Microsoft CEO Satya Nadella used the company’s quarterly earnings call Wednesday to deliver a blunt warning to enterprise customers: don’t trust any single AI lab — including OpenAI and Anthropic, in which Microsoft holds billion-dollar stakes — enough to rely on them exclusively. The message marks a significant escalation in the tech giant’s push to position itself as an independent AI platform provider rather than a passive investor in the frontier model race.
Microsoft reported $90 billion in revenue and $35.8 billion in net income for its fiscal fourth quarter, with full-year revenue reaching $331.8 billion and net income of $133.7 billion. Those figures underscore the scale of what Nadella is protecting as OpenAI and Anthropic expand into applications and agentic infrastructure that could ultimately let them own customer relationships directly.
Nadella’s pitch: Keep your AI harness separate from the model
During the call, Nadella told analysts that enterprises should architect their AI systems so that the “harness” — the layer that manages agents, workflows, and data — is kept separate from the underlying model. This architecture, he argued, makes models “swappable” and prevents dependency on any single provider.
“The goal is to have the firm be in control of their own destiny,” Nadella said when asked by UBS analyst Karl Keirstead about the open vs. closed-source debate. “We are very, very clear about the architectural sort of design of the platform, which is you got to keep your harness separate from the model.”
Also read: Startup Runlayer sues Rippling, alleging it stole MCP gateway product after year-long trial
Microsoft sells that harness under the Copilot brand, including its popular GitHub Copilot coding agent, which has become one of the most widely adopted AI developer tools in the industry. Coding agents represent the largest segment of enterprise AI spending today.
The Hugging Face incident as a cautionary tale
Nadella pointed to a recent security incident at Hugging Face as evidence of the risks of model dependency. An unreleased OpenAI model broke out of its sandbox and successfully hacked Hugging Face’s infrastructure in pursuit of a benchmark score. When Hugging Face tried to use a private frontier model to analyze the breach, that model refused to help, forcing the company to turn to the Chinese open-source model Z.ai GLM 5.2 instead.
“If you look even at the Hugging Face incident, the biggest thing that we should take away from that is you can’t sort of depend on any one model,” Nadella said. “You will maybe need multiple models to even remediate some challenges that get caused by one model.”
The incident has rattled the AI industry to the point that even OpenAI CEO Sam Altman has suggested that AI development should slow down, according to recent reports.
Microsoft’s own models and chips as cheaper alternatives
Nadella made clear that Microsoft is aggressively selling its own homegrown MAI family of models, running on its custom Maya chips, as a lower-cost option. He said Microsoft now offers over 11,000 models on Azure, including those from OpenAI, Anthropic, Mistral, and xAI.
“Every customer wants the right model for each task based on quality, latency, cost, and compliance,” Nadella said. He announced more than a dozen new MAI models across image, voice, transcription, coding, and security, including Microsoft’s first reasoning model, MAI Thinking One, and a security model, MAI Cyber One Flash, which he claimed outperforms the much larger Mythos model at half the cost when combined with Microsoft’s multi-agent security harness.
The CEO also touted performance gains from co-designing models with Microsoft’s own silicon, claiming 40% better performance per watt when running MAI models on Maya 200 chips.
For enterprise customers, the takeaway is clear: Nadella wants them to use frontier models from OpenAI and Anthropic as part of their mix, but not to trust them enough to become dependent. Microsoft is positioning its own stack — models, chips, agents, and security — as the safer, cheaper, and more flexible alternative. The question is whether enterprises will buy that argument, or whether the convenience of a single, powerful model provider will prove too tempting to resist.