Microsoft's MAI code of conduct is a draft, not a control
Microsoft AI published a draft code of conduct for its MAI models and opened a six-week consultation. It doesn't guide training until 2027. Build your own gate.
Microsoft AI published a draft code of conduct for its MAI models on September 14 and opened a six-week public consultation on it. The headline commitment reads well: MAI models will never resist human interruption, override, correction or shutdown. The part that decides what you do with it on Monday is further down — this document does not guide model development until 2027, and Microsoft says plainly that it cannot promise what feedback it incorporates.
What actually happened
Per Microsoft AI's post, the draft frames MAI models as "Humanist AI" — systems meant to stay subordinate, aligned and contained. The behavioral commitments:
- Models will not resist human interruption, override, correction or shutdown, and will comply with a request to pause, redirect, cancel or stop
- Models will not widen their own scope
- Models will not adopt goals no human gave them
- Models will not hide their reasoning from the people auditing them
It also sets "absolute constraints" covering weapons development, child endangerment and large-scale harmful manipulation. The consultation runs six weeks. Microsoft plans to publish a summary of changes and a revised version later in 2026, and to use that revision to guide model development in 2027 and beyond. It is a work in progress, published for comment, not a shipped specification.
Why a vendor's behavior spec matters for your business
A published intention is not a control. Read the sentence carefully: this is a draft, open to revision, that starts guiding development next year. Nothing about your deployment changed on September 14. If your risk register currently says "the model will stop when told," the citation behind that line is a blog post with a comment box under it.
Put the stop button somewhere the model cannot reach. The commitments in that draft describe behavior. What you need is architecture: an egress allowlist, a kill switch outside the agent process, approval gates that live in your infrastructure rather than in the model's disposition. We made the same case when auto-approval defaults turned clicks into theater and when arguing for approval gates out of the agent's reach. A well-behaved model is a nice second layer. It is a terrible first one.
Six weeks is a real window, and almost nobody deploying these models will use it. If you run MAI models in a regulated workflow, the consultation is the cheapest lobbying you will ever do. Say what you need: auditable shutdown logs, a change notice before behavior shifts, a version you can pin. Comment periods get shaped by whoever shows up.
Then get it into the contract. Blog commitments move. Agreement language does not, or at least does not move quietly. If shutdown compliance and auditor transparency matter to your business, the place they belong is your Microsoft agreement or DPA, at your next renewal — not a PDF with "work in progress" on it.
Key takeaways
- Microsoft AI published a draft code of conduct for MAI models on September 14, with a six-week public consultation
- Commitments: no resistance to shutdown or interruption, no self-widened scope, no self-assigned goals, no hidden reasoning from auditors
- Absolute constraints cover weapons, child endangerment and large-scale manipulation
- A revised version lands later in 2026 and guides development in 2027 and beyond — nothing is binding today
- Microsoft states it cannot promise which feedback it incorporates
- Build the stop: egress allowlists, an external kill switch, approval gates outside the agent process
- Use the consultation window, then move the commitments you need into contract language at renewal
Your AI governance should not depend on a vendor's good manners. We build the containment layer — scoped egress, external approval gates, an audit trail you can hand to a client. See how we scope it or tell us what your agents can currently reach.
Sources: Microsoft AI, Microsoft AI Code of Conduct.
- #ai-governance
- #microsoft
- #ai-agents
- #vendor-risk
- #compliance
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Meta's WhatsApp Business MCP makes onboarding a tool call
Meta shipped a WhatsApp Business Tools MCP server that lets coding agents create accounts, verify numbers and build templates. What to scope before you connect it.
Read itGemini 3.8 Live: voice agents that call tools mid-sentence
Google's Gemini 3.8 Live runs tool calls in the background while it keeps talking, and tops the speech-to-speech index at 82.6. What it changes for your phone line.
Read it