ASD Warns Businesses: AI's Biggest Flaw Can't Be Patched, Only Contained
The Australian Signals Directorate (ASD) has released guidance warning that a fundamental security weakness in agentic AI systems has no reliable technical fix. The issue, known as prompt injection, occurs because AI language models process instructions and data in the same stream and cannot reliably tell the difference between the two. This means malicious content fed to an AI agent can be mistaken for a legitimate command.
ASD's guidance introduces the concept of the 'harness', everything surrounding the AI model itself, including connectors, permission systems, and memory stores. Because organisations cannot fix the underlying model, ASD argues the harness is the part they actually control and should focus on securing. The agency notes this harness will likely remain in use across multiple generations of AI models.
This view aligns with the UK's National Cyber Security Centre, which reached a similar conclusion last year, comparing AI models to an inherently 'confusable deputy' rather than a system with a bug that can simply be patched. Both agencies suggest that where the risk is too high, some use cases may simply not be suitable for AI at all.