16 Sep 2026

New ASD Guidance Puts the Spotlight on Agentic AI Harnesses

As organisations explore agentic AI, the Australian Signals Directorate (ASD) has released new guidance focusing on a critical part of these systems that sits beyond the AI model itself: the agentic AI “harness”.

Agentic AI.png

Published on 11 September 2026, Agentic AI Harnesses: The layer above the model explains how this software layer connects a large language model (LLM) with organisational data, tools and systems, and why it should be a major focus for security, governance and risk management.

What is an AI harness?

ASD describes the LLM as the “brain” of an agentic AI system, while the harness acts as the “body”. The harness provides the model with context and memory, enables it to access data and use tools, and can enforce permissions and controls over what the AI is able to do.

This distinction becomes particularly important when AI moves beyond generating content and begins interacting directly with enterprise systems, accessing organisational information or performing actions.

According to ASD, many of the highest-impact organisational risks arise from what an AI agent can access, the actions it is permitted to perform and how it interacts with connected systems. The guidance identifies the harness and its surrounding technical ecosystem as a primary area for security and risk management.

Security and governance need to go beyond the model

ASD warns that no harness is inherently secure. Organisations should apply established cybersecurity practices including least-privilege access, identity and access management, secure design, monitoring, human oversight and integration with incident response processes.

The guidance also recommends a phased approach to adopting agentic AI, including defining approved use cases, classifying data, selecting appropriate harnesses and validating security controls before broader deployment.

One of the key messages is that organisations need to understand not only the AI model they are using, but also the infrastructure surrounding it. This includes the harness’s capabilities, permissions, integration points and security controls.

As agentic AI becomes increasingly connected to organisational information and business systems, understanding this layer will be an important part of establishing appropriate security, governance and accountability.

Original source: Australian Signals Directorate, Australian Cyber Security Centre, Agentic AI Harnesses: The layer above the model, published 11 September 2026, read here.