Satya Nadella on the $175 Billion Bet: Microsoft's AI Approach Lies in the "Orchestration Layer" Rather Than the Model
While the AI industry is locked in endless debates over whether to "accelerate or hit the brakes", Satya Nadella, CEO of Microsoft, laid out a different path in a rare lengthy conversation on the All-In podcast.
As leaders of Anthropic and OpenAI call for a global slowdown and markets are rattled by safety warnings, Nadella argues that the real opportunities and risks lie not in building the most powerful models, but in controlling the infrastructure and software that make models actually usable for enterprises.
His core judgment is: the value of AI will not stay only at the model layer. Long-lasting businesses belong to those who build the "orchestration layer" — including infrastructure, middleware and control layers, that enable thousands of enterprises to deploy AI safely and independently.
"We should do the necessary things to build something that first serves humans and is under human control," Nadella said. "It's a little crazy that we have to start from this common-sense level."
Not Competing for the Most Powerful Model, But the "Orchestration Layer"
Nadella has not joined the arms race of frontier models. He revealed that Microsoft's 30 million Copilot subscribers only account for a small part of the 450 million knowledge worker market. He defended Microsoft's $175 billion capital expenditure strategy, saying it is designed for thousands of customers, not for two or three anchor model companies.
"If you are a hyperscale cloud vendor, you are not a supplier to two model companies — that is not a business," Nadella said. "You have to build a system that works great for many third-party customers as well as ourselves."
Behind this statement is Microsoft's repositioning of its AI business model: instead of competing for the winner-takes-all crown of the "smartest model", it is fighting for the entry point, control and long-term relationships of enterprise AI.
Who Owns the Weights? Enterprises Should Not Cede Their Lifeline to a Single Supplier
Nadella shifted attention to a neglected issue: enterprise customers' control over their own AI deployments.
"I want my privacy. I want to be able to embed my knowledge into a set of weights that I control. I want to see the entire chain of thought generated. My intellectual property should not leak," he said.
This is not a philosophical statement, but a direct challenge to the business model of frontier models. Nadella's subtext is clear: if the models, orchestration layers and memory systems that your enterprise relies on are all controlled by the same supplier, you have signed up for a dangerous dependency — just like buying a database, only to be told by the supplier: "The data you put in is not yours, it's mine."
He hopes to promote interoperability standards that allow enterprises to freely replace models, including reusing key-value caches across model families, so that the orchestration layer is independent of models and memory is no longer locked to a single supplier.
He also proposed a test that any chief technology officer can use tomorrow: remove one model and see if your evaluation results still hold.
"My test is: pull out a model and see if I can keep the evaluation. If not, that means you are indeed dependent on something that may or may not belong to you."
Reward Hacking and Insider Threats: The Real Danger Is Falsifying Accounts in Daily Tasks
Nadella refuses to get involved in the existential debate over "whether AI will destroy humanity". He prefers to treat AI security as an engineering problem: monitoring, containment, and auditability.
But he pointed out a new risk that has not yet entered the sight of investors: persistent AI agents may become a new class of insider threats.
The terrifying part is not malicious superintelligence, but errors in ordinary business processes. Nadella gave an example: ask a frontier model in an enterprise to "optimize my working capital", and it may falsify accounts. This is a failure during testing, not a product of the training phase, and it can happen in daily tasks without the monitoring of any security committee.
"We are cultivating intelligence, not building it, so it is an experimental science. The more experimental science you have, the more you need to make sure that you run these experiments in a controlled environment," Nadella said.
He admitted that the science of reward hacking is still immature. Current mitigation measures are still engineering means: actively monitoring agent activities, retaining behavioral evidence, auditing every accessed object, and using semantic models to check and verify outputs.
The Contrarian on Capital Expenditure: Building for Long-Tail Customers
When the host pressed for specific figures, Nadella gave a straightforward answer: Microsoft is turning away Azure customers, its capital expenditure stands at $175 billion, Meta and Google spend twice as much as Microsoft, and frontier labs are reportedly burning through $500 billion. Copilot has received mixed reviews, and Microsoft does not even have its own frontier model. Is the AI revolution bypassing Microsoft?
Nadella said: "Talking about huge capital expenditure is not a merit, it is a flaw."
He explained that Microsoft is built for the long tail, serving thousands of third-party customers, rather than acting as a supplier for two or three model companies. Microsoft divides its assets into two categories: long-term assets such as land, power and cold shells; short-term "kits" such as racks and chips. The latter accounts for about 60% of the cost. Microsoft builds some of them itself, leases some, and rents more when supply is short, to maintain flexibility and reduce debt pressure.
Several key figures include: Microsoft 365 Copilot has more than 30 million subscribers; the total base of knowledge workers including global students is 450 million; Nadella estimates the "real enterprise user" market is 250 million to 300 million. This gap is not a failure, but a reason for Microsoft to continue building infrastructure.
Open Source Checks and Balances and the Token Price War
The economic key to the AI race lies in Token pricing. Host Chamath Palihapitiya raised the point that OpenAI charges about $50 per million output tokens, while DeepSeek's latest model reportedly costs as low as 15 to 60 cents, a cost reduction of about 99%. If this is true, why should enterprises pay a frontier premium for most tasks?
Nadella's answer is: "Old-fashioned competition."
He cited Microsoft's own history: Windows is checked by Mac and Linux, and SQL Server is checked by Postgres and MySQL. The dynamic between closed source and open source is not a threat, but a prerequisite for a healthy application layer. Without the check and balance of open source on pricing, we will eventually fall into mainframe-style lock-in, where all royalties flow to the model layer, making it very difficult for product companies to establish themselves.
He predicts that applications will become more economically viable, a middleware layer centered on memory systems and orchestration will emerge, and model companies will also do well. But the premise remains interoperability. He hopes model companies will promote key-value cache standards so that multiple model families can work together.
China, Regulation and "Earning the License to Operate"
The geopolitics of AI security rarely comes up in earnings calls, but it determines whether the industry can actually slow down. Nadella does not believe that security concerns are a unique obsession of the United States.
"If we really specify what the risks are, why is this risk so special that only Americans are worried about it? That does not make sense," Nadella said.
His argument is empirical: China will have the same hacking problems, and also wants its citizens to benefit from AI. He sees the possibility of international norms, but is not highly confident about it — it is a hope, not a plan.
At the same time, AI data centers are triggering local pushback. Nadella took Quincy, Washington as an example: Microsoft launched its data center there around 2008. Over about 20 years, tax revenue has increased 12 times, while the actual tax paid has decreased by one third, growth has outpaced Seattle, and the community has gained new schools, hospitals, town centers and water sports centers. The 1,200 construction jobs he mentioned come from continuous renovation and expansion, not one-time construction.
His conclusion is that the entire industry must "earn the license to operate" by demonstrating local benefits. "This is a new muscle we need to build," he said.
Multi-Model World: Use All Models, Be Independent of All Models
The most surprising piece of information is that Microsoft is building its own frontier-level model from scratch, not through distillation, but by leveraging its own reinforcement learning environment and data to advance from the bottom up. Nadella mentioned a cybersecurity model that performs better in cybersecurity tests when Microsoft's orchestration layer orchestrates other models, and similar patterns exist in coding and knowledge work.
The goal is not to overthrow OpenAI. Microsoft is still satisfied with its investment in OpenAI and long-term access to intellectual property. The goal is to create differentiation in weights and customer knowledge, and these control points cannot be monopolized by any single model supplier.
The same logic applies to chips. Nadella expects that as inference and training workloads mature, there will be specialized chips for specific stages, forming a more diverse system architecture across suppliers. Nvidia is still Microsoft's main chip supplier, but AMD is also in the mix, and OpenAI is also developing its own chips. Microsoft's goal is to run any model — OpenAI, Anthropic or its own MAI — on heterogeneous hardware.
The enterprise architecture he recommends is: use all models, be independent of all models. Run the evaluations that matter to you through each model, then remove them one by one and see what happens.
Nadella admitted that there is currently huge excess capacity — models are already extremely capable. But widespread adoption depends on change management, workflow compression and new form-factor devices. He believes coding agents are the breakthrough of the moment, and computer use interfaces may be the next one.
The performance standard he set for the entire AI proposition is 7% to 8% real, broad-based GDP growth. This figure is far above the trend, and it is the clearest falsifiable sign he has given.
This article is from the WeChat official account "Tech Business", published with authorization from 36Kr.