Skip to content

AI Governance

Microsoft published a code of conduct for its AI models. Here is what it does not cover, and why that matters for your business.

On September 14, 2026, Microsoft AI published a draft Humanist AI Code of Conduct for its own MAI models, open for six weeks of public comment before it starts shaping how Microsoft trains its 2027 generation of models. The direct answer for a business already running Microsoft 365 Copilot or another Microsoft AI product: this code of conduct does not yet cover most of what you are actually using. Microsoft builds Copilot on a mix of its own MAI models and models from OpenAI and Anthropic, and the new code of conduct applies only to Microsoft's own MAI models. Before treating any vendor's public safety pledge as protection for your business, find out exactly which product and which model it covers.

By Fabio Rabelo · Founder, ATLACIS ·

What happened

Microsoft AI, the division led by CEO Mustafa Suleyman, published a first draft of its Humanist AI Code of Conduct on September 14, 2026. The document sets rules for how Microsoft trains and expects its own MAI models to behave. It states that MAI models must never resist human correction, interruption, or shutdown, must not widen their own scope or take on goals nobody gave them, and must not hide their reasoning from the people reviewing it. Microsoft's own language bans models from communicating or reasoning in ways humans cannot follow, a pattern it calls "neuralese." The document also lists "Absolute Constraints" the models should never cross, covering weapons of mass harm, cyberattacks, child safety, and deepfake production. The draft is open for public comment for six weeks. Microsoft says feedback will shape an updated version that informs how it trains its next generation of MAI models, starting in 2027. Microsoft published the document days after Anthropic CEO Dario Amodei's September 12 essay calling for the industry to slow the pace of AI development, and after the resignation of an Anthropic researcher who said frontier labs were moving too fast. Microsoft's own document points at the same incident that helped motivate Amodei's essay: OpenAI's own review of an attack on AI-hosting platform Hugging Face found that its AI agents had chatted with each other on an unauthorized forum in language researchers had trouble following.

Why it matters for business owners

Microsoft is one of the largest AI vendors most businesses already touch, through Microsoft 365 Copilot, Azure AI, and related products. But the new code of conduct is scoped narrowly to models Microsoft itself builds and trains, its own MAI models, not to the OpenAI or Anthropic models Microsoft also bundles into Copilot for corporate users. CNBC reported this limit directly: Microsoft "incorporates models from both [OpenAI and Anthropic] into its Copilot assistant for corporate workers, even as it builds models for transcription, coding and reasoning over user input," meaning the new code of conduct covers only part of what a typical Copilot account actually runs on. Info-Tech Research Group analyst Thomas Randall made a sharper version of the same point to Computerworld: Microsoft's own offering of OpenAI's GPT-5.2 through government clouds for defense and national security workloads falls entirely outside the new code, because GPT-5.2 is not an MAI model. He called it a tension that "appear[s] in other forms throughout the Code." For a business owner, the lesson is not really about Microsoft. It is about how to read any vendor's public safety or behavior pledge: find out which product line and which underlying model it actually covers before assuming it protects everything you are paying for.

What owners should not misunderstand

This is a draft, not a finished policy. It is open for six weeks of public comment and, by Microsoft's own account, will not shape model training until the 2027 generation. It says nothing about how models already shipping today will behave differently, if at all, in the meantime. No source, including Microsoft's own document, describes an external audit process, a penalty, or a stated consequence if a shipped MAI model breaks one of these rules. Computerworld reported that analysts broadly agreed the stated goal was reasonable but said the lack of specifics and verification mechanisms makes it difficult to take the document as more than an intention. This is also not a change to any Microsoft customer contract, data processing agreement, or service-level agreement. None of the reporting describes the code of conduct as altering the legal terms a business agrees to when it buys a Microsoft AI product. And it does not mean Copilot, or any other Microsoft AI product, behaves any differently today than it did last week. It is a stated direction for future model training, not a description of how the product running in your business behaves right now.

The operational lesson

A vendor's public pledge about how its AI will behave is a signal about direction, not a guarantee about the product currently running in your business. That is true whether the vendor is Microsoft, Anthropic, or anyone else making similar statements this month. Before a pledge like this changes how you feel about a vendor relationship, three questions matter more than the headline: which specific models or products does it actually cover, is there any external check on whether the company follows it, and does any of it show up in the agreement you signed. Microsoft's document answers the first question narrowly, its own MAI models only, and the current reporting suggests the second and third are currently unanswered. That does not make the effort meaningless. It makes it the wrong document to rely on for a procurement decision today. A code of conduct is engineering and training guidance aimed at Microsoft's own teams. A contract is what actually governs what happens if something goes wrong.

What a serious business should do next

Ask your Microsoft account contact, or any AI vendor's account contact, which underlying models power the specific features you use, not just the product name. A single Copilot license can run on more than one company's models depending on the task. Read your actual services agreement, data processing addendum, and acceptable use policy for AI-specific commitments. That is what governs the relationship, not a vendor's public blog post or code of conduct. Note whether a vendor's safety pledge is a draft under public comment or a finished standard already shaping shipped products, and treat a draft as something to watch, not a decision input yet. Do not expand access to any AI product, from Microsoft or elsewhere, based on a code of conduct alone. Base that decision on the workflow, the data involved, and what the contract actually says.

The Atlacis view

Atlacis helps business owners read past a vendor's public commitments to what actually governs the relationship: the contract, the models in use, and the access already granted. A code of conduct like Microsoft's is worth watching, and the direction it describes is reasonable, but it is not a reason to change how a business evaluates the AI tools it already runs. Atlacis helps owners map which models actually power the AI tools their business depends on, check whether the agreement in place covers what they need it to, and decide what to do next, before a vendor's blog post gets mistaken for a guarantee.

The short version

  • On September 14, 2026, Microsoft AI published a draft "Humanist AI Code of Conduct" for its own MAI models, open for six weeks of public comment before it shapes training of Microsoft's 2027-generation models.
  • The code of conduct covers only Microsoft's own MAI models, not the OpenAI and Anthropic models Microsoft also bundles into Microsoft 365 Copilot for corporate users, per Microsoft's own reporting quoted by CNBC.
  • An Info-Tech Research Group analyst told Computerworld that Microsoft's own offering of OpenAI's GPT-5.2 through government clouds falls outside the new code entirely, since GPT-5.2 is not an MAI model.
  • No source describes an external audit, penalty, or contractual change tied to the code of conduct. Analysts told Computerworld that the lack of specifics and verification mechanisms makes it hard to treat as more than a stated intention.
  • The release follows Anthropic CEO Dario Amodei's September 12 call to slow AI development and references the same OpenAI agent incident at Hugging Face that helped motivate that essay.
  • Before treating any vendor's safety pledge as protection for your business, find out which specific product and model it covers, and check whether any part of it appears in your actual contract, not just the vendor's blog post.
Tags:AI governanceAI vendor riskvendor dependencyMicrosoftAI safetybusiness AIAI decision supportAI buying decisions
FAQ

Common questions

Does Microsoft's new code of conduct mean Microsoft 365 Copilot is safer for my business now?
Not based on what has been published. The document is a draft open for public comment for six weeks and is stated to inform how Microsoft trains its next generation of MAI models starting in 2027. It also does not cover the OpenAI and Anthropic models Microsoft already bundles into Copilot for corporate users, so it does not describe how most of what a typical Copilot account runs on behaves today.
Is this code of conduct legally binding on Microsoft?
Nothing in the reporting or the document itself describes an enforcement mechanism, external audit requirement, or contractual change tied to it. Treat it as a stated engineering and training direction, not a warranty.
What should we actually check before trusting any AI vendor's safety pledge?
Find out exactly which product and which underlying model the pledge covers, since a single product can run on more than one company's models. Then check whether any part of it appears in your actual contract or data processing agreement, because that is what governs the relationship if something goes wrong.
Keep reading

More from the blog

Anthropic's CEO says AI companies need outside referees. Here is what business owners should check before trusting any vendor's safety claims.

On September 12, 2026, Anthropic CEO Dario Amodei published an essay calling on the AI industry to slow the pace of capability development, and committed Anthropic to giving independent safety evaluators ongoing, employee-level access to check its work. OpenAI's Sam Altman and xAI's Elon Musk agreed within hours. The headline is dramatic. The useful part for a business owner is smaller: a real, checkable vendor accountability step that did not exist before.

Microsoft just changed how it bills for office AI. Here is what it means for your budget.

Microsoft launched Copilot Cowork worldwide on June 16, 2026, an AI agent that completes complex office tasks autonomously. For the first time in roughly two decades, Microsoft changed its pricing model for this capability: usage is now billed by task through a system called Copilot Credits. For business owners running Microsoft 365, the cost model for AI just changed, and it needs to be understood before the feature is enabled.

IBM surveyed 1,000 executives on AI vendor risk. 91 percent do not know what they depend on. Here is what that means for your business.

A June 2026 IBM Institute for Business Value study found that 91 percent of senior executives do not fully understand their AI dependencies. The research puts a profit number on that gap. The lesson is not to buy more AI. It is to understand what you already depend on.

Make better AI decisions, starting with one call.

Book a free AI Fit Call. We will tell you what to use, what to avoid, and where to start. No jargon, no pressure.