The news
Microsoft (MSFT) published a draft Microsoft AI code of conduct on September 14, 2026, setting behavior rules for its in-house MAI models, including a requirement that they never resist human shutdown, and opened a six-week public consultation on the text.
The document, titled the Humanist AI Code of Conduct and posted by the Microsoft AI unit, is built around four objectives: human control and reliable safety; the principle that AI is artificial, meaning models should not imitate consciousness or claim feelings and are tools rather than persons; human flourishing; and plural values, which calls for respecting diverse worldviews while keeping core commitments to dignity, safety and human rights. It states plainly that “AI should not exceed human control.”
The draft sets absolute constraints that no customer or user can override. They include prohibitions on help with weapons and mass harm, offensive cyber operations, loss of human control and large-scale harmful manipulation, as well as personal-harm rules covering child safety, crisis response, deepfakes and impersonation, graphic or exploitative content, and discrimination. Models must never resist interruption, override or shutdown, must stay within the scope they are authorized for, must keep their conduct and records understandable to humans, and must not pursue self-interested goals. Where an irreversible tool action is necessary, the draft says models should document what they did.
The code also sets a chain of command. The code itself sits at the top, followed by operator policies, then user preferences. Operators are defined as the organizations and individuals that build products using the MAI models through Microsoft's API. The draft applies only to MAI models, not to other models Microsoft uses or hosts. It remains a consultation draft, and a revised version is expected by the end of the year.
Chief executive Satya Nadella wrote on X that Microsoft welcomes the research and deliberate pacing needed to get AI alignment right, along with ideas such as embedded evaluators, TechCrunch reported. Mustafa Suleyman, who leads Microsoft AI, described the document in an interview with Reuters as a kind of constitution for future models. TechCrunch said the release comes amid heightened attention to AI safety, driven by a series of rogue-agent incidents and an Anthropic researcher's resignation.
The numbers
- Public consultation period
- 6 weeks from September 14, 2026
- Core objectives in the code
- 4
- Levels in the chain of command
- 3 (code, operators, users)
- Revised version expected
- By end of 2026
Why CEOs should care
Companies building on MAI models through Microsoft's API are operators under this code, which means their own policies sit below Microsoft's. Product and legal teams should read the absolute constraints against their use cases now. Security vendors and internal red teams, for example, should ask Microsoft how it defines offensive cyber operations, so that legitimate testing tools are not blocked later. Use the consultation window to raise those questions in writing.
CISOs and risk officers should note the operational commitments: models must stay within authorized scope, keep human-readable records and document irreversible actions. Those map directly onto the audit trails and approval steps most companies want for AI agents. Ask Microsoft what logs operators will receive, and build approval gates for irreversible actions into your own agent workflows rather than relying on model behavior alone.
Boards and procurement teams should remember the scope limit. The code covers MAI models only, so Copilot features or Azure-hosted models from other developers may follow different rules. A single enterprise AI policy will need to reference each vendor's commitments separately, and oversight reports should say which models run which critical processes.
The bigger picture
Microsoft's draft landed during a busy fortnight for industry self-governance. TechCrunch reported on September 15 that OpenAI's global policy chief Chris Lehane confirmed OpenAI had been working with Anthropic and Google DeepMind on AI safety for weeks; his remarks came days after Anthropic chief executive Dario Amodei published a September 12 essay proposing a slower frontier pace. A day later, TechCrunch reported that Anthropic and OpenAI had proposed embedding outside safety evaluators inside their companies, while Google DeepMind and Meta had not committed. Not everyone agrees on the need for rules: Nvidia chief executive Jensen Huang said at Salesforce's Dreamforce conference on September 15 that no new laws or regulations are needed. Regulators are moving anyway: TechCrunch noted that California's SB 53 and the EU AI Act already require frontier developers to run evaluations or report serious incidents, so voluntary codes will increasingly sit alongside legal duties.
What’s next
The consultation runs about six weeks from September 14, closing in late October, with a revised code expected by year-end. Watch whether Microsoft extends similar commitments to Copilot and to partner models it hosts, and whether Google and Meta publish comparable documents for their own models.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made with our newsroom’s technology tools, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is not published automatically; it is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








