AI Security Testing LimitationsAgent harnesses can change red-team results: Lasso found that changing an AI agent’s runtime framework can significantly alter offensive-security performance. Strengthen AI Risk ManagementImprove AI risk management:Maintain an inventory of AI applications and agents, classify approved data usage, and establish governance policies. Continuously monitor AI activity and require human review before high-risk outputs or automated actions reach production. Integrate AI Governance With Existing SecurityStrengthen AI governance:Inventory AI assets, approve trusted models, and define ownership, policies, and acceptable-use rules. Test incident response for prompt injection, model abuse, compromised AI credentials, and data exposure.