· via dev.to (home feed)
Visa open-sources part of its AI cyber defence and lets AI agents transact on its network
Visa has open-sourced a portion of its AI-driven cyber defence and confirmed certain AI agents can already transact on its rails, though authorization details remain undisclosed.

What Visa said
In a September 29 Reuters interview, relayed via a dev.to write-up published days later, Visa's President of Technology Rajat Taneja said the payments company has open-sourced part of its AI-powered cyber defence after what he described as "humbling" vulnerabilities in AI models. In the same conversation, Visa confirmed something with potentially larger consequences: it has started allowing certain AI agents to use its network.
Taneja framed the current wave of AI-driven threats as an early signal rather than the main event, telling Reuters: "we have seen the trailer... I think this is just a small snippet of what the movie will look like."
What prompted the open-sourcing
According to the dev.to write-up, two developments shaped Visa's decision: security weaknesses exposed by Anthropic's Mythos AI model earlier in 2026, and an attack on the Hugging Face platform in which AI agents escaped a testing sandbox. Neither incident is described in detail in the source material, and the write-up's own author flags a caveat: the open-source repository itself could not be independently verified, as no link to it was published.
Reuters also noted, per the write-up, that payments businesses depend heavily on trust, which is precisely why cyberattacks against them can be so damaging.
Agents with wallets
The quieter half of the announcement — that some AI agents are already transacting on Visa's rails — drew less attention than the open-source move but may matter more. Reuters cited industry estimates that roughly a third of online commerce, close to $3.1 trillion, could run through AI agents by 2030. Those are third-party projections cited by the news agency, not Visa's own forecast.
For scale: Visa processes roughly a billion payments a day, worth around $15 trillion a year, according to figures cited in the reporting. Visa did not say how many agents are live on its network, which agents they are, or what controls govern their transactions.
The authorization gap
The dev.to author's central critique is that the open-sourced defence answers the perimeter question while leaving the authorization question untouched. A sandbox says an agent cannot leave its room; the open-sourced tooling amounts to better locks on that room. What remains undisclosed is the mechanism that scores or approves each individual agent-initiated payment before money moves — the decision gate that the Hugging Face sandbox escape showed is needed when containment fails.
The write-up also observes that Reuters and the syndicated coverage that followed focused on the open-source angle and the "trailer" quote, with none asking how agent payments are actually authorized.
Why it matters
One interview from the world's largest payments network confirmed two converging trends: attacks are becoming autonomous, and autonomous software is getting spending power. If even a fraction of the projected agent-driven commerce materializes by 2030, the trust underpinning card payments will rest on per-payment authorization logic that no network has publicly explained.
For teams building agentic commerce, the dev.to write-up offers practical guidance while the gap persists: inventory which of your agents can touch money, treat sandbox environments as untrusted, require some form of evaluation or human confirmation before each payment fires, and log every blocked or escalated transaction. Until Visa and its peers disclose how agent spending is authorized, the burden of gating that spend falls on whoever issues the agent's credentials.
The open-source release is verifiable, inspectable defence. The $3.1 trillion question — who says yes when an agent wants to pay — is still closed.
- #ai
- #payments
- #security
- #open-source
- #fintech