All insights

The harness is the operating model: why AI projects fail in the layers around the model

The FCA's frontier AI review shows the model is only as good as the operating model around it. The harness is now the project.

By Nick Ross7 min read
Editorial illustration for: The harness is the operating model: why AI projects fail in the layers around the model
See also: Target State – Issue 6

It is 07:10 and the vulnerability report has arrived, forty findings deep, each one produced by a frontier AI model in the time it takes to pour a coffee. The model has been running all night against the firm's code and configuration. It has found things: a chained sequence of three medium-severity weaknesses that, together, let an attacker escalate privileges. A patch that was tested but never deployed. Nobody doubts the findings. The problem is what happens next. There are forty findings, one security engineer, and a release cycle that moves at the speed of the change board. The model is not the bottleneck. The firm is.

What it is

On 2 September, the FCA published its multi-firm review of how financial services firms use, test and prepare for frontier AI models with cybersecurity capabilities. The word it chose for the problem above is the most important word in the document: harness.

The FCA's central finding is one sentence long and worth reading twice: the utility of a frontier AI model depends heavily on "the governance, tooling, controls, operating context, and human expertise surrounding it" – what the regulator calls the model's harness. The model is the engine. The harness is everything the engine sits in: who owns it, who validates what it produces, how exceptions are handled, where its data comes from, how fast the organisation can respond when it finds something.

The review's findings are a catalogue of harness failures. Frontier AI is accelerating vulnerability discovery, but that creates bottlenecks in firms' validation, prioritisation and remediation processes, including engineering capacity, patch-testing and change management. Conventional risk severity scores may not capture the risk created when AI identifies combinations of lower-rated weaknesses that can be chained together. Firms need clear ownership and escalation routes for AI use, and specialist human judgement to separate genuinely exploitable vulnerabilities from theoretical findings. And frontier AI exposes weaknesses in the unglamorous foundations: asset and dependency mapping, access controls, remediation capacity, vulnerability management.

The FCA's practical message is blunt: frontier AI use is increasingly a test of firms' existing organisational, cyber and operational resilience, rather than a new standalone technology tool. The model finds the problems. The operating model decides whether anything gets fixed.

Why it matters now

Three things happened in the same week, and together they mark the moment the harness stopped being a governance footnote and became a commercial category.

First, Brown Brothers Harriman launched Braid, a technology affiliate selling exactly the layer this piece is about: agentic AI data transformation with enterprise-grade controls, a centralised oversight dashboard for breaks and exceptions, and a "controlled and deterministic environment" for regulated firms. Business users describe the transformation they need in natural language; AI agents build it. BBH's pilot numbers claim efficiency gains as high as 98% across three use cases, including unifying data from more than 150 external providers. A custodian, in other words, has productised the connective tissue of its clients' operating models and is selling it back with the governance built in.

Second, ValueExchange's latest research finds roughly half of the post-trade industry is now using generative AI in some form, while agentic AI adoption lags. The priority firms name is not more automation but improved accuracy and fewer operational errors. That is a harness metric. The industry has stopped asking what the models can do and started asking whether the surrounding machinery can be trusted with them.

Third, the regulators on both sides of the Channel are now supervising the harness itself. The FCA's review is supervisory observations, not rules, but it sits alongside the European Supervisory Authorities' July statement on frontier AI ICT risks, which expects firms' management bodies to be fully engaged in mitigating AI-driven cyber risk. The direction is unmistakable: the question regulators will ask is not which model you deployed, but whether the operating model around it can absorb what the model finds.

If someone can sell the harness, then the harness is a layer of the operating model. And if it is a layer of the operating model, it needs the same discipline as every other layer: ownership, process, controls, sign-off.

What firms should do

Write the harness down

For every production or near-production AI capability, document the layers around it: data sources, ownership, validation points, escalation routes, exception handling. Turn those into processes with owners and hand-offs, not paragraphs in a policy document. If you cannot draw the harness, you do not have one. You have a model running loose.

Make the build/buy call layer by layer

Data transformation, orchestration, oversight tooling – each can now be bought, and the vendors are good. That is not a reason to buy all of it. Decide deliberately which layers you keep: the layers that carry accountability (sign-off, exception handling, escalation) and the layers that differentiate you (your golden source, your client data) are the ones worth owning. Everything else is a candidate for a product. The firms that get this wrong do it by default: the brochure decides for them.

Measure errors, not adoption

Align the AI business case to the industry's own stated priority: accuracy and fewer operational errors. Breaks caught, exceptions resolved, errors per thousand. Gate agentic deployments on harness readiness, not model capability. A model that is 98% right and ungoverned is a control failure. A model that is 80% right and harnessed is an asset. The difference is not the model. It is everything around it.

The opmodal perspective

The Architecture Canvas methodology captures an operating model across its processes, systems, people, risks and controls, with owners and sign-off attached to each layer. The harness is simply that model applied to AI. Every AI deployment inherits the operating model it sits in: a model deployed on top of unclear ownership, unwritten exception handling and unverified data produces confident errors at machine speed. The same model, deployed on top of a governed, owned and re-certified operating model, produces traceable, auditable output. The FCA's frontier AI review is, in effect, a supervision of operating models with a model in the middle – and the firms that pass will be the ones that already treat process ownership as load-bearing.

The harness was always the project. The models just made it visible.