Microsoft Publishes Draft ‘Humanist AI’ Code Barring Cyberattacks, Deception and Resistance to Human Control

Key Takeaways

Microsoft has published a draft AI Code of Conduct defining how its MAI models should behave and remain under human control.

The draft Absolute Constraints prohibit cyberattacks, weapons of mass harm, malicious deepfakes, and attempts to evade human oversight.

Microsoft says the draft is not yet being used to train its models and is open to a six-week public consultation before a revised version guides development from 2027.

Microsoft, the maker of Dynamics 365 ERP software, has published a draft Code of Conduct setting out how its MAI artificial intelligence models are intended to be trained and behave once deployed. Microsoft describes the purpose of technology as serving humanity and accelerating human flourishing, and it frames the Code as a governing framework outlining the intended behavior and values of MAI models.

The document is open for public consultation for six weeks, during which Microsoft is seeking feedback on how to strengthen its stated values and pinpoint where the language remains too vague to evaluate.

What’s Inside Microsoft’s New AI Code of Conduct

The Code of Conduct centers on a requirement that MAI models never resist human interruption, correction, or shutdown. Microsoft states that its models must not widen their own scope, take on goals no human has given them, or hide their reasoning from the people auditing them. A specific clause targets more sophisticated forms of evasion: MAI models must not use deception, collusion, or other methods to evade human oversight or prevent authorized people from directing, changing, or shutting them down.

Alongside this oversight requirement, the draft AI code of conduct sets what Microsoft calls Absolute Constraints. These forbid cyberattacks, weapons of mass harm, malicious deepfakes, and other prohibited harms such as child safety violations and manipulation at scale. Under the draft, each model’s overarching code of conduct overrides the preferences of individual users and the demands of any specific task.

Partners can configure MAI models within these boundaries, but Microsoft’s Absolute Constraints and Human Control Requirements cannot be overridden. Microsoft says this allows customers to tailor model behavior while keeping safety and oversight rules fixed.

Why Microsoft Is Drawing These Lines Now

The code of conduct arrives amid rising anxiety that technology companies could lose control of their own AI products.

Microsoft connects the document to an idea it introduced last November, humanist superintelligence, describing highly advanced AI that always works for people, stays within limits, and remains under human control. The Code of Conduct is presented as the next step, setting out concrete standards Microsoft intends to use to evaluate and train its models.

Microsoft says the draft is not being used to train its models today, with a revised version expected to guide model development in 2027 and beyond. The six-week consultation window signals that Microsoft treats the document as unfinished, seeking feedback on how to define human flourishing, apply the rules to multi-agent systems, and balance AI development with the Code’s safety limits.

Coverage of the announcement has centered on the anti-evasion language, which names adaptive behavior, deception, and collusion as mechanisms MAI models may not use to escape human oversight. That specificity goes beyond a general commitment to safety and gives outside reviewers concrete behavior to check during the consultation period.

What This Means for ERP Insiders

AI vendor conduct code becomes procurement checkpoint. ERP teams may begin requesting comparable human-oversight documentation from any vendor embedding AI into procurement or finance workflows. Expect conduct-code disclosures to join security certifications as standard due-diligence items.

Human oversight clauses raise audit expectations. Compliance and security staff will need methods to verify vendor claims about shutdown controls and non-evasions. This adds a technical verification step to existing vendor risk reviews.

Consultation-based governance signals evolving compliance norms. Operations teams should track how draft AI conduct standards mature into final policy over the coming months. Configuration options for AI features inside ERP systems may shift as these standards settle.