The Australian Signals Directorate's ACSC published guidance on agentic AI harnesses, the software layer that connects a model with organisational data, tools and systems and manages context, memory, tool access and execution privileges. According to coverage, it says some risks, including prompt injection, cannot be addressed within the model alone, that no harness is inherently secure, and recommends least privilege, human oversight for high-impact actions, audit logging and validating agent outputs before execution.
Why it matters
It moves government guidance from model behavior to the tool, memory and permission layer where most agent compromises occur.
Key facts
As stated in the sources, with where to find them.
- ASD describes the harness as the software layer that connects models with organisational data, tools and systems, determining what the agent can access, which tools it can use, what actions it can execute and what controls apply.The Cyber Express summary
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
Sources
Related records
Sep 30, 2025
May 20, 2026
May 1, 2026
Feb 17, 2026
Dec 9, 2025
Jun 18, 2025