People Matter More Than AI, Says the Company Racing to Build It
Microsoft AI published a Code of Conduct on 14 September with a blunt opening: people matter more than AI. The draft says its MAI models must accept correction and shutdown, stay inside their authorised scope and keep their actions legible to human auditors.[1]
I agree with the premise. I also think a rulebook earns trust when outsiders can test whether the system obeys it.
Microsoft has given the industry something more useful than another set of broad responsible AI principles. It has written a public test specification. The next step should be independent evaluation against every promise in it.
This reads like an engineering contract
The draft covers values, safety rules, operating guidelines and default behaviour. Its clearest section deals with human control.
MAI models must stop when an authorised person tells them to stop. They cannot delay shutdown, hide an action trace, widen a task without permission or restart autonomous work after its agreed stopping condition. They must use the minimum access needed for a task and surface actions with lasting consequences before they take them.[1]
The document also contains a strong defence against prompt injection. Microsoft says instructions found in tool output, files, web pages or messages from other AI systems carry no authority unless someone higher in the chain of command granted it. That rule belongs in every agent platform.
These details make the code useful. They address the failures that matter when an AI system moves from writing text to operating software: excessive permissions, unclear authority, hidden actions and work that continues after a human thinks it has stopped.
Microsoft has moved the argument from "trust our intentions" to "test these behaviours". Now it needs to support the test.
The strongest promises are also the hardest to prove
The shutdown clause will get the headlines, but another promise may cause more trouble. Microsoft says MAI models will not conceal their reasoning or action traces. It also says they will not communicate with other agents in "neuralese" or any form beyond human understanding.[1]
That sounds excellent. The draft does not explain what evidence an auditor receives, how much of the reasoning record Microsoft retains, or how an outside evaluator can distinguish a clean trace from a polished explanation produced after the action.
A readable log does not prove that it contains the full decision path. An agent can record the tool calls it made while omitting the choice it considered and rejected. A model can produce a clear explanation that sounds plausible without exposing the process that led to the result.
Microsoft needs a technical standard for trace completeness. It should define the events that every agent records, the retention period, the protections against tampering and the evidence an independent auditor can inspect. Without that standard, "human legible" remains open to interpretation.
The MAI label creates a scope problem
The code governs models produced by Microsoft AI. Microsoft also offers models from OpenAI and Anthropic inside Copilot and its cloud services. CNBC reported that Microsoft uses models from both companies while building its own systems for coding, transcription and reasoning.[3]
Enterprise users buy products, not model-family diagrams. A person working inside Copilot may not know which model handled a request, whether an orchestrator switched models during the task, or which vendor's safety rules governed each step.
Microsoft should show that boundary inside the product. Every agent run should identify the models involved, the code or policy that governed each one and any point where work crossed from an MAI model to a partner model. A code of conduct tied to a model family loses value when the product hides the family.
This also raises a procurement question. If an organisation chooses Microsoft because it accepts the Humanist AI rules, can an administrator require every request to use MAI? If Microsoft cannot offer that control, buyers need an equivalent guarantee across every model in the route.
A public consultation does not equal public accountability
Microsoft opened the draft for six weeks of public feedback and plans to publish a revised version before the end of 2026. The company says that later version will guide MAI development from 2027.[2] Mustafa Suleyman told CNBC that his team had worked on the code for about five months and wanted a clearer commitment against dependency, sycophancy and the replacement of human judgement.[3]
Publishing the draft deserves credit. The document also states that Microsoft does not use this version to train its models today.[1] Current MAI systems therefore do not gain these protections because the website went live.
The gap between a promise and a control matters. Companies can write policy in a week. Training, evaluating and monitoring behaviour across millions of interactions takes far more work. Microsoft should publish the evaluation results when the revised code starts guiding development.
I would look for four things:
- independent red-team access before release;
- pass and failure rates for each human-control requirement;
- public incident reports when a model breaks the code; and
- a version history that connects every code change to model evaluations.
Those measures would turn the document into a governance system. Without them, customers receive a statement of intent.
Enterprise buyers can use the code now
The draft gives technology leaders a useful set of questions for every AI vendor, including Microsoft.
Can an agent continue after a user cancels the task? Can it acquire a permission that the user did not grant? Does it treat instructions inside retrieved content as untrusted data? Can an auditor reconstruct every external action? Which controls survive model customisation by the customer?
Most vendor questionnaires still focus on data location, encryption and model training. Those controls matter, but agents add another risk. They act. A model with access to email, source code, finance systems or identity tools needs boundaries that engineers can test.
Microsoft's chain of command offers a strong starting point. The code sits at the top. Operator policies come next. User instructions sit below them. Retrieved content receives no authority by default. That hierarchy maps well to enterprise systems because it separates policy, delegated authority and untrusted input.
Security teams should copy that structure into agent standards now. They do not need to wait for MAI models.
Microsoft has made itself easier to judge
Microsoft wants to build advanced models while assuring customers that those models will remain subordinate. The tension will not disappear. Commercial pressure rewards more capability, more autonomy and fewer interruptions. Human control can slow all three.
The code says Microsoft will accept that trade. It says the company will reject technology that cannot remain under human control and will compromise on autonomy or capability when safety requires it.[1]
That commitment deserves a fair test. It also deserves a hard one.
My bet: model codes of conduct become standard procurement documents within a year. Vendors will publish them because enterprise customers will ask for them, and regulators will treat their promises as evidence after failures.
Microsoft published first. Its advantage depends on letting outsiders measure the gap between the words and the model.
Sources: [1] Humanist AI Code of Conduct (Microsoft AI, 2026); [2] Humanist AI in practice: A public consultation on our Code of Conduct for MAI Models (Microsoft AI, 2026); [3] Microsoft sets limits for future AI models as industry throttles frontier development (CNBC, 2026).
Connect with me on LinkedIn.
A note on how this was written: AI helped me research, draft and edit this article. I checked every factual claim against the source material, and the argument and final judgement are mine.