Satya Nadella just published an essay every engineering leader should read: Models as Insider Risks in the Super Intelligence Era. Even Elon Musk called it an interesting piece. I agree with almost every word, and I want to add the view from where I sit.
Interesting piece from CEO of Microsoft
I have spent the last nine years building Waydev and looking at how enterprise engineering teams actually work. What I see inside companies today tells me Satya is not describing a future problem. He is describing this quarter.
The short version
- Treat AI models like powerful insiders: useful, capable, and never the ones holding the keys.
- In the SI SDLC, agents write and review code, so traceability has to come from a layer outside them.
- Our last enterprise contract took one lawyer and a week instead of three lawyers and a month. The authority stayed human.
Separate the intelligence from the authority
His argument is simple. With traditional software, we could trace any behavior back to a specific code path. With frontier models, we can’t. And yet we are giving these models our most sensitive data and letting them take actions that matter.
This is not a new thread for him. On the All-In podcast he described long-running agents as a new kind of insider risk, and he has said publicly that superintelligence must stay under human control.
His answer is to treat models the way we treat any powerful insider. Not because they are malicious, but because anyone with access to important systems can make mistakes or be compromised. Enterprises already know how to handle that: identity, least privilege, logs, containment.
The principles he lays out are the ones your security, legal and procurement teams will soon ask about:
None of this is new in spirit. It goes back to the reference monitor concept from a 1972 US Air Force study: the thing that enforces permissions must be tamper-proof and impossible to bypass. What is new is that the “program” is now a model that writes code, drafts contracts and takes action.
The SDLC is becoming an SI SDLC
For twenty years, the software development lifecycle assumed a human at every step. A person wrote the code, a person reviewed it, a person approved the deploy. Traceability came for free, because every commit had an author you could walk over and ask.
That assumption is gone. Agents now write code, open pull requests and review each other’s work. The code path is still traceable. The decision behind it often is not. Satya’s picture of nested black boxes, an opaque model inside an opaque orchestration layer watched by another opaque model, describes a lot of the AI coding setups I see in large organizations right now.
So the questions engineering leaders have to answer are changing:
I have written before about why AI adoption is not the same as AI ROI, and why so many teams are asking why their ROI isn’t showing up. The SI SDLC makes that gap wider, not smaller.
This is why I believe measurement has to sit outside the model, exactly as Satya says the controls must. The model doing the work cannot be the one grading it. That is the principle behind Waydev Brain: a private layer, running on your own data, that observes what humans and agents do across the SDLC and gives leaders independent evidence of adoption, impact and ROI.
It is also why Waydev built its own model. Waydev 15B is a 15-billion-parameter model trained for the SDLC, and we tailor it to each customer. It runs private and air-gapped, inside the organization’s own environment. Your code, your data and your engineering signals never leave your walls, and no outside model provider sits between you and the evidence. That is Satya’s separation in practice: the intelligence works for you, and the authority stays with you.
Waydev 15B
- Built for the SDLC. Trained to understand how software gets planned, written, reviewed and shipped.
- Tailored to each customer. Adapted to your codebase, your teams and the way you work.
- Private and air-gapped. Deployed inside your organization, with no data leaving your environment.
Three lawyers and a month, or one lawyer and a week
This shift is not limited to engineering. Here is a real example from our own business.
We sell to large enterprises, and not long ago signing one of those contracts meant three lawyers and about a month of back and forth. Redlines, security questionnaires, data processing terms, and then more redlines.
Our most recent enterprise contract took one week. One lawyer, working alongside the company’s LLM.
Signing an enterprise contract, then and now
Roughly 4x faster, with one person accountable instead of three. Approximate calendar days.
What matters is how it worked, because it is Satya’s framework in practice. The model did the heavy lifting: drafting, comparing clauses, flagging risks. The lawyer kept the authority: reviewing every change, deciding what to accept, and signing off. The intelligence came from the model. The authority stayed with a person.
I expect to see this pattern everywhere. Not AI replacing the expert, but one expert with AI doing the work of a team, with clear accountability for every decision.
What this means for enterprise leaders
The contract story and the SDLC story are the same story. Work that took teams and months now takes one person and days. The bottleneck is no longer producing the work. It is trusting the work.
That changes where value sits. Generating code, contracts and analysis is getting cheap. Knowing what was generated, by which model, under whose authority, and whether it actually delivered is getting expensive. The companies that win will not be the ones with the smartest model. They will be the ones that can prove what their models did.
For engineering leaders, I would start with three things this quarter. Keep the authority with people. Put observability and measurement outside the model. And be ready to show your board, with evidence, what AI is actually doing to delivery, quality and cost. Speed without observability is just risk at scale.
The most trustworthy Super Intelligence system will not be the one with the model we trust most. It will be the one that enables us to trust the model the least.
Satya Nadella, Chairman and CEO of Microsoft
If you want the full method, our guide to measuring AI adoption, impact and ROI and the Impact That Compounds playbook lay out the metrics and a 90-day plan.
See what AI is really doing inside your engineering org
Waydev gives engineering leaders independent, auditable evidence of AI adoption, impact and ROI across humans and agents.
Book a demoFurther reading
- Models as Insider Risks in the Super Intelligence EraSatya Nadella on X
- Agents as a new insider riskSatya Nadella on the All-In podcast
- The reference monitor conceptThe 1972 principle behind external controls
- The Gap Nobody Talks About: Why AI Adoption Is Not the Same as AI ROIWaydev blog
- A Guide to Measuring AI Adoption, Impact, and ROI in EngineeringWaydev guide