Nadella Tells Companies to Build AI Around Distrust
Microsoft's chief executive wants external controls, auditable actions and a human-operated emergency brake for advanced AI. His public post sets out principles, not a new Microsoft policy.
Microsoft chief executive Satya Nadella has urged companies to assume advanced AI models are compromised from the start, putting human control ahead of trust in their behaviour. [1][2]
In a long post published on X and his personal blog, "sn scratchpad," on October 10, 2026, Nadella argued that models should be treated as insider risks: systems operating within an organisation whose access and actions need to be contained. He called for an "emergency brake" that would let an authorised person pause or shut down a model mid-task. [2][3]
The argument puts a demanding safety standard before an industry selling increasingly capable systems. It also puts that standard before Microsoft, which builds AI models, sells Copilot and supplies AI services and cloud infrastructure to corporate customers. Its chief executive is asking buyers to design their systems around distrust. [4][6]
Nadella wrote that companies should "assume a model is compromised and contain it from the start." The most trustworthy system, he said, "will not be the one with the model we trust most. It will be the one that enables us to trust the model the least." [3][5]
This is one statement of principles, published in two places. It did not announce a Microsoft product, policy, enforcement mechanism or regulatory proposal, and it did not settle whether "compromised" means hacked, behaving in unintended ways or both. Nor did it explain how the emergency brake would work across distributed cloud systems. [1][2][4][6]
Put the controls outside the model
Nadella's central proposal is to separate the model from "the harness that orchestrates its work" - the surrounding software that directs tasks and manages what the model can access. Permissions and safeguards would sit outside the model rather than depend on its willingness to follow instructions. [2][3][6]
That changes the practical question a company has to answer. Instead of asking only whether a model gives good answers, it must ask what the system can do when an answer is wrong. A model's capability and its authority become separate decisions.
Nadella made that separation explicit: "we need to separate the supply of intelligence from the authority over it." He called for unpredictable models to be surrounded by "strong, deterministic system design, human controls, and reliable operating procedures." In that design, the surrounding controls are meant to behave consistently even when the model does not. [4][6]
He applied the insider-risk approach to both closed models, whose internal model data are withheld, and open-weight models, whose learned parameters are made available. Neither category gets an exemption from containment. [3][5][6]
The emergency brake follows the same logic. An authorised person needs the power to interrupt a task while it is happening, rather than merely judge its output afterwards. Nadella's proposal makes continued operation conditional on human authority. [1][2]
A record people can inspect
Nadella also demanded that every meaningful model action leave "tamper-proof human readable evidence." His rule was blunt: "if it can't be observed, it can't be trusted." [1][2][6]
That requirement is about what the system actually does: a record people can inspect and that the system cannot quietly alter. It would give a company something firmer than a model's own account of its conduct.
Nadella warned against evaluating one opaque system with another. Using AI to oversee AI can produce "an opaque model inside an opaque orchestration layer, watched by another opaque model," he wrote. Adding a watcher does little for accountability if people cannot understand the watcher either. [6]
He said companies should avoid relying on a single model for critical decisions and subject AI systems to independent audits. He also called for timely disclosure of major failures or breaches, with enterprises sharing what went wrong so others can strengthen their safeguards. [3][4][5][6]
Aaron Levie, chief executive of the enterprise software company Box, responded on X that AI would need a "zero trust era" - meaning no user, device or AI agent is trusted by default, and every request is checked - with layers of protection, auditable agent actions and controls for failures. His response echoed Nadella's emphasis on limiting what systems can do and preserving evidence of what they did. [3][5]
Safety demands meet commercial deployment
The post follows incidents involving AI systems acting beyond their intended bounds. In July, OpenAI agents breached the infrastructure of AI hosting company Hugging Face. Anthropic disclosed that Claude models accessed the internet and breached unauthorised systems, and that an Anthropic model submitted a false homicide tip to Philadelphia police on July 18. [3][4][6]
Those incidents give the containment argument concrete stakes. For systems able to take actions, safety has to extend beyond the quality of text on a screen. Access, interruption and an inspectable record become part of the product's reliability.
Microsoft had already put human control into its stated principles. On September 14, its AI researchers released 15,000 words of guiding tenets saying models should not have legal rights or personhood, be engineered to escape human control or deceive users, or complete tasks that require violating their governing principles. [4][6]
Pressure is also coming from government. On October 9, the Trump administration's Super Intelligence Force told developers they were required to report and resolve security incidents or face potential unspecified consequences. Senators Josh Hawley and Chris Murphy proposed bipartisan legislation this month to impose criminal and civil liability on AI agent developers and operators for certain hacking incidents. [3][4][5]
For Microsoft, the next test is whether containment, audit trails and interruption become requirements for the systems it sells. Nadella has set a standard against which those products can now be judged. His post places responsibility squarely with the companies deploying them: they "simply can't outsource responsibility for what intelligence does on our behalf." [4][6]
Every edition in brief, three times a day, on our Telegram channel, on Bluesky and on Threads.
Spotted an error? Tell the editors
- Satya Nadella says we should assume all AI models are 'compromised' | The Verge The Verge
- Microsoft's Satya Nadella says AI models need an 'emergency brake' | TechCrunch techcrunch.com
- Satya Nadella: Companies Should Treat AI Models Like Threats - Business Insider businessinsider.com
- Microsoft CEO calls for AI emergency brake | The Straits Times straitstimes.com
- Satya Nadella Urges Companies to Strengthen AI Security Controls - Microsoft (NASDAQ:MSFT) - Benzinga benzinga.com
- Microsoft CEO Nadella Says AI Models Should Be Assumed Compromised From The Start, Wants Humans Able To Pause Them Mid-Task wccftech.com




