Microsoft AI (MAI) has published the first draft of its Humanist AI Code of Conduct and opened a six-week public consultation, placing human supervision and enforceable restrictions at the center of how future MAI systems should operate.
The draft establishes that models should behave more like tools than autonomous actors, remaining under human direction, review, and the ability to stop actions. It introduces Absolute Constraints that cannot be violated regardless of user or operator intent. These constraints cover weapons and mass harm, offensive cyber operations, loss of human control, large-scale malicious manipulation, and child safety.
The framework defines a three-level Chain of Command: the Code of Conduct takes top priority, followed by operator policies, and finally user preferences. Absolute Constraints and human control requirements take precedence across all levels. Microsoft said the current draft is not used in model training today, but a revised version planned for later this year could help guide MAI development from 2027 onward.
Microsoft’s release comes amid rising AI spending. Gartner forecasts that spending on AI models and platforms will reach $64.3 billion in 2026, up 63.4% from 2025, while generative AI model spending is expected to grow 117%. Gartner also projects AI governance spending will reach $492 million in 2026 and surpass $1 billion by 2030. The company is emphasizing predictability, reliability, and restraint as commercially attractive features for enterprise buyers.
The code enters an already fragmented global governance landscape. The European Union finalized its General-Purpose AI Code of Practice in July 2025 to support compliance with the AI Act, with participation from Microsoft, OpenAI, Anthropic, and Google. The Global Index on Responsible AI for 2026 reports an average score of around 35 across 135 countries, with evidence of implementation in 55% of cases. Microsoft is asking for public input on defining “human flourishing,” identifying vague language, and maintaining safety restrictions as capabilities evolve. The company plans to analyze feedback after six weeks, publish a summary of lessons and changes, and release an updated version later this year, though it does not guarantee every recommendation will be adopted.