Changelog
The doctrine is versioned, dated, and revised in the open.
A doctrine that asks enterprises to govern autonomous behavior must itself be governed: every substantive change to the AI Harness Doctrine is versioned, dated, and recorded here. The current version is v3.2.
In review
RFC 001: The Conformance Layer proposes a fourth doctrine layer for v4: twenty-nine testable, mechanism-agnostic Conformance Criteria across the five Architectural Planes, an Action Tiering construct that closes the Law 5 gap recorded below, an architectural home for Intent Hijacking, and a rebuild of the Maturity Model as an assessment instrument in which each level licenses a tier of agent action. Now at revision 2 (1 August 2026), which corrects three internal contradictions found in adversarial review of revision 1 and records them openly. Open for comment through 31 October 2026. It is a proposal and is not in force.
v3.2 · July 31, 2026
- Opened the standards landscape section: mappings between the doctrine and published standards or government guidance on agentic AI.
- First mapping published: CISA's Careful Adoption of Agentic AI Services (30 April 2026). Three of the four named Threat Surface items have verbatim counterparts in its risk categories, arrived at independently.
- Recorded two acknowledged gaps in the doctrine relative to that guidance: Agent Identity & Lifecycle states the identity requirement without specifying mechanism, and Humans Retain the Right to Intervene asserts the right without defining the stakes tiers at which it is exercised. Both are carried as open revision items.
- Recognised “authority drift” as a secondary term in circulation for the failure mode Least Agency constrains, noted on the CISA mapping. Least Agency remains the canonical name.
v3.1 · June 10, 2026
- Added stable anchor identifiers to every Law, Plane, and Pillar so external documents can cite doctrine sections directly.
- Introduced doctrine versioning, this changelog, and structured publisher metadata (author: AI Harness Institute).
- Published the category comparison series: AI Harness vs Identity & Access Management, Security Monitoring, Orchestration, and AI Guardrails.
- Published llms.txt for language-model discoverability.
v3.0 · May 11–12, 2026
Major revision of the doctrine's structure and vocabulary.
- Least Agency introduced as a first-class principle, the third leg of the governance trilogy (Least Privilege → Least Trust → Least Agency) — and landed in Law 1.
- Law 4 renamed from "Agent-to-Agent Trust Must Be Explicit" to "Trust Does Not Travel," broadening its scope to every handoff type: delegation, orchestration, tool invocation, and subagent spawning.
- Architecture expanded from 4 to 5 Planes. Plane 5 (Multi-Agent Trust & Delegation) added as the architectural home of Law 4; Plane 1 renamed to Agent Identity & Lifecycle; Plane 4 broadened to Human Oversight, Audit & Traceability.
- Framework expanded to 6 Pillars. Mission Definition split out from Agent Identity; Multi-Agent Governance added.
- Threat Surface section added to the Declaration: prompt injection, intent hijacking, cascading failure, behavioral drift.
- Maturity Model published as a standalone page: Identified → Governed → Continuous.
- The Declaration's three non-negotiables sharpened; homepage redesigned.
v1.0 · May 8, 2026
- Initial public publication of the AI Harness Doctrine at aiharnessdoctrine.org: Declaration, 5 Laws, Architecture, Framework, and the Zero Trust parallel.
Proposed revisions are evaluated against one test: does the change make autonomous AI agents more governable at runtime, across systems, at the level of behavior?