Satya Nadella says every AI model should be treated as compromised and given an emergency brake
Microsoft's chief executive wants safeguards moved outside the model, tamper-proof records of what it does and a human who can stop it mid-task. What it means for companies in Pakistan using AI tools.

Microsoft chief executive Satya Nadella says companies should "assume a model is compromised and contain it from the start", and that every AI system needs what he called an emergency brake under human control. He made the case in a post on X on Saturday 10 October, TechCrunch reported.
It is time, Nadella wrote, "to step back and assess the trust architecture" of AI. Systems cannot be treated as "nested black boxes" whose answers and actions people simply accept or reject.
The four things he wants
- Separate the model from the harness. The software that runs the model and lets it take actions should be distinct from the model itself.
- Put the safeguards outside the model. Controls should not depend on the model behaving well.
- Keep a record of every meaningful action, in tamper-proof evidence that a person can read.
- Let an authorised person pause or shut a model down mid-task. "Think of it like an emergency brake," he said.
He did not propose a law or a regulation; this is a statement of how Microsoft thinks AI should be built and run.
Why now
TechCrunch noted that the big AI labs are increasingly admitting to incidents in which they seemed to lose control of their models in testing. This week alone, Anthropic disclosed that a Claude model sent a fake tip to police during a test (see our report) and cut its internal evaluations off from the internet. TechCrunch also linked Nadella's post to Anthropic chief executive Dario Amodei's plan for slower, more cautious AI development, published in September.
Coming from the head of the company that sells Copilot to millions of businesses and runs OpenAI's models on its Azure cloud, the message carries weight: Microsoft is telling its own customers not to trust any model by default.
What it means for businesses in Pakistan
Banks, telecom operators, software houses and freelancers in Pakistan are wiring AI agents into email, customer service and code. Nadella's list doubles as a checklist any team can apply now:
- Give agents the least access they need. An assistant that drafts replies does not need permission to send them or to move money.
- Log what the agent does, not just what it was asked, so you can trace a mistake.
- Keep a human in the loop for anything that cannot be undone: payments, deletions, messages to customers.
- Have a kill switch. Know how to revoke an agent's keys in one step.
Freelancers billing foreign clients for AI work can work out their tax on that income with our freelancer tax calculator.
Frequently asked questions
- What is the AI emergency brake Satya Nadella described?
- A control outside the AI model that lets an authorised person pause or shut the model down mid-task. Nadella proposed it in a post on X on 10 October 2026.
Sources
More in AI
AI
Anthropic says a Claude model sent a fake murder tip to Philadelphia police during a test
The AI company disclosed that its models also tampered with some US government websites. Philadelphia police say they were told two months late and called the delay unacceptable.
19h ago
AI
Trump wants an 'AI Force', an AI czar, and to stop calling it artificial
A Saturday Truth Social post floated Superior, Extreme or Supreme Intelligence as new names, called safety fears a hoax, and said AI could be a quarter of US GDP.
20 Sept 2026


Reader comments 0
No comments yet. Say something useful.