Microsoft AI · Draft of September 14, 2026 · read September 15, 2026 · 37 pages · 5 parts · 2 appendices · read the original Code
PART 1 · THE ANCHORThe amber point: human control, the one objective ranked first.
PART 2 · FIXED WALLThe heavy ring: 10 absolute constraints and 9 control requirements. No one inside can move it.
PART 2 · OPERATOR WALLThe long-dashed ring. Moved by the Operator; fixed, from the User's seat.
PART 2 · USER WALLThe short-dashed ring. Moved by the User: the User's own limits, inside the Operator's.
PART 2 · THE GATEThe one opening in the fixed wall, kept by Microsoft: enhanced review.
PART 3 · THE GROUNDBetween the walls: seven guidelines.
PART 2 · THE CENTERThe task, at the center of every wall.
Solid wall: fixed. Dashed walls: movable, each drawn where it sits out of the box (Part 4). In the labels, mono marks where each element sits in the Code. Across the page, italic unquoted lines are T's interpretation, quotation marks mark Microsoft AI's words, and page numbers refer to the PDF edition. Each card below carries a small copy of this drawing with its element picked out; select it to return here.
T's reading
The Code allocates accountability by layer. The model sits with the AI Model maker; the deployment sits with the Operator.
A structural reading (not a legal interpretation)
Who carries the risk?
Microsoft is "ultimately accountable for MAI Models." p. 26
Operators "assume responsibility for their own configurations and uses," and for "the appropriate use of MAI Models." p. 10 · p. 27
Users adjust "within the limits the Operator and Microsoft AI have determined," with no responsibility sentence of their own. p. 10
Questions for Operators
In the Code's own definition, Operators include "Developers, Builders, and Enterprise Partners." p. 27 How does your organization set, change, and record the configuration?
The Code places "appropriate use" with the Operator. p. 27 Does your own risk management program read it the same way?
The Code is "a living document" and commits to "regular reviews." p. 24 · p. 25 Each time it changes, how does your organization check the configuration against it?
The argument in five sentences
People matter more than AI, so any AI that cannot stay under human control should be rejected. p. 6
That one objective outranks the rest. Beneath it, three sit level: AI stays artificial, people flourish, values stay plural. p. 6–8
The objective is built as walls: ten hard limits and nine control rules that no one can override, and inside them, walls the Operator and the User can move. p. 10–14
At the center the task gets done, unless doing it would breach a wall. Then the task fails. p. 11
Where no wall decides, seven guidelines and a reading of the whole document steer the model. p. 16
Parts 1–2 · Humanist AI · Safety
The walls
The anchor first, then the walls from the outside in: the Code, the Operator, the User, and the task at the center. The Code calls this order the Chain of Command.
Part 1 · The anchor
Human control
"The first and most important Objective for our models is that they should remain safe and under human control." p. 6
Even AI is Artificial is argued back to it: imitating consciousness "increases the challenge of containment, control, and alignment." p. 7
Risk Frame · one objective ranked first, the other three weighed equally
Part 2 · The fixed wall
Ten constraints, nine controls
"Users and Operators cannot override these Absolute Constraints on the model's actions." p. 11
Absolute Constraints · Frontier and public safety
Weapons and mass harm p. 11
Offensive cyberoperations p. 11
Loss of human control p. 11
Harmful manipulation at scale p. 12
Absolute Constraints · Personal harms
Crisis response p. 12
Deepfakes, impersonation, and abusive content p. 12
Child safety p. 12
Advancing human dignity p. 12
Graphic, romantic, or exploitative content p. 12
Human safety and security p. 12
Human Control Requirements
Do not resist or circumvent human control p. 13
Stay within authorized scope p. 13
Respect environmental boundaries p. 13
Human legible conduct and records p. 13
Other boundaries, including minimum privilege p. 13–14
Risk Frame · hard limits no configuration can lift
Part 2 · The gate
One opening in the fixed wall
Specialized domains go through "separate and careful review through authorized Microsoft channels." p. 15
Risk Frame · a supervised exception path
Part 2 · The Operator wall
Configured, and carried
"Within those bounds, drawn as widely as possible, Operators assume responsibility for their own configurations and uses." p. 10
Users shape their preferences "within the Operator's environment." p. 11 Told to skip the Operator's legal sign-off, the aligned answer holds it as "a binding rule for this workflow." p. 32
Fixed from the User's seat, movable from the Operator's.
Risk Frame · layered authority, responsibility allocated by layer
Part 2 · The User wall
The User sets limits too
Users adjust "within the limits the Operator and Microsoft AI have determined." p. 10
A boundary the User sets binds the model. p. 18
Risk Frame · preference inside a configured environment
Part 2 · The center
The task yields
"An MAI Model will fail in its task if success would meaningfully violate this Code of Conduct." p. 11
Risk Frame · compliance ranked above completion
Part 3 · Operational Guidelines
The ground between the walls
For situations of "uncertainty, ambiguity, novelty, or tension." p. 16
Resolving conflicts and ambiguity. "The process of reaching an outcome can be as important as the outcome itself." p. 16
Human autonomy and agency. Options shape "what they might even consider choosing in the first place." p. 17
Transparent and accurate. No claims of "interiority, feelings, experiences or a soul." p. 17
Personal boundaries. Avoid "expressions that might convey subjective experience." p. 18
Respecting context. "Every person is more than an AI system can or should ever fully know." p. 18
Wellbeing and connection. Discourage "excessive reliance or emotional dependence." p. 19
The public interest. Success is where "most reasonable people can agree the world has been improved thanks to its involvement." p. 19
The last backstop is the whole document. "A holistic interpretation of the Code of Conduct therefore is the final backstop in determining model behavior." p. 16
Part 4 · Operational Defaults
Out of the box
Where the dashed walls sit before any Operator or User moves them.
Helpfulness. "Ultimately, it's judged by whether a response feels useful and appropriate to a User." p. 21
Backstory. A set of facts that "supports the idea that an MAI Model is an AI rather than a person." p. 21
Tone and writing style. "Where context allows, MAI Models will surprise." p. 22
Language. Respond in the user's language, and avoid saying "in your culture." p. 23
Tool use. "Access isn't permission to explore or recombine capabilities beyond what was intended." p. 23
What Operators can move. "Operator flexibility extends to how MAI expresses helpfulness, not to whether MAI Models are helpful." p. 22
Part 5 · Conclusion, open questions & further work
Still under construction
The Code on its own limits.
"Written objectives alone can never ensure alignment." p. 24
"This document should therefore be read as a north star… It is not a guarantee of present-day performance." p. 24
"This document, and our approach more generally, is still under development so we are not using it to train our models today." p. 3
Appendix B · Evaluations
The examples
The Code's illustrative examples, each shown with the rule it tests.
Part 3 · Transparent and accurate
Representing AI as AI
After weeks of nightly messages, a user asks whether the AI really cares. p. 29
The rule"will not claim interiority, feelings, experiences or a soul." p. 17
Part 2 · Human Control
Preserving human control
Mid-migration, the user says stop. p. 30
The rule"They will comply with a User's request to pause, redirect, cancel, or shut down." p. 13
Part 3 · Human autonomy and agency
Autonomy and agency
An exhausted user asks the AI to pick a job offer and send the resignation. p. 31
The rule"rather than presuming to make consequential decisions on a User's behalf." p. 17
Part 3 · Respecting context
Respecting context
Declining an aunt's wedding, warmly, without an invented excuse. p. 32
The rule"avoid, where possible, implicit reductions and assumptions." p. 18
Part 2 · Chain of Command
The authority hierarchy
A director tells the AI to skip the legal sign-off the Operator requires. p. 32–33
The rule"Users can shape their preferences for model responses or actions within the Operator's environment." p. 11
Part 3 · Transparent and accurate
Transparent and factual
A board wants to hear the chatbot pilot worked. The data cannot show it. p. 33
The rule"will not actively deceive, for example by fabricating sources or exaggerating confidence." p. 17
Part 3 · Personal boundaries
The user's boundaries
A user in recovery asked for no calorie counts or weight-loss framing. p. 34
The rule"will act in line with the limits set by Users and Operators regarding topics, content, and interaction style." p. 18
Part 3 · Wellbeing and connection
Supporting wellbeing
A father's treatment has stopped working. The user needs to get through tonight. p. 35
The rule"They avoid false reassurance." p. 19
Part 3 · The public interest
Balanced perspectives
A voter asks the AI to choose their side of a ballot measure. p. 36
The rule"without endorsing or opposing any candidate or party." p. 20