
A major AI supplier calls for treating models as insider risks
The sharpest part of Microsoft's chief executive's new essay is not a claim that every model has actually been hacked. It is an instruction to design systems as though a capable model can fail, be compromised or pursue a task across the wrong boundary. Satya Nadella argues for separating the model from the software harness that grants tools and permissions, placing safeguards outside the model, recording meaningful actions as tamper-resistant human-readable evidence and giving an authorized person a way to pause or shut down work mid-task. The Verge and TechCrunch reported the essay; the original X article is the source for his proposal. It is not a product launch, a published standard or evidence that Microsoft's own deployments have passed such a test. The distinction matters because 'assume compromise' is a familiar security design posture, not an accusation against a particular model. Recent incidents involving agents and real websites make the engineering question urgent: if the model's instruction text is bypassed or misunderstood, can a separate system still deny an external write? A credible answer requires scoped credentials, independent logs, an operator who can intervene and tests that attempt to cross the boundary. It also needs a failure mode for the brake itself: who monitors the human operator, and what happens if the network or vendor is unavailable? The essay's value is that it shifts the burden from trusting a model's promise to proving the surrounding system's control.










































