Most trustworthy AI system demands least inherent model trust: Microsoft CEO Satya Nadella
The most trustworthy Super Intelligence system will not be the one powered by the model users trust the most, but rather the system that allows people to trust the model the least, Microsoft CEO Satya Nadella stated in a post on X.

"The most trustworthy Super Intelligence system will not be the one with the model we trust most. It will be the one that enables us to trust the model the least," he said in a post on X.
Addressing the governance challenges of advanced artificial intelligence, Nadella noted that modern systems lack the mechanistic clarity of legacy computing. While engineers once traced software operations directly to specific code paths, such visibility is missing in contemporary frontier architectures.
"As traditional software systems were being deployed across the economy over the last few decades, we had the tools and capability to trace behaviors to a specific code path," Nadella stated.
"That same kind of mechanistic understanding eludes us in today's Super Intelligence systems, even as the frontier models powering these systems are now more capable than traditional software systems. We can't attribute model behaviors and outputs to specific inputs of training data or configurations of model weights. And yet we are deploying these complex agentic systems and models, with access to our most sensitive data and giving them the ability to take mission-critical actions on our behalf!" he said.
"Setting aside the hard problem of alignment, we need to start with an engineering approach to containment and governance. We need to surround non-deterministic models with strong, deterministic system design, human controls, and reliable operating procedures, and establish industry standards where existing ones are insufficient," Nadella explained.
To manage these risks, Nadella proposed treating both closed and open-weight models as potential insider threats. Because any privileged actor can fail or face compromise, organizations must isolate the models through proven enterprise security practices, such as identity controls, activity logging, and strict permission boundaries.
"It's why the controls that govern what a model can access and what actions it can take must sit outside the model. This builds on an information security principle dating back to the 1970s that a program must not be able to bypass or tamper with the mechanisms that enforce its permissions," he observed.
Nadella outlined key principles for observing and governing these networks, including model diversity, tamper-proof logging, continuous verifiability across edge cases, independent audits, reliable containment shutoffs, and industrywide incident disclosure.
The Economic Times Business News App for the Latest News in Business, Sensex, Stock Market Updates & More.
The Economic Times News App for Quarterly Results, Latest News in ITR, Business, Share Market, Live Sensex News & More.