Visa launched a whitepaper on frontier AI and cyber resilience at Global Fintech Fest 2026, revealing that exploit time has collapsed from 18 months in 2016 to under an hour today. The company proposes shifting from human-in-the-loop to AI in the loop defense systems and introduces Mean Time to Adapt as a new cybersecurity metric while open-sourcing its Vulnerability Agentic Harness tool.

Visa Addresses Accelerating Cyber Threat Landscape with Frontier AI Framework

Visa launched its whitepaper titled "Frontier AI: A New Era of Cyber Resilience" at Global Fintech Fest 2026, addressing a stark reality facing financial institutions and payment systems worldwide

1

2

. Subra Kumaraswamy, Chief Information Security Officer at Visa, revealed that the time required to find and exploit a weakness in payment systems has collapsed dramatically from approximately 18 months in 2016 to under an hour today

2

. Some security experts argue the situation has already turned negative, with attackers exploiting flaws before defenders even know they exist. The whitepaper was launched by Kumaraswamy and Suresh Sethi, Group Country Manager for India and South Asia at Visa, reflecting the urgency of adapting cybersecurity approaches to match the pace of automated cyber threats

1

.

India's Digital Payments Infrastructure Faces Mounting Cyber Fraud Losses

Source: MediaNama

Source: MediaNama

The whitepaper arrives as India's digital payments ecosystem confronts escalating security challenges alongside explosive growth. Total digital payment transactions surged from 6,365 crore in 2021 to 26,762 crore in 2025, while transaction value grew from INR 1,675 lakh crore to INR 3,144 lakh crore over the same period

1

. However, in 2025, India recorded INR 22,495 crore in cyber fraud losses across 2.81 million cases, marking a 24% year-on-year increase

1

. Investment scams accounted for 76% of these losses, while digital arrest scams represented 9%. The cybercrime helpline (1930) logged 32.4 million calls in 2025, equivalent to approximately one victim every second

1

. These figures underscore why maintaining trust and cyber resilience has become critical for financial institutions and the broader digital payments infrastructure.

Shift from Human-in-the-Loop to AI in the Loop Defense Systems

Kumaraswamy argued that security operations built around human approval for each step cannot keep pace with machine-speed threats. "A security operations centre which is human in the loop, has to move to more of AI in the loop," he stated at Global Fintech Fest 2026

2

. This position creates tension with India's Ministry of Electronics and Information Technology (MeitY), which has separately proposed mandatory human-in-the-loop interventions in agentic AI payments as a consumer protection measure

2

. Kumaraswamy also highlighted two critical convergence points. First, the line between cybersecurity and payment security is disappearing, merging into what Visa calls an "agentic control plane" governing applications, code and interfaces behind transactions

2

. Second, fraud is shifting from human-led schemes to agentic impersonation, where synthetic identities conduct transactions on behalf of humans

2

.

Mean Time to Adapt Emerges as New Cybersecurity Effectiveness Metric

The whitepaper introduces Mean Time to Adapt (MTTA) as a new measure of cybersecurity effectiveness, reflecting the compressed timeline between vulnerability discovery and exploitation

1

. MTTA covers three phases: discovery, remediation and validation—the complete cycle of finding a weakness, patching it and confirming the path is closed

2

. Kumaraswamy contends that vulnerability detection is no longer the constraint, as AI-driven cyber defense models can now identify vulnerabilities and chain them into exploitable paths. "That part has been solved. It's yesterday's problem," he said

2

. The emphasis has shifted to how quickly organizations can adapt their defenses once weaknesses are identified. The whitepaper draws on lessons from Visa's participation in Project Glasswing, described as Anthropic's frontier AI cybersecurity initiative, where the company deployed a model called Anthropic's Mythos to hunt for flaws in its own network

1

2

.

Visa Open-Sources Vulnerability Agentic Harness for Broader Industry Access

Visa open-sourced the Visa Vulnerability Agentic Harness (VVAH) in June 2026 and expanded it on August 27, making it available on GitHub with support for models from multiple providers

2

. The tool now generates patches in addition to finding flaws, enabling organizations to move from periodic testing and manual remediation to continuous, intelligence-driven security operations

1

. Kumaraswamy explained that Visa released the harness to democratize access, as not all organizations have access to frontier AI models under the same terms. The harness allows others to connect whichever model they have to the same vulnerability detection tasks. Visa scanned hundreds of its own applications within weeks using this approach

2

. However, critical questions about governance remain unaddressed. No one on stage discussed what happens when the harness makes an error, particularly when an agent patches production code and validates its own fix without human oversight

2

.

Unanswered Questions About Regulatory Oversight and Failure Modes

The presentation at Global Fintech Fest 2026 left significant gaps regarding regulatory implications and risk management. The failure mode of an AI system that makes security decisions with nobody in the loop went unexamined during the session

2

. Additionally, there was no discussion of how Indian regulators would respond to this approach. Visa operates in India under Reserve Bank of India (RBI) oversight, yet the pitch was made to a room of Indian payment companies without addressing regulatory considerations

2

. Suresh Sethi emphasized that while AI can significantly enhance fraud detection, risk management and security operations, threat actors are adopting the same technologies to create sophisticated attacks including deepfakes, advanced phishing campaigns and automated fraud at scale

1

. He stressed that collaboration across industry participants will be critical, and that organizations must complement automation with strong governance, oversight and accountability to build resilient security programmes at scale

1

. Watch for how regulators respond to AI in the loop proposals and whether financial institutions can balance speed with accountability in deploying autonomous security systems.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved