Microsoft chief executive Satya Nadella has called for advanced artificial-intelligence systems to be designed on the assumption that they may be compromised, arguing that authorized people must retain the ability to interrupt or shut them down while they are operating.

In a lengthy post on X described by The Verge, Nadella set out a security model centered on containment, observation and accountability. His proposal rejects the idea that users and institutions should simply accept or reject outputs from opaque systems. Instead, he wants models to operate within controls that make their behavior visible and leave evidence that people can inspect afterward.

The most direct element of the proposal is an emergency-stop mechanism. Nadella said an authorized person should be able to pause or terminate a model during a task. He also argued that increasingly capable systems will need stronger containment technology and that the industry should develop common standards for those safeguards.

That framing treats AI security as an architectural requirement rather than a response applied only after a failure. Assuming compromise from the outset means designers would plan for a model to behave unexpectedly, to be manipulated or to operate beyond its intended limits. The aim is to limit the consequences and preserve a human route to intervention.

Nadella also called for tamper-resistant, human-readable records of model activity. Such records could give operators, auditors and investigators a clearer account of what a system did and why a particular incident occurred. The proposal is meant to replace what he described as nested black boxes with systems whose actions can be observed and reconstructed.

Several other elements align with safety measures already discussed across the AI industry. Nadella backed prompt reporting of incidents, independent audits and verifiable data, alongside containment. Together, those measures would create multiple layers of oversight: organizations would document failures, outside reviewers could test claims, and operating records could support scrutiny after deployment.

The Verge noted that Nadella repeatedly used the term “super intelligence” in presenting his argument. The terminology does not change the immediate focus of the proposal, which is practical control over models while they carry out tasks.

No technical standard or implementation timetable was announced in the supplied report. The significance of Nadella's intervention is therefore in the direction it sets: one of the largest AI providers is publicly advocating systems that can be stopped, inspected and contained by design, while placing responsibility on the industry to standardize stronger controls as model capabilities advance.