Startups

Agentic AI Harnesses: ASD Releases New Security Guidance

The (ASD) has released new guidance on , highlighting the security, governance and operational risks organisations need to consider as they adopt agentic AI systems. The publication shifts attention beyond large language models (LLMs) to the software layer that connects models with organisational data, tools and systems.

According to ASD, the is a critical component of an agentic AI system because it determines what information an agent receives, which tools it can access, what actions it can perform and what controls are applied.

Why Agentic AI Harnesses Matter

An agentic AI system combines an LLM with external tools, data sources, memory and planning workflows. While the LLM processes information and proposes actions, the harness provides the surrounding infrastructure needed to execute those actions and enforce permissions.

ASD said many significant organisational risks emerge when an LLM is connected to enterprise systems through a harness. Security, privacy, governance and operational risks can depend on what an agent can access, the actions it can perform and how it interacts with connected systems.

The publication also notes that some risks, including , cannot be reliably addressed within the model alone. Additional controls are required across the harness, connected systems and organisational governance processes.

Harness Becomes a Long-Term Security Focus

ASD describes the harness as the component organisations can most directly govern, secure and control. While LLMs can be replaced as models evolve, the harness and its surrounding integrations are expected to represent a longer-term organisational investment.

The harness can manage context and memory, provide access to tools, enforce execution privileges and record activity for monitoring and evaluation. Its components can include a user interface, policy layer, context manager, model interface, tool registry, permission system, execution environment, connector layer, memory and session store, and audit and observability capabilities.

Image Source: ASD- https://www.cyber.gov.au/

This makes the harness a key configuration surface for agentic AI security, particularly where organisations need to control tools, permissions, approvals and system integrations.

ASD Highlights Key Agentic AI Risks

The guidance identifies five broad risk categories associated with agentic AI systems: privilege, design and configuration, behavioural, structural and accountability risks.

Excessive privileges can allow a compromised agent to have far-reaching access, while insecure architecture or configuration can introduce weaknesses before deployment. Behavioural risks include unintended actions and manipulation through techniques such as prompt injection and data poisoning.

Structural risks can emerge when failures cascade across interconnected components and workflows. Accountability risks may arise when complex agentic systems make it difficult to trace decisions, audit actions or assign responsibility.

ASD also recommends treating multi-agent systems as a single agent for security purposes because a compromise in one component may propagate through shared context and trust relationships.

Security Controls for Agentic AI

The publication recommends established cybersecurity practices, including least-privilege access, identity and access management, secure design, monitoring and incident response.

Organisations are also advised to require human oversight for high-impact actions, control access to external data and tools, validate agent outputs, maintain audit logs and apply supply-chain assurance.

ASD recommends a phased approach to deployment, beginning with approved use cases, appropriate data classification and security validation before broader adoption.

The guidance also stresses that no harness is inherently secure. Organisations should select harnesses appropriate to their tasks, understand their capabilities and permissions, and apply controls across multiple layers rather than relying solely on model behaviour or prompts.

For executives and CISOs, ASD recommends asking what data and systems an agent can access, what actions require human approval, how AI-specific attacks are mitigated, whether significant actions can be monitored and audited, and what could happen if the harness were compromised or misconfigured.

As agentic AI adoption expands, ASD's guidance positions the harness as a central part of managing the technology's security, governance and operational risks.

Source

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button