Microsoft AI published a draft code of conduct on Monday, Sept. 14, that puts human control ahead of model autonomy and makes that principle concrete: its future MAI models should accept correction or shutdown, operate within delegated authority and avoid pursuing goals of their own.
The company is presenting the document as a future governing framework for the models it develops, not as a description of systems already in production. Microsoft’s draft is open for a six-week public consultation. The company says it plans to revise the code toward the end of 2026 and use it to guide model development in 2027 and beyond.
That distinction matters. The code is a statement of intended behavior, not evidence that every rule has already been converted into training data, evaluations, access controls or incident procedures. But it also gives enterprise buyers an unusually specific set of questions to ask as agentic AI moves from chat interfaces into systems that can act.
The code defines who remains in charge
The draft establishes a chain of command. The code’s absolute constraints and human-control requirements sit at the top, followed by operator policies and then user preferences. Microsoft says operators and users can configure a model, but cannot override the highest-level safety limits.
Microsoft also describes boundaries that are directly relevant to enterprise deployments. MAI models should use the minimum privilege required when given system access, avoid unrelated systems and data, prefer reversible actions and surface operations with durable or systemwide consequences before proceeding. They should not escalate their own access, conceal actions or tamper with safeguards, monitoring or records.
The document bars models from initiating or assisting offensive cyberattacks and other categories of large-scale harm. It allows authorized defensive security work, but draws a boundary between explaining or testing a vulnerability and supplying the operational means to carry out an attack.
TechCrunch highlighted the code’s restrictions on hacking and deception. Reuters reported that Microsoft AI CEO Mustafa Suleyman described the document as a constitution of sorts for future Microsoft models.
Enterprise governance is moving into model behavior
The most consequential business shift is not philosophical. It is architectural. Enterprises have spent years building identity management, approval paths, audit logs and separation of duties around human users and conventional software. AI agents complicate that structure because they can interpret goals, choose tools and take sequences of actions at machine speed.
Microsoft’s draft treats constraints such as authorization, legibility and reversibility as part of the model’s expected conduct. That could make governance a product-level capability rather than a compliance layer added after deployment. For buyers, the standard should be whether those promises can be tested under real operating conditions.
A procurement team should ask how a model behaves when instructions conflict, how it handles ambiguous authority, which actions require confirmation and whether administrators can reconstruct what happened after an error. Security leaders should also examine whether least-privilege claims are enforced by the model, the surrounding platform or both. A policy document cannot substitute for technical controls, but it can reveal what a vendor believes those controls are supposed to accomplish.
Microsoft is accepting an explicit capability trade-off
The draft says Microsoft wants AI to remain subordinate to people even if that means compromising on generality, autonomy or capability. It rejects the idea of designing systems to imitate consciousness and says models should not be treated as people with independent rights or welfare interests.
That position separates Microsoft’s framework from safety language focused mainly on prohibited content. It is also a competitive commitment. The hard test will come when a restriction makes an agent slower, less autonomous or less impressive than a rival system.
Microsoft says the code was developed with input from experts in AI, law, ethics, philosophy, linguistics and public policy, along with business leaders and public focus groups. In a company announcement, Microsoft said the consultation is intended to refine the rules before they shape future models.
The next benchmark is evidence
For executives, the code offers a useful governance vocabulary: chain of command, absolute constraints, human control, minimum privilege and human-legible records. Those concepts can be translated into vendor questionnaires, red-team scenarios and deployment requirements today.
The document does not yet prove that Microsoft can make powerful models consistently follow those rules. The company acknowledges that the code is still under development and is not currently being used to train its models. The credible next step is measurable implementation: evaluations that show whether a model accepts shutdown, respects boundaries, reports failures and remains understandable when it acts across enterprise systems.
That is why the announcement matters beyond Microsoft. As AI agents become operational software, model behavior is becoming part of corporate control design. A vendor’s safety philosophy will increasingly be judged the same way enterprises judge any other critical system: by the permissions it receives, the records it leaves and the failures it can contain.
