AI Harness and the Standards Landscape

Standards bodies are converging on agentic risk faster than they are converging on agentic architecture. These mappings show where each document lands.

The category comparisons ask how AI Harness relates to the existing control stack — IAM, security monitoring, orchestration, guardrails. This section asks a different question: how does the doctrine relate to the published standards and guidance that address the same problem?

The answer is usually the same shape. Standards work is strongest at the control layer — what to require, what to prohibit, what to log. It is weakest at the architectural layer — where each control lives, which must hold simultaneously, and how far an organisation can safely extend autonomy today. Each mapping below is written to be useful in both directions: what the standard supplies that the doctrine does not, and what the doctrine supplies that the standard does not.


CISA — Careful Adoption of Agentic AI Services

The first multi-nation government guidance written specifically for agentic AI, published 30 April 2026 by six national cyber agencies. Its five risk categories independently reproduce three of the four threats this doctrine names. The most prescriptive control-level document published to date — and the clearest illustration of what a control catalogue cannot do on its own.


Further mappings are planned against the NIST AI Risk Management Framework, the EU AI Act, the OWASP Top 10 for Agentic Applications, and ISO/IEC 42001. Each will follow the same structure: what the document establishes, where the two converge, where each is thinner, and the gap that survives compliance.