{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/asd-agentic-ai-harnesses-guidance-2026/",
 "asOf": "2026-09-26",
 "id": "asd-agentic-ai-harnesses-guidance-2026",
 "date": "2026-09-11",
 "datePrecision": "day",
 "title": "Australia's ASD issues guidance on securing agentic AI harnesses, the layer around the model",
 "lane": "policy",
 "kind": "guidance",
 "summary": "The Australian Signals Directorate's ACSC published guidance on agentic AI harnesses, the software layer that connects a model with organisational data, tools and systems and manages context, memory, tool access and execution privileges. According to coverage, it says some risks, including prompt injection, cannot be addressed within the model alone, that no harness is inherently secure, and recommends least privilege, human oversight for high-impact actions, audit logging and validating agent outputs before execution.",
 "whyItMatters": "It moves government guidance from model behavior to the tool, memory and permission layer where most agent compromises occur.",
 "actors": [
  "asd-acsc"
 ],
 "topics": [
  "standards-and-guidance",
  "tool-and-mcp-security",
  "sandbox-containment"
 ],
 "atlas": [
  "tools",
  "memory",
  "credentials"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/agentic-ai-harnesses",
   "publisher": "Australian Signals Directorate",
   "title": "Agentic AI harnesses: The layer above the model",
   "date": "2026-09-11",
   "type": "primary",
   "accessed": "2026-09-26"
  },
  {
   "url": "https://thecyberexpress.com/agentic-ai-harnesses-asd-releases-new-guidance/",
   "publisher": "The Cyber Express",
   "title": "Agentic AI Harnesses: ASD Releases New Security Guidance",
   "date": "2026-09-11",
   "type": "secondary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "ASD describes the harness as the software layer that connects models with organisational data, tools and systems, determining what the agent can access, which tools it can use, what actions it can execute and what controls apply.",
   "locator": "The Cyber Express summary"
  }
 ],
 "significance": 3,
 "fideQuestions": [],
 "methods": [
  "capability-restriction",
  "memory-poisoning"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}