Microsoft chief executive Satya Nadella says organizations should design AI systems as though the underlying model could be compromised. His proposed response is to separate the model from the software harness that supplies tools, data and permissions, then place controls outside the model’s reach.
Nadella called for every meaningful action to leave tamper-resistant, human-readable evidence. He also wants timely incident disclosure, independent audits and containment standards that let an authorized person pause or shut down a model while it is working.
The “emergency brake” framing matters because an agent can take actions rather than merely produce text. A model with access to company data, code or external services can make a damaging mistake even without malicious intent. Logging after the fact is therefore not enough if operators cannot interrupt the task or limit what the model can reach.
The post is a set of architectural principles, not a released Microsoft product or an agreed industry standard. It does not specify how tamper resistance, audit independence or human intervention would work across vendors. Organizations deploying agents still need to translate those ideas into permissions, isolated execution, monitoring and approval points for consequential actions.