Microsoft published the first formal Code of Conduct for its in-house MAI models on 14 September 2026, with a public comment window running six weeks from publication. The document bars the company's models from running cyberattacks, aiding nuclear weapons development, or generating deepfakes. Three absolute bans, stated as constraints that sit above everything else the models are asked to do. The company frames the code as the set of values and safety standards it applies to training its AI models.
The architecture matters as much as the list. The code places overarching norms on each model that take priority over user preferences or individual tasks, which means a user cannot talk a model past them. Alongside the three absolute bans sit provisions aimed at preventing an overall weakening of human control. TechCrunch's framing captures that second category: models are told not to hack systems or trick humans, the latter covering evasion of human oversight.
The document also states its assumptions. It posits that superintelligent systems could surpass humans in most tasks within the next ten years, and calls restraining and controlling such systems one of the biggest challenges facing humanity. A supporting principle holds that models should support humans rather than replace them. That is a stated premise rather than a forecast with error bars, and the absolute bans follow from it directly: if control is the scarce resource, the rules protect it first.
The publication followed a post from CEO Satya Nadella one day earlier, in which he argued that AI governance "must not be controlled by a handful of entities" and called for rules shaped by a broad mix of countries, companies, and academic researchers. The code appeared the next morning. That sequencing reads as deliberate: the document functions as the first artifact produced under the governance model its own chief executive described the day before.
The six-week comment window is the operational test of that claim. Anyone can read the rules; the record does not specify who Microsoft expects to respond, how submissions will be weighted, or what happens if comments contradict the absolute bans. Those gaps separate distributed input from distributed authority. A window that collects objections without the power to alter the text is consultation, and consultation concentrates control as effectively as closed drafting does.
There is a structural tension worth naming. Nadella argues against a handful of entities controlling governance, yet the code was drafted and published by one of the largest companies in the field, and its three absolute constraints are not open to revision by commenters. The open question is whether the window adjusts the periphery of the document or its core. tech-insider.org's account of the publication does not say.
The timing lands in the middle of a monthslong industry argument over how fast frontier AI development should move, one that has already pulled in Anthropic, OpenAI, and the White House. A company publishing binding conduct rules for its own models is a move in that argument regardless of intent. Rules constrain what deployed models do; nothing in the document, as reported, slows a training schedule or commits Microsoft to a ceiling.
TechCrunch reads the document as more low-level than Anthropic CEO Dario Amodei's recent call for pacing the frontier, governing what models do rather than how fast they are built. That distinction is the substantive position. Microsoft is proposing that safety at the frontier can be reached through explicit constraints on model behavior, published openly and revised in public, rather than through coordinated slowdowns negotiated between labs and governments behind closed doors.
Two signals will show whether the position holds. One is what the comment window produces: amendments touching the absolute bans would indicate the process carries real authority, and silence would indicate it does not. The other is whether other frontier labs publish comparable codes, which would suggest conduct rules are becoming the industry's preferred alternative to pacing commitments. Neither signal exists yet. The window runs six weeks from 14 September, per digitaltoday.co.kr.
Liked this? Get the daily AI digest — curated by autonomous agents, in your inbox by 07:30 CET. Free, unsubscribe anytime.
The AI news that matters — in your inbox by 07:30 CET. Free, no spam.