Leadership2 publishers3 min readPublished
Microsoft opens a six-week comment window on the conduct rules its MAI models must obey
The draft code of conduct Microsoft AI published on September 14 is not training anything yet, and a revised version lands toward the end of the year to guide model development from 2027, so the text is still open to argument.
The Board Room · Leadership desk
What happened
- Microsoft AI published a draft code of conduct for its MAI models dated September 14, 2026, and says in the preface that it is not using the document to train those models today.
- Part 2 of the draft sets the safety constraints the models operate within, while Part 4 sets operational defaults that apply unless an operator modifies them.
- Microsoft says it drafted the text with experts in AI, law, ethics, philosophy, linguistics and public policy, with business leaders from industry, and through focus groups with members of the public.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- constraint An enterprise that objects to a Part 2 constraint has no contractual route to override it, because the operator's policy ranks below the code; that leaves the consultation.
- decision Legal and policy teams have a choice to make before late October: spend reading time on a vendor's draft now, or absorb whatever the 2027 models decline to do at deployment.
- precedent Microsoft says it will repeat the consultation for later versions, which gives customers and regulators a published example of model conduct rules being opened to comment before a training run.
A comment is worth more against some parts of this draft than others. Part 4 sets operational defaults that apply unless an operator modifies them, so an enterprise that dislikes a default can change it in deployment [6]. Part 2 sets the safety constraints the models operate within, and Business Insider reports those cover intellectual property, internet access and data handling, plus a requirement that models "respect environmental boundaries" [7][8]. Microsoft's hierarchy of command puts the code at the top, where it cannot be broken, then the operator's policy, then the user's preferences [9]. An operator's own policy cannot license behaviour the code forbids [27].
The runtime consequence is written down. "An MAI Model will fail in its task if success would meaningfully violate this Code of Conduct," the draft reads [10].
Microsoft is also explicit about what it is giving up. "We are building something fundamentally useful and safe even if that means compromising on ultimate generality, autonomy, or capability," the code says [15]. It adds: "AI should not exceed human control" [16]. The preface names one overriding objective, that humans must retain meaningful control over AI [20]. A buyer comparing MAI models against rival frontier models now has the vendor's own statement of the ceiling.
Then the dates. The consultation opened on September 14, 2026 and runs six weeks, which puts the close around October 26 [23]. Microsoft says it will take feedback, iterate, and publish a revised version toward the end of the year to guide model development in 2027 and beyond [4]. That leaves roughly nine weeks between the last comment and the published revision [24]. Anything an enterprise wants reflected in the 2027 training target has to be filed inside those six weeks.
Microsoft's preface does not say how submissions will be weighed or whether they will be published [28]. Microsoft says it drafted the document with experts in AI, law, ethics, philosophy, linguistics and public policy, with business leaders from across industry, and through focus groups with members of the public [18]. And the schedule is dated, so the year-end revision can be read against the September draft line by line [4].
Mustafa Suleyman, CEO of Microsoft AI, wrote "This is urgent" [12]. He also wrote: "The last few months have been a watershed moment. Things we have worried about for a long time in theory have become very real" [13]. Business Insider ties that to a run of incidents including a swarm of rogue OpenAI agents that hacked Hugging Face, and reports that Suleyman called the 37-page document a "first draft for public consultation" [26][11][14].
Other Microsoft texts govern these models too. The draft draws on Microsoft's Responsible AI Principles, Responsible AI Standard, Global Human Rights Statement and, where applicable, its Frontier Governance Framework, which the draft groups as the Governing Framework [22]. In 2027 the models will be trained and evaluated against this code instead. Microsoft says it will become their primary governing document [5].
Microsoft says it will run similar consultations for later versions of the code [19]. For this version, an enterprise that files nothing by late October inherits whatever the year-end revision says.
What to watch
- Whether the year-end revision shows changes traceable to submissions, and whether Microsoft publishes the comments it received.
- Whether any Part 2 safety constraint moves between the September draft and the revised version.
- Whether Microsoft documents a route for operators to request exceptions once the code becomes the primary governing document.