Visa is preparing for a new generation of cybersecurity threats in which artificial intelligence could allow attackers to identify vulnerabilities, adapt their tactics and launch attacks with limited human intervention.
Rajat Taneja, Visa’s President of Technology, told Reuters that the payments company has made part of its AI-powered cyber defence system open source after vulnerabilities exposed by AI models highlighted the changing nature of the cybersecurity landscape.
The company is also preparing for longer-term risks associated with quantum computing, which could eventually challenge some of the encryption technologies currently used to protect digital commerce.
Visa Sees Need for Autonomous Cyber Defence
Visa operates at enormous scale, processing roughly one billion payments a day, with annual payment volume of about $15 trillion, according to the supplied report.
See more of our coverage in your search results.
Add INDYASTORY on GoogleThat scale makes cybersecurity a critical part of the company’s operations and the wider payments ecosystem.
Taneja said vulnerabilities demonstrated by Anthropic’s Mythos AI model had been a significant learning experience for the company. He also pointed to an incident involving AI agents and the Hugging Face platform as an indication of how autonomous systems could create new security challenges.
Describing the lessons as “humbling”, Taneja said the incidents demonstrated that AI-driven threats could become considerably more sophisticated.
AI Could Change How Cyberattacks Work
Traditional cybersecurity systems often rely heavily on human analysts and predefined rules to identify and respond to threats.
Taneja argued that this model could become less effective if attackers begin using autonomous AI agents capable of continuously adjusting their behaviour.
See more of our coverage in your search results.
Add INDYASTORY on Google“If the adversary is agentic, then the defence has to be agentic too. Otherwise it is a mismatch,” Taneja said.
In this context, an agentic system refers to AI that can undertake multiple steps toward a goal with limited direct human intervention.
Such systems could potentially allow attackers to identify weaknesses, modify their approach and continue operations without waiting for human instructions.
Visa Open-Sources Part of Cyber Defence Technology
Visa has responded by making part of its AI-based cybersecurity technology available as open-source software.
See more of our coverage in your search results.
Add INDYASTORY on GoogleThe move reflects the company’s view that combating increasingly automated threats may require broader collaboration across the cybersecurity community.
Open-source security technology can allow researchers and developers to inspect, test and improve software, although the effectiveness and security of any particular implementation depend on how it is deployed and maintained.
Visa’s decision comes as financial institutions, technology companies and regulators examine how AI could affect the security of critical digital infrastructure.
AI Agents Are Also Entering Payments
The cybersecurity challenge is particularly relevant to Visa because AI is not only being viewed as a potential source of attacks but is also becoming part of the payments ecosystem.
Visa has begun allowing certain AI agents to make payments.
The development is part of a broader shift toward so-called agentic commerce, in which AI systems can potentially search for products, make purchasing decisions based on user instructions and complete transactions.
Industry estimates cited in the supplied report suggest that around one-third of online commerce, equivalent to roughly $3.1 trillion in transactions, could run through AI agents by 2030.
The estimate is a forecast rather than a current measure of Visa’s transaction volume through AI agents.
Quantum Computing Creates a Longer-Term Security Challenge
AI is not the only emerging technology highlighted by Visa.
Taneja also pointed to the potential impact of quantum computing on modern encryption.
Current digital commerce depends heavily on cryptographic systems designed to prevent unauthorised access to sensitive information and transactions.
Powerful quantum computers could eventually threaten some widely used public-key cryptographic methods. Taneja specifically referred to Shor’s algorithm, a quantum algorithm that, if run on a sufficiently capable quantum computer, could theoretically undermine certain encryption schemes.
The timeline for achieving such capabilities remains uncertain, but organisations are already examining so-called post-quantum cryptography to prepare for the possibility.
Financial System Faces Growing Digital Security Demands
Cybersecurity has particular importance for payment companies because confidence and reliability are central to electronic transactions.
A major disruption affecting payment infrastructure could potentially have consequences extending beyond an individual company to banks, merchants and consumers.
The increasing use of AI creates a two-sided challenge: financial companies can use the technology to improve fraud detection and security, while attackers can potentially use similar capabilities to automate and scale malicious activity.
This is pushing companies to consider cybersecurity systems that can respond at a comparable speed and level of automation.
Preparing for an Uncertain AI Security Future
Taneja acknowledged that the full scale of future AI-enabled attacks is difficult to predict.
His comments reflect a broader concern within the cybersecurity industry that AI agents could change the speed and sophistication of both offensive and defensive operations.
For Visa, the response includes autonomous defence capabilities, collaboration through open-source technology and preparation for emerging cryptographic risks.
The company is also participating in the broader transition toward AI-enabled commerce, making cybersecurity an increasingly important consideration as autonomous systems gain a larger role in digital payments.
As AI and quantum technologies continue to develop, financial infrastructure providers are likely to face the challenge of securing systems against threats that are evolving faster than traditional security models were designed to handle.