Microsoft CEO wants artificial intelligence to be seen as risky at work – insider

Every business eventually learns hard lessons. Those with the most access can cause the most damage, whether they mean to or not.

That’s why your bank limits the amount a teller can approve, logs the activity on its trading desk, and has two people sign off on large wire transfers.

No one thinks the teller is a liar. The system prepares you for unintentional mistakes, bad days, and the rare employee who falls for a scammer.

Security teams have a name for this. They call it internal risk and treat it as a matter of design rather than a judgment of character.

This playbook is decades old. Give each worker an identity, grant only the access they need to do their job, log what happens and keep a way to quickly cut off access.

Now, a new type of worker wants the same keys. AI agents can read your inbox, compare loan offers, book travel and, increasingly, spend money on your behalf.

Microsoft (MSFT) CEO Satya Nadella said these agents should be treated the same as powerful employees: trustworthy on the job, but never blindly trusted.

You may never manage a corporate security team. But if you’ve ever thought about letting an AI tool touch your bank account, his argument applies to you, too.

Satya Nadella lists 7 rules for dealing with artificial intelligence agents for money.

Heather Diehl/Getty Images

How an AI agent can access your account so quickly

A year or two ago, most people used AI chatbots as smarter search engines. You ask the question, it answers, and you decide what to do next.

This model is quickly disappearing. Agents can now act on their own, filling out forms, moving documents and comparing loan offers in seconds.

Consumers are increasingly enthusiastic about the idea, but it has its limitations. According to Experian research conducted by Forrester Consulting, in a survey of 6,247 credit-active consumers across 13 markets in Europe, the Middle East, Africa and Asia Pacific, 54% said they were satisfied with an AI agent applying for credit for them.

However, only 5% would give agents complete autonomy. About 23% will allow an action once pre-agreed rules are met.

Related: Microsoft’s $665 target hinges on new AI advantage

American shoppers are more cautious. According to a Harris Poll survey of 2,065 adults released by Visa on September 9, only 23% trust generative artificial intelligence to process payment transactions on their behalf.

The company has greater exposure. According to IBM, in its latest cost of data breach study, artificial intelligence played a role in a quarter of malicious data breaches, a 56% increase from the previous year.

The average cost of these AI attacks is $6 million, which is about $1 million higher than the global average of $4.99 million. According to TechRepublic, approximately 92% of organizations that have suffered AI-related breaches lack appropriate access controls for their AI systems.

Why guardrails need to be outside the software

Nadella elaborated on his views in an article titled “Models for the Age of Superintelligence as Internal Risks,” which he posted on X on October 10.

More artificial intelligence:

  • Trump’s “superintelligence” directive has taken the tech world by storm. But will this last?
  • Meta Muse gives AMD and Intel investors a reason to cheer
  • Microsoft’s $665 target hinges on new AI advantage

His starting point is a problem that engineers rarely say out loud. With traditional software, undesirable results can be traced to specific lines of code. In today’s cutting-edge models, he writes, no one can tie a given output to specific training data or settings within the model.

Yet companies are handing over sensitive information and the authority to take what he called mission-critical actions to those systems.

“We simply cannot outsource responsibility for what intelligence does on our behalf. Assurances from model providers do not absolve us of our responsibility,” Nadella wrote.

His solution can be summed up in one sentence. “We need to separate the provision of intelligence from the authority of intelligence,” he wrote.

He was careful about his tone. He argued that calling the model an internal risk is a design choice “because any actor with the ability to access a critical system could make a mistake or be compromised.”

The idea draws on one of the oldest rules of computer security. Nadella pointed to a 1970s principle that programs must never bypass or tamper with the mechanisms that enforce their authority.

In my mind, this is the “reference monitor”, a gatekeeper that checks every access request. The National Institute of Standards and Technology still defines it as always-callable, tamper-proof, and small enough to be tested.

Nadella’s 7 rules for controlling powerful models

Nadella listed seven rules that he believes every serious AI deployment should follow:

  • Model diversity. No single model should be the sole dependency for important results or check its own work
  • Observe everything. Every meaningful model operation should leave human-readable tamper-proof evidence
  • Verifiability. In addition to successful missions, systems should be tested for failures, attacks, and edge cases
  • Independent control. The organization, not the model, determines what it can access and do
  • Independent auditability. Inspectors must be separated from the intelligence they are examining
  • contain. Authorized personnel must always be able to pause or close the model during a task
  • Event Disclosure. When a system fails, those affected should be notified promptly and clearly explained what went wrong

“If you can’t see it, you can’t trust it!” Nadella wrote.

He also called the transparency of the model’s step-by-step reasoning “non-negotiable,” while warning that it was not inherently reliable. He added that using one AI to oversee another could leave you with “nested black boxes.”

Turn your company safety memo into a family habit

Nadella wrote a paper for enterprise technology executives. My analysis is that when an AI tool asks to be connected to your account, almost every principle translates into the choices you make at home.

Here’s what company rules say about family budgeting:

  1. Restrict permissions. If the agent can buy stuff, give it a separate card or an account with a lower limit. A $200 cap turns out-of-control mistakes into annoyances rather than draining checking accounts
  2. Keep your own written record. Turn on your bank’s instant transaction alerts. The record comes from your bank, so it doesn’t rely on the agent’s summary of what it did
  3. Don’t let robots grade your own assignments. Confirm loan applications, transfers and large purchases within your bank’s own app before processing them
  4. Know where the off switch is. Learn how to revoke an AI tool’s access to a linked account before you need it
  5. Get a second opinion. For big money decisions, compare AI answers to other tools or human advisors

Most people already gravitate this way. About 75% of consumers in Experian’s survey said they would be more comfortable using artificial intelligence connected to a financial institution they already trust.

Microsoft has business stakes in containment tools

Investors should keep one fact in mind when reading Nadella’s article: Microsoft sells the kind of control he describes.

According to Computerworld, the company launched Agent 365 in November 2025 as a “control plane” that can track AI agents within an enterprise and provide each agent with its own identity so that IT teams can develop policies.

Nadella has been working toward this argument all year. According to “Digit”, in June this year, he said on the Possible podcast that artificial intelligence agents need identities, sandboxes and management policies.

In September, he wrote on X that artificial intelligence that cannot help humans and is “under human control” is not worth pursuing, according to Fox Business.

Related: Artificial Intelligence’s Biggest Business Opportunities May Not Look Like Artificial Intelligence

The need is real. According to a Ponemon Institute study sponsored by DTEX Systems, insider risks now cost organizations an average of $19.5 million annually, a 20 percent increase in two years. Only 19% of respondents from 354 organizations viewed AI agents as equivalent to human insiders, while nearly half had little or no understanding of their agents’ behavior.

Risk control can also determine which AI projects survive. Gartner predicts that by the end of 2027, more than 40% of agency AI projects will be canceled due to rising costs, unclear business value, or insufficient risk control.

“The most trustworthy superintelligent system will not be the one in which we trust the most models. It will be the system in which we trust the least models,” Nadella wrote.

Apply this rule at home and you can enjoy the benefits of artificial intelligence without handing it the keys to your financial future.

More stock news

  • Elon Musk just created a new problem for Intel that Wall Street can’t ignore
  • Lockheed bets ‘revolutionary’ Patriot missile can stop faster missiles
  • JPMorgan Chase CEO issues stern warning to corporate America
  • OpenAI’s $20 billion revenue gap disrupts the AI ​​industry

Leave a Comment