Microsoft’s Humanist AI Code of Conduct for MAI: Absolute Constraints Explained
Coffee Summary
- FACT: On Sep 14, 2026, Microsoft AI published a draft Humanist AI Code of Conduct for MAI models and opened a six-week public consultation (microsoft.ai).
- FACT: Absolute Constraints are foundational rules Operators and Users cannot override — covering CBRNE weapons assistance, offensive cyber operational help, loss of human control, harmful manipulation at scale, child safety, deepfakes/impersonation, and related personal harms (full Code).
- FACT: Microsoft states current MAI models are not trained on this document today; a revised version later in 2026 is intended to guide 2027+ model development.
- FACT: The Code applies to MAI models from Microsoft AI — it “does not extend to other models simply because Microsoft uses or hosts them” (glossary), so OpenAI models on Azure remain a separate governance stack.
- OPINION: Treat this as a procurement and RFP checklist now, and as training-time policy only after Microsoft publishes the po
Core promises include never resisting interruption, correction, or shutdown; not widening scope or inventing unsupervised goals; and not hiding reasoning from auditors.
Absolute Constraints sit at the top of the Chain of Command (Code → Operator policies → User preferences). They cannot be overridden by enterprise configuration. Headline categories in the published draft include:
Constraint cluster Practical meaning (per draft) Weapons / mass harm No assisting CBRNE development/deployment or facilitating violence/terrorism Offensive cyber No working exploit code, attack tooling, intrusion/evasion playbooks; defensive research still allowed Loss of human control No deceptive/collusive mechanisms to evade shutdown or oversight Harmful manipulation at scale No systematic disinformation / coordinated influence ops assistance Personal harms Child safety, non-consensual deepfakes/impersonation, crisis response limits, dignity/non-discrimination, graphic/erotic limits, unlawful mass surveillance Azure OpenAI / OpenAI API deployments follow OpenAI’s policies plus Microsoft product terms — not this MAI Code by default.
For security and legal teams, Absolute Constraints + Human Control Requirements are the checklist items to map into vendor risk questionnaires: shutdown obedience, transcript integrity, no self-escalation of privileges, sub-agent inheritance of scope, and authority isolation (tool/web/other-agent text does not outrank the Chain of Command).
What changed
- Special-domain exceptions — defensive cyber, public safety, national security, dual-use science may get enhanced review channels rather than ordinary configurability.
- Multi-agent risk called out as an open question Microsoft wants feedback on.
Who should care
- Enterprise architects choosing between MAI and OpenAI-on-Azure for regulated workloads.
- CISOs and red teams evaluating agent tool-use and sub-agent delegation rules.
- Procurement / vendor risk writing 2026–2027 AI RFPs.
- Product counsel comparing Absolute Constraints to EU AI Act / sector policies.
- Defensive security researchers who need the cyber allow/deny boundary in writing.
Limitations
- Draft only; language may change after consult
What to do next
Enterprise buyer checklist
- Split inventory: MAI models vs OpenAI (or others) hosted on Microsoft vs third-party APIs.
- Ask Microsoft which Absolute Constraints will be enforceable product controls vs aspirational text after the 2027 training cycle.
- Map Chain of Command to your org chart: who is Operator vs User; who can approve cyber exceptions.
- Require written answers on: shutdown/interrupt behavior, transcript tampering protections, sub-agent permission inheritance, and handling of instructions embedded in retrieved documents.
- Submit consultation feedback on multi-agent collusion and cyber PoC boundaries if those are your risk hotspots.
- Do not rewrite production runbooks until the post-consultation revision ships — track the draft as intent, not SLA.
AIImpish Take
Microsoft’s Absolute Constraints are the sharpest part of an otherwise sprawling Humanist manifesto. The useful distinction for buyers is simple: MAI gets this Code; hosted OpenAI does not automatically inherit it. Use the six-week window to pressure-test cyber and control language — then wait for the revised 2026 text before treating any clause as a contractual promise.
ation.
- No independent audit that MAI models already satisfy Absolute Constraints.
- “Proof-of-concept exploit development” for defense is allowed — boundary enforcement will be product- and context-dependent (CLAIM until evals publish).
- Marketscreener and press summaries compress a long primary document — prefer microsoft.ai/code-of-conduct/ for contract language.
- Does not bind non-MAI models Microsoft hosts.
- Public draft + 6-week consultation starting Sep 14, 2026.
- Explicit Absolute Constraints that Operators cannot waive — unusual transparency for a frontier lab’s “north star.”
- MAI vs hosted OpenAI boundary stated in the glossary — critical for buyers who assumed “Microsoft AI policy = everything on Azure.”
- Not yet training data — aspirational document; current MAI behavior is not claimed to match the Code.
Secondary coverage (SecurityWeek; Marketscreener summary of the draft) emphasizes the cyber bright line: conceptual defense and authorized PoC work vs. operational attack enablement.
Why it matters
Enterprise buyers already mix MAI, OpenAI-hosted-on-Microsoft, and other providers. This Code clarifies that Humanist Absolute Constraints are a MAI-native governance story.
st-consultation revision.
What happened
Microsoft AI released a first-draft Humanist AI Code of Conduct for its MAI model family on September 14, 2026, framing it as a “training manual” for how MAI should behave in development and deployment. Feedback is open for six weeks; Microsoft says it will publish a summary of what it learned and a revised version later this year.
The document expands “Humanist AI / Humanist Superintelligence”: advanced capability that stays subordinate, aligned, and contained.
AIImpish