Microsoft’s chief executive has an unusual piece of advice for anyone wiring frontier AI into their business: trust it as little as possible. In an essay titled “Models as Insider Risks in the Super Intelligence Era”, published on his personal blog sn scratchpad on October 10, 2026 and shared in a lengthy post on X, Satya Nadella argued that companies should handle advanced models the way security teams handle powerful employees with access to sensitive systems.
His starting point is a blunt admission. With traditional software, engineers could trace a behaviour back to a specific code path. With today’s frontier models, he writes, we can’t attribute outputs to particular training data or configurations of model weights, yet these agentic systems are being handed sensitive data and the ability to take mission-critical actions. Nadella’s conclusion: we can’t treat AI as a “set of nested black boxes” and simply accept or reject its answers and actions. In his words, “we need to separate the supply of intelligence from the authority over it.”
Crucially, he frames this as an engineering problem rather than a philosophical one. Setting aside “the hard problem of alignment”, Nadella calls for surrounding non-deterministic models with deterministic system design, human controls and reliable operating procedures. Closed and open weight models alike should be treated as insider risks, “not because they are necessarily malicious”, but because any capable actor with access to important systems can make mistakes or be compromised.
The essay leans on decades of enterprise security practice: establish identity, limit privileges, log activity, build containment boundaries. Chain-of-thought transparency is called “a non-negotiable”, though Nadella concedes it is not sufficient on its own, since model outputs are not yet consistently faithful. Hence his key architectural point: the controls over what a model can access and do must sit outside the model.
He then lays out seven principles:
- Model diversity – no single model should be the sole dependency for an important outcome or verify its own work.
- Observe everything – every meaningful action must leave “tamper-proof human readable evidence”.
- Verifiability – continuously test the whole system, including failures, attacks and edge cases.
- Independent controls – organisations decide for themselves what a model can access and do.
- Independent auditability – no model should control both a system’s behaviour and the evidence used to judge it.
- Containment – assume compromise from the start.
- Incident disclosure – timely notice to those affected, and industry-wide sharing of what went wrong.
Many of these ideas echo what others in the industry have been saying, as The Verge noted. Where Nadella goes a step further is containment. “We must assume a model is compromised and contain it from the start. Think of it like an emergency brake,” he writes. “An authorized person should always be able to pause or shut down a model mid-task.” More advanced models, he adds, will need more advanced containment technologies that the industry should standardize on.
The essay names no Microsoft product. Its closing line sums up the philosophy: the most trustworthy Super Intelligence system “will not be the one with the model we trust most. It will be the one that enables us to trust the model the least.”