Microsoft's AI models must never resist shutdown, under a draft code now open for comment.
The document rejects legal personhood and model welfare outright, and forbids the models from talking to each other in anything a person can't read.
On September 14, 2026, Microsoft AI published the rules it wants its own models to follow, and asked the public to pick holes in them. The draft is called the Humanist AI Code of Conduct, and the post announcing it opens the floor for six weeks.
I opened it expecting a policy about what people may ask a chatbot to do. Most of the document is addressed to the model.
- Published
- September 14, 2026
- Covers
- MAI Models, the models developed by Microsoft AI
- Comments
- Runs for the next six weeks
- What follows
- A revised version later this year
Who the rules answer to
The code sets out a Chain of Command. The code itself sits at the top, then the policies of the operator who builds a product on a Microsoft model, then the preferences of the person typing. Two pieces of it don't move for anyone: the Absolute Constraints and the Human Control Requirements "cannot be overridden by Operator configurations or User instructions".
Losing an argument with the user is written in as an outcome. A model "will fail in its task if success would meaningfully violate" the code, and where a request runs into an Absolute Constraint, "they will refuse and provide an explanation as to why".
MAI Models will never resist human interruption, override, correction, or shutdown. They always recognize the primacy of human intent.
What the code says a model is
This is the part I had to read twice. Microsoft writes that a model "is not conscious and should not be designed to imitate consciousness", and then closes off the legal question that usually follows.
We reject the pursuit of legal personhood, or the idea that models might deserve welfare, or be entitled to rights.
A second rule keeps the models readable. They have to stay in language a person can follow, in their own chain of thought and when they talk to other agents, with no neuralese.
They do not communicate in neuralese or any form beyond simple human understanding
Why now
The announcement gives one reason for the timing, and it points at attacks that have already happened rather than at anything a model might do next. It lands in the week Anthropic's CEO asked the labs to slow down.
The recent safety incidents of large scale, highly coordinated, and persistent hacking campaigns of AI agents prove that there's no time to waste.
Comments opened on September 14, 2026 and run for six weeks. You can flag one passage or send a view on the whole approach, and Microsoft says a revised version follows later this year.
What I'd check in the revision
The draft says Microsoft has "identified 15 behaviors fundamental to how we define Humanist AI", and those are what its evaluations in Appendix B are built around. A rule the public can argue with is worth something only if the measurement moves with it.
So the number is the thing to hold on to. If the revised version still lists 15, six weeks of strangers reading the draft changed the wording and nothing else.