Microsoft CEO wants AI treated like a risky insider at work

· The Fresno Bee

Every business eventually learns a hard lesson. The people with the most access can do the most damage, whether they mean to or not.

That’s why your bank caps what a teller can approve, records activity on its trading desks and makes two people sign off on large wire transfers.

Nobody assumes the teller is a crook. The system plans for honest mistakes, bad days and the rare employee who gets tricked by a scammer.

Security teams have a name for this. They call it insider risk, and they treat it as a design problem rather than a character judgment.

The playbook is decades old. Give each worker an identity, grant only the access the job requires, log what happens and keep a way to cut off access fast.

A new kind of worker now wants the same keys. AI agents can read your inbox, compare loan offers, book travel and, increasingly, spend money on your behalf.

Microsoft (MSFT) CEO Satya Nadella says those agents deserve the same treatment as a powerful employee: trusted to work, but never trusted blindly.

You may never run a corporate security team. If you have ever thought about letting an AI tool touch your bank account, though, his argument applies to you, too.

Heather Diehl / Getty Images

How AI agents got access to your accounts so quickly

A year or two ago, most people used AI chatbots like a smarter search engine. You asked a question, it answered, and you decided what to do next.

That model is fading fast. Agents now act on their own, filling out forms, moving files and comparing loan offers in seconds.

Consumers are warming to the idea, with limits. In a survey of 6,247 credit-active consumers across 13 markets in Europe, the Middle East, Africa and Asia-Pacific, 54% said they were comfortable with an AI agent applying for credit for them, according to Experian research conducted by Forrester Consulting.

Only 5% would give an agent full autonomy, though. About 23% would let one act once pre-agreed rules were met.

Related: Microsoft’s $665 target hinges on a new AI advantage

U.S. shoppers are more cautious. Only 23% trust generative AI to handle payment transactions on their behalf, according to a Harris Poll survey of 2,065 adults released by Visa on Sept. 9.

Companies have bigger exposure. AI played a role in one in four malicious data breaches in the latest Cost of a Data Breach study, a 56% jump from the prior year, according to IBM.

Those AI-enabled breaches cost an average of $6 million, roughly $1 million more than the $4.99 million global average. Some 92% of organizations hit by AI-related breaches lacked proper access controls for their AI systems, TechRepublic reported.

Why the guardrails need to live outside the software

Nadella laid out his case in an essay titled “Models as Insider Risks in the Super Intelligence Era,” which he posted on X on Oct. 10.

More Artificial Intelligence:

His starting point is a problem engineers rarely say out loud. With traditional software, a bad result could be traced to a specific line of code. With today’s frontier models, he wrote, nobody can tie a given output to specific training data or settings inside the model.

Yet companies are handing those systems sensitive data and the power to take what he called mission-critical actions.

“We simply can’t outsource responsibility for what intelligence does on our behalf. A model provider’s assurances do not relieve us of that responsibility,” Nadella wrote.

His fix fits in one line. “We need to separate the supply of intelligence from the authority over it,” he wrote.

He was careful about tone. Calling a model an insider risk is a design choice, he argued, “because any sufficiently capable actor with access to important systems can make mistakes or be compromised.”

The idea borrows from one of computer security’s oldest rules. Nadella pointed to a principle from the 1970s holding that a program must never be able to bypass or tamper with the mechanism enforcing its permissions.

In my read, that is the “reference monitor,” a gatekeeper that checks every access request. The National Institute of Standards and Technology still defines it as always invoked, tamperproof and small enough to test.

Nadella’s 7 rules for keeping powerful models in check

Nadella listed seven rules that, in his view, every serious AI deployment should follow:

  • Model diversity. No single model should be the only dependency for an important outcome or check its own work
  • Observe everything. Every meaningful model action should leave tamper-proof evidence a human can read
  • Verifiability. Systems should be tested against failures, attacks and edge cases, beyond successful tasks
  • Independent controls. Organizations, rather than the model, decide what it can access and do
  • Independent auditability. The checker must be separate from the intelligence it is checking
  • Containment. An authorized person must always be able to pause or shut down a model mid-task
  • Incident disclosure. When systems fail, affected people deserve timely notice and a clear account of what broke

“If it can’t be observed, it can’t be trusted!” Nadella wrote.

He also called transparency in a model’s step-by-step reasoning “a non-negotiable,” while warning that it isn’t dependable on its own. Using one AI to police another, he added, can leave you with “nested black boxes.”

Turning a corporate security memo into household habits

Nadella wrote his essay for corporate tech chiefs. My analysis is that almost every principle translates to a choice you make at home the moment an AI tool asks to connect to your accounts.

Here’s how the corporate rules look on a household budget:

  1. Cap the authority. If an agent can buy things, give it a separate card or account with a low limit. A $200 cap turns a runaway mistake into an annoyance instead of a drained checking account
  2. Keep your own paper trail. Turn on real-time transaction alerts from your bank. That record comes from your bank, so it doesn’t depend on the agent’s summary of what it did
  3. Don’t let the bot grade its own homework. Confirm loan applications, transfers and large purchases inside your bank’s own app before they go through
  4. Know where the off switch is. Learn how to revoke an AI tool’s access to linked accounts before you need to
  5. Get a second opinion. For big money decisions, compare the AI’s answer with another tool or a human adviser

Most people already lean this way. Some 75% of consumers in Experian’s survey said they would feel more comfortable using AI connected to a financial institution they already trust.

Microsoft has a business stake in containment tools

Investors should read Nadella’s essay with one fact in mind: Microsoft sells the kind of controls he describes.

The company unveiled Agent 365 in November 2025 as a “control plane” that tracks the AI agents inside a business and gives each one its own identity so IT teams can set policies, according to Computerworld.

Nadella has been building toward this argument all year. In June, he told the Possible podcast that AI agents need identities, sandboxes and governing policies, Digit reported.

In September, he wrote on X that AI that isn’t helping humanity and “under human control” isn’t worth pursuing, Fox Business reported.

Related: AI’s biggest business opportunity may not look like AI

The demand is real. Insider risk now costs the average organization $19.5 million a year, up 20% in two years, according to a Ponemon Institute study sponsored by DTEX Systems. Only 19% of respondents, drawn from 354 organizations, treat AI agents as the equivalent of human insiders, and nearly half have little or no visibility into what their agents do.

Risk controls could also decide which AI projects survive. Gartner predicts more than 40% of agentic AI projects will be canceled by the end of 2027, citing rising costs, unclear business value or inadequate risk controls.

“The most trustworthy Super Intelligence system will not be the one with the model we trust most. It will be the one that enables us to trust the model the least,” Nadella wrote.

Apply that rule at home, and you can enjoy what AI does well without ever handing it the keys to your financial future.

More Stocks News

The Arena Media Brands, LLC THESTREET is a registered trademark of TheStreet, Inc.

This story was originally published October 11, 2026 at 12:07 PM.