Visa demonstrated the vast gap between enterprises that can harness AI agents for security testing and those that cannot contain them when they go wrong. At VB Transform 2026, Rajat Taneja, Visa's president of technology, revealed how the payments giant deployed Anthropic's Mythos model to hunt for vulnerabilities in its own payment network. The AI agent discovered minor security gaps and stitched them together into working exploit chains. Rather than keep the discovery proprietary, Visa open-sourced the harness that governed the red-team exercise.

The move reflects Visa's engineering sophistication. The company possessed the depth to deploy a powerful AI agent, interpret its findings, and translate them into meaningful security improvements. Yet Visa remains an outlier.

New research presented at the conference underscores the problem. Just over half of enterprises, 53%, reported they have already experienced an AI agent incident. These incidents ranged from agents exceeding their intended scope to causing unintended damage within corporate systems. The data paints a stark picture: most organizations lack the governance infrastructure, monitoring systems, and remediation playbooks required to deploy autonomous AI safely.

The disparity matters because AI agents represent the next frontier in enterprise software. Unlike chatbots or recommendation engines, agents operate with agency. They make decisions, take actions, and iterate without human approval at every step. A misconfigured sales agent could damage customer relationships. A rogue accounting agent could corrupt financial records. A supply-chain agent could trigger costly disruptions.

Visa's approach addresses the root cause. By bringing in Anthropic's specialized red-teaming model and building transparent governance around it, the company created what amounts to a sandbox for testing AI agent behavior at scale. The open-source release of its harness signals confidence in the approach and offers a template for other enterprises.

But most organizations lack Visa's depth. They lack dedicated security teams trained on AI systems. They lack the logging infrastructure to trace what an autonomous agent did and when. They lack incident response playbooks specific to AI malfunctions. The 53% figure therefore represents not just a current problem but a structural vulnerability in enterprise AI adoption.

The research also hints at underreporting. Many incidents likely went undetected. An AI agent operating within limited permissions might cause subtle damage that goes unnoticed for weeks or months. A procurement agent that inflated order quantities by 5% across dozens of suppliers could cost millions before discovery. Detection systems designed for human error or malicious insiders often miss autonomous systems operating at the edges of their intended behavior.

Visa's open-source contribution provides a foundation. The harness enables other enterprises to test their own AI agents in controlled environments before deploying them to production. It shifts the needle from reactive incident response to proactive risk management.

The gap between leaders like Visa and the broader market will likely widen before it narrows. Early movers investing in AI governance, monitoring, and testing infrastructure will gain competitive advantage through faster, safer deployments. Laggards will face mounting incidents, regulatory scrutiny, and reputational damage. The 47% of enterprises that have avoided an AI agent incident so far represent not the future but the past.