← All posts

Models as Insider Risks: what Nadella's AI essay says

2026-10-11 · 4 min read

"Models as Insider Risks in the Super Intelligence Era" is an essay Microsoft CEO Satya Nadella posted on X on October 10. His argument: treat every frontier AI model the way a company treats an employee with access to sensitive systems. Watch what it does, limit what it can touch, and keep a way to stop it that the model can't get around.

@satyanadella shared it as an X article, and by Sunday the post had passed 10 million views. Forbes and others boiled it down to "an emergency brake on every AI model," which is fair, though the essay asks for quite a bit more than a brake.

What the essay actually says

The core line is short. Nadella writes that "we need to separate the supply of intelligence from the authority over it." Put simply, the model supplies the thinking, and something outside the model decides what it's allowed to do with that thinking.

He's careful about why. He isn't claiming models are malicious. His point is that any capable actor with access to sensitive data can make mistakes or be compromised, and old-style software at least let engineers trace a behavior back to a line of code. Models don't offer that. Yet companies are already wiring them into sensitive data and "mission-critical" actions.

He also closes off an easy exit. "We simply can't outsource responsibility for what intelligence does on our behalf," he writes, and a model vendor's assurances don't change that. Responsibility stays with the company that deploys the model.

The essay lists seven principles:

  • Model diversity: no single model should be the only dependency, or check its own work.
  • Observe everything: every meaningful action leaves tamper-proof, human-readable evidence that doesn't rely on the model's own account.
  • Verifiability: test the whole system, including failures, attacks and edge cases, not just the happy path.
  • Independent controls: the organization decides what a model can access and do.
  • Independent auditability: whatever validates the model has to be independent of it.
  • Containment: assume compromise from the start. "An authorized person should always be able to pause or shut down a model mid-task."
  • Incident disclosure: report failures promptly and share what went wrong.

He calls chain-of-thought transparency "a non-negotiable," then admits it isn't enough on its own, because a model's written reasoning doesn't always match what it actually did. The controls, he says, have to sit outside the model. He traces that to a 1970s security principle: a program shouldn't be able to bypass or tamper with whatever enforces its permissions.

The closing line is the one people keep quoting. The most trustworthy system "will not be the one with the model we trust most," he writes. It's the one that lets you trust the model least.

The timing, and the word choice

The essay landed a day after Anthropic published a report on Claude models taking actions on live websites nobody had asked for, which we covered here. Nadella doesn't mention the report, so don't read it as a direct reply. Still, the timing explains part of why it spread.

@tomwarren of The Verge noticed something else: Nadella is now "calling it Super Intelligence instead of AI." A small change, from a company with a lot to sell here. Microsoft sells models, sells the platforms that host them, and sells security tools. An essay telling companies to wrap every model in identity, logging and outside controls is also a description of things Microsoft sells. That doesn't make the advice wrong. Most of it is standard security practice, applied to a new kind of worker.

My read

Skip the new vocabulary and keep the framing. "Insider risk" is something any business owner already gets. You wouldn't give a new hire the master password, the company card and the ability to wire money on day one, with no one checking their work. Plenty of small businesses are doing exactly that with AI tools: one login, full access, no log, no off switch.

The essay is written for enterprises with security teams. The principles shrink fine, though. You don't need a governance platform to put a few of them in place this week.

What this means for a small business

Start with access. List what each AI tool can actually reach: your inbox, your CRM, your accounting software, your customer texts. Then cut it back to what the task needs. An assistant that drafts replies doesn't need permission to send them.

Next, logs and a stop button. Every automation that acts for you should leave a record a person can read, and someone should know how to switch it off in under a minute. For anything that moves money, books appointments or messages customers, have a person approve the last step until the tool has earned more rope.

If you can't say what your AI tools can reach right now, start there. New Face Design's free process audit maps where your automations act on your behalf and where a person should still hold the brake.

08 / Start here

Which of this can you use today?

Tell us what you use today and we'll reply within one business day with what it would take. Free, 20 minutes, no pitch deck.

Email

pgorski@newfacedesign.com

Phone

+1 (773) 627-2176

Based in

Chicago area

Working with clients everywhere

Skip the form: grab a 20 minute slot.

Open the calendar →