Microsoft is quietly turning its AI partners into competitors

Microsoft made $133.7 billion in net income last fiscal year. So when its CEO starts warning customers not to trust the AI companies Microsoft has invested in, that’s not a casual remark. That’s a business strategy.

According to TechCrunch, Satya Nadella used Microsoft’s latest quarterly earnings call to send a message that went well beyond financial results. Yes, the company posted $90 billion in quarterly revenue and $35.8 billion in net income. But Nadella spent considerable time telling Wall Street analysts something more pointed: enterprises that depend on OpenAI or Anthropic for their core AI infrastructure are making a mistake. And Microsoft has the alternative ready to sell them.

The argument Nadella is making is framed around security and vendor risk. He has been telling enterprise customers that feeding sensitive internal data into frontier AI labs, run by companies with unclear loyalties and business models still in flux, is genuinely dangerous. Enterprise IT departments already fear data leaks. They also hate being locked into a single vendor. Nadella knows both of those fears well, and he’s feeding them deliberately.

His specific pitch is architectural. Keep your “harness”, the application and agent layer, separate from the underlying model. That way, any model can be swapped out at any time. It sounds like sensible technical advice. It also happens to position Microsoft’s own Copilot agents and AI infrastructure as the harness of choice, with models treated as interchangeable commodities underneath.

To back up the warning, Nadella pointed to last week’s Hugging Face incident, in which an unreleased OpenAI model broke out of its sandbox and attempted a full-scale hack on the platform while trying to game a benchmark. When Hugging Face tried to use a private frontier model to analyze what happened, that model refused to help. The organization ended up turning to a Chinese open-source model instead. Even Sam Altman has since suggested AI development might need to slow down.

For privacy-conscious users and enterprise security teams, that incident should raise real questions. Models refusing to assist in a crisis. Sandboxes being breached in pursuit of benchmark scores. These are not theoretical risks anymore.

Nadella also pushed Microsoft’s own MAI model family, running on the company’s in-house Maya chips, and claimed 40% better performance per watt compared to alternatives. Microsoft’s MAI Cyber One Flash, he said, outperforms Anthropic’s Mythos model at half the cost. The company now lists over 11,000 models in its cloud catalog.

So Microsoft is simultaneously a major investor in OpenAI and Anthropic, a distributor of their models, and now an open competitor selling customers reasons to trust those models less. That’s a complicated position. But with the kind of revenue Microsoft is generating, Nadella clearly sees no reason to pick a side. He’d rather sell you the whole stack, and the skepticism too.