We've long argued for a balanced approach to AI regulation. One that keeps humans in control. Since 2023, Microsoft has advocated for "safety brakes" or an “off switch" that keeps advanced AI systems under human control. And it should ensure that AI systems that control critical infrastructure and autonomous systems be run in secure cloud infrastructure with layered safeguards that provide additional intervention points as needed. Put simply, powerful AI systems should always remain under human control, including interruption, correction, and shutdown. This approach is tried and tested. In the 1850s, Elisha Otis’ demonstration of a safety brake at the World’s Fair helped earn the public’s trust – and made modern cities possible. We should adopt this principle for AI. If we do, AI can become a powerful tool for human progress. If we don't, a lack of public trust, not regulation, will become the limiting factor that slows AI adoption. Read more here: https://lnkd.in/e7eSXfuJ
Human control is the right principle. But there is an important distinction between being able to stop an AI system and having authority to authorize what it is allowed to execute. A safety brake is an intervention point. An authorization boundary is a pre-execution control. The first can stop the system after a condition is detected. The second determines whether a consequential action is authorized before execution. Proposal ≠ Permission. Permission ≠ Execution. That distinction becomes critical as AI moves from generating outputs to taking actions in the real world.
An off switch has to be an operational capability, not only a design requirement. For critical systems, the intervention path should be independent of the AI control loop, governed by clear human authority, tested under degraded conditions, and paired with an auditable recovery process. That is how the safety brake earns trust before it is needed.
The connection between human control and trust is an important one. People need confidence that AI systems can be interrupted, corrected and held within clear boundaries when it matters. Building those safeguards into the systems from the start will be critical as AI becomes more capable and more embedded in everyday life.
Brad Smith - as a former employee and MSFT fan (HALO 😂) I cannot express the pride I felt when you sent this memo. Thank you sir. https://blogs.microsoft.com/on-the-issues/2025/09/25/update-on-ongoing-microsoft-review/
The shutdown mechanism needs to work when the rest of the system is behaving unexpectedly. I’d like to see interruption tested during delegated tasks and queued tool calls, with evidence that work actually stops. An off switch is much more reassuring when its limits have been exercised.
Every consequential AI system should have a human-controlled, independently enforceable kill switch. No system should ever be beyond meaningful human intervention. Government has a legitimate role in requiring accountability, transparency, and enforceable safeguards. However, detailed AI governance should not be designed or controlled by politicians who lack the necessary technical expertise. Those standards should be developed and maintained by qualified experts in AI, cybersecurity, engineering, safety, ethics, and the industries where these systems are deployed—operating through an independent, non-governmental oversight body with transparent rules, conflict-of-interest protections, and public accountability.
Circuit breakers didn't slow electricity down, they're the reason people let it into their walls, and AI companies dragging their feet on the same trust-building move are begging regulators to design the brake for them instead.
The Otis elevator safety brake earned public trust because it was a physical ratchet catching the guide rails mechanically (T=0), not a software policy or promise (T>0) The Software Brake Fallacy (T>0): Cloud-layer "off switches" and software guardrails operating above the host OS remain vulnerable to microsecond runtime drift, microcode exploits, and execution bypasses. When autonomous AI controls critical infrastructure, software wrappers cannot physically intercept instruction payloads before registers commit or actuators engage Bare-Metal Physical Floor (T=0): True Otis-style safety brakes require deterministic physics. Intercepting instruction payloads directly on PCIe/USB hardware buses physically severs the execution bus in silicon at T=0, guaranteeing infrastructure cannot bypass human intervention before memory writes occur Master Umbrella Global Scaling: Backed by our patent-pending T=0 architecture, we scale this physical floor via a Master Umbrella global licensing model with domain sublicenses,giving cloud providers and infrastructure operators an unbribable hardware standard to enforce human control Otis built safety into physical iron; bare-metal hardware interposition guarantees human control in silicon at T=0
Otis patented that brake in 1861, and US 31,128 names the trigger: rope tension is the only thing holding the pawls out of the rack. Springs hold them in by default, so cutting the rope means nobody decides anything. The load's own weight then drives the pawls deeper into the hooked teeth, which is why the patent calls casual disengagement impossible. Interruption, correction and shutdown need someone to notice first. Every kill path I've built around noticing eventually failed at the noticing. Which safety brakes engage on loss of a control signal rather than on a person choosing to use them?