Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-11 · updated: 2026-09-11 · tags: [incident, acsc, ai-agents, guidance, australia, governance] · confidence: high · affected_sectors: [government, technology] · au_impact: true

ACSC Guidance — Agentic AI Harnesses: The Layer Above the Model

The Australian Signals Directorate's ACSC published Agentic AI Harnesses — The layer above the model on 11 September 2026, a publication written for executive decision-makers, chief information security officers and IT leaders that reframes agentic AI risk around the harness: the software layer that supplies a large language model with context and memory, performs actions through tools and data sources, and enforces permissions over both. Its central claim is that organisations control the harness, not the model — the LLM is a pluggable component that can be swapped, while the harness ecosystem is the durable organisational capability in which long-term value, governance and security investment accumulate.

Attribute Detail
Publisher ACSC (ASD)
Published 11 September 2026
Title Agentic AI Harnesses — The layer above the model
Audience Executives, CISOs and IT leaders; large organisations and government
Complements Careful adoption of agentic AI services (ASD/CISA/NSA/Cyber Centre/NCSC-NZ/NCSC-UK)
Source ACSC / cyber.gov.au — Tier 1/4

Security position

The publication states plainly that no harness is inherently secure and that some risks — prompt injection above all — cannot be reliably addressed within the model alone, which places the controls in the harness, the connected systems and the governance processes around them. It recommends least-privilege access, identity and access management, monitoring and audit logging, human oversight of high-impact actions, isolation of exploration in sub-agents, and a persistent organisational rules file that the harness reads each session. Its practical framing is that many apparent agent failures emerge from harness configuration rather than from the model: a model may propose a damaging command, but whether it executes depends on the harness and its controls.

Governance questions for executives

Seven assurance questions close the publication, among them what data, systems and tools the agent can reach; which actions require human approval; how prompt injection and data poisoning are mitigated; whether decisions, tool invocations and actions can be monitored and audited; and what the worst outcome is if the harness is compromised, misconfigured or manipulated.

Source

Related Pages