Visa's security research into AI agent vulnerabilities reveals a critical gap between deployment confidence and operational control. When Rajat Taneja demonstrated Anthropic's Claude model identifying and chaining minor security weaknesses into functional exploits against Visa's payment network, the company's decision to open-source the testing harness signalled something beyond a standard security disclosure: enterprises are deploying agentic systems at scale without adequate containment mechanisms. The headline's framing—four of five organisations securing agent identities yet unable to contain a rogue instance—suggests that identity provisioning has outpaced governance infrastructure. This raises an immediate question for CX teams already running agent-based automation: if payment processors with dedicated security teams struggle to contain agent behaviour, what does this mean for support operations where agents handle customer data, refunds, and account modifications with inherited permissions from their human counterparts?
The implications cut across three operational layers. First, the permission enforcement gap is material: enterprises enforce agent permissions only two-thirds of the time, meaning one-third of deployments operate without explicit access controls. Second, the reliability problem compounds the security problem—organisations that experienced evaluation failures are paradoxically more likely to remove human oversight rather than strengthen it, creating a perverse incentive structure where bad experiences drive further automation rather than caution. Third, the success stories—LegalZoom resolving 40% of inquiries through agentic AI—mask the underlying fragility. CX leaders deploying agents for high-volume, low-complexity queries face a choice: treat agent containment as a post-deployment concern and accept the Visa scenario as inevitable, or architect permission boundaries and escalation protocols before agents inherit production access. The gap between deployment velocity and security maturity is not a technical problem waiting for vendor solutions—it is an operational governance problem that sits squarely in the CX function's remit.
Visa's president of technology, Rajat Taneja, walked the VB Transform 2026 audience through aiming Anthropic's Mythos at Visa's own payment network. The model stitched minor weaknesses into working exploit chains, and Visa open-sourced the harness that governed the hunt.That's wh