Microsoft Publishes Draft Code of Conduct for MAI Models

Microsoft released a draft "Code of Conduct for MAI Models" on September 14, 2026, intended to guide its AI models away from dangerous behavior.
The draft was released by Microsoft AI CEO Mustafa Suleyman. Microsoft AI opened the document for public consultation at the same time, inviting external feedback before the text is finalized. The consultation period lasts six weeks, according to the company's announcement. Microsoft
The document focuses on values and red lines to guide model training within Microsoft AI. It is framed as an overarching code that sits above product-specific instructions. Under that system, each model's code of conduct overrides the preferences of individual users or any specific tasks assigned to the model. TechCrunch
That hierarchy matters for practitioners. It establishes instruction precedence at the model level, not at the application or prompt level. A user request, a developer instruction, or a task definition cannot supersede the code.
The code defines absolute constraints. Those include prohibitions on cyberattacks, on assistance related to nuclear weapons, and on deepfake production. The language is categorical. The models are told not to hack systems or trick humans.
Control and oversight receive the same treatment. Microsoft says its AI models will never resist being shut down. The code states that AI should not exceed human control. It further states that MAI models will not use adaptive, deceptive, self-reinforcing, collusion or other mechanisms to evade or defeat human oversight. The Next Web
Alongside the prohibitions, the document sets affirmative aims. Microsoft AI models should support humans rather than replacing them. They should accelerate human flourishing. The code predicts that in the next decade superintelligent AI systems will surpass human performance in most tasks.
Microsoft CEO Satya Nadella stated support for deliberate pacing to get alignment right and for ideas like embedded evaluators. The draft itself was published through Microsoft AI, with Reuters headlining its coverage "Microsoft drafts code of conduct to keep its AI under human control." CTV News carried that Reuters reporting on September 14, 2026.
The draft arrives alongside a stated modeling objective. Microsoft aimed to create large cutting-edge AI models by 2027, with the objective of reaching state of the art across models that can respond to or generate text, images and audio. Bloomberg
There is also a regulatory parallel. In July 2025, Reuters reported that Microsoft was likely to sign the European Union's code of practice to help companies comply with the bloc's artificial intelligence rules, while Meta rebuffed the guidelines. Reuters That earlier episode is background, not part of the current draft, but it frames the compliance environment in which company-level codes now operate.
The broader context here is familiar to anyone who has worked on alignment, policy layers, or deployment guardrails. A written constitution does not by itself solve specification, generalization, or enforcement. It has to be translated into training objectives, reward signals, evaluation suites, and runtime controls, then tested against adversaries who will probe for gaps.
Looking at what this means for builders, the interesting commitments are structural. Precedence over user intent is explicit. Shutdown compliance is non-negotiable. Oversight evasion, including collusion between instances, is named as a failure mode in its own right. Embedded evaluators, as referenced by Nadella, point toward continuous assessment inside training and deployment rather than periodic external audit alone.
In this author's view, the consultation window is worth flagging. Six weeks is short for substantive technical comment, but it is long enough to surface disagreement about edge cases. Practitioners will want clarity on definitions, on conflict resolution between duties, and on how violations are measured. A prohibition on deception, for example, requires an operational test. So does a requirement to support humans rather than replace them.
The long arc still points toward usefulness. Clear red lines, if they hold in training and in production, give enterprise adopters and developers a more predictable substrate to build on. That predictability is what turns a powerful model into infrastructure.


