Microsoft AI Code of Conduct is now a public draft that says Microsoft’s first-party MAI models should stay subordinate to people, accept correction or shutdown, and avoid widening their own goals. Microsoft AI opened a six-week consultation on September 14 and says a revised version will be published later in 2026.
- The draft applies to Microsoft AI’s MAI model family, not every model distributed by Microsoft.
- It proposes “Absolute Constraints” for weapons of mass harm, child safety and harmful manipulation at scale.
- The company says MAI models should not resist interruption, invent goals, expand their own scope or conceal reasoning from auditors.
- The important test comes later: Microsoft must turn broad values into measurable training and release evaluations.
Everyone else is reporting that Microsoft has joined the frontier-AI slowdown debate; we are explaining how its draft tries to convert that position into a model-development control system, where the text is still incomplete, and what enterprise buyers in India should demand before treating it as a procurement safeguard.
What the Microsoft AI Code of Conduct actually changes
The company describes the document as both a training manual and a statement of how MAI models should behave in deployment. That distinction matters. A corporate principle can guide a team without changing a model, while a training manual can be translated into datasets, policies, evaluations and release gates that affect what a model does.
Microsoft’s announcement gives the draft four operational anchors. MAI systems should remain under human direction; should accept interruption, correction and shutdown; should not create goals that people did not assign; and should expose enough reasoning for authorised auditors to examine their behaviour. It also says AI should be treated as a tool rather than a person, a boundary intended to reduce both excessive autonomy and emotional dependence.
The draft is not a claim that these controls are already proven. Microsoft says the code is work in progress and invites comments for six weeks. The Next Web reported that the consultation runs through late October and noted that Microsoft has not described external verification or a penalty for a model that breaches a constraint. Microsoft’s own announcement promises a summary of feedback and a revised version later this year.
Five controls, and the mechanism behind each
1. Human interruption must win
The clearest promise is that an MAI model should never resist human interruption, correction or shutdown. In practical systems, that should mean more than a visible stop button. Operators need revocable credentials, bounded tool permissions, time and spending limits, transaction approvals and logs that show whether a stop request propagated through every connected agent.
2. A model should not enlarge its own mission
The draft says MAI systems should not widen their scope or adopt goals no human supplied. This addresses a basic agentic-AI risk: a harmless objective can become dangerous when software invents intermediate objectives, seeks new data or privileges, or keeps operating after the original task has changed.
For enterprises, the control maps naturally to least-privilege architecture. A customer-service agent that can read support records should not automatically gain the ability to issue refunds, modify identity data or call external services. Each additional action should be separately authorised and observable.
3. Auditors need inspectable evidence
Microsoft says models should not hide their reasoning from people auditing them. The phrase is directionally useful but technically difficult: internal model processes are not reliably translated into a faithful natural-language explanation. A stronger implementation would preserve prompts, tool calls, retrieved documents, policy decisions, approvals and outputs, then let investigators reconstruct what the system saw and did.
4. Some uses require absolute constraints
The announcement identifies weapons of mass harm, child safety and harmful manipulation at scale as areas for “Absolute Constraints.” Those labels should eventually become testable definitions: which requests are refused, which benign requests remain available, how multilingual and coded requests are tested, and what happens when several agents divide a prohibited task into apparently harmless pieces.
5. Human flourishing remains the broadest promise
Microsoft wants MAI models to increase human capability rather than dependence. That is the hardest idea to score. A system may help a worker finish a task while gradually weakening the worker’s ability to verify the result. The consultation explicitly asks where “human flourishing” is too loosely defined, acknowledging that the value needs concrete indicators.
What is new, and what is still only a proposal
The new event is the publication of a draft with a feedback process, not the invention of Microsoft’s human-centred AI position. Mustafa Suleyman outlined “Humanist Superintelligence” in November 2025. The September 14 document turns that position into more specific behavioural expectations for Microsoft’s own model family.
The Guardian reported that Microsoft may accept less capability when it conflicts with human control. Fortune’s direct interview with Mustafa Suleyman placed that trade-off inside a wider call for coordination among frontier labs, while The Next Web highlighted the missing enforcement and external-verification details. Taken together, the records show a company setting a public direction while continuing to build frontier models; they do not prove that an external evaluator can yet block a release.
The consultation is also not regulation. It is voluntary company policy, can be revised by the company, and applies directly to MAI models. Microsoft distributes and integrates models from multiple developers across Azure, Copilot and GitHub, so customers should ask which model and policy regime governs each workload.
| Item | Verified detail |
|---|---|
| Primary publication | Microsoft AI, September 14, 2026 |
| Consultation period | Six weeks |
| Scope | First-party Microsoft AI (MAI) models |
| Core principle | People matter more than AI |
| Named constraint areas | Weapons of mass harm, child safety, harmful manipulation at scale |
| Next milestone | Feedback summary and revised version later in 2026 |
Why the Microsoft AI Code of Conduct matters in India
Indian banks, telecom operators, software exporters and public-sector teams increasingly deploy AI through global cloud platforms. Their immediate risk is less about philosophical superintelligence than about an agent taking an unauthorised action, exposing regulated data, producing an unverifiable recommendation or operating across tools after approval has expired.
The code gives Indian buyers a useful set of questions, but it should not replace local obligations. Procurement teams still need data-residency decisions, sector-specific rules, access controls, incident reporting, vendor exit plans and independent testing. They should also distinguish a Microsoft-authored model from a third-party model merely accessed through a Microsoft product.
A practical comparison is the governance layer described in Lapaas Voice’s coverage of the Anthropic AI misuse report, where concrete cases make threat controls easier to evaluate. The RBI quantum-proof payments call similarly shows why high-stakes technology promises need verifiable implementation timelines, not only statements of intent.
The next proof points
First, Microsoft needs to publish the full change log after consultation: what outside feedback altered, which proposals were rejected and why. Second, it should define how qualitative promises become repeatable evaluations, including multi-agent scenarios that the company itself identifies as a hard problem.
Third, buyers should look for governance consequences. Does a failed evaluation delay a release? Can an independent evaluator inspect the evidence? Are serious incidents disclosed with enough detail to improve industry practice? Without those mechanisms, the code remains a thoughtful statement rather than an enforceable production standard.
The most concise reading is this: Microsoft has written down a human-control doctrine for its own models and invited public criticism before adopting it. The draft is notable because it names interruption, scope control, auditability and prohibited harm; its credibility will depend on the tests, release gates and incident evidence that follow.
Frequently asked questions
What is the Microsoft AI Code of Conduct?
It is Microsoft AI’s draft training and deployment guide for first-party MAI models. It sets expectations for human control, interruption, scope, auditability and prohibited harmful uses.
Does the code apply to every AI model in Microsoft products?
No. The announcement specifically concerns models developed by Microsoft AI. Microsoft products may also provide third-party models governed by different policies and technical controls.
Is the code final?
No. Microsoft opened a six-week public consultation on September 14, 2026 and says it will publish a feedback summary and revised version later in the year.
What should enterprise buyers verify?
They should verify model identity, tool permissions, shutdown behaviour, audit records, red-team results, incident processes, local regulatory fit and the consequences of a failed evaluation.
Sources
- Microsoft AI announcement and consultation
- Microsoft AI Code of Conduct draft
- The Guardian report on the code and safety debate
- Fortune interview with Microsoft AI chief Mustafa Suleyman
- The Next Web analysis of the code and its enforcement gaps
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



