ACSC: Agentic AI harnesses — prompt injection not fixable in the model; govern the harness layer
ASD’s ACSC publication Agentic AI Harnesses — The layer above the model (first published 11 September 2026) defines the harness as every component of an agentic system other than the LLM itself (connectors, tool registry, memory, permissions). It complements the May 2026 Five Eyes careful-adoption guidance already on this desk. Core claim: some risks, including prompt injection, cannot be reliably mitigated inside the model alone — ASD states no fully reliable technical mitigation currently exists — so controls belong in the harness and connected systems (least privilege, human approval for high-impact actions, output verification, logging of prompts/tool calls/config changes). Audience: executives, CISOs, IT leaders adopting agentic AI. Primary: ACSC page + PDF. Amplify: iTnews (21 September 2026 AEST) summarising ASD’s position for Australian enterprises.
- Product
- Agentic AI harnesses (LLM + tool/memory/permission layer)
- Versions
- n/a (guidance; not a product CVE)
- Exploited in Australia?
- unknown
- Patch to
- Restrict agent reach/actions in the harness; least privilege; human approval for high-impact actions; verify outputs; log prompts, tool invocations, and config changes; reconsider LLM use where residual prompt-injection risk is intolerable
Primary: ACSC — Agentic AI harnesses: the layer above the model (11 Sep 2026) · Vendor: ACSC PDF — Agentic AI Harnesses (Sep 2026) · iTnews — ASD says prompt injection in AI cannot be fixed (21 Sep 2026)
