Skip to content
Insights
Field Notes

Harness Ships Security Agents That Patch, But Humans Still Sign Off

Harness, the software delivery platform company, launched AI agents that scan, triage, patch and virtually shield vulnerabilities, with developers approving every fix before it ships. What the agents actually do, where the approval boundary sits, and what the vendor's own numbers do and don't prove.

By Adam Maguire Wilson11 min read
On this page

Let me give the sceptics their best line first, because it's a good one: every security vendor on earth now claims its AI finds real bugs and writes real fixes, and most of those claims dissolve the moment a practitioner runs the thing on a codebase that isn't a demo. "Agentic AppSec" is the most crowded pitch in the industry this year. So when Harness, the software delivery platform company, announced on 19 August that its agents can scan, triage, patch and shield vulnerabilities at machine speed, the right first reaction is a raised eyebrow. Mine was raised too.

What kept my attention is where the agents stop. Every fix they write lands in a pull request that a human developer has to approve before anything ships. That sounds like a small design choice and it isn't: it's a bet about where the trust boundary in automated security actually sits, and it's the opposite bet to the fully autonomous offensive agents making headlines the same week. I've read the announcement and the coverage. Here's what the launch actually contains, and one housekeeping note: the company is called Harness, and the generic runtime concept I often write about is a harness, and the collision is coincidence. One wry line, delivered, moving on.

Key Takeaways - Harness launched five security capabilities on 19 August 2026: AI SAST, LLM Scan Orchestration, a Triage Agent, a Remediation Agent and a Zero-Day Agent, plus virtual patching that shields production without code changes. - The approval boundary is explicit: the Remediation Agent writes and validates a fix, then opens a pull request. A developer reviews and approves. Nothing merges itself. - The pitch rests on vendor figures: attackers going from disclosure to exploit in as little as six hours, an average fix time above 50 days, and Project Glasswing participants surfacing roughly ten times more vulnerabilities with LLM scanning. Treat these as reported, not audited. - The underlying tech is Qwiet AI's Code Property Graph, acquired last year, plus the Traceable merger from early 2025. This is an 18-month buildout, not a sudden pivot. - Deployment evidence is thin so far: "available now" to platform customers, no named early adopters for the agents themselves.

What happened

On 19 August, Harness announced what it calls machine-speed vulnerability response, a set of agents covering the whole life of a vulnerability from discovery to deployed fix. The components, per the press release and SiliconANGLE's coverage:

  • AI SAST. A deterministic static scanner with an AI layer on top that strips noise. Harness says the layer cuts false positives and catches logic flaws like IDOR and missing authorisation checks, the classes conventional pattern-matching tends to miss entirely.

  • LLM Scan Orchestration. If your team already runs its own LLM scanners, their output feeds into the same triage and remediation workflow natively in the pipeline, rather than dying in a separate dashboard.

  • Triage Agent. Takes the flood of scanner findings and narrows it to what's actually exploitable, using reachability data shared across all the agents.

  • Remediation Agent. Drafts a fix for a prioritised finding, validates it, and opens a pull request against the vulnerable function for a developer to approve.

  • Zero-Day Agent. Watches newly disclosed vulnerabilities around the clock, instantly maps every affected pipeline and artefact in a customer's environment, and generates a validated fix, often within minutes of a disclosure going public.

  • Virtual patching. Deploys a protective shield the moment a vulnerability is found during testing, blocking exploitation in production while the real fix is finished. No code changes required.

Everything is available now as part of the Harness platform. The spokesperson is Rahul Sood, general manager of application security, who arrived via Harness's acquisition of Qwiet AI and whose Code Property Graph technology underpins the scanning work.

Harness launched AI security agents on 19 August 2026 spanning SAST, triage, remediation, zero-day response and virtual patching, with the Remediation Agent opening pull requests that developers approve before fixes ship, per Harness's announcement and SiliconANGLE.

The approval boundary is the product

The detail I'd anchor on is the pull request. Harness could have shipped auto-merge. Plenty of vendors are heading that way, and the same week as this launch, Wiz was demonstrating an agent that exploits production systems without a human anywhere near the loop. Harness went the other direction: the Remediation Agent's output is a PR, full stop, and a named human merges it or doesn't.

That's a judgement about where agentic security earns trust in 2026, and I think it's the right call for the defensive side. The failure modes aren't symmetric. An offensive agent that oversteps produces a scary report. A remediation agent that auto-merges a bad fix produces an outage, or worse, a quietly broken security control that looks patched. Anyone who's read my piece on agent governance will recognise the shape: autonomy is something you grant per action class, not per product, and "proposes" is a much easier class to trust than "commits". The virtual patching feature is the one exception, since it acts on production without a code change, but it acts at the layer Harness already controls (the delivery pipeline and the web application protection it picked up with Traceable), and it's reversible by design.

The other boundary worth noting is scope. These agents only see what flows through Harness: your pipelines, your artefacts, your deployments. That's a smaller world than a general scanner claims, and smaller is good here. The Zero-Day Agent's trick of mapping a fresh CVE to every affected artefact in your environment in minutes only works because Harness already holds the software delivery knowledge graph of what you shipped and where. An agent grounded in your actual inventory beats a smarter agent guessing from a scan. That principle generalises well beyond security, and it's a big part of how I frame agentic architecture with clients.

Harness draws its approval boundary at the pull request: agents scan, triage, validate and draft, but a developer approves every code change before it ships. Virtual patching is the exception, acting on production through the delivery layer Harness already operates, per the announcement.

The numbers are the pitch, so read them like a pitch

The launch leans on three figures. Attackers using frontier models now go from public disclosure to working exploit in as little as six hours. The average vulnerability takes more than 50 days to fix. And participants in Anthropic's Project Glasswing, the programme giving defenders early access to Claude Mythos for security work, have surfaced roughly ten times more vulnerabilities using LLM-based scanning. As SC World and others repeated them, these all trace back to Harness.

Directionally, all three match what I hear from security teams: the discovery side has industrialised faster than the fixing side, and the backlog is the bottleneck. But I'd treat the specific figures as reported rather than audited. The six-hour number is a floor, not a median. The 50-day average is the kind of industry statistic that survives because nobody can quite falsify it. And the ten-times-finding number cuts both ways in a way the pitch glosses: if your LLM scanner finds ten times more vulnerabilities, and a chunk of those are false positives or unexploitable-in-practice, you've bought yourself a bigger haystack. Harness's answer is the Triage Agent and the shared reachability data, which is the right answer architecturally. Whether it holds up on a messy monorepo is exactly the kind of thing a press release can't tell you. Run it on your own backlog before you believe it.

The competitive context is real, though. Microsoft's MDASH and Project Perception, Anthropic's own defending-code harness, Wiz's Atlas topping CyberGym: the defensive agent category is arriving from several directions at once, and when that many serious teams ship the same layer of software within a year, the layer is probably load-bearing. It's the same pattern I noted when TrueForge open-sourced its agent runtime the same month.

Harness's launch figures (exploits in as little as six hours, 50-plus days average time to fix, roughly ten times more findings from LLM scanning among Project Glasswing participants) are vendor-reported and not independently validated, per SiliconANGLE's coverage. The direction matches the wider market; the specific numbers deserve a pinch of salt.

What the deployment evidence shows, and doesn't

Here's the honest inventory. The technology has a real lineage: Qwiet AI's Code Property Graph is a known quantity in AppSec, the Traceable merger brought web application and API protection in early 2025, and Agent DLC launched on 21 July with governance for AI coding agents. This is a company that spent 18 months assembling the pieces, backed by a $240 million raise at a $5.5 billion valuation last December. "Available now" means GA on the platform, not a waitlist.

What isn't there: a named customer running these agents in production, a published false-positive rate, an independent benchmark of the remediation quality, or any third-party validation that the fixes survive review. The strongest deployment claim in the launch is the Zero-Day Agent generating validated fixes "often within minutes", which is a capability statement rather than a case study. None of that makes the launch hollow; it makes it a launch. It does mean the evidence bar for adopting it should be your own trial data, not the announcement. If you're earlier in the journey and weighing whether to build this kind of capability in-house, the build versus buy trade-offs apply here exactly as they do anywhere else in the agent stack.

The security buildout behind the launch spans roughly 18 months: the Traceable merger in early 2025, the Qwiet AI acquisition bringing Code Property Graph scanning, Agent DLC in July 2026, and the security agents in August, per Harness's announcement and SiliconANGLE. Named production deployments of the new agents have not been published.

What to do now

If vulnerability response is on your plate:

  1. Measure your own two numbers first. Time from disclosure to exploit matters only relative to your time from finding to fix. Pull your actual mean time to remediate before you let a vendor's six-hour stat scare you into a procurement.

  2. Pilot on triage, not remediation. The Triage Agent is the lowest-risk entry point: worst case, it ranks your backlog badly and you ignore it. Let it chew on a quarter of real findings and check its exploitability judgements against your own before you let the Remediation Agent open PRs against anything that matters.

  3. Keep the approval boundary where Harness put it. Whatever tool you use, resist the temptation to auto-merge agent-written fixes this year. The economics of a human reviewing a diff are nothing next to the economics of an agent-shipped regression.

  4. Ask what the agent can see. The strongest part of this design is the inventory grounding. Whatever you adopt, prefer agents that reason over your real artefact graph over agents that reason over a filesystem snapshot.

FAQ

What do Harness's security agents actually do?

Five things. AI SAST scans code with an AI layer that filters false positives and catches logic flaws. The Triage Agent narrows findings to what's genuinely exploitable. The Remediation Agent drafts and validates a fix, then opens a pull request. The Zero-Day Agent monitors new disclosures and maps them to affected systems, often with a fix ready in minutes. Virtual patching shields production while the code fix is finished.

Do the agents deploy fixes on their own?

No. Code changes ship only as pull requests a developer reviews and approves. The one capability that touches production autonomously is virtual patching, which applies a protective shield at the delivery layer without changing code, and is designed to be reversible.

Who is Harness and why are they doing this?

Harness is a San Francisco software delivery platform company, last valued at $5.5 billion in a December raise. It merged with API security firm Traceable in early 2025, acquired Qwiet AI for its Code Property Graph scanning, and shipped Agent DLC for AI coding-agent governance in July 2026. The security agents are the next step in that buildout, and the name's resemblance to the agent-harness concept is pure coincidence.

Are the launch's security statistics reliable?

They're vendor-reported. The six-hour disclosure-to-exploit figure, the 50-plus day average fix time and the ten-times-finding claim from Project Glasswing all trace to Harness's own announcement. They point the right direction, but treat them as reported rather than audited until independent data appears.

The bottom line

The interesting thing about this launch isn't that AI can write patches; half the industry demoed that this year. It's that a delivery-platform company decided the trustworthy shape of a security agent is one that stops at a pull request, and grounded it in the inventory graph it already holds. Whether Harness's specific agents are good is a question only customer trials will answer, and the published evidence is still thin. But the design instinct, fast machines proposing, accountable humans disposing, is the one I'd bet on for defensive security this year. Watch for named deployments and independent fix-quality data over the next quarter. That's the difference between a launch and a shift.

If you're weighing agentic security tooling against your own pipeline, that's a conversation I have with clients regularly. Get in touch.

Sources

  • Harness, "Harness Launches AI Agents for Machine-Speed Vulnerability Response" (press release): https://www.harness.io/press-and-news/harness-launches-ai-agents-for-machine-speed-vulnerability-response (published 2026-08-19, retrieved 2026-08-29)

  • SiliconANGLE, "Harness launches AI agents that triage and patch vulnerabilities": https://siliconangle.com/2026/08/19/harness-launches-ai-agents-triage-patch-vulnerabilities/ (published 2026-08-19, retrieved 2026-08-29)

  • SC World, "Harness launches AI agents to find and fix software vulnerabilities": https://www.scworld.com/brief/harness-launches-ai-agents-to-find-and-fix-software-vulnerabilities (published 2026-08-20, retrieved 2026-08-29)

  • Unite.AI, "Harness Ships AI Agents to Scan, Triage, and Patch Vulnerabilities at Machine Speed": https://www.unite.ai/harness-ships-ai-agents-to-scan-triage-and-patch-vulnerabilities-at-machine-speed/ (published 2026-08-19, retrieved 2026-08-29)

  • DevOps Digest, "Harness Releases New Set of Security Capabilities": https://www.devopsdigest.com/harness-releases-new-set-security-capabilities (published 2026-08-28, retrieved 2026-08-29)

  • Harness Drone repository: https://github.com/harness/drone (retrieved 2026-08-29)

Keep reading

Agent Field Notes

Get the next issue.

Agent harnesses, runtimes, security and governance, explained for the people who have to operate them.

Facing a decision like this?

We run architecture reviews, governance assessments and version-pinned framework evaluations for teams making consequential agent decisions.

About the author

Adam Maguire Wilson

Founder and independent advisor on AI agent systems.

adam.mw