Field Notes · daily AI intelligence for Australian business
← Field Notes

AI Use Cases

Buying an AI Agent? The Risk Is the Harness, Not the Model

Australia's cyber agency (ASD) says the risk in an AI agent isn't the model — it's the harness that holds your keys. What to check before you buy one.

The part of the AI agent nobody demos

The AI agent a vendor wants to sell you runs on a model you've heard of — ChatGPT, Claude, Gemini. The part that can actually cost you money is the part that never makes it into the demo. On 11 September, the Australian Signals Directorate's Cyber Security Centre put out guidance with a blunt message for anyone deploying one: the model isn't where your risk lives. The harness is.

What ASD actually published

An AI agent is not a chatbot. A chatbot answers; an agent acts. To do that, the language model has to be wired into your real systems — your inbox, your accounting file, your job-management software, sometimes your bank feed — and handed the authority to take steps on its own, in a loop, until it decides the task is done. ASD's guidance, *Agentic AI Harnesses — the layer above the model*, is about that wiring. The harness is the software layer that connects the model to your tools and data, enforces what the agent is allowed to do, and runs the loop.

Its central finding: most of the serious risks — privilege, design, behavioural, structural and accountability — come from the harness, not the model. The guidance is written for the people signing off on agentic AI, and it is freely available on cyber.gov.au. Its practical advice is short: match the harness to the task, grant only the access the job needs, put controls at every layer, and keep a human accountable for what the agent decides and does.

Want to know what this means for your business? We'll map it in one call.

Book a call

Why this changes what you're buying

For a small business, this reframes the buying decision. Vendors sell on the model — "powered by frontier AI". But the model is the commodity; every serious agent rents one of the same handful. What differs, and what you're actually paying for, is the harness around it: how tightly it's scoped, whether it asks before it acts, whether it keeps a record. Two agents running the identical model can be worlds apart on risk. The brand on the box tells you almost nothing about whether the thing is safe to let near your business.

The line that should stop an owner-operator is the one about accountability. The harness can act for you; it cannot be liable for you. If an agent emails the wrong client file, approves a payment to a spoofed supplier, or quotes a job at a number that loses you money, that's your business's mistake — the same hard edge we hit when Australian firms started pulling their customer-facing AI agents. And an agent works in a loop at machine speed: a bad instruction doesn't cost you one error, it can cost you a hundred before anyone looks. On a $65–95 loaded hourly rate, the time to unwind that is real money — and a client-facing slip costs more than the hours. The upside is genuine; this is an Admin Leverage play. ASD's point is that you capture it by controlling the harness, not by trusting the model. If you're weighing where an agent could safely start in your business, that's the question to settle before you sign anything.

96%

of organisations already run AI agents in some form

OutSystems, 2026 — global, directional for SMEs

12%

have a central way to manage the agents they've deployed

The gap ASD's harness guidance is about

5

risk categories ASD ties to the harness, not the model

Privilege, design, behavioural, structural, accountability

Five checks — and a script for the vendor

You don't need a security team to act on this. You need a short checklist, drawn straight from ASD's own advice, and it doubles as a buyer's script. Match the harness to the task: a tool that drafts and summarises needs far less reach than one that pays and sends. Grant least privilege — the minimum access for the job, read-only wherever reading is enough. Insist on a human checkpoint for anything irreversible: money leaving the account, a contract, an external send. Require an audit log, so you can see what the agent did and with whose access. And deploy in phases — prove it on low-stakes internal work before you widen its scope.

Then turn those five into questions for the vendor: what can your harness reach, what does it do without asking, and can you show me the log? A vendor who can't answer plainly is selling you the model, not the harness. This is the buy-side companion to a decision we've covered from the other direction — what to limit before you connect an agent to your data.

Key takeaways

01On 11 September 2026, ASD's Australian Cyber Security Centre published guidance saying the main risks of an AI agent come from the harness — the layer that wires the model to your tools and takes actions — not the model itself.
02The model is a commodity; the harness is what you're actually buying. Two agents on the same model can differ completely on risk depending on how the harness is scoped.
03You keep human accountability for what an agent does. It acts in a loop at machine speed, so one bad instruction can multiply before anyone notices.
04ASD's controls double as a buyer's script: match the harness to the task, grant least privilege, require a human checkpoint on irreversible actions, demand an audit log, and deploy in phases.

Common questions

What is an AI agent 'harness'?

It's the software layer that connects the AI model to your tools, data, memory and planning, enforces what the agent is allowed to do, and runs the loop until a task is done. ASD's 11 September 2026 guidance says most of an agent's risk lives in this layer, not in the model.

Does the AI model an agent uses determine how safe it is?

Largely no. ASD's guidance says the harness — how the model is wired to your systems and what it's permitted to do — drives the risk. Two agents built on the same model can differ completely in safety depending on how their harness is scoped and controlled.

Who is liable if an AI agent makes a mistake in my business?

You are. ASD stresses keeping clear human accountability for an agent's decisions, actions and outcomes. The harness can act on your behalf but can't hold the liability, so keep a human checkpoint on anything irreversible — payments, contracts and external sends.

Sources

Assumptions & methodology
  1. ASD's ACSC guidance 'Agentic AI Harnesses — the layer above the model' was first published on 11 September 2026 and is available on cyber.gov.au. It defines the harness as the software layer connecting the model to tools, data, memory and planning workflows, and attributes privilege, design, behavioural, structural and accountability risks to that layer.
  2. The 96% and 12% figures are from OutSystems' 2026 agentic-AI research (nearly 1,900 IT leaders worldwide). They are global and skew to larger organisations, so treat them as directional for an Australian SME, not SME-specific.
  3. The $65–95 loaded hourly rate is a general range for Australian small-business labour, used to illustrate the cost of unwinding an agent's error. It is illustrative and not drawn from the ASD guidance.
ShareLinkedInEmail

Field Notes are general commentary on AI trends for Australian businesses. They don’t constitute professional advice. Talk to your accountant, lawyer, or IT adviser before acting on anything specific to your situation.

Talk to us

Not sure what to ask before you buy an AI agent?

The gap between an agent that saves you a day a week and one that becomes a liability is the harness around the model — and most vendors won't volunteer the difference. A short call will give you the questions to ask and the limits to set before you commit. Book a call to talk it through.

Don't miss the next one

Get each new Field Note in your inbox as it publishes — short, practical AI intelligence for business owners.