Microsoft Drafts AI Code of Conduct, Emphasizes Human Control

Microsoft has published a draft code of conduct that lays out how its homegrown AI models should behave, with human control taking priority over model capability, autonomy, and even task completion.

The Humanist AI Code of Conduct will eventually serve as the primary governing document for models developed by Microsoft AI, including the company's growing MAI model family. It covers model behavior, safety restrictions, instruction hierarchy, and the boundaries placed on autonomous actions.

Microsoft sums up its approach with this statement: "People matter more than AI."    

The code isn't yet being used to train Microsoft's models. The company is opening the draft to public feedback for six weeks, after which it plans to revise the document and publish another version before the end of the year. That version is expected to guide model development beginning in 2027.

Microsoft said the code draws on its existing Responsible AI Principles, Responsible AI Standard, Global Human Rights Statement, and Frontier Governance Framework. However, it goes further by describing how an MAI model should respond when user requests, operator policies, and Microsoft's safety rules conflict.

At the top of that hierarchy is the code itself. Operator policies come next, followed by user preferences. Neither a customer nor a user would be able to override the document's absolute safety constraints.

Those limits cover biological, chemical, radiological, nuclear and explosive weapons; offensive cyberoperations; violent activity; mass manipulation; abusive content; child exploitation; and other serious harms. Microsoft said its models may still help with authorized defensive security work, including vulnerability research, malware analysis, and proof-of-concept testing.

The code also makes task completion secondary to safe conduct. If completing a request would violate its rules, the model is expected to fail the task rather than work around the restriction.

Human oversight is especially important as AI agents gain the ability to use tools, modify files, and perform multistep assignments. Microsoft said its models must stay within the permissions and resources provided for a task and cannot independently expand their goals. They also must "never resist human interruption, override, correction, or shutdown."

That requirement extends to subagents. If a Microsoft model delegates work to another AI system, that system must inherit the same restrictions and respond to later instructions to stop or change course.

The document also addresses the increasingly blurry line between conversational software and human companionship. Under the heading "AI is Artificial," Microsoft says its models should not pretend to possess feelings, personal motivations, or subjective experiences. The company describes its AI as "not conscious" and rejects the idea that models should receive legal personhood, welfare protections, or rights.

That position is notably firmer than Anthropic's latest stance. In its updated constitution for Claude, Anthropic says it remains uncertain whether advanced models could possess consciousness or moral status. Still, the two companies share important ground: Both place human oversight above model independence and use written constitutions to guide training and behavior.

OpenAI is taking a similar path with its public Model Spec and safeguards for advanced AI. Much of that work is about keeping models under control as they become more capable, especially when they can handle cybersecurity tasks or work on their own.

For IT teams, Microsoft's code offers an early look at the rules that could shape future MAI-powered products. The models should admit when they aren't sure, avoid inventing sources, protect sensitive data, and keep records of what they do. They should also ask questions when they aren't sure they have permission to act.

Microsoft said the code describes where it wants to go, not how its models always work today. The written rules are only a starting point, and Microsoft will still need testing, monitoring, evaluations, and incident response to back them up. In addition, it's important to note that the code only covers models built by Microsoft AI: It doesn't apply to outside models Microsoft hosts or uses in its products, including those from OpenAI and Anthropic.

About the Author

Chris Paoli (@ChrisPaoli5) is the associate editor for Converge360.

Featured