Natalie
Isak
AI safety researcher & engineer focused on frontier risks

Passion for AI Safety
I am deeply passionate about Artificial Intelligence safety and driven to make a meaningful impact in this critical field. My journey began at Cornell University, where I led a research team developing computer vision models for environmental monitoring and studied bias in information networks under Jon Kleinberg.
My ambition led me to join Microsoft through the Microsoft AI Development Acceleration Program. This opportunity allowed me to contribute to cutting-edge AI research and development initiatives across the company.
When generative AI emerged in 2022, I was invited to join an internal Responsible AI review board for all generative AI releases at Microsoft. The responsibility for assessing safety across dozens of product releases became mine, a role that fundamentally shaped my understanding of AI safety challenges. Today, my work centers on developing monitoring systems and mitigation strategies for emerging AI risks, with an emphasis on privacy-preserving and compliant approaches.
Safety First
Designing mitigations before risks manifest
Research x Product
Identifying novel challenges at scale
Top of Mind
- →Understanding and measuring emergent risks without compromising user privacy
- →Detecting harmful content (e.g. cross prompt injections) in multimodal inputs and outputs
Experience
Machine Learning Engineer II
Microsoft AI Safety
New York, NY
- •Co-invented and productionized BinaryShield, the first privacy-preserving fingerprinting system for correlating AI threat signals across compliance boundaries; implemented the production architecture, co-authored the paper, and drove a patent filing.
- •Developed and evaluated detections for novel AI risks (agentic memory poisoning, psychosocial harms, multi-session malware campaigns, etc.) using agents, fine-tuning, and heuristics.
- •Architected, built, and scaled a 0-to-1 AI safety detection platform across 60+ Microsoft services, processing 26.8B log lines monthly and enabling privacy-preserving, retroactive detection across compliance boundaries.
- •Led the design and implementation of a “write once, run everywhere” detection framework across heterogeneous products and compliance boundaries, reducing detection-authoring time by 67% and enabling previously impossible retroactive analysis.
- •Architected and executed the first AI-powered scan of M365 telemetry during a live security incident, analyzing 90M+ logs across multiple regions and achieving 99.84% accuracy in offline evaluation.
- •Defined new observability requirements for AI capabilities across Microsoft AI’s product portfolio.
- •Drove the cross-company technical design and service contracts integrating AI safety detections into Microsoft Defender and Sentinel, surfacing abuse signals through established customer security and investigation workflows.
- •Mentored junior engineers and interns.
Machine Learning Engineer II
Microsoft AI Development Acceleration Program
Cambridge, MA
- •Architected AI data entry agent with >200K MAU, improving latency by 90.72% and saving ~$300K CAD annually.
- •Architected backend contracts and service enhancements for tenant-level fine-tuning of enterprise agents, aligning model-customization interfaces across Copilot Studio and M365 and leading end-to-end security reviews.
- •PaLed technical Responsible AI reviews for dozens of product launches, translating safety risks into measurable release criteria and production mitigations.
- •Developed open-source Semantic Kernel agentic framework (awarded 3 independent patents).
- •Built a RAG-based M365 Chat plugin projected to deflect up to 80% of an HR support queue; designed end-to-end quality and Responsible AI evaluations covering retrieval and generated responses.
- •Added full stack support for object detection in RAI Dashboard, released at Microsoft Build.
- •Designed and implemented a new machine learning (ML) pipeline for a Smart News feed using AI Builder, simplifying onboarding (saving 6 weeks of development time per customer).
Software Engineering Intern
Microsoft
Remote
- •Implemented dynamic status feature for PSTN endpoint within Microsoft Teams.
Researcher
Cornell Netlab
Ithaca, NY
- •Researched intermediate representations for formal verification.
- •Composed a pretty printer for Petr4 and designed compiler from Petr4 to C.
Data Science Intern
Tesla
Remote
- •Designed automated ML model to predict vehicle order cancellation frequency.
- •Created Tableau visualizations for senior engineers and director of analytics.
Backend Software Engineering Intern
Uber
Remote
- •Integrated external vendor API for rider verification feature using government-issued ID.
- •Implemented fuzzy matching library with extensive integration tests.
Education
Cornell University
B.S. Computer Science
College of Engineering
GPA: 3.70 / 4.3
Dean's List: Fall '18, Spring '21, Fall '21, Spring '22
Oxford University
MSt Applied Ethics, incoming
Research Impact
Contributing to the frontier of AI safety through peer-reviewed publications, patents, and thought leadership.
AI Memory, Mapped
Presented risks and mitigations of agent memory risks. Read more here.
Developing & Deploying AI Fingerprints for Advanced Threat Detection
Presenting BinaryShield to audience of 1000+ including CISOs and top-level security government officials. Watch here.
Privacy-Preserving Fingerprinting for AI Threat Detection and Mitigation
Novel technique for detecting AI threats while preserving user privacy across compliance boundaries.
Cross-Service Threat Intelligence in LLM Services using Privacy-Preserving Fingerprints
SaTML '26
Research paper on enabling cross-service threat detection in LLM systems while maintaining privacy.
AI Risks and Mitigations
Women Impact Tech Conference
Keynote presentation on AI risks and practical mitigations to a conference audience of 1,200 attendees. Watch here.
Artifact Designer for Guided Conversation Artifacts
System for designing and managing conversational AI artifacts with guardrails.
Generatively-guided artifact construction with constraints
Framework for constrained generation of AI artifacts using semantic guardrails.
Cyclic Behavior Detection in Generative Agents
Detection system for identifying and preventing cyclic behaviors in AI agents.
P4Cub: A Little Language for Big Routers
CPP '23
Formal verification research on intermediate representations for network routers.
BinaryShield: Privacy-Preserving Threat Detection
When my team faced the challenge of detecting adversarial attacks on AI systems while navigating customer privacy protections, I co-architected and productionized BinaryShield, a technique for cross-compliance boundary searches. This work exemplifies what excites me most: identifying novel AI safety challenges and rapidly generating solutions with real-world impact. This work was patented and peer-reviewed at the IEEE Conference on Secure and Trustworthy Machine Learning.
Expertise
Specialized in building safe, scalable AI systems with a deep understanding of responsible AI practices.
Tools & Technologies
Awards
2nd Place Winner - Executive Challenge Hack
2023 Global Microsoft Hackathon
Revolutionizing Customer Security Scenarios
Intel URP Scholar
Spring 2020
Undergraduate research scholarship recipient
Rewriting The Code Fellow
2020-2021
Fellowship for women in technology
Lockheed Martin Corporate Award
Spring 2022
Recognition for excellence in engineering
Leadership
Research Advisor
AguaClara Project Team
Ithaca, NY
Led three sub-teams (~15 people) developing an app to measure effectiveness of water purifying techniques.
Executive Board Member
Women In Computing At Cornell
Ithaca, NY
Organized ~8 inclusivity events per semester, including the sold-out CIS formal under budget of $7,750.
Head Consultant
Cornell Intro to CS Class
Ithaca, NY
Supervised ~60 undergraduate teaching assistants. Designed coursework and graded assignments.
Volunteering & Teaching
Get in Touch
Interested in discussing AI safety, responsible AI development, or potential collaborations? I'd love to hear from you.