Regulation5 minNewsroom

Microsoft Releases 38-Page Code for MAI Models

Documento impresso de 38 páginas aberto sobre mesa de conferência de madeira sob luminária pendente, caneta-tinteiro atravessada na página

The 38-page document outlines what MAI models can and cannot do, and who has the authority to disable them. The public consultation lasts six weeks.

A Constitution for the Models


On Monday, September 14, Microsoft AI published the first version of the Humanist AI Code of Conduct, a 38-page document detailing how MAI models should operate, what they cannot do under any circumstances, and who has the authority to disable them. Mustafa Suleyman, CEO of Microsoft AI, told Reuters that the text is "a sort of constitution" for the company's future models. The draft is open for public consultation for six weeks, with a second version expected by the end of 2026, promising to guide development from 2027 onward.


What Models Cannot Do


The code prohibits, without exception, three things: assisting in the development of CBRNE (chemical, biological, radiological, nuclear, or explosive) weapons, conducting cyberattacks, or generating non-consensual deepfakes. This is a shorter list than those published by Anthropic and OpenAI in their own policies, and this is not accidental. A shorter catalog forces the model to misfire on fewer and more severe cases rather than rejecting millions of legitimate inquiries, which is a constant complaint from corporate clients purchasing GPT and Claude via API. For the CISO trying to standardize guardrails among three LLM providers, Microsoft’s document becomes a negotiation anchor: both client and supplier now share a common map of which rejections are absolute and which are configurable preferences.


Human Interruption as an Immutable Clause


The most stringent part of the document isn't the list of prohibitions; it's the requirement that any MAI system must accept interruption, correction, redirection, and shutdown by a human operator. If a task can only be completed by breaking the code, the model must fail the task, not the rule. This changes the reference architecture that Microsoft sells to banks: fully autonomous systems that operate end-to-end, without a human in the loop, need an auditable shutdown hook accessible to the client, not just the supplier. It is a direct response to the debate opened by Anthropic with the concept of "constitutional AI," to which OpenAI responded with the Model Spec. Microsoft arrived third in this document race but introduced something that Anthropic has yet to formalize: a public comment cycle with a defined deadline.


The Counter-Argument Microsoft Needed to Publish


The biggest risk of the document isn't technical; it’s political. According to researchers cited by Unite.AI, a short list of prohibitions can create a false sense of security and omit second-level risks: misuse of training data, algorithmic discrimination in hiring, psychological dependence on conversational agents. Suleyman preemptively addressed part of this criticism by defining Microsoft as a signatory to the principle "AI subordinate to the human user," but preemption is not an answer. A preamble claiming to be humanist does not neutralize omissions in the body of the standard, and the final version will have to choose: incorporate second-level risks and accept the commercial cost of additional rejections, or maintain a narrow scope and become an example of corporate capture of the responsible AI agenda.


Corporate Reading: Two Markets at Play


Microsoft needs this document to sell autonomous agents to the regulated sector. In Brussels, the EU AI Act requires providers of high-risk systems to publish internal security policies verifiable by third-party audits, and the European Commission has already signaled that it accepts voluntary codes as part of compliance. In the United States, the executive orders signed by the current administration have made it mandatory to report security incidents in frontier models, and a public code of conduct serves as evidence of due diligence. In Brazil, where PL 2338 remains stalled, Suleyman's text becomes a lobbying tool: banks and insurers will cite it as evidence that private self-regulation is possible and will pressure Brasília not to copy the more restrictive European version. Those writing public policy in the country will spend the next six weeks reading the 38 pages.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Regulation