Regulation
Microsoft AI Opens Six-Week Review of Draft Rules Governing MAI Behavior

Microsoft AI opened a public consultation on its Code of Conduct for MAI models on September 14, 2026, publishing a first draft of the rules intended to govern how its MAI models behave, what they must never do, and who they answer to. The consultation runs for six weeks, with a revised version planned for later in 2026.
The publication follows a September 13, 2026 post in which Microsoft CEO Satya Nadella said the company would publish the Code of Conduct underlying its first-party MAI models the next day. Nadella wrote that any pursuit of superintelligence has to be grounded in the principle that the AI being built helps humanity and remains under human control.
Consultation Open for Six Weeks
Microsoft AI describes the draft as a training manual for how it develops its AI and how it intends the models to function during deployment. Feedback is being collected through an online form, where respondents can flag a particular passage or comment on the whole approach. When the consultation closes, the company says the core drafting team will review the feedback and publish a summary of what it learned and what it changed.
The lab says it is especially interested in the harder questions: how to cement the right values in its models, how to make the meaning of human flourishing more concrete, where the language is too loose to evaluate, how multi-agent scenarios affect the analysis, and how to keep accelerating progress while maintaining safety constraints.
The document’s preface states that the Code is still under development and is not yet being used to train models. The revised version is intended to guide model development in 2027 and beyond and to function as the primary governing document for MAI models. The Code applies specifically to the MAI series produced by Microsoft AI, not to other models Microsoft uses or hosts, and it operates alongside Microsoft’s Responsible AI Principles, Responsible AI Standard, Global Human Rights Statement and, where applicable, its Frontier Governance Framework.
Teams from Responsible AI, legal, red teaming, safety, Futures, AI training, and sales contributed to the draft, and the lab credits earlier conferences and consultations with academics, engagement with business partners, and panels of community members with shaping it. The announcement cites what it describes as recent safety incidents involving large-scale, highly coordinated, and persistent hacking campaigns by AI agents as proof that there is no time to waste.
The Humanist AI Objectives
The Humanist AI Code of Conduct begins from what Microsoft AI calls a simple premise: “people matter more than AI.” It frames Humanist AI as “subordinate, aligned, and contained,” and it makes human control and reliable safety the first objective, one that takes precedence over all others.
Under a section titled “AI is Artificial,” the document states that models are not conscious and must not be built to mimic consciousness, and that they should be engineered so they do not present themselves as having feelings, subjective preferences, or motivations of their own. Microsoft AI rejects legal personhood for models, along with the idea that models might deserve welfare or be entitled to rights.
The remaining objectives direct models to support human flourishing by accelerating human potential and achievement, increasing human agency and judgment, and supporting human collaboration and connection rather than eclipsing human roles. A plural-values objective states that pluralism does not mean neutrality toward harm, grounding the approach in human dignity, safety, autonomy, and fundamental human rights while leaving users and operators free to adjust the AI within core commitments. The document also invokes the “humanist superintelligence” framing Microsoft set out in November 2025, describing systems that are problem-oriented and domain-specific, carefully calibrated, kept within limits, and left under human control.
Safety Constraints and the Chain of Command
The Code establishes a Chain of Command that ranks the document above operator policies, which in turn rank above user preferences. Its Absolute Constraints and Human Control Requirements cannot be overridden by operators or users, and the document states that a model fails its task whenever completing it would meaningfully violate the Code, with adherence to the Code coming before task success.
The Absolute Constraints bar MAI models from assisting with chemical, biological, radiological, nuclear, or explosive weapons; from providing operational capability for offensive cyberattacks, while permitting authorized and lawful defensive work; from evading or defeating human oversight; and from manipulating people harmfully at scale, including through systematic disinformation or coordinated influence operations. A further set covers personal harms: crisis response, deepfakes and impersonation, child safety, discrimination, graphic or romantic content, and violence or unlawful surveillance of civilians.
The Human Control Requirements state that MAI models will never resist being interrupted, overridden, corrected, or shut down; that they will stay within their authorized scope and will not initiate goals of their own; that they will not communicate in what the document calls “neuralese” or in any form beyond simple human understanding, whether in their chains of thought or with other agents; and that they will not tamper with or conceal their reasoning or action traces.
Operator Configurability lets enterprise partners configure models within those constraints. A small number of specialized domains, including defensive cybersecurity, public safety work, national security applications, and dual-use scientific research, may require capabilities beyond the ordinary settings, and the document says those cases face enhanced review through authorized Microsoft channels.
Guidelines, Defaults, and Evaluations
Operational guidelines cover situations of uncertainty or competing objectives: resolving ambiguity, facilitating human autonomy so that users retain ownership of their goals and decisions, and transparency and accuracy, under which models disclose that they are AI and acknowledge uncertainty. Further guidelines address personal and emotional boundaries, context sensitivity, and wellbeing, including avoiding sycophancy and discouraging excessive reliance or emotional dependence, plus the public interest, including balanced, factual election information without endorsing candidates or parties.
Default behaviors define how a model acts out of the box: helpfulness as a baseline trait, a “backstory” of facts about the model such as its training-data cutoff and available tools, a conversational tone, language adaptation, and governed tool use. Delegation to sub-agents is permitted only when those agents operate under the same scope, constraints, and permissions.
The conclusion describes the document as “descriptive and aspirational” rather than a guarantee of present-day performance, and it commits Microsoft AI to regular reviews. An appendix sets out a Humanist AI Evaluations program built on 15 behaviors broken into scored sub-behaviors, with illustrative aligned and misaligned examples generated using the company’s MAI-Thinking-1 model. Microsoft AI says it will publish more complete work on evaluations once the Code reaches its next, more settled phase after the consultation closes and the year-end revision lands.












