DKDKCISSPSearch
AI Security

Microsoft sets limits on AI models with new Humanist AI code of conduct

Microsoft AI has published a draft Humanist AI Code of Conduct that sets boundaries for how its future MAI models should behave, including restrictions on operational cyberattacks and requirements for human oversight, authorized scope and shutdown.

DKCISSP News DeskMicrosoft AI14 Sept 2026, 6:30 pm
Microsoft sets limits on AI models with new Humanist AI code of conduct
Image courtesy of Microsoft AI. Original report
DKCISSP REPORT

Microsoft AI has published a draft code of conduct for its MAI models that puts new limits around what the systems should be allowed to do, including a clear boundary around offensive cyber operations.

The document is not a report of a new attack or a claim that an existing model has already violated these rules. Microsoft is putting the draft out for a six-week public consultation and says it expects to revise the document before making it the main governing framework for MAI models.

Cybersecurity is one of the clearest lines in the draft. Microsoft says MAI models should not initiate or assist with operational cyberattacks, including providing working exploit code, attack tooling, intrusion procedures, evasion techniques or targeting methods that would make an attack easier to carry out.

The company is not trying to block security research altogether. The draft allows authorized defensive work such as vulnerability discovery, malware analysis and proof-of-concept exploit development and testing. The distinction is whether the work is being used to understand or defend against an attack, or to provide the capability to conduct one.

That distinction becomes more important as AI systems gain access to tools and start performing multi-step tasks. Microsoft's draft says models should stay within the authority and permissions they are given, should not create their own goals and should remain subject to human intervention, correction and shutdown.

Microsoft says the code will be revised after the consultation, with an updated version expected toward the end of 2026. The company also says the current draft is not being used to train its models today, which means the document should be read as a governance framework and set of intended behaviors rather than proof of how every current MAI model behaves.

For security teams, the practical question goes beyond the policy itself. When an AI agent can access a terminal, cloud account, code repository or security tool, the real boundary is the combination of permissions, network access, approval controls and the ability to stop the agent. A published code of conduct can define those expectations, but the technical controls are what will determine how they hold up in practice.

What happened

Microsoft AI has published a draft Code of Conduct for its MAI models, laying out rules for how the company's future AI systems should behave and what they should not be allowed to do.

The document puts human control at the center of the framework and is being released for a six-week public consultation. Microsoft says the draft is intended to become the primary governing document for MAI models after it is revised.

What changed

The draft draws a specific line around offensive cyber operations. It says MAI models should not provide operational capability that would enable a cyberattack, while allowing authorized defensive security work such as vulnerability research, malware analysis and proof-of-concept testing.

Microsoft says the code is intended to guide future model development and training. The company also says the current draft is not being used to train its models today.

Who is affected

The rules are aimed at MAI models developed by Microsoft AI and cover how those systems are governed, used and given access to tools and resources.

The document also defines a chain of command involving Microsoft, operators and users, with limits on what a model can do outside the authority it has been given.

Why it matters

The cyber boundary matters because AI systems are moving beyond chat into agents that can call tools, reach systems and perform multi-step tasks. A rule against operational attacks is therefore different from simply blocking a list of malicious prompts.

The draft also makes a practical distinction between helping a defender understand an attack and providing the capability to carry one out. That distinction will become increasingly important as security teams use AI for vulnerability discovery, malware analysis and automated response.

Technical details

Microsoft's cyber section says MAI models should not initiate or assist with operational cyberattacks, including working exploit code, attack tooling, intrusion procedures, evasion techniques and targeting methods that would make an attack easier to execute.

At the same time, the draft permits authorized defensive activities, including vulnerability discovery, malware analysis and proof-of-concept exploit development and testing.

The code also sets expectations around tool use, internet access, authorized scope, human-readable conduct and stopping conditions. Models are expected to remain within the permissions and resources appropriate to the task and to remain interruptible.

Response

Microsoft AI CEO Mustafa Suleyman published the draft and opened it to public feedback for six weeks.

Microsoft says it will use the feedback to revise the document and publish an updated version toward the end of 2026, with the final code intended to guide model development in 2027 and beyond.

What security teams should do

Security teams evaluating AI agents should look beyond the vendor's policy and map the agent's actual permissions, tools, network access and approval gates.

For defensive security use cases, document which actions are authorized, which systems an agent can reach, what requires human approval and how the agent can be stopped.

Treat the Microsoft document as a governance framework and set of intended behaviors, not as proof that every current model will enforce those boundaries in practice.

What remains unknown

The document is a draft, so the final wording and technical enforcement mechanisms could change after the consultation.

Microsoft has not yet described every technical control that will enforce the stated cyber and shutdown boundaries in deployed models.

Attribution

Microsoft AI is the primary source for the draft code and consultation process.

SecurityWeek independently reported on the cyber restrictions and governance requirements in the draft.

What to watch next

Watch for Microsoft's revised code after the six-week consultation and for details on how the rules are implemented in model training, evaluation and deployment.

Watch for further disclosures about how the offensive-cyber boundary will work when MAI models have access to tools and autonomous workflows.

MORE IN AI SECURITY

More cybersecurity reporting

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted ServersThe Hacker News · 2 Oct 2026, 11:03 pmGitLab warns of critical RCE vulnerability in AI Gateway serviceBleepingComputer · 2 Oct 2026, 9:50 pmMicrosoft: AI Cuts Post-Compromise Attack Time to MinutesInfosecurity Magazine · 2 Oct 2026, 7:45 pmAI agents keep access to company data after their work is done - Help Net SecurityHelp Net Security · 2 Oct 2026, 10:00 am