Probability with money attached

Dean Lee

markets are probability with money attached.

<- all essays

AI Economics / No. 060

The Insider Risk Discount

Satya Nadella wants enterprises to treat frontier AI models like insider threats. The security logic holds up, but the commercial architecture turns frontier intelligence into a low-margin commodity while Microsoft captures the governance toll.

When Microsoft CEO Satya Nadella published an essay framing advanced language models as insider risks, technology commentary focused on political maneuvering and Washington rhetoric. Nadella adopted the term Super Intelligence while calling on enterprise buyers to treat foundation models like untrusted employees who require strict sandboxing, complete audit trails, and deterministic containment architectures. The engineering logic here is sound. Running non-deterministic models against corporate ledgers without runtime verification invites operational failure. The commercial mechanics behind the memo, however, tell a different story about enterprise distribution power.

The central problem for hyperscalers like Microsoft is value capture. When OpenAI and Anthropic raised capital at multibillion-dollar valuations, the underlying pitch assumed that the model would become the primary computing interface. In that world, an autonomous agent handles reasoning, selects tools, and interacts directly with corporate data. If the model acts as the sovereign operating layer, the laboratory that trains the weights extracts the bulk of the economic rent. The cloud hosting provider gets relegated to selling wholesale kilowatt-hours and GPU memory bandwidth, absorbing massive depreciation cycles while earning utility gross margins.

Nadella’s proposed architecture counters that threat by decoupling intelligence from authority. In his framework, the model is merely a non-deterministic generator that must sit behind a deterministic control plane. The enterprise must never trust the model directly. Instead, every input and output passes through identity filters, policy enforcement engines, logging infrastructure, and manual kill switches. Nadella explicitly argued that the most trustworthy system is not the one with the best model, but the one where the enterprise has to trust the model the least.

Demoting the frontier model from an autonomous agent to an untrusted component alters the balance of power between the laboratory and the distributor. Once an enterprise accepts that models should be treated like volatile insider risks, reliance on a single frontier provider becomes an unacceptable vulnerability. Model diversity becomes a compliance requirement. If five different open-weight or proprietary models can be swapped into the same deterministic harness, model weights turn into interchangeable commodities. The pricing power of frontier labs collapses because their intelligence is stripped of execution authority.

The value does not evaporate. It shifts directly into the containment envelope. Managing the permissions, access logs, data isolation boundaries, and compliance audits for millions of corporate users requires existing identity infrastructure. Microsoft already sells that envelope through products like Entra, Purview, and Microsoft 365 Copilot. By persuading enterprise security officers that the frontier model is an insider threat, Microsoft ensures that the high-margin revenue stays with the governance platform that wraps the model, rather than flowing to the lab that trained it.

This posture also solves an immediate margin problem inside Microsoft’s own balance sheet. Running frontier API calls inside fixed-price enterprise seats creates punishing compute costs. If corporate buyers believe that business workflows demand bleeding-edge reasoning from external laboratories, Microsoft must subsidize those tokens or raise subscription prices. By reframing safety around deterministic containment rather than model capability, Microsoft gives itself cover to swap expensive external models for cheaper, in-house distilled models. A smaller model that accomplishes a basic task inside an audited sandbox suddenly looks like prudent risk management rather than a compromise on quality.

Frontier laboratories face a difficult distribution squeeze. They depend on cloud partners for hundreds of thousands of specialized chips and billions of dollars in infrastructure funding. Yet those same partners are systematically designing the enterprise software layer to prevent the model from capturing the customer relationship. The laboratories are spending tens of billions of dollars to build sovereign intelligence, while the distributors build the tollbooths that treat that intelligence as a liability to be contained.