You rent the model. You own the harness.
Why regulated finance needs harness engineering, and why governance is load-bearing design.
If you are evaluating an AI agent for your product, the most important part is the one nobody demos. Engineers call it the harness: everything built around the model that makes it safe to rely on. The model does the reasoning. The harness decides what the agent knows, what it is allowed to say, when it must stop, and how you know it is working.
The vocabulary is new. Mitchell Hashimoto gave it a name in early 2026 with a simple formula: an agent is a model plus a harness. The formula matters because of what it implies. Everyone rents the model, and increasingly they rent the same few. What you own is the harness. In most industries that makes the harness a differentiator. In regulated finance it makes the harness the product.
A wrong answer is a liability
Consider what a wrong answer costs in different domains. A coding agent that writes a bad function costs a code review. A travel agent that books the wrong hotel costs an apology and a refund. In both cases the failure is contained and the remedy is cheap.
Now put an agent inside a lending product and let it talk to a customer about money. Here a wrong answer can be an unfair or deceptive practice. It can be a mishandled dispute, a missed adverse action notice, or advice the company is not licensed to give. The remedy for those is a finding, a consent order, or a headline.
This changes the engineering problem at its root. You cannot make a probabilistic system deterministic by asking it nicely. Prompts are suggestions, and regulators do not accept suggestions as controls. So reliability cannot live in the model. It has to live in the structure around the model, which is to say the harness.
What the harness has to do
Four design problems come up in every regulated deployment I have seen. They sound similar, but each one needs its own design.
First, what the agent knows. The knowledge base is a designed artifact. It encodes the domain, the product, the tone, and the boundaries, structured so the right piece surfaces at the right moment. A pile of documents does none of that.
Second, what the agent may say. Knowing and saying are different permissions. An agent inside a financial product may understand a customer’s full situation. It can still be limited in what it surfaces, because licensing rules, suitability, privacy, and timing all constrain what is sayable. Separating knowledge from permission is the core architectural move, and most teams skip it.
Third, when the agent must stop. Escalation is a designed outcome, with its own triggers, its own handoff, and its own audit trail. Deterministic policy layers sit above the model and do not negotiate. They require step-up confirmation for consequential actions, refuse where the law draws lines, and route to a human where judgment is required.
Fourth, how you know it holds. Evals are the sensors of the harness. In finance the interesting metric is rarely task completion. It is behavioral: did the customer understand, did the action match their interest, and did the conversation stay inside policy under pressure. Ship with gates that measure those outcomes.
Governance is load-bearing
The common failure pattern treats all of this as a wrapper. Build the agent, send it to compliance, then bolt on guardrails wherever the reviewers object. Wrapper thinking has two outcomes, and both are bad. Either the launch stalls while governance retrofits what should have been foundations, or the product ships and the risk ships with it.
The alternative is to treat governance as load-bearing design. The policy layer determines what the agent can see, say, and do in the first place, instead of filtering its output afterward. Designed in from the start, governance stops being the department of no. It becomes the reason the product is allowed to exist.
There is a quieter benefit too, and it is behavioral. People can feel the difference between a system that is confident and one that is trustworthy. An agent that holds back when it should, confirms before consequential steps, and hands off gracefully earns something valuable. It earns the customer’s willingness to come back tomorrow. In financial products, trust is retention.
The part you own
The models will keep improving, and everyone’s models will improve together. Waiting for a smarter model to solve reliability is waiting for a rising tide to build your boat.
The harness is where the durable work is. It encodes your domain, your policies, your risk appetite, and your understanding of the people you serve. It is the part that compounds, the part a competitor cannot rent, and the part a regulator can actually inspect.