ASD Urges Organizations to Secure the Layer Behind Agentic AI, Here’s Why
The Australian Signals Directorate (ASD) has released new guidance on Agentic AI Harnesses, highlighting the security, governance and operational risks organisations need to consider as they adopt agentic AI systems.

The Australian Signals Directorate (ASD) has released new guidance on Agentic AI Harnesses, highlighting the security, governance and operational risks organisations need to consider as they adopt agentic AI systems. The publication shifts attention beyond large language models (LLMs) to the software layer that connects models with organisational data, tools and systems. According to ASD, the AI harness is a critical component of an agentic AI system because it determines what information an agent receives, which tools it can access, what actions it can perform and what controls are applied. Why Agentic AI Harnesses Matter An agentic AI system combines an LLM with external tools, data sources, memory and planning workflows.
Excessive privileges can allow a compromised agent to have far-reaching access, while insecure architecture or configuration can introduce weaknesses before deployment. Security Controls for Agentic AI The publication recommends established cybersecurity practices, including least-privilege access, identity and access management, secure design, monitoring and incident response. As agentic AI adoption expands, ASD's guidance positions the harness as a central part of managing the technology's security, governance and operational risks.
Organisations should select harnesses appropriate to their tasks, understand their capabilities and permissions, and apply controls across multiple layers rather than relying solely on model behaviour or prompts.
ASD recommends a phased approach to deployment, beginning with approved use cases, appropriate data classification and security validation before broader adoption. The guidance also stresses that no harness is inherently secure.
Who is affected
Its components can include a user interface, policy layer, context manager, model interface, tool registry, permission system, execution environment, connector layer, memory and session store, and audit and observability capabilities.
Image Source: ASD- https://www.cyber.gov.au/ This makes the harness a key configuration surface for agentic AI security, particularly where organisations need to control tools, permissions, approvals and system integrations.
ASD Highlights Key Agentic AI Risks The guidance identifies five broad risk categories associated with agentic AI systems: privilege, design and configuration, behavioural, structural and accountability risks.
Accountability risks may arise when complex agentic systems make it difficult to trace decisions, audit actions or assign responsibility.
ASD also recommends treating multi-agent systems as a single agent for security purposes because a compromise in one component may propagate through shared context and trust relationships.
For executives and CISOs, ASD recommends asking what data and systems an agent can access, what actions require human approval, how AI-specific attacks are mitigated, whether significant actions can be monitored and audited, and what could happen if the harness were compromised or misconfigured.
Why this matters
Excessive privileges can allow a compromised agent to have far-reaching access, while insecure architecture or configuration can introduce weaknesses before deployment.
Security Controls for Agentic AI The publication recommends established cybersecurity practices, including least-privilege access, identity and access management, secure design, monitoring and incident response.
As agentic AI adoption expands, ASD's guidance positions the harness as a central part of managing the technology's security, governance and operational risks.
The technical picture
Organisations should select harnesses appropriate to their tasks, understand their capabilities and permissions, and apply controls across multiple layers rather than relying solely on model behaviour or prompts.
How organizations are responding
ASD recommends a phased approach to deployment, beginning with approved use cases, appropriate data classification and security validation before broader adoption.
The guidance also stresses that no harness is inherently secure.
What remains unknown
The available reporting does not establish whether the issue is being actively exploited in the wild.
The available reporting does not establish who is behind the activity, if an attacker is involved.