The layer above the model — ASD says security lives in the harness
The Australian Signals Directorate's executive guide, "Agentic AI Harnesses," names the harness — the software layer around the model — as where agentic-AI security must be applied, because the deepest weakness cannot be fixed in the model itself. MoorAI is a runtime control at that layer, and this post maps it to ASD's guidance without inflating it: strong on privilege and behavioural risk, tool and connector validation; partial by design on accountability, since content-free logging keeps categories and hashes rather than verbatim text; and an honest gap on design-time review, cascade tracing, sandboxing and model provenance. A government framework read straight, with the unflattering parts left in — and no claim that ASD endorses anything.