A Microsoft Insider's Guardian Essay Points at Azure, Not Superintelligence
The essay is a response to a recent wave of warnings about AI from industry leaders. The clearest example is Bill Gates. Gates argued on August 26 that artificial intelligence needs significant limits or else the harm to humans will outweigh any potential good, in a 6,000-word essay entitled "The turbulent AI era is here. The choices we make now are critical." Coverage of his essay focused on long-range risks. Gates told MIT Technology Review, "We've crossed the threshold in terms of [AI's] bio-capabilities, cyber-capabilities, psychosocial capabilities, job-market-destruction capabilities, and even the lack of control." CBS News focused on jobs, reporting that one idea Gates floated would be a tax on AI tokens and robots, which he argued would slow companies' displacement of human workers.
Kim and Hussein say Gates's warning came as no surprise to them. They describe two years of organizing with other Microsoft employees and activists to press the company to cut ties with the Israeli military. They also claim that Sam Altman, Elon Musk, Demis Hassabis, Dario Amodei and Satya Nadella have joined calls for a slowdown, and that a researcher's posts on X set off the latest round of alarm. Those framing claims are the authors' own, and this article does not treat them as established.
Their main argument is narrower and easier to test. The dangers people predict for future frontier models are, they say, already visible in how today's AI and cloud systems are used. Their examples are Gaza, a US strike on an Iranian school, ICE, the New York Police Department and datacenter siting. The evidence behind each one is uneven, so each is taken separately below.
What Microsoft Has Confirmed About Unit 8200's Use of Azure
The Israeli case has the most solid record, and much of it comes from Microsoft. In a May 15, 2025 statement, Microsoft said internal and external reviews had found "no evidence to date" that Azure and its AI technologies were used to target or harm people in Gaza. In the same statement it confirmed that it provides the Israel Ministry of Defense (IMOD) with software, professional services, Azure cloud and Azure AI services, including language translation.
The statement also spelled out the limits of those reviews. Microsoft said it has no visibility into how customers use its software on their own servers or devices. It also has no visibility into IMOD's government cloud operations, which other cloud providers support. It added that militaries usually rely on proprietary or defense-contractor software for surveillance and operations, and that Microsoft had not built such tools for IMOD.
Microsoft changed course after The Guardian, with +972 Magazine and Local Call, reported on August 6, 2025 that an Israeli military intelligence unit was storing recordings of mass-intercepted Palestinian phone calls in Azure. On August 15, Microsoft said it had hired the law firm Covington & Burling, with technical help from an independent consultancy, to run a formal review. It noted that its standard terms of service prohibit that kind of use. The Guardian later reported that shortly after the inquiry began, Microsoft cut off the Israeli military's access to the cloud and AI services behind the surveillance project, after initial findings showed that Unit 8200, Israel's signals-intelligence agency, had violated the terms of service.
In June 2026, Microsoft published what it called a "final update." According to The Guardian's account of the five-page summary, the company said its factual findings had not changed and listed governance changes:
- Microsoft will change how it vets "national security-related" business before contracts are signed.
- It will review how it manages employees who hold security clearances issued by foreign governments "in certain countries."
- It will run periodic checks on whether customers follow its acceptable use policies when political circumstances change or sensitive projects change.
- It will strengthen human-rights due diligence in conflict-affected and high-risk areas.
This record supports a specific claim. A Microsoft customer used Azure storage and AI services for mass surveillance, the use broke Microsoft's terms, and Microsoft disabled the services involved. It does not show that Azure picked targets in Gaza. It also does not show that Microsoft ended its wider relationship with IMOD. The essay's figure of 12,000 AI-generated targets in the first month of the war, which it attributes to journalist Yuval Abraham's investigative work, refers to Israeli military systems, not Microsoft products.
ICE's Azure Footprint Grew From 400TB to Nearly 1,400TB
The essay says the Department of Homeland Security uses AI tools, "including Microsoft's Azure," to monitor, arrest and deport immigrants. The most detailed evidence is a February 17, 2026 Guardian investigation based on leaked documents obtained with +972 Magazine and Local Call.
According to those files, ICE stored about 400 terabytes in Azure in July 2025 and almost 1,400 terabytes by January 2026. That is more than a threefold increase in six months, during which ICE's budget grew by $75 billion and its workforce more than doubled. The documents show ICE using Azure blob storage for raw data, virtual machines to run software, AI services that analyze images and video and translate text, and an expanded Microsoft productivity suite that includes an AI chatbot.
The same reporting is clear about what the files do not show. They do not say what kind of data ICE stores. They also do not show whether Azure holds or analyzes information from ICE's surveillance or intelligence work, or whether it mainly supports administrative functions such as running detention centers or deportation flights. The essay's claim that Azure is being used to "monitor, arrest and deport" goes further than those documents.
Microsoft told The Guardian that it provides cloud productivity and collaboration tools to DHS and ICE through resellers. It said its policies prohibit mass surveillance of civilians and that it does not believe ICE is doing that. Its internal wording has also narrowed over time. In December 2025, responding to an employee ethics report, Microsoft said it had no current contracts that "support immigration enforcement." It later told employees it did have ICE and DHS contracts but "does not presently maintain AI services contracts tied specifically to enforcement activities." The difference between general agency use of Azure and a contract written for enforcement is the key point in this dispute.
The Minab School Strike Was a Database Failure Inside Maven
The essay's most serious claim is that a US airstrike "involving AI" hit the Shajareh Tayyebeh school in Minab, Iran, killing 156 people, and that the cause was "most likely" a targeting mistake based on faulty data. The strike itself is well documented. The AI framing is the part that needs correcting.
A March 26, 2026 Guardian long read by Kevin T Baker reported that US forces hit the school at least twice on the morning of February 28, the first day of Operation Epic Fury. It put the death toll at between 175 and 180, most of them girls aged 7 to 12. Casualty counts differ between reports, so any figure needs its source and date attached.
Baker's account, which cites CNN, says the building was listed as a military facility in a Defense Intelligence Agency database. That database had never been updated to show that the building had been separated from a neighboring Islamic Revolutionary Guard Corps compound and turned into a school. Satellite imagery shows that change had happened by 2016 at the latest. The targeting ran on the Maven Smart System, a Palantir platform built after Google dropped the Pentagon's Project Maven contract in 2018. Maven combines satellite imagery, signals intelligence and sensor data into a Kanban-style pipeline that moves targets from detection to strike. Its machine-learning parts detect and classify objects and give each detection a confidence score. The large language model layer, where Anthropic's Claude sits, was added in late 2024 so analysts could search and summarize intelligence reports. Baker argues it did not detect targets or pair them with weapons.
So "faulty data" is the part of the essay's account that holds up, and it may be the more important part. Baker describes a system designed for speed. A 2024 target of 1,000 targeting decisions an hour works out to one decision every 72 seconds for each targeteer. At that pace, a stale database entry became a lethal strike. The evidence points to human choices, outdated records and a compressed kill chain, not a chatbot choosing the target. The essay is right that automated targeting infrastructure played a role. It is wrong to suggest that generative AI caused the strike.
NYPD Surveillance, Datacenters and the Claims That Remain the Essay's Own
Several of the essay's other claims go beyond the evidence gathered for this article, and they are attributed to the authors here. They cite the New York Daily News for the claim that the NYPD built its Domain Awareness System with Microsoft, using Azure to connect to 18,000 security cameras, and that the system has since spread to Georgia, Brazil and Singapore. The essay also makes broader claims about facial-recognition errors leading to wrongful arrests of Black and Latino Americans, and about air pollution from datacenters built in low-income rural areas. Those are serious claims with a long public history, but this article has not independently verified the essay's specific figures.
The same applies to the essay's political claims. These include Donald Trump reportedly calling AI risks a "hoax," House Republicans blaming Chinese disinformation for opposition to datacenters, and Israel's culture minister, Miki Zohar, threatening to revoke the citizenship of filmmakers Yuval Abraham and Rachel Szor. They matter to the authors' argument about dissent. They are not part of the Microsoft record.
The Ban Artificial Superintelligence Act Is a Proposal, and the "Frontier Act" Is Unverified
The essay welcomes two pieces of legislation and then argues neither goes far enough. The first is the Ban Artificial Superintelligence Act from Senator Bernie Sanders and Representative Greg Casar, announced September 3, 2026. According to Sanders's press release, the bill would permanently ban building and deploying superintelligent AI and pause advanced AI development until a federal regulator sets safety rules. It would create a cabinet-level agency to monitor frontier systems and direct the US to seek international agreements. Penalties would include up to 20 years in prison for individuals and what the release calls a "corporate death penalty" for companies. These are the sponsors' own descriptions of a bill that has not passed.
The second is a House "Frontier Act," which the essay says would place third-party evaluators inside tech companies to run safety assessments. This article could not find the bill text or its legislative status in a primary source, so those details remain the essay's description.
The authors' own demand is broader than either bill. They want frontier AI companies and governments to stop selling and using AI for military targeting, autonomous weapons and mass surveillance, and they say employees at Anthropic, OpenAI and Google DeepMind are calling for the same thing. That is an advocacy position, not a description of any current policy.
What This Means for Microsoft Cloud Customers and Administrators
For most Windows and Azure users, nothing in the essay changes how a product works. What it shows is how Microsoft's acceptable use policies are enforced, and that affects any organization whose own compliance depends on them. Microsoft's May 2025 statement describes those terms as requiring core responsible-AI practices, such as human oversight and access controls, and as banning use of its cloud and AI services to harm individuals. The Unit 8200 case shows those terms can be enforced. Microsoft disabled specific services for a sovereign military customer.
The same statement also shows where enforcement stops. Microsoft can only review what runs on its own cloud. It cannot see on-premises software, customer-owned devices or workloads hosted with other providers. It also says it did not access customer content during its review. Its checks rely on contracts, account data and interviews, not on inspecting what customers store.
- Organizations that rely on Microsoft's Acceptable Use Policy or AI Code of Conduct as part of their own responsible-AI compliance should know that those terms put human oversight and access controls on the customer, not on Microsoft.
- Microsoft's review process cannot see how its software runs on-premises or with other cloud providers, so internal governance has to cover those deployments.
- The June 2026 changes add pre-contract vetting for national-security-related business and periodic acceptable-use reviews when circumstances change, so public-sector and defense-adjacent customers should expect more scrutiny.
- The ICE records show that storage growth and a list of services are not proof of any particular use, and the same caution applies when judging any vendor's government contracts.
- The Minab case is a warning about stale reference data in automated pipelines, since one outdated database record led to a strike that system speed made hard to catch.
For now, Microsoft treats its Israel review as closed. The ICE contracts are still an open question inside the company, and both of the essay's bills are still proposals. Kim and Hussein have nonetheless moved the argument from speculative superintelligence to the specific services, contracts and data pipelines Microsoft sells today. Their strongest examples, Unit 8200's use of Azure and the Minab database failure, rest on documented human decisions and data errors, not on runaway AI. The next concrete test will be whether Microsoft's promised periodic acceptable-use reviews reach its growing ICE business the way they reached Unit 8200.