Essay · June 2026
Social Permission Is a Distrust Problem
Satya Nadella says AI companies have to earn society's permission. He's right. But permission isn't won by building trust — it's won by giving distrust nothing to grip.
Satya Nadella gave an interview to The Wall Street Journal this week that I've been turning over since. The headline framing is about market power — Microsoft pushing cheaper models, commoditizing the frontier, declining to let a few companies “do all of the learning for the world.” That's the business story, and it's a real one. But the line that stayed with me wasn't about pricing. It was this: “We now have to do the hard work in earning the social permission.”
He's right, and I want to take the phrase more seriously than a soundbite usually gets taken — because I think most people will read “social permission” as a communications problem, and it isn't. It's a structural one. Nadella said as much in the same breath: “No amount of just narrative is going to do it.” The question he's really raising is what, other than narrative, actually earns permission. I've spent three years researching the answer, and it isn't the one the industry keeps reaching for.
I want to be precise about what permission is, because the word does a lot of quiet work. Permission is not approval. Approval is a survey result — a number that tells you how people feel about a thing in the abstract. Permission is what people grant in the particular: the willingness to let a system act inside their work, their records, their decisions, with their name attached to the outcome. You can have approval without permission, and most AI products right now do. People will say AI is useful and then refuse to let it touch anything that matters. That gap is the whole problem, and it does not close with a better message.
The trust story is the wrong story
The reflex, when a technology faces resistance, is to go build trust. Make it more capable, more impressive, more clearly beneficial, and people will come around. My doctoral research said that reflex is right — for the kind of AI we've had until now. When a person reviews every output before it counts, trust in the system's usefulness is what drives whether they'll champion it. Prove the value, and advocacy follows.
I want to be honest about how confident I was in that finding, because the reversal matters more in light of it. The data were clean. Across a large sample, trust in the technology predicted advocacy, and the prediction held under the controls I threw at it. I had a result that said: if you want people to adopt and champion a system, demonstrate that it works. That is the conventional wisdom, and my work confirmed the conventional wisdom. I had no reason to expect the ground to shift.
Then I looked at what happens when you take the human out of the loop — when the AI doesn't suggest but acts, the way Nadella's own Copilot Cowork is built to act, choosing models and running long tasks on its own. And the finding reversed on me. In that world, trust stops being the thing that decides adoption. Distrust does.
These are not the same variable with opposite signs. This is the part that trips people, so I want to slow down on it. The intuition most of us carry is that trust and distrust sit on a single dial — turn one down and the other goes up, and the two always sum to the same total. That intuition is wrong. A large body of work, going back to Lewicki and colleagues in the management literature, establishes that trust and distrust are separate systems with separate triggers. You can hold both at once about the same thing. You trust your surgeon's skill and distrust the hospital's billing in the same breath, and neither feeling dilutes the other. They run on different tracks.
And what I found is that they have different jobs. Trust feeds on how useful and legitimate a system seems — the upside, the competence, the track record. Distrust feeds on something else entirely: risk. On the cost of being wrong. On what happens to you if the thing fails in the worst way it can fail. The two are not measuring the same quantity from opposite ends. They are answering two different questions — “is this worth using?” and “what does it cost me if this betrays me?” — and a system can score well on the first and catastrophically on the second.
That is why the loop matters so much. When a human supervises, distrust is cheap, because you catch the mistake before it lands. The cost of being wrong is bounded by the review step — whatever the system proposes, a person stands between the proposal and the consequence. Remove the human, and distrust wakes up, because now the mistake is real and it has your name on it. Nothing stands between the action and the world. The same system that felt fine as an advisor becomes a liability as an actor, and the feeling that governs whether you'll let it act is no longer trust in its competence. It's distrust of its consequences.
When the machine only suggests, you manage trust. When the machine acts, you manage distrust. Earning permission is the second problem, and almost everyone is still solving the first. This is why “earning social permission” is not a narrative exercise. You do not argue someone out of distrusting a system that can act against their interests without their knowledge. The distrust is rational. It is a correct response to a real change in exposure. The only thing that brings it down is changing what the system can actually do to you.
What actually lowers distrust
Here is where I'd push past Nadella's framing, and past the “transparency” answer that usually fills this space. Transparency is the reflexive answer in this field — show your work, explain the model, publish the reasoning, and trust will follow. I understand the appeal. But transparency — showing people the reasoning after the fact — is necessary and not sufficient, because it arrives too late to do the real work. An explanation of why an agent did something comes after the action is already a consequence. The email is sent. The record is changed. The transparency report tells you, with clarity, exactly how you got hurt. What lowers distrust is not a better explanation afterward. It's predictability beforehand.
The distinction is the whole argument, so let me put it plainly. Transparency is retrospective — it tells you what happened. Predictability is prospective — it tells you what will happen before it does. Distrust is a forward-looking emotion. It is about exposure to a future action, not comprehension of a past one. You cannot lower a forward-looking fear with a backward-looking explanation. You lower it by letting people form an accurate expectation of what the system will do, and then having the system meet that expectation, again and again, until the expectation hardens into something they can rely on.
Concretely, that means four things, and none of them are messaging.
Bounded authority. An agent scoped to do a few things is one whose behavior you can actually anticipate — it cannot surprise you in territory it can't reach. The instinct in the field runs the other way: give the agent broad capability and trust it to use the capability well. But breadth of authority is exactly what makes behavior unpredictable, and unpredictability is what distrust feeds on. A narrow agent is not a less capable product. It is a more grantable one. You will let something act when you know the outer edge of what it can do, and the edge has to be real — enforced by what the system can reach, not by what you asked it not to do.
Legible intent. An agent that declares what it's about to do, and can be made to wait, lets you form an expectation before it acts rather than after. This is the prospective version of transparency — not an explanation of the completed action, but a statement of the intended one, surfaced while there is still time to stop it. The difference between “here is what I did” and “here is what I am about to do” is the difference between a report and a brake. Distrust can live with the second. It cannot survive the first as the only control.
Observable behavior. A history a person can actually inspect, not a log nobody opens. The test is not whether the system records what it did — everything records what it did. The test is whether a human being can look at the record and understand it without specialized effort, in time for the understanding to matter. A log that requires an engineer and a week is not observability. It is plausible deniability with a timestamp. Observable behavior means the people exposed to the system's actions can see those actions in terms they understand, as a matter of course.
Reversibility. Actions that can be undone are mistakes you can survive, and survivable mistakes are how people learn to predict a system instead of fearing it. This is the one the field undervalues most. We treat reversibility as a safety feature — a way to limit damage. It is that, but it is also the engine of permission. You do not learn to trust a system you've never seen recover from a mistake. You learn to trust it by watching it fail in a way that did not cost you, and then watching it fail that way again, and discovering that the failure is bounded. Reversibility is what turns a single act of permission into a standing one, because it lets people accumulate evidence about the system's worst case at a survivable price.
Notice that every one of these is an architectural choice, not a communications choice. That's the part I think the industry keeps missing. None of the four can be retrofitted with language. You cannot describe your way into bounded authority; either the agent can reach the thing or it can't. You cannot message legible intent; either the system pauses or it doesn't. Permission isn't granted because you explained yourself well. It's granted because you built a system whose worst-case behavior is bounded, visible, and recoverable — so the distrust has nothing left to feed on.
Why the industry keeps reaching for narrative
It's worth asking why the field defaults to the communications answer when the structural answer is the one that works. I don't think it's stupidity. I think it's incentive. Narrative is fast and the architecture is slow. You can ship a trust-and-safety page in a week; you cannot ship bounded authority, legible intent, observable behavior, and reversibility in a week, because those are properties of the system, not properties of the marketing around it. When the pressure is to demonstrate responsibility on a quarterly cadence, the messaging layer is where responsibility goes to be demonstrated, because it's the layer that moves at the speed of the pressure.
There's a second reason, and it's more flattering to no one. Narrative is the layer the company controls. The architecture exposes the company to a verdict it does not control — the verdict of people using the thing, who will find out within a week whether it behaves the way the narrative said. So there is a quiet preference for the layer where the company gets the last word. The trouble is that permission is granted by the people who use the system, not by the people who describe it, and those people are running their own test continuously. The narrative can win the launch. It cannot win the week.
Where Nadella is pointing in the right direction
The part of his argument I'd underline is the one getting the least attention. Nadella talked about companies needing both “token capital” and human capital, and about a firm's real advantage being its tacit knowledge running inside “a machine you control.” Strip the market-power framing off that and it's the same point I'm making from the trust side. A machine you control is a machine whose behavior is bounded and observable — which is exactly what makes it one your people will let act on their own.
So the control isn't only about avoiding dependency on a frontier vendor, though that's the angle Nadella is selling. Control is what produces comprehensibility, and comprehensibility is what earns permission. The two arguments — his about market structure, mine about trust — converge on the same architectural fact. A system you control is a system you can bound, observe, and reverse. A system you merely rent, whose behavior changes when someone else ships a model update you didn't ask for, is a system whose worst case you cannot predict. The dependency problem and the distrust problem have the same solution, which is why I think Nadella is closer to the real point than the market-power framing of his own interview suggests.
The enterprises that win the agentic transition won't be the ones with the most autonomous agents. They'll be the ones whose agents are the most legible — bounded enough to distrust safely, predictable enough to trust appropriately. Those two phrases are doing deliberate work. You want both feelings calibrated, not one maximized. An agent you trust completely and cannot bound is a liability waiting for its first bad day. An agent you distrust so thoroughly that you bound it into uselessness is a cost with no return. The skill is holding the two in proportion — trusting the competence as far as the evidence warrants, distrusting the consequences enough to keep the worst case survivable. That proportion is an engineering target, and the field has barely started treating it as one.
That's the hard work Nadella is right to name. It just doesn't happen in the messaging layer. It happens in the architecture — the part you can't fake with a narrative, because your people will find out within a week whether the machine actually behaves the way you said it would. Social permission, in the end, is just distrust that ran out of things to grip. You earn it by building agents that give it nothing.
That's the working draft of where my thinking is. Offered, not finished.
The views expressed here are entirely my own and do not represent the policy or position of my employer or any customer.