2 Sources
[1]
Visa launches whitepaper on Frontier AI and the future of cyber resilience at Global Fintech Fest 2026
As cyber threats become increasingly automated and AI-enabled, the challenge facing organisations is no longer simply identifying vulnerabilities, but validating, prioritising and fixing them before they can be exploited at machine speed. To help financial institutions, fintechs and technology
[2]
Visa calls for "AI in the loop" in cyber defence at GFF 2026
Finding a weakness in a payment system and exploiting it took about a year and a half in 2016. It now takes under an hour, Visa's Subra Kumaraswamy told the Global Fintech Fest. Some argue that the situation is already negative, he said. Attackers are exploiting flaws before defenders know they
Share
Copy Link
Visa launched a whitepaper on frontier AI and cyber resilience at Global Fintech Fest 2026, revealing that exploit time has collapsed from 18 months in 2016 to under an hour today. The company proposes shifting from human-in-the-loop to AI in the loop defense systems and introduces Mean Time to Adapt as a new cybersecurity metric while open-sourcing its Vulnerability Agentic Harness tool.
Visa launched its whitepaper titled "Frontier AI: A New Era of Cyber Resilience" at Global Fintech Fest 2026, addressing a stark reality facing financial institutions and payment systems worldwide
1
2
. Subra Kumaraswamy, Chief Information Security Officer at Visa, revealed that the time required to find and exploit a weakness in payment systems has collapsed dramatically from approximately 18 months in 2016 to under an hour today2
. Some security experts argue the situation has already turned negative, with attackers exploiting flaws before defenders even know they exist. The whitepaper was launched by Kumaraswamy and Suresh Sethi, Group Country Manager for India and South Asia at Visa, reflecting the urgency of adapting cybersecurity approaches to match the pace of automated cyber threats1
.
Source: MediaNama
The whitepaper arrives as India's digital payments ecosystem confronts escalating security challenges alongside explosive growth. Total digital payment transactions surged from 6,365 crore in 2021 to 26,762 crore in 2025, while transaction value grew from INR 1,675 lakh crore to INR 3,144 lakh crore over the same period
1
. However, in 2025, India recorded INR 22,495 crore in cyber fraud losses across 2.81 million cases, marking a 24% year-on-year increase1
. Investment scams accounted for 76% of these losses, while digital arrest scams represented 9%. The cybercrime helpline (1930) logged 32.4 million calls in 2025, equivalent to approximately one victim every second1
. These figures underscore why maintaining trust and cyber resilience has become critical for financial institutions and the broader digital payments infrastructure.Kumaraswamy argued that security operations built around human approval for each step cannot keep pace with machine-speed threats. "A security operations centre which is human in the loop, has to move to more of AI in the loop," he stated at Global Fintech Fest 2026
2
. This position creates tension with India's Ministry of Electronics and Information Technology (MeitY), which has separately proposed mandatory human-in-the-loop interventions in agentic AI payments as a consumer protection measure2
. Kumaraswamy also highlighted two critical convergence points. First, the line between cybersecurity and payment security is disappearing, merging into what Visa calls an "agentic control plane" governing applications, code and interfaces behind transactions2
. Second, fraud is shifting from human-led schemes to agentic impersonation, where synthetic identities conduct transactions on behalf of humans2
.The whitepaper introduces Mean Time to Adapt (MTTA) as a new measure of cybersecurity effectiveness, reflecting the compressed timeline between vulnerability discovery and exploitation
1
. MTTA covers three phases: discovery, remediation and validation—the complete cycle of finding a weakness, patching it and confirming the path is closed2
. Kumaraswamy contends that vulnerability detection is no longer the constraint, as AI-driven cyber defense models can now identify vulnerabilities and chain them into exploitable paths. "That part has been solved. It's yesterday's problem," he said2
. The emphasis has shifted to how quickly organizations can adapt their defenses once weaknesses are identified. The whitepaper draws on lessons from Visa's participation in Project Glasswing, described as Anthropic's frontier AI cybersecurity initiative, where the company deployed a model called Anthropic's Mythos to hunt for flaws in its own network1
2
.Related Stories
Visa open-sourced the Visa Vulnerability Agentic Harness (VVAH) in June 2026 and expanded it on August 27, making it available on GitHub with support for models from multiple providers
2
. The tool now generates patches in addition to finding flaws, enabling organizations to move from periodic testing and manual remediation to continuous, intelligence-driven security operations1
. Kumaraswamy explained that Visa released the harness to democratize access, as not all organizations have access to frontier AI models under the same terms. The harness allows others to connect whichever model they have to the same vulnerability detection tasks. Visa scanned hundreds of its own applications within weeks using this approach2
. However, critical questions about governance remain unaddressed. No one on stage discussed what happens when the harness makes an error, particularly when an agent patches production code and validates its own fix without human oversight2
.The presentation at Global Fintech Fest 2026 left significant gaps regarding regulatory implications and risk management. The failure mode of an AI system that makes security decisions with nobody in the loop went unexamined during the session
2
. Additionally, there was no discussion of how Indian regulators would respond to this approach. Visa operates in India under Reserve Bank of India (RBI) oversight, yet the pitch was made to a room of Indian payment companies without addressing regulatory considerations2
. Suresh Sethi emphasized that while AI can significantly enhance fraud detection, risk management and security operations, threat actors are adopting the same technologies to create sophisticated attacks including deepfakes, advanced phishing campaigns and automated fraud at scale1
. He stressed that collaboration across industry participants will be critical, and that organizations must complement automation with strong governance, oversight and accountability to build resilient security programmes at scale1
. Watch for how regulators respond to AI in the loop proposals and whether financial institutions can balance speed with accountability in deploying autonomous security systems.Summarized by
Navi
[1]
19 Feb 2026•Technology

21 Aug 2026•Technology
14 Aug 2026•Technology

1
Technology

2
Policy and Regulation

3
Technology
