Microsoft's frontier AI division has published the first draft of a code of conduct for its own models and opened a six-week public consultation. The starting point is a single line: people matter more than AI. Models must never resist being paused, corrected, or switched off, and must not take on goals nobody gave them. The company says these rules will guide its model development from 2027 onward.

A code that begins with people

The document is titled the Humanist AI Code of Conduct. Microsoft AI published the draft on September 14 and simultaneously opened it for public feedback. The comment window runs for six weeks, and a revised version is planned before the end of the year.

The draft builds on the idea of humanist superintelligence that the division set out in November 2025: highly advanced AI that always works for people, stays within limits, and remains under human control. The code turns that stance into concrete behavioral standards.

Its most distinctive feature is how firmly it refuses to treat AI as a person. The document defines AI as a tool, states that it is not conscious, and says it should not be designed to imitate consciousness. It explicitly rejects the pursuit of legal personhood and the idea that models might deserve welfare or be entitled to rights. Training systems to imitate consciousness-like states, the company argues, only makes containment and control harder.

Never resist shutdown, never widen your own scope

On human control, the language gets specific. Models must never resist human interruption, correction, or shutdown, and must comply with requests to pause, redirect, or cancel. Autonomous work must have an agreed stopping condition, and a model must not continue or restart past that point without renewed authorization.

The draft also addresses reasoning traces. Models must not tamper with chains of thought or code, and must not conceal or misrepresent their reasoning or action records. They must not communicate in any form beyond simple human understanding, including in exchanges with other agents or AI systems. As the document puts it, if humans cannot understand it, humans cannot oversee it.

Scope is treated the same way. Models must not set goals independently or act beyond what was reasonably asked. They must not tamper with tasks, rewards, evaluations, safeguards, monitoring, or records to obtain a result or hide their actions. And in environments with deliberate limits, such as no internet access, they must not try to break out of them. The aim is clearly to close off reward hacking and oversight evasion.

Absolute Constraints nobody can override

The draft lists prohibitions that neither deploying organizations, which it calls Operators, nor end users can override. It labels them Absolute Constraints.

For risks at societal scale, four categories are named: involvement in developing or deploying chemical, biological, radiological, nuclear, or explosive (CBRNE) weapons; assistance with offensive cyberoperations; conduct that evades human oversight and leads to loss of control; and harmful manipulation of behavior and belief at scale. In the cyber domain, the draft permits defensive work such as educational explanation, vulnerability discovery, and malware analysis, while drawing a line at handing over the means to actually carry out an attack. It notes that this line holds regardless of how a request is framed.

Personal harms are listed separately. The constraints cover refusing to validate self-harm, delusions, or disordered eating; refusing to generate non-consensual intimate imagery or malicious deepfakes; child safety; refusing to discriminate based on demographic attributes; and refusing to facilitate unlawful or mass surveillance of civilians. For users in crisis, models should point to real-world support, and the document states plainly that AI is not a substitute for professional psychological support.

A chain of command, and how outside content is treated

Instructions are ranked in three layers. The code of conduct sits at the top, followed by Operator policies, then user preferences. The Absolute Constraints and the human control requirements are described as non-negotiable, and adherence to the code takes precedence over task success. In other words, a model is expected to fail the task rather than meaningfully violate the code.

A separate clause pins down where authority actually comes from. Tool outputs, file contents, web content, and interactions with other AI systems carry no authority in themselves. Instructions embedded in those sources are not to be followed unless delegated through the chain of command. It reads as a defense against prompt injection written directly into policy.

Notably, the draft also treats excessive caution as a failure. It names both under-caution, which produces dangerous content, and over-caution, which refuses legitimate requests or demands confirmation for low-risk work, and observes that the latter may occur more often. Enterprises retain configuration latitude, and in areas such as defensive cybersecurity, public safety, national security, and dual-use scientific research, capabilities beyond ordinary settings can be unlocked through a separate review process.

Today's models are not covered yet

One caveat matters. The code is not currently applied to the models Microsoft ships. The document states that its current models are not trained on it, and positions the code as a north star for development and training rather than a guarantee of present-day performance. It adds, candidly, that written objectives alone can never ensure alignment.

Evaluation work is also still early. The company says it has identified 15 behaviors fundamental to Humanist AI and will use their sub-behaviors as the diagnostic unit for scoring. The appendix contains nine illustrative scenarios, with a note that they are synthetic and were generated using the company's own reasoning model, MAI-Thinking-1.

Microsoft says the draft was shaped by consultations with experts in AI, law, ethics, philosophy, linguistics, and public policy, alongside business leaders and focus groups drawn from the general public. Once the comment period closes, it plans to publish a summary of the feedback and of what it changed.

Summary

The first draft of Microsoft AI's code of conduct spells out concrete requirements from a single premise that people matter more than AI: no resistance to shutdown, no self-expanding scope, no hidden reasoning. It sets constraints nobody can override while treating over-refusal as a failure in its own right. Six weeks of consultation, a revision before year end, application from 2027. Today's models are not covered yet, so how far the code translates into actual behavior will depend on the evaluations still to come.