
The AI harness
AI security has a hype problem. Every week brings a new headline about agents escaping sandboxes, AI replacing security teams, or models becoming “too smart” to control. But the more useful question for CISOs is much more practical: where do the actual security controls belong? In this episode, I sit down with Diana Kelley , CISO at Noma Security and one of the clearest voices in AI security, to separate AI mythology from operational reality. Diana explains why the LLM itself is not the security boundary, why the “harness” around the model matters, and how security teams should think about contamination, consequence, and runtime control as agentic AI moves into the enterprise. This conversation is not about AI hype. It is about what CISOs, security architects, and technical leaders need to understand before AI systems start taking autonomous action at machine speed. What You’ll Learn Why AI security is different from traditional AppSec What an AI “harness” is and why it matters Why the LLM should not be treated as a security control How prompt injection relates to trust boundaries and context windows Why agentic AI increases both speed and consequence Key Takeaways The model is not the control point. The LLM is powerful, but it is not deterministic enough to serve as the primary security boundary. Security controls need to live before and after inference — in the harness, surrounding software, workflow, and runtime environment. Think in terms of contamination and consequence. Contamination is what enters the context window. Consequence is what the system does after inference. Both need controls, especially when AI agents can act repeatedly and autonomously. Agentic AI changes the scale problem. A single bad prompt is one thing. Hundreds or thousands of agents looping through tasks at machine speed is another. The risk is not just bad output. It is autonomous action without adequate guardrails.


