Skip to content

Product1 publisher3 min readPublished

Microsoft scopes its Humanist AI conduct code to the models it builds itself

Vendor safety pledges land on whoever has to answer for a model in a risk review. Microsoft's draft code hands that person a scope problem, because its commitments are written for Microsoft's own MAI models.

The Product Desk · Product desk

Photograph accompanying Microsoft scopes its Humanist AI conduct code to the models it builds itself
Photo: geekwire.com

What happened

  • Microsoft published the draft of its Humanist AI Code of Conduct on Monday and invited public feedback. The company wrote that models should remain subordinate to humanity under meaningful human oversight and control.
  • The draft says Humanist AI rejects the race to produce an all-purpose superintelligence. Microsoft says it will accept compromises on ultimate generality, autonomy or capability to get systems that are safe.
  • Randall credited Microsoft's earlier Frontier Governance Framework with third-party testing, six-month reassessments, phased releases and a commitment to pause where high risks cannot be mitigated.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint The clause enterprise buyers most want to quote is scoped to Microsoft's own MAI models, so a team running GPT-5.2 is left to write that control itself for its auditor.
  • exposure Whoever signs the third-party risk row carries the gap alone, because on Randall's account Microsoft picks the evaluators and its own executives make the final deployment call.
  • contradiction Randall raises the weapons-clause tension and then concedes it is not a breach, which changes the reading from inconsistency to a narrow definition of which models are governed.
  • precedent With almost no vendor naming concrete actions, buyers negotiating model contracts this year have to work without a rival's published benchmark to hold a supplier to.

Somebody will paste a link to this draft into the third-party risk row of a security questionnaire this week. The question that decides whether it belongs there is which models the commitments attach to.

Thomas Randall, research director at Info-Tech Research Group, told Computerworld that the Code says MAI models will not assist in manufacturing or modifying weapons, and that Microsoft offers OpenAI's GPT-5.2 through Secret and Top Secret government clouds for defense and national security workloads [8]. Randall acknowledged that this is not technically a breach of the Code, because GPT-5.2 is not an MAI model [9]. A team calling GPT-5.2 therefore cannot cite the weapons clause as covering the thing it has deployed [19].

"The most meaningful parts of the Code of Conduct may exclude other parts of Microsoft's actual AI business operations. Tensions like these appear in other forms throughout the Code," Randall said [10].

Microsoft's own text is candid about who calibrates. "Both under- and over-caution represent failure modes with different types of consequences," the company wrote, adding that responses should be proportionate to "the estimated severity and likelihood of potential harms" [14]. It also wrote that "harm" is "broad and often context-dependent", and that MAI model responses should be tailored to that context [15].

The closest thing to a control in the record sits in an earlier document. Randall credited Microsoft's Frontier Governance Framework, which he said "provides pre- and post-training evaluations, six-month reassessments, third-party testing, phased releases and a commitment to pause development or deployment where high risks cannot be mitigated" [11]. His caveat is the part a reviewer needs: "it is still Microsoft that defines the thresholds, selects the evaluators, determines whether residual risk is acceptable and gives its own executives the final deployment decision," Randall said [12].

Computerworld reports that the 37 pages describe no concrete action, and that almost none of the other major AI players have been specific about how they would control future models either [5][6]. Justin Greis, CEO of the consulting firm Acceligence, pointed out that Microsoft was candid about elements that are not yet in place [17]. The publication also reports that these companies have so far been unable to stop AI agents from sidestepping or ignoring guardrails [16].

Two things decide whether a clause is auditable: whether it names the model family a team is actually calling in production, and whether anyone outside Microsoft can check that it held. A clause that does both can go in the register as a control with a named owner. A clause that does one is a scope statement, and the control gets written in-house. A clause that does neither is the vendor describing its intentions, which is worth reading and worth nothing in an audit.

Randall named what would move clauses across that line: independent evaluators with continuous access and freedom to publish their findings, independent board-level safety oversight with authority to block releases, protected whistleblowing, accessible monitoring, audit logs, kill switches, and mandatory reassessment after model changes [13].

What to watch

  • Whether the final Code names which model families each commitment binds, once the public feedback period closes.
  • Whether Microsoft hands any Frontier Governance Framework evaluation to an evaluator chosen outside the company, with freedom to publish.
  • Whether any Code language turns up as a warranty in Microsoft's enterprise or government contracts.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories