Visa has released part of an AI-powered defensive system developed after internal testing with Anthropic’s Mythos exposed weaknesses in its security posture. The company is preparing for autonomous attacks against infrastructure processing roughly one billion payments per day.



What changed
A major payment network is treating offensive and defensive AI agents as an operational security requirement.
Why it matters
Agentic attacks can chain reconnaissance, credential discovery and exploitation faster than conventional alert-review workflows.
Practical takeaway
Replay representative attack chains against the defensive agent and measure detection latency, false positives, containment success and human overrides.
Analysis
Open sourcing can improve scrutiny, but adopters must independently evaluate the system against their own architecture and threat model.
Published
29 September 2026
