latest version of the Visa Vulnerability Agentic Harness (VVAH), an open-source framework designed to automate the discovery and resolution of security flaws. The update focuses on reducing the Mean Time to Adapt (MTTA), allowing security teams to validate and fix attack paths significantly faster. Key technical enhancements include a closed-loop remediation system that provides structured feedback to refine failed fixes, and a flexible architecture that supports models from Anthropic and OpenAI, as well as other AI models via configuration rather than code changes.
The framework now offers real-time progress views for transparency during long-running scans. Originally developed following Visa’s work with Anthropic’s Project Glasswing, VVAH has seen tens of thousands of downloads since its open-source release in June 2026. Complementing the software, the Visa Consulting & Analytics (VCA) Cybersecurity Advisory Practice is launching three new services: AI Cyber Leadership Education, which offers executive workshops and certification; a VVAH-Informed Cybersecurity Maturity Assessment; and a Cyber Risk Prioritisation and Roadmap service.
These offerings are intended to help clients operationalise AI-powered security insights. Visa is also contributing VVAH to NVIDIA’s Open Secure AI Alliance and collaborating with IBM and Red Hat on the Project Lightwell initiative to secure open-source software.
"AI is compressing the time between vulnerability discovery and exploitation, which means defenders need a faster, more reliable path to action. By advancing VVAH and expanding our cybersecurity advisory capabilities, we're helping organisations move from insight to validated remediation while strengthening resilience in an increasingly AI-driven threat landscape."
Rajat Taneja, President, Technology, Visa.
The companies involved
Visa is a global payments technology company that connects consumers, businesses, and financial institutions. With a significant presence in the market, the company has expanded its focus toward cybersecurity and consulting through its Visa Consulting & Analytics (VCA) division. This latest initiative involves several prominent technology partners. Anthropic, an AI safety and research firm, collaborated with Visa on Project Glasswing, which served as the foundation for the VVAH framework. OpenAI, another major player in the artificial intelligence sector, provides models that are now supported within the VVAH ecosystem.
The announcement also highlights Visa’s participation in broader industry alliances. This includes NVIDIA, a leader in AI computing, through the Open Secure AI Alliance. Furthermore, Visa is collaborating with IBM and its subsidiary Red Hat on Project Lightwell. IBM is a global provider of enterprise technology and consulting, while Red Hat is a specialist in open-source software solutions. These collaborations reflect a move toward securing the open-source software supply chain against the rapid evolution of AI-driven threats.
What FF News has reported before
FF News has previously covered the activities of Visa’s partners and the broader trend of AI integration in financial services. For instance, we reported on how SACOMBANK Modernizes Core Banking with Temenos and IBM to Power 13 Million Daily Transactions, highlighting IBM's role in core infrastructure. The rise of AI-native tools has been a recurring theme, as seen in our coverage of SEI Partners With Zocks to Deliver AI-Native Workflow Automation for Financial Advisors and BillingPlatform Appoints Three Key Executives to Drive AI-Native Growth and Market Scaling. These stories underscore the industry-wide push to adopt AI-driven automation, a trend that is now extending into the cybersecurity domain.
What this means
The release of VVAH as an open-source, model-agnostic tool signals a strategic shift in how major financial players approach security. By moving away from proprietary, siloed defenses, the industry is acknowledging that the speed of AI-driven attacks requires a collective, transparent response. This puts pressure on traditional cybersecurity vendors who rely on closed solutions, as financial institutions may now prefer frameworks that allow them to swap AI models as technology evolves. The move also highlights a critical gap in the market: while many firms have adopted AI for operations, few have the internal expertise to secure those systems, creating a significant opportunity for specialized advisory services.
Companies in this story: IBM, Red Hat, Visa, Anthropic, OpenAI, Nvidia
People in this story: Claudio Di Nella, Rajat Taneja