The Australian Signals Directorate has published “Agentic AI Harnesses – The layer above the model”. Its argument is practical: you don’t control the AI model, but you do control the harness — the software that connects a model to your email, files, apps and data, and decides what it’s allowed to do.
The controls it recommends will look familiar to anyone who has worked through the Essential Eight: least privilege for the agent, human oversight for high-impact actions, audit logging, checking what the agent produces before it runs, layered controls, and a phased rollout rather than switching everything on at once.
Update, 25 September: the Medicare portal incident has since given the guidance a very public example. For a small business, the harness is usually the connectors and permissions inside Microsoft 365 Copilot, Copilot Studio or a third-party AI tool. Start with an inventory: which AI tools can reach which data, and which can take actions rather than just read.
