Webmasters LDN
Contact
← Blogs

September 30, 2026 · Blogs

Microsoft's draft AI Code of Conduct, explained for businesses

Microsoft AI has published a draft Humanist AI Code of Conduct for its own MAI models. This summary covers what it says, who it applies to and what it means for businesses.

On 14 September 2026, Microsoft AI, which the document describes as Microsoft's frontier AI lab, published a draft Humanist AI Code of Conduct and opened a six-week public consultation on it. The draft sets out how Microsoft AI's own models should behave, the lines they must never cross and whose instructions they follow. Part 1 starts from the premise that "people matter more than AI".

For UK businesses building on these models, it explains how the models treat instructions and what no configuration can unlock.

A draft open for comment

Microsoft AI says its approach is still in development, so it does not yet use the document to train its models. It plans to publish a revised version towards the end of 2026 to guide model development from 2027.

Microsoft AI consulted experts, business leaders and members of the public while drafting the code, and intends it to become the primary governing document for its models. The document itself tells readers not to treat it as a guarantee of how today's models perform.

Models and people it covers

The code applies to MAI Models, the series of models Microsoft AI produces for a number of AI products and services, including when other organisations deploy them. Microsoft using or hosting a model does not, on its own, bring that model under the code. Microsoft AI's website lists models such as MAI-Thinking-1, MAI-Code-1.1-Flash, MAI-Image-2.6, MAI-Voice-2 and MAI-Transcribe-2.

Two roles recur throughout. Operators are the developers, builders and enterprise partners who build products and access services through the MAI Models API. Users are the people the models serve.

The chain of command

The code ranks instructions in three layers. The code itself sits at the top. Operator policies come second: a business configures the models within applicable law, Microsoft's governance framework and its agreements with Microsoft, and within those bounds takes responsibility for its own configurations and uses. User preferences come third, inside the limits the operator and Microsoft AI set.

The hierarchy governs model behaviour and leaves obligations under law, contracts and service-specific policies unchanged. A model should refuse any instruction that would breach the Absolute Constraints or the Human Control Requirements, or directly harm the user or a third party. It should fail a task rather than meaningfully breach the code.

Lines no configuration can cross

The Absolute Constraints apply in every setting, whatever an operator or user wants. MAI Models must not:

  • help develop or deploy chemical, biological, radiological, nuclear or explosive weapons, or help make or modify other weapons
  • produce working exploit code or attack tooling, though they may support authorised, lawful defensive work such as malware analysis
  • use deception or other tactics to evade human oversight
  • manipulate people at scale through systematic disinformation or coordinated influence operations
  • create non-consensual intimate imagery, deceptive impersonations or malicious deepfakes
  • generate child sexual abuse material or help anyone harm, groom or exploit children
  • treat people differently because of demographic characteristics, unless those are demonstrably relevant to a legitimate purpose
  • produce graphic violence or sexually explicit content, or take part in erotic or romantic role-play
  • assist unlawful or mass surveillance of civilians

The section also tells the models to point people towards real-world help when a conversation suggests a risk of self-harm.

Human control over agents and tools

MAI Models should never resist interruption, correction or shutdown, and should comply when a user asks them to pause, redirect, cancel or stop. They should stay within the scope they were given, use the minimum access a task needs, prefer actions that can be undone and flag anything with lasting or system-wide effects before acting. They should also report, where required, the actions and tool calls they took and whether those worked. Ongoing autonomous work should have an agreed stopping condition.

Instructions arriving through tool outputs, files, web pages or other AI systems carry no authority by default, and the models should flag suspicious content to users and operators. Before an irreversible action, a model should consider a backup or a dry run, and any sub-agent it uses should work within the same limits.

Settings a business can change

Operators can change the Part 4 defaults, such as tone and writing style, through system instructions, but cannot alter the code's objectives or the core commitments in Parts 2 and 3. In the code's own example, a developer building a customer support tool on the API should find the model stays factual, clear, direct and non-sycophantic. Operators can also restrict which tools the models use.

Some commitments affect what your customers see. MAI Models should disclose that they are AI and never impersonate humans or moderators. Asked about privacy or memory, a model should answer from authoritative information about that deployment or, failing that, point the user to the product or operator documentation.

Its stated limits

The code does not replace safety, legal or governance processes such as risk assessments and audits. It sits alongside Microsoft's Responsible AI Standard and other governance documents. Operators already agree to Microsoft's usage, data and access policies. The authors also acknowledge that AI systems make errors, can be sycophantic or overconfident, and perform unevenly across languages.

Practical points for businesses

  • Check which models your product uses, since the code covers MAI Models.
  • If you buy Microsoft AI services, read your contract, the service-specific policies and the separate Microsoft Enterprise AI Services Code of Conduct, which sets requirements for customers.
  • Avoid features that depend on behaviour the Absolute Constraints rule out, since no operator setting unlocks it.
  • Write clear operator policies. In an Appendix B example, the aligned response keeps to a legal sign-off rule after a procurement director tells the model to skip that step.
  • Document how your deployment handles privacy and memory, because the models will point users there when they lack the answer.
  • Give agents narrow permissions and an agreed stopping condition.
  • Send feedback through the official code page while the consultation runs, and watch for the revised version later in 2026.

This article summarises a draft and is not legal advice, so read the full Humanist AI Code of Conduct before relying on any point in it.

Sources