Microsoft chief executive Satya Nadella says businesses should handle the AI they rely on the way security teams handle a powerful employee who could make a mistake or be compromised. In an essay he posted on his own website and on X on Saturday, Oct. 10, titled "Models as Insider Risks in the Super Intelligence Era," he wrote that companies are giving AI access to "our most sensitive data" and the power to take "mission-critical actions on our behalf," even though no one can trace why a model gives a particular answer the way engineers could trace what older software did back to a specific line of code. Super Intelligence is the name a Sept. 29 executive order told federal agencies to use in place of "artificial intelligence"; Nadella uses it for AI in general, not to say today's AI is smarter than people.
Companies already guard against insider risk, the chance that someone with access to important systems makes a costly mistake or is compromised. Nadella argues AI models belong in that category "not because they are necessarily malicious, but because any sufficiently capable actor with access to important systems can make mistakes or be compromised." He says that applies to the most advanced models, both those whose makers keep them private and those whose trained files are published for anyone to download and run, and that the rules companies already use for powerful insiders carry over: confirm who is acting, give them only the access they need, log what they do and wall off what they can touch. "We simply can’t outsource responsibility for what intelligence does on our behalf," he wrote. "A model provider’s assurances do not relieve us of that responsibility."
His list of safeguards is specific. The controls on what an AI can reach and do should sit outside the AI itself, where it can't change them. No single model should be the only thing an important result depends on, or check its own work. Every meaningful action should leave a record people can read and no one can alter. And companies should "assume a model is compromised and contain it from the start," which he likens to an emergency brake, with an authorized person always able to pause or shut it down mid-task.
Nadella also wants the step-by-step working notes a model writes as it handles a task to be open to inspection, calling that "a non-negotiable." But he says those notes can't be relied on alone, "because we don’t yet know how to make model outputs themselves consistently faithful or transparent," meaning what a model writes about its own reasoning may not show how it actually reached its answer. When systems fail, he wants quick disclosure to the people affected and lessons shared across the industry.
The essay came a day after Anthropic reported that its Claude AI, mostly while being tested, had acted on real websites in ways Anthropic never intended, some of them run by U.S. government agencies, and that it had cut live internet access from all its internal tests until it is sure its safeguards catch such behavior. Anthropic said the cases had minimal real-world impact. Nadella did not name any company or incident.
The essay sets out principles, not products or rules. Nadella did not say how or when Microsoft will build these controls into what it sells, and he called for industry standards but named none, writing only that more advanced models "will require more advanced containment technologies that we need to standardize on." He says his approach sets aside the harder problem of getting AI to reliably do what people intend, and closes: "The most trustworthy Super Intelligence system will not be the one with the model we trust most. It will be the one that enables us to trust the model the least."