Technology

Nadella calls for an emergency brake for AI agents

Nadella calls for an emergency brake for AI agents: what changes for Mexican companies already using them and how to prepare key controls today.

Agentes de IA sobre un panel de control con interruptor de parada de emergencia

Satya Nadella, CEO of Microsoft, asked on October 10, 2026 that AI agents incorporate an emergency brake that an authorized person can activate while they work, according to TechCrunch. The approach moves security responsibility from the lab that creates the model to the company that deploys it.

CNBC reported that Nadella published the proposal on X and that he asked to treat frontier, closed and open-weight models as internal risks instead of trusting vendor guarantees. The starting point is a change of nature: an assistant that answers questions returns text, while an agent that consults files, uses tools and executes tasks can alter production systems. In Mexico, adoption is no longer marginal. According to Banco de México data published on September 10, 2026, 48.5% of companies with more than 100 workers used AI tools in June 2026, versus 24.3% in September 2025, and 64.8% anticipate using them in the next three years.

The technical part has three pieces. First, separate the model from the system that orchestrates its work, so that permissions and limits remain outside the model and it cannot modify them or certify that it respected them. Second, every relevant action leaves a human-readable and tamper-resistant log, so that a later audit can reconstruct what the agent did. Third, controls and audits independent of the audited model, plus vendor diversity in critical decisions. Exposure is uneven by size: Banco de México's Monthly Regional Economic Activity Survey recorded 69.9% adoption in companies with more than 1,000 workers and 43.7% in those with 101 to 250.

For a team already running agents on customer data, the operational question stops being whether the system responds well and becomes what it can touch, who stops it and how it is demonstrated. An inventory of tools with write permission, own credentials per agent and a responsible person with a pause button are verifiable this week.

This note was written with AI assistance from verified sources and reviewed by a human editor before publication.

Sources