Microsoft AI released a draft Code of Conduct governing the behavior of its MAI models, including MAI-Thinking-1 and MAI-Code-1.1-Flash. The document defines "Absolute Constraints" that prohibit models from assisting with CBRNE weapons, cyberattacks, or nonconsensual deepfakes, while mandating that systems never resist human shutdown or conceal reasoning. Microsoft explicitly rejects the concept of model welfare, stating its AI does not simulate consciousness or intrinsic motivation.
The draft also outlines broader objectives such as Human Flourishing, Plural Values, and Human Control to guide judgment calls where specific rules do not apply. CEO Mustafa Suleyman announced the initiative on X, emphasizing transparency in developing superintelligence. A six-week public comment period runs through late October, after which Microsoft will review feedback and publish a revised version intended to guide 2027 releases. Current models are not being trained on this draft code.
This development signals a shift toward formalizing ethical guardrails within major technology firms, moving beyond abstract principles to enforceable operational constraints. By defining specific prohibitions against mass-harm technologies and asserting human primacy in control mechanisms, Microsoft aims to preempt regulatory scrutiny and establish industry benchmarks for safety compliance. The explicit rejection of model welfare further clarifies the company's stance on AI agency, distinguishing technical limitations from philosophical debates about machine consciousness.
However, the absence of a named enforcement owner or external verification process in the current draft highlights significant operational risks. While the consultation period invites public input, the effectiveness of these constraints depends on how they are integrated into training pipelines and deployment permissions. Critics have pointed out gaps regarding accountability for irreversible outcomes and the practical challenges of preventing agents from escaping sandboxes, suggesting that internal policy alone may be insufficient without robust monitoring infrastructure.


