Harness design dictates frontier AI success in cyber defence
The Bank of England published findings from its Frontier AI Information Sharing Forum on September 2, 2026, highlighting that effective AI cyber defence depends on the architecture of surrounding harnesses rather than raw model capabilities alone.
Beyond raw model power
Frontier AI models require specialized harnesses—composed of workflows, validation controls, tools, and operating environments—to deliver actionable cyber defence.
Access to a raw model does not create an effective security capability on its own.
Instead, organizations must structure architectures that frame tasks, cross-check findings across specialized agents, and route issues to engineering teams.
While vendor platforms offer tight model alignment, they often lack contextual adaptability.
Conversely, internal and open-source components from initiatives such as Visa, XBow, and Terra increase flexibility but demand deeper engineering maintenance.
Orchestration layers help coordinate multiple tools without locking firms into single suppliers.
Balancing context with exposure
Deploying AI in cyber defence introduces critical trade-offs between organisational context and data security.
Feeding models source code or system architecture improves detection but elevates confidentiality risks.
Consequently, firms utilize isolated, sandboxed environments rather than live production networks.
Furthermore, scaling AI defence shifts pressure onto human teams: high volumes of automated findings require substantial validation and remediation capacity to prevent operational bottlenecks.
Plumbing over raw compute
Institutions risk wasting AI investments if they treat cyber defence as a simple model upgrade.
True operational gains depend on the rigorous plumbing of environment isolation and human triage.
Without solving the downstream remediation backlog, stronger models will only accelerate alert fatigue.
Source: Frontier AI: Harness engineering
IN: