Visa deployed Anthropic's Claude model to probe vulnerabilities across its global payment network, which processes transactions in 160 currencies and connects nearly 5 billion payment credentials. The AI successfully identified exploit chains by linking minor weaknesses throughout the network stack, uncovering security gaps that traditional penetration testing typically discovers much later in the process.

The key innovation lies in how Claude operated. Rather than flagging isolated flaws, the model connected disparate vulnerabilities into functional attack sequences. This synthetic approach to threat detection mirrors how real attackers think across systems rather than examining each component in isolation.

Visa's response stands out: the company open-sourced the harness that controlled the entire security hunt. By releasing this framework publicly, Visa shifts from proprietary testing to collaborative vulnerability discovery. The move signals confidence in the tool's effectiveness while enabling other organizations to adopt similar AI-driven security practices.

Rajat Taneja, Visa's president of technology, presented the findings at VB Transform 2026, detailing how the company moved beyond traditional remediation metrics. Rather than measuring success by counting fixed vulnerabilities, Visa adopted new benchmarks that capture the quality and criticality of discovered threats. This distinction matters: a handful of serious, exploitable chains outweighs hundreds of minor issues in real security terms.

The payment network's scale amplifies the stakes. Visa's infrastructure spans over 200 countries and territories, serving 175 million merchant locations. A single unpatched vulnerability affecting systems this large carries massive financial and reputational risk. Using Claude to systematically build exploit chains from minor weaknesses addresses this scale problem directly.

The approach represents a broader shift in how enterprises handle security. Rather than humans manually chaining vulnerabilities together during expensive penetration tests, AI models now perform this synthesis automatically, catching issues earlier and at lower cost. For payment systems handling trillions in annual volume