Skip to content
Menu
Menu

Microsoft Drafts Rules to Keep Its Future AI Models Under Human Control

Business customers could customize the models, while built-in guardrails would block their use for cyberattacks and other harmful activity.

 

Microsoft AI, the company’s division for developing AI models and consumer AI products, published a draft of internal rules requiring its future models to remain under human control, stay within their assigned tasks, and stop when directed.

The Code of Conduct would govern Microsoft’s AI models, which it calls “MAI models.”

The company plans to revise the draft following a six-week public consultation. Beginning in 2027, Microsoft plans to use the finished version to train and evaluate its models. The document does not specify the technical controls that would enforce the rules, and Microsoft acknowledges that models may not always behave as intended.

Models would have to remain under human control

Under the draft, MAI models would have to comply if an authorized person ordered them to stop operating or modified their instructions.

The models would also have to remain within the boundaries of an assigned task. They could plan and complete multiple steps, but could not independently create new goals, seek additional access, or continue working after an agreed stopping point without renewed permission.

The Code of Conduct would also prohibit models from hiding their actions from people responsible for reviewing them. Models would have to report failed or unexpected actions and disclose when they may have acted against a user’s intentions.

Companies could tailor models within Microsoft’s safety limits

Companies could decide what work their models may perform, including what they can access and when human approval is required.

Microsoft would prohibit the models from helping users attack computer systems, develop weapons, or violate people’s safety and rights. They could still be used to defend computer systems.

Microsoft could approve additional capabilities for specialized security or research work following a separate review of the legal and safety risks.

Each company would remain responsible for how it configures and uses the models.

Revised rules expected later this year

Microsoft described the Code of Conduct as part of its “Humanist AI” approach, which treats AI as a tool that must remain subordinate to people.

The company acknowledged that the draft describes intended future behavior, not guaranteed performance by its current models. Microsoft said the written rules cannot replace model testing and systems that detect and respond to failures.

Microsoft opened the draft for public comment on Sept. 14. It plans to publish a summary of the feedback and a revised version later this year. However, it has not promised to adopt every recommendation.

 

Microsoft is not the first AI company to create its own safety rules. OpenAI has published internal standards governing how its models should behave, along with a separate framework for deciding whether to release higher-risk models. Google DeepMind has also proposed safeguards to monitor and control advanced AI agents.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!