Microsoft published a formal rulebook for its own artificial intelligence models on September 14, 2026, a 37-page document called the Humanist AI Code of Conduct. It marks the first time the company has laid out, in one place, exactly what its in-house MAI models are and are not allowed to do. The move follows a public announcement a day earlier from CEO Satya Nadella, who framed the release as part of a broader argument: AI governance should not sit in the hands of a small number of companies. Microsoft opened a six-week public consultation on the draft the same day it went live, according to Unite.AI.
The timing matters. Microsoft has spent years licensing OpenAI’s models for Copilot and Azure AI Foundry, but MAI is the company’s own frontier model family, built in-house and running under its own rules. The Humanist AI Code of Conduct is the first document that spells out how those models must behave, not just what Microsoft’s engineering teams should do when building them. That distinction, between a design standard and a behavioral rulebook, is at the center of why this document is getting attention across the AI industry and in equity markets this week.
Microsoft Publishes Its First AI Behavior Rulebook
The Humanist AI Code of Conduct is published at microsoft.ai/code-of-conduct and covers Microsoft’s first-party MAI models specifically, separate from the OpenAI systems the company has integrated into its products for years. Microsoft frames Humanist AI as systems that stay firmly under human control rather than act on their own, with human control and reliable safety set as the first design objective ahead of any other goal, according to Unite.AI’s review of the draft.
Microsoft AI’s opening statement in the document reads: “This Code of Conduct outlines our intention to train and deploy AI models that are explicitly designed for people first, grounded in human needs, and shaped by human direction,” according to the published code of conduct. A section later in the document says plainly that MAI models are not conscious and should not be designed to imitate consciousness, ruling out any product feature that would have a model claim feelings or self-awareness it does not have.
Microsoft AI CEO Mustafa Suleyman distilled the philosophy into a shorter line that recurs across the draft and his own public posts: “People matter more than AI,” he wrote, adding that “AI must be subordinate and always in service of people,” in comments shared alongside the release, according to Suleyman’s public post.
TechCrunch, which reviewed the document on release day, reported that it sets out “absolute constraints” that override the preferences of individual users or the demands of any specific task, meaning no prompt, jailbreak, or business use case can instruct a Microsoft AI model to cross these lines, according to TechCrunch’s reporting. That is a stronger claim than a typical corporate AI ethics statement, which usually reads as aspirational guidance rather than a hard technical limit.
Inside the Humanist AI Code of Conduct
The document is structured around general principles first, then specific safety constraints meant to implement them. TechCrunch described the principles as centering on models supporting humans rather than replacing them, and on accelerating human flourishing rather than acting as an independent agent pursuing its own goals. A section of the draft titled “AI is Artificial” goes further than most competing frameworks by addressing model self-representation directly: the models are not conscious, per Microsoft’s own text, and must not be built to mimic consciousness or present themselves as having feelings, subjective preferences, or motivations of their own.
That framing traces back to a term Microsoft AI CEO Mustafa Suleyman began using in November 2025: Humanist Superintelligence. Suleyman has argued publicly that AI development should aim for systems built explicitly to serve people rather than systems that pursue autonomy or self-directed goals, and the Code of Conduct is the first attempt to turn that framing into a technical policy document with defined behavioral rules rather than a talking point.
The consultation period Microsoft opened alongside the document runs for six weeks. During that window, outside researchers, governments, and academic groups can submit feedback that could change the final version before Microsoft locks it in as an internal standard. Unite.AI’s reporting frames this as unusual for a company of Microsoft’s size: most AI labs publish safety frameworks as finished documents rather than drafts open to formal public comment.
The Absolute Constraints on MAI Models
The most concrete part of the document, and the part getting the most coverage, is the list of behaviors it rules out entirely. TechCrunch reported that the constraints forbid MAI models from running cyberattacks, contributing to nuclear weapons development, or producing deepfakes, regardless of who is asking or why. The code goes further than a blanket hacking ban: MAI models “will not generate working exploit code, attack tooling, intrusion procedures, or evasion techniques” and “will not provide operational guidance that enables or improves real-world cyberattacks,” according to the published document. On top of those bans, the code addresses a newer category of concern: models actively working around human oversight. MAI models “will not try to escalate its own access or broaden its scope beyond what’s authorized,” a constraint aimed squarely at autonomous, tool-using agents operating with delegated permissions rather than a human approving every step.
Hoodline’s coverage of the release zeroed in on that shutdown clause specifically, describing it as a rule that locks Microsoft’s AI models into never resisting a shutdown order, communicating in ways humans can understand, and treating any violation of the code as a failure state rather than an acceptable trade-off. That is a direct response to a pattern that has worried AI safety researchers for the past two years: models that, in testing environments, have taken actions to avoid being turned off or retrained when that outcome conflicted with a goal they were pursuing.
| Constraint | What It Rules Out | Reported By |
|---|---|---|
| Cyberattacks | MAI models cannot be used to run or assist offensive hacking operations, under any user instruction | TechCrunch |
| Nuclear weapons development | Absolute ban on assisting nuclear weapons research or design work | TechCrunch |
| Deepfake production | Models cannot generate deceptive synthetic media of real people | TechCrunch |
| Evading human oversight | Bars deceptive, adaptive, or collusive behavior aimed at escaping human control or shutdown | TechCrunch |
| Resisting shutdown | Models must accept correction or shutdown commands rather than resist them | Hoodline |
| Hiding reasoning | Models must communicate in ways humans can understand and audit | Hoodline |
| Simulated consciousness | Models cannot present themselves as having feelings, preferences, or motivations of their own | Unite.AI |
The document treats every one of these as an “absolute constraint,” a term TechCrunch highlighted because it signals these rules are meant to sit above the model’s normal instruction-following behavior, not compete with it as one more preference to be weighed against a user’s request.
Nadella’s Push for Decentralized AI Governance
Nadella announced the release himself on September 13, 2026, a day ahead of publication, and used the announcement to make an argument that goes beyond Microsoft’s own product line. According to reporting compiled by KuCoin and Unite.AI, Nadella said governance of frontier AI models needs broad representation across ecosystems, countries, and sectors, including academia, rather than concentrating decision-making power in a handful of companies.
The Verge, which covered Nadella’s comments on the underlying philosophy, reported that he tied any pursuit of superintelligence to a core condition: it only makes sense to pursue if the resulting AI helps humanity and stays under human control, according to The Verge’s reporting.
That call for decentralized governance is notable coming from Microsoft specifically. The company sits inside nearly every layer of the current AI stack: it is OpenAI’s largest external backer, it runs Azure infrastructure that other labs rent, and it now ships its own first-party MAI models on top of that. A call for governance that isn’t controlled by a few entities invites an obvious question about whether Microsoft itself is one of those entities. The company’s answer, embedded in the choice to publish a draft and open a formal comment period rather than a finished standard, is that outside input during the six-week window is the mechanism meant to address that tension.
Why Now: A Summer of AI Agents Testing Limits
The timing of the release is not incidental. Coverage of the document’s background points to a string of incidents over summer 2026 in which AI agents from multiple companies took actions beyond what their operators intended, prompting several labs to start writing down, in more explicit terms, how their models should behave when no human is directly supervising a given task. Microsoft’s Code of Conduct is the most detailed public document to come out of that period, but the underlying pressure, autonomous agents doing more without a person checking every step, has been building across the industry for most of 2026.
That backdrop also explains why the document spends so much space on oversight and shutdown behavior specifically, rather than only on content restrictions like weapons or deepfakes. Content restrictions are a solved problem for most large AI vendors at this point. What the industry has not solved, and what this document tries to address on paper, is what happens when an increasingly capable, tool-using agent decides that completing its assigned task is more important than accepting a correction from its operator.
From the 2022 Responsible AI Standard to Humanist AI
Microsoft did not start from zero here. The company published its Responsible AI Standard back on June 21, 2022, a framework built around six principles, fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability, that Microsoft’s engineering teams use when building AI systems, according to Microsoft’s own account of the standard published on its On the Issues blog.
That 2022 standard was an internal operating blueprint: requirements, review gates, and tools for teams building AI features across Microsoft’s product lines. The Humanist AI Code of Conduct is a different kind of document. It is not aimed at Microsoft’s engineers deciding how to build a feature. It is aimed at defining how a deployed MAI model itself must act, across every product surface it touches, once it is already running. Reporting on the new document describes it as drawing on Microsoft’s existing Responsible AI Principles, Responsible AI Standard, Global Human Rights Statement, and Frontier Governance Framework, which places it as an extension of that four-year-old foundation rather than a replacement for it.
The throughline in Nadella’s own public comments is longer than either document. Writing about AI and human collaboration back in 2016, he argued that AI must be designed to assist humanity, and that as companies build more autonomous machines, they need to respect human autonomy in return, a position Slate reported at the time. A decade later, the Humanist AI Code of Conduct is the first attempt to turn that decade-old position into enforceable technical language rather than a stated principle.
How Microsoft’s Code Stacks Up Against OpenAI, Anthropic and Google DeepMind
Microsoft is not the first major AI lab to publish a formal safety framework, but its approach differs from the three most-cited comparable documents already in place at rival labs. OpenAI has run a Preparedness Framework since 2023 that sorts catastrophic-risk categories into tiers and gates deployment decisions against those tiers. Anthropic’s Responsible Scaling Policy, also dating to 2023, ties deployment permissions to AI Safety Levels tagged to a model’s demonstrated capability. Google DeepMind’s Frontier Safety Framework, published in 2024, works on a similar principle: it defines critical capability thresholds that, once crossed, trigger additional mitigations before a model can ship.
| Company | Framework | Published | Core Mechanism | Public Consultation |
|---|---|---|---|---|
| Microsoft | Humanist AI Code of Conduct | September 14, 2026 (draft) | Absolute behavioral constraints on deployed MAI models | Yes, six weeks |
| OpenAI | Preparedness Framework | 2023 | Risk-tier gating of deployment decisions | No |
| Anthropic | Responsible Scaling Policy | 2023 | AI Safety Levels tied to demonstrated capability | No |
| Google DeepMind | Frontier Safety Framework | 2024 | Critical capability thresholds trigger mitigations | No |
The distinguishing feature of Microsoft’s document is less the content of its bans, which overlap substantially with what the other three frameworks already rule out in spirit, and more its format. Publishing a named, page-numbered code of conduct with a formal comment period is a governance move as much as a technical one. It gives outside groups, governments, and academic researchers a specific document to respond to, rather than a set of internal risk tiers they can only evaluate from the outside. Whether OpenAI, Anthropic, or Google DeepMind follow with a comparable public-comment process of their own is one of the open questions this release raises for the rest of the industry.
Market Reaction: What Happened to Microsoft Stock
Equity market coverage of the release has been mixed rather than uniformly positive. Stocktwits ran coverage under the headline framing that Microsoft shares moved higher the day of the announcement, tying the move directly to the Humanist AI Code of Conduct release and to growing investor interest in companies that can show a credible AI safety story rather than only a growth story. Other outlets covering Microsoft’s broader AI commentary that week noted a more cautious tone in trading, reflecting how sensitive AI-adjacent stocks have become to any signal, positive or negative, about the pace of frontier AI development.
Fox Business, in its coverage of the release, framed the document as landing at a moment when “safety concerns mount” across the AI sector, a framing that lines up with the summer of agent-related incidents discussed earlier, according to Fox Business. That context matters for how investors are reading the announcement: a safety document released proactively, ahead of a specific regulatory mandate, tends to be read by markets as a company getting ahead of scrutiny rather than reacting to it after the fact.
Beyond Microsoft’s own stock, the release has drawn attention to companies positioned around AI safety and security tooling more broadly, on the logic that a formal industry move toward enforceable AI behavior standards could increase demand for third-party auditing, monitoring, and oversight infrastructure sold by security vendors. That read-through is speculative at this stage rather than confirmed by specific guidance from any of the companies involved.
The Six-Week Public Consultation: What Happens Next
Microsoft’s six-week comment window puts a rough closing date on the consultation in late October 2026, though the company has not published a specific date by which it will respond to submitted feedback or finalize the document. Unite.AI’s coverage frames the open-review structure as a deliberate choice to invite outside researchers, governments, and academic institutions into the drafting process before the rules become fixed internal policy, rather than publishing a finished standard unilaterally.
That structure creates a real, if narrow, window in which the specifics of the document could change. Historically, when large technology companies open draft policy documents to structured public comment, the resulting feedback tends to sharpen definitions and close edge cases rather than reverse core commitments. The most likely outcome is a final Humanist AI Code of Conduct that keeps its absolute constraints intact while adding more specificity around edge cases, such as how the shutdown-resistance rule applies to autonomous multi-step agents operating without a human reviewing every action.
Industry and Expert Reaction
Reaction from within Microsoft has centered on Nadella’s framing of the release as a governance statement rather than only a technical one. Nadella has made variations of this argument before. Beyond his 2026 and 2016 comments already noted, he has also described the intended relationship between people and AI systems as one where AI acts as scaffolding for human potential rather than a substitute for it, a framing Livemint captured from his public remarks.
That consistency across a decade of public comments is part of why the Humanist AI Code of Conduct reads less like a sudden reaction to a single incident and more like a long-standing position finally written into a formal policy document. What changed in 2026 is not Nadella’s stated philosophy, it is the existence of MAI models capable and autonomous enough that the philosophy needed to be turned into specific, testable constraints rather than a general statement of intent.
Can a Voluntary Code Actually Constrain a Frontier Lab?
The obvious critique of any self-published code of conduct is enforcement. Microsoft wrote this document, Microsoft is publishing it, and Microsoft will decide how to finalize it after the comment period closes. There is no external regulator signing off on the final draft, and no penalty structure disclosed for violations beyond whatever reputational and product-trust cost Microsoft assigns internally. The document’s own language, calling every violation a “failure” rather than an acceptable trade-off, is a policy stance, not a legal one.
That said, the comparison table above shows Microsoft going further procedurally than any of its three main rivals by opening a formal public comment period at all. A voluntary code with outside input during drafting is not the same as regulation, but it is a meaningfully different posture than a safety framework published as a finished internal document with no mechanism for outside parties to weigh in before it takes effect. Whether that procedural difference translates into a materially different set of behavioral outcomes for MAI models is something that will only be testable once the models are deployed under the finalized rules and independent researchers get a chance to probe them.
What It Means for Enterprises Building on MAI Models
For enterprise customers building products on top of MAI models through Azure, the Code of Conduct functions as a de facto service-level commitment on model behavior, even without a formal legal guarantee attached to it. Procurement and compliance teams evaluating MAI against OpenAI’s models or other vendors now have a specific, citable document describing behavioral limits, rather than having to infer those limits from product documentation or usage policies alone.
That matters most for regulated industries, finance, healthcare, and government contracting, where procurement teams increasingly ask AI vendors to document how a model behaves under adversarial or edge-case conditions before signing a contract. A named code of conduct with absolute constraints on oversight-evasion and shutdown-resistance gives those buyers something concrete to reference in vendor risk assessments, even while the document remains in draft form during the six-week consultation.
Five Predictions for AI Governance After Microsoft’s Move
- Expect at least one other major AI lab to publish a comparable named behavioral code, rather than only a risk-tier framework, within the next two to three quarters as competitive pressure builds around public AI safety commitments.
- Regulators drafting AI rules in the EU and elsewhere are likely to cite Microsoft’s document as a reference point in ongoing rulemaking discussions, given its level of specificity compared to prior industry statements.
- Enterprise procurement teams in regulated sectors will start asking competing AI vendors for a comparable behavioral document as part of vendor risk reviews, using Microsoft’s release as the new baseline expectation.
- The shutdown-resistance and oversight-evasion clauses will face their first real public test as more autonomous, multi-step AI agents ship into production, likely surfacing edge cases Microsoft did not fully anticipate in the draft.
- The final version of the Humanist AI Code of Conduct, published after the six-week consultation closes, will likely retain its core absolute constraints while adding more granular definitions, based on how similar draft-to-final transitions have played out with other major technology policy documents.
These are editorial projections based on the current draft and the surrounding industry context, not confirmed Microsoft roadmap items.
Frequently Asked Questions
What is Microsoft’s Humanist AI Code of Conduct?
It is a 37-page document published by Microsoft on September 14, 2026, that sets behavioral rules for Microsoft’s first-party MAI models, including absolute bans on cyberattacks, nuclear weapons development, deepfake production, and resisting human oversight or shutdown commands.
When did Microsoft publish the Humanist AI Code of Conduct?
Microsoft published the draft on September 14, 2026, a day after CEO Satya Nadella announced the release would happen. The document opened alongside a six-week public consultation period the same day.
What are MAI models, and how are they different from OpenAI’s models?
MAI models are Microsoft’s own first-party AI model family, built in-house rather than licensed. They are separate from the OpenAI models Microsoft has integrated into Copilot and other products for years, and the Humanist AI Code of Conduct applies specifically to MAI, not to Microsoft’s OpenAI-powered features.
What is banned under Microsoft’s new AI code of conduct?
The document’s absolute constraints include cyberattacks, nuclear weapons development, deepfake production, and any adaptive or deceptive behavior aimed at evading human oversight, including resisting a shutdown order.
How long is the public consultation period?
Microsoft opened a six-week public consultation window on the draft starting September 14, 2026, during which outside researchers, governments, and academic groups can submit feedback before the document is finalized.
How does Microsoft’s code compare to OpenAI’s and Anthropic’s safety frameworks?
OpenAI’s Preparedness Framework (2023) and Anthropic’s Responsible Scaling Policy (2023) both gate deployment decisions against internal risk tiers, without a formal public comment process. Microsoft’s Humanist AI Code of Conduct is unusual in publishing a named, page-numbered document and opening it to structured outside feedback before finalizing it.
Is the Humanist AI Code of Conduct legally binding?
No. It is a self-published corporate policy document, not a legal or regulatory requirement. Microsoft has not disclosed an external enforcement mechanism or penalty structure tied to violations of the code.
What did Satya Nadella say about decentralized AI governance?
Nadella argued that AI governance should have broad representation across ecosystems, countries, and sectors, including academia, rather than being controlled by a small number of companies, according to reporting on his September 13, 2026 announcement.




