ACSC Guidance — Agentic AI Harnesses: The Layer Above the Model
The Australian Signals Directorate's ACSC published Agentic AI Harnesses — The layer above the model on 11 September 2026, a publication written for executive decision-makers, chief information security officers and IT leaders that reframes agentic AI risk around the harness: the software layer that supplies a large language model with context and memory, performs actions through tools and data sources, and enforces permissions over both. Its central claim is that organisations control the harness, not the model — the LLM is a pluggable component that can be swapped, while the harness ecosystem is the durable organisational capability in which long-term value, governance and security investment accumulate.
| Attribute | Detail |
|---|---|
| Publisher | ACSC (ASD) |
| Published | 11 September 2026 |
| Title | Agentic AI Harnesses — The layer above the model |
| Audience | Executives, CISOs and IT leaders; large organisations and government |
| Complements | Careful adoption of agentic AI services (ASD/CISA/NSA/Cyber Centre/NCSC-NZ/NCSC-UK) |
| Source | ACSC / cyber.gov.au — Tier 1/4 |
Security position
The publication states plainly that no harness is inherently secure and that some risks — prompt injection above all — cannot be reliably addressed within the model alone, which places the controls in the harness, the connected systems and the governance processes around them. It recommends least-privilege access, identity and access management, monitoring and audit logging, human oversight of high-impact actions, isolation of exploration in sub-agents, and a persistent organisational rules file that the harness reads each session. Its practical framing is that many apparent agent failures emerge from harness configuration rather than from the model: a model may propose a damaging command, but whether it executes depends on the harness and its controls.
Governance questions for executives
Seven assurance questions close the publication, among them what data, systems and tools the agent can reach; which actions require human approval; how prompt injection and data poisoning are mitigated; whether decisions, tool invocations and actions can be monitored and audited; and what the worst outcome is if the harness is compromised, misconfigured or manipulated.
Source
Related Pages
- Acsc Publishes Guidance On Secure Adoption Of Agentic Ai In Defence — the earlier ASD guidance this publication complements
- Acsc When Ai Agents Take Unexpected Actions — ACSC framing of goal misalignment and agent safeguards
- Aws Agentcore Harness Leaks Identity Vault Credentials To Prompt Injection Under — a concrete harness-level credential-exfiltration finding
- Ai Orchestrated Papercut Campaign Compromised 395 Organisations Most In Educatio — an AI-orchestrated campaign running in the same window