Microsoft's Nadella urges an emergency brake for AI
Satya Nadella wants authorised people to stop AI models mid-task, with permissions and audit records controlled independently. His proposal treats powerful models as insider risks.

Listen to this articleListen
An authorised person should be able to stop an AI model while it is working, Microsoft chief executive Satya Nadella argues. In a 10 October 2026 post, he calls for an emergency brake as part of a wider approach to containing powerful systems.
The proposal applies to models given sensitive data and the authority to take consequential actions. Nadella wants organisations to retain control over their access, observe their behaviour and test their limits.
Why compare AI models with insider risks?
Nadella’s insider-risk comparison concerns capable actors with access to important systems who can make mistakes or be compromised. It covers both closed models and models whose weights are available to others.
He draws on established enterprise safeguards: identifying an actor, limiting its privileges, recording its activity and setting boundaries around what it can do. He wants organisations to build on the assumption that a model could be compromised from the outset.

People control the permissions and the evidence
Nadella wants independent controls over a model’s access and actions, alongside records that let people reconstruct what happened. Meaningful actions should leave evidence protected against tampering, and validation should be independent of the system being checked.
His proposed brake lets an authorised person “pause or shut down a model mid-task”. He also calls for continuous testing and timely disclosure when systems fail or are compromised. These are principles he wants organisations to build around and standardise.
Access checks already underpin zero trust
NIST’s August 2020 zero-trust guidance makes authentication and authorisation separate checks before access to an enterprise resource. Its SP 800-207 publication focuses protection on users, assets and resources. A device’s network location alone gives it no automatic entitlement to access.
That offers a useful comparison for AI agents, which can use software tools to act on a person’s behalf. A practical application is to give the agent a defined set of permissions and check access at the resource it wants to use. The comparison follows the access-control principles; Nadella’s post proposes extending containment and oversight to advanced models.

The White House has adopted super intelligence terminology
Nadella uses the term super intelligence in the title and text of his post. The wording matches the terminology directed by President Donald Trump’s 29 September executive order.
The order tells federal agencies to use super intelligence and SI in communications and other covered documents, to the extent permitted by law. Section 3 currently defines those terms using the technologies and systems covered by the existing statutory definition of artificial intelligence. It also orders proposed legislative language for a federal definition within 60 days.
Nadella’s practical demand is for organisations deploying powerful models to retain authority over what those systems can access and do, including the ability to interrupt them while work is under way.


