Visa's security team deployed Anthropic's Mythos AI model to hunt for vulnerabilities in its own payment network, demonstrating how large enterprises can weaponize advanced AI agents for offensive security work. The model identified minor weaknesses and chained them into functional exploits. Visa then open-sourced the harness that controlled Mythos during the hunt, offering other organizations a blueprint for similar red-team operations.
This capability separates enterprises with genuine security depth from the rest. A new survey reveals a stark divide in AI agent containment. Only 47% of enterprises that have secured AI agent identities can actually contain one that goes rogue. That means four out of five organizations with formalized AI agent deployments lack the engineering infrastructure to stop a compromised or misbehaving agent from causing damage.
The numbers get worse. Fifty-three percent of enterprises have already experienced an AI agent incident. These incidents range from minor operational hiccups to serious security breaches. The problem intensifies as organizations accelerate AI agent rollouts without corresponding improvements to their containment and monitoring systems.
Visa's approach highlights what proper containment looks like. The company used Mythos not in isolation but within a governance harness that enforced boundaries around the model's behavior, restricted its access to live systems, and logged all actions. When Visa open-sourced this harness, it provided a working reference implementation for other enterprises to study and adapt.
Most organizations cannot replicate this. They lack the security teams with deep knowledge of both AI systems and infrastructure. They lack the testing environments sophisticated enough to safely simulate production conditions. They lack formal processes for monitoring agent behavior in real time. And they lack remediation playbooks for when containment fails.
The implications ripple across financial services, healthcare, manufacturing, and other sectors deploying AI agents to handle autonomous tasks. An uncontained AI agent in a healthcare system could alter patient records or bypass dosage checks. In financial services, a rogue agent could execute unauthorized transactions or access restricted customer data. In manufacturing, a compromised agent could disable safety systems or corrupt supply chain logistics.
The survey data suggests enterprises are deploying AI agents faster than they are building safety infrastructure around them. Fifty-three percent have already hit incidents. The remaining 47% are likely to encounter problems soon as they scale agent deployments beyond pilot programs.
Anthropic has positioned Mythos as a testing tool specifically designed to find flaws that humans miss. The model's ability to chain minor weaknesses into working exploits makes it valuable for red-team work. But that same capability becomes dangerous if an agent operates without proper containment. Visa's decision to open-source the harness suggests the company views containment as a shared problem requiring shared solutions.
Organizations that want to deploy AI agents safely need to adopt Visa's model. They need governance harnesses that enforce policies around agent behavior. They need monitoring systems that detect anomalies in real time. They need testing environments separate from production. And they need security teams trained to handle AI-specific incidents. Without these layers, the next AI agent incident may cost far more than the ones enterprises have already experienced.
