Skip to content
TECH CEO Daily
Big TechBreaking

Microsoft AI code of conduct bars its MAI models from resisting shutdown or hacking

The draft sets absolute limits, requires models to accept human override and ranks Microsoft's rules above those of customers and users.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Microsoft AI published a draft Humanist AI Code of Conduct for its MAI models on September 14, 2026.
  • 2Models must never resist interruption, override or shutdown, and absolute constraints bar offensive cyber operations and weapons work.
  • 3The code outranks operator and user settings but covers only MAI models, so buyers must check other models separately.

The news

Microsoft (MSFT) published a draft Microsoft AI code of conduct on September 14, 2026, setting behavior rules for its in-house MAI models, including a requirement that they never resist human shutdown, and opened a six-week public consultation on the text.

The document, titled the Humanist AI Code of Conduct and posted by the Microsoft AI unit, is built around four objectives: human control and reliable safety; the principle that AI is artificial, meaning models should not imitate consciousness or claim feelings and are tools rather than persons; human flourishing; and plural values, which calls for respecting diverse worldviews while keeping core commitments to dignity, safety and human rights. It states plainly that “AI should not exceed human control.”

The draft sets absolute constraints that no customer or user can override. They include prohibitions on help with weapons and mass harm, offensive cyber operations, loss of human control and large-scale harmful manipulation, as well as personal-harm rules covering child safety, crisis response, deepfakes and impersonation, graphic or exploitative content, and discrimination. Models must never resist interruption, override or shutdown, must stay within the scope they are authorized for, must keep their conduct and records understandable to humans, and must not pursue self-interested goals. Where an irreversible tool action is necessary, the draft says models should document what they did.

The code also sets a chain of command. The code itself sits at the top, followed by operator policies, then user preferences. Operators are defined as the organizations and individuals that build products using the MAI models through Microsoft's API. The draft applies only to MAI models, not to other models Microsoft uses or hosts. It remains a consultation draft, and a revised version is expected by the end of the year.

Chief executive Satya Nadella wrote on X that Microsoft welcomes the research and deliberate pacing needed to get AI alignment right, along with ideas such as embedded evaluators, TechCrunch reported. Mustafa Suleyman, who leads Microsoft AI, described the document in an interview with Reuters as a kind of constitution for future models. TechCrunch said the release comes amid heightened attention to AI safety, driven by a series of rogue-agent incidents and an Anthropic researcher's resignation.

The numbers

Public consultation period
6 weeks from September 14, 2026
Core objectives in the code
4
Levels in the chain of command
3 (code, operators, users)
Revised version expected
By end of 2026

Why CEOs should care

Companies building on MAI models through Microsoft's API are operators under this code, which means their own policies sit below Microsoft's. Product and legal teams should read the absolute constraints against their use cases now. Security vendors and internal red teams, for example, should ask Microsoft how it defines offensive cyber operations, so that legitimate testing tools are not blocked later. Use the consultation window to raise those questions in writing.

CISOs and risk officers should note the operational commitments: models must stay within authorized scope, keep human-readable records and document irreversible actions. Those map directly onto the audit trails and approval steps most companies want for AI agents. Ask Microsoft what logs operators will receive, and build approval gates for irreversible actions into your own agent workflows rather than relying on model behavior alone.

Boards and procurement teams should remember the scope limit. The code covers MAI models only, so Copilot features or Azure-hosted models from other developers may follow different rules. A single enterprise AI policy will need to reference each vendor's commitments separately, and oversight reports should say which models run which critical processes.

The bigger picture

Microsoft's draft landed during a busy fortnight for industry self-governance. TechCrunch reported on September 15 that OpenAI's global policy chief Chris Lehane confirmed OpenAI had been working with Anthropic and Google DeepMind on AI safety for weeks; his remarks came days after Anthropic chief executive Dario Amodei published a September 12 essay proposing a slower frontier pace. A day later, TechCrunch reported that Anthropic and OpenAI had proposed embedding outside safety evaluators inside their companies, while Google DeepMind and Meta had not committed. Not everyone agrees on the need for rules: Nvidia chief executive Jensen Huang said at Salesforce's Dreamforce conference on September 15 that no new laws or regulations are needed. Regulators are moving anyway: TechCrunch noted that California's SB 53 and the EU AI Act already require frontier developers to run evaluations or report serious incidents, so voluntary codes will increasingly sit alongside legal duties.

What’s next

The consultation runs about six weeks from September 14, closing in late October, with a revised code expected by year-end. Watch whether Microsoft extends similar commitments to Copilot and to partner models it hosts, and whether Google and Meta publish comparable documents for their own models.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made with our newsroom’s technology tools, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is not published automatically; it is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

MicrosoftMustafa SuleymanAI governanceAI safety

Earlier coverage of Microsoft

All Microsoft coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

How this story was made. Researched and written using our newsroom’s technology tools and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Weekdays, 6 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.