metir
metir
Docs
Download on App StoreGet it on Google PlayLoginSign Up
Back to Blog
Microsoft
AI Governance
AI Safety
Regulation
MAI

Microsoft Publishes a Code of Conduct for Its Own AI Models

Microsoft opened a six-week public comment window on rules for its first-party MAI models, barring cyberattacks, nuclear weapons help, and deepfakes. How a hyperscaler's self-governance compares to the labs' frontier frameworks.

Metir AI TeamSeptember 15, 20266 min read
Microsoft Publishes a Code of Conduct for Its Own AI Models

On September 14, 2026, Microsoft published a Code of Conduct for its in-house MAI models and opened a six-week public comment window on it. The document bars Microsoft's first-party models from three uses: running cyberattacks, aiding the development of nuclear weapons, and generating deepfakes. It arrived one day after chairman and chief executive Satya Nadella wrote on X that Microsoft welcomes the "deliberate pacing" of AI development, a phrase that placed the company inside a live industry debate about how fast the frontier should move.

The specifics matter less than the shape of the move. A hyperscaler is now writing published, consultable rules for the behavior of its own models, in the same governance vocabulary the frontier labs have used for two years. That tells you something about where AI oversight is settling while formal regulation remains unfinished.

What the Code of Conduct actually says

The published document is narrow and concrete. It defines a small set of prohibited outcomes rather than a broad statement of values.

3Prohibited use categories
6 weeksPublic comment window
MAIMicrosoft's first-party model family

The three prohibitions, cyber-offense, nuclear-weapons assistance, and deepfake generation, map closely to the "catastrophic and clearly-wrong" end of the risk spectrum. That is a deliberate choice. Bright-line bans on a few extreme categories are easier to state, easier to test, and harder to argue against than open-ended commitments about fairness or societal benefit. The tradeoff is coverage: a short list of banned outcomes says little about the larger gray zone of everyday misuse.

What the MAI Code of Conduct covers

Three bright-line prohibitions, published for a six-week public comment window.

Prohibited
Cyberattacks

Models must not be used to run offensive cyber operations.

Prohibited
Nuclear weapons

No assistance with the development of nuclear weapons.

Prohibited
Deepfakes

No generation of deceptive synthetic media of real people.

Not addressed by the three bans

The wider gray zone of everyday misuse sits outside this short list. Bright-line bans trade broad coverage for clarity and testability.

Source: Microsoft MAI Code of Conduct, published September 14, 2026. Categories summarized from the announced document.

The more unusual feature is the public comment window. Frontier safety documents are typically written and revised inside the companies that publish them. Opening a six-week consultation invites outside researchers, civil-society groups, and other companies to critique the rules before they harden, which is closer to how regulators draft guidance than to how a private policy is usually shipped.

The "deliberate pacing" backdrop

Nadella's post did not appear in a vacuum. It responded to an essay by Anthropic chief executive Dario Amodei arguing that the rate of capability improvement should be slowed so that risk-prevention work has time to keep up. Nadella wrote that any pursuit of superintelligence "has to be grounded in the core principle that if the AI we build is not helping humanity and under human control, it's not worth pursuing," and welcomed ideas such as "embedded evaluators" and mechanisms to make safety commitments "more than just talk."

“

If the AI we build is not helping humanity and under human control, it's not worth pursuing.

Satya Nadella, Microsoft, September 2026
Microsoft chairman and chief executive Satya Nadella
Microsoft chairman and chief executive Satya Nadella. Official Microsoft executive portrait, 2017, by Brian Smale and Microsoft, via Wikimedia Commons, CC BY-SA 4.0.

The pairing of an essay, an executive endorsement, and a concrete artifact within about a week is itself informative. It shows the pacing debate moving from opinion pieces toward documents that make specific claims a company can be held to. Whether those documents change behavior depends entirely on enforcement, which no code of conduct can supply on its own.

How it compares to the labs' frameworks

Microsoft is not inventing self-governance. The frontier labs already run structured versions of it, and reading the Code of Conduct against them shows what is new and what is familiar.

Anthropic's Responsible Scaling Policy and OpenAI's Preparedness Framework both tie model release to capability thresholds: as a model gets more dangerous on defined evaluations, more safeguards are required before it ships. Those are process documents about when and how to deploy. Microsoft's Code of Conduct is closer to an acceptable-use standard for the deployed model: a list of things the model must not do, regardless of capability level.

The two approaches are complementary rather than competing. A threshold framework governs the release decision; a conduct standard governs the running product. What Microsoft adds to the mix is the hyperscaler vantage point. Because it distributes models to a vast enterprise base through Azure and its own products, a Microsoft conduct rule can propagate to far more downstream deployments than a single lab's internal policy, which raises the stakes on getting the wording right.

The open question is enforcement

Every self-governance document faces the same test, and honesty requires stating it plainly: a published rule is a claim, not a control. A ban on generating deepfakes is only as strong as the classifier, the refusal training, and the monitoring that sit behind it, and none of those are visible in the document itself. The public comment window can improve the rules, but it cannot verify the mechanisms.

That is where the value and the limits of voluntary governance meet. Voluntary codes move faster than legislation, can be updated as models change, and let a company signal intent before regulators arrive. They also lack an external body that can audit compliance or impose a penalty for breaking the rule. The six-week consultation is a partial answer, because outside scrutiny is the closest thing a voluntary regime has to an audit, but it stops at the point where the company decides what to keep.

For organizations relying on these models, the practical takeaway is to read the conduct rules of every provider they use, not just one, because the terms are starting to diverge. As governance fragments across labs and hyperscalers, keeping tooling and data portable across providers makes it easier to compare policies on their merits and to move if a provider's terms stop fitting a use case. Microsoft's document is a useful addition to that comparison set. It is specific, it is public, and it invites criticism. The next thing to watch is not the wording but the evidence that the rules bind the model in practice.

Sources:

  • Microsoft floats rules for its own AI models as industry debates a slowdown | GeekWire
  • Nadella Announces Public Consultation on Microsoft's MAI Model Rules | Unite.AI
  • Satya Nadella says superintelligence must remain human-controlled | Dataconomy
  • Anthropic's Responsible Scaling Policy | Anthropic
  • Preparedness Framework | OpenAI

Image credits

Satya Nadella, by Brian Smale and Microsoft, via Wikimedia Commons, licensed under CC BY-SA 4.0.

Ready to experience AI that adapts to you?

metir brings together the world's best AI models in one seamless experience. Start for free today.

Get Started Free
metir

Agentic Operating System for Professionals buried in meetings, emails and docs.

© 2026 metir. All rights reserved.

Product

  • Features
  • Pricing
  • Research
  • Docs
  • Blog
  • Enterprise

Company

  • Docs
  • Support
  • Careers

Legal

  • Terms of Service
  • Privacy Policy

Personalisation is powerful. Privacy is non-negotiable.

Status: All systems operational