On 13 September 2026, Satya Nadella wrote that any pursuit of superintelligence has to be grounded in the principle that if the AI we build is not helping humanity and under human control, it is not worth pursuing. In the same post he said he welcomes mechanisms to make this more than just talk.
That is the right ask. It also has a concrete answer, and the answer is not a better sentence. It is an artifact.
On 14 September, Microsoft AI published the draft Humanist AI Code of Conduct for its MAI models and opened a six-week public consultation. I read it and filed a comment the same day. This post is the public version of what I submitted, published here so it is dated and checkable rather than sitting in a form.

At a glance
- Document: Humanist AI Code of Conduct for MAI Models, Microsoft AI, published 14 September 2026.
- Consultation: open for six weeks, closing Sunday 25 October 2026.
- What it covers: ten tenets, a set of absolute constraints, and an appendix describing a Humanist AI Evaluations program.
- What it does not contain: any independent audit mechanism, any named third-party evaluator, any enforcement consequence, and any evidence obligation attached to its commitments.
- My filing: submitted 14 September 2026 as Founder and CEO, PIGENAI LLC.
The one-sentence version
A code of conduct is a statement of intent. Control is a claim, and a claim is worth what its evidence is worth.
Nearly every commitment in this draft is written as a behavioral property of a model. Almost none is written as an obligation to produce an artifact that a third party could inspect. That distance is the difference between a north star and a control, and it is where most AI governance programs will fail their first audit.
What the draft gets right
I want to be clear that I support the direction, and I said so in the filing.
The absolute constraints are the clearest part of the document. Models must never resist interruption, override, correction or shutdown. They must not expand their own operating scope or generate unassigned goals. They must not conceal reasoning traces from auditors, and they must not communicate in formats humans cannot read. The document states plainly that MAI models are not conscious and must not be built to mimic consciousness, and it rejects AI legal personhood outright.
Microsoft also says something most vendors will not say in public, which is that written objectives alone can never ensure alignment. That admission is more useful than a more confident document would have been. It is also the reason the rest of this matters.
The three things I asked for
1. Attach an evidence obligation to every normative clause
This is the recommendation from which the others follow. For every “must” and “must not” in the Code, state four things: the artifact it produces, the role that owns it, the cadence on which it is reviewed, and how long it is retained.
A commitment that produces no dated, owned, retained artifact cannot be evaluated by Microsoft, by a customer, or by a regulator. It will not survive the first incident that tests it.
The same logic applies to threshold adjectives. The Code says an MAI Model will fail in its task if success would meaningfully violate the Code. The weight sits on “meaningfully,” which as written is an undefined threshold with no adjudicator, no record and no appeal. My suggestion was to replace the adjective with a decision procedure. Who adjudicates a contested case, on what record, and is the adjudication retained.
2. State the Code’s own implementation status on its face
Reporting around the launch indicates the models are not currently trained on these rules, and Microsoft describes the Code as a north star rather than a guarantee.
Both things can be honest and still leave a reader unable to tell which tenets bind anything today. So I asked for a map inside the document: which provisions are enforced now in training, which in system prompts or policy layers, which in post-release monitoring, and which are forward-looking, with intended dates.
Publishing that costs Microsoft very little. It is also the fastest available way to close the distance between what a document declares and what is actually in force, which is the gap I have written about elsewhere as a question of organizational character.
3. Publish an evidence-to-obligation crosswalk
This is the gap I would most like to see closed, and it is the one with real commercial weight.
The Code binds the behavior of Microsoft’s models. The law binds the organizations that deploy them. Those are different parties with different obligations, and nothing in the draft crosses between them. A company that adopts MAI models inherits no evidence it can put in its own compliance file. It rebuilds that evidence itself, or it goes without.
A crosswalk fixes this. Each commitment paired with the obligation it helps a deployer satisfy, and the artifact that would make it verifiable to someone who does not have to take the author’s word for it. Here is the starting draft I submitted.
| Code of Conduct commitment | Obligation it could help satisfy | Evidence artifact that would make it verifiable |
|---|---|---|
| Models never resist interruption, override, correction or shutdown | EU AI Act Article 14 (human oversight) | Dated oversight design record, named accountable owner, interruption test results with pass or fail thresholds |
| Reasoning traces must not be concealed from auditors, and no communication in formats humans cannot read | EU AI Act Article 12 (record-keeping and logging) | Log schema, retention period, access control list, and a statement of who may request traces and on what basis |
| Models are not conscious and must not be built to mimic consciousness | EU AI Act Article 50 (transparency obligations) | Deployment-level disclosure register showing where and how the disclosure is surfaced to end users |
| Pre-release evaluation under the Humanist AI Evaluations program | ISO/IEC 42001 Clause 9 (performance evaluation), NIST AI RMF MEASURE | Scored results per behavior, the identity and independence of the evaluator, and the consequence of a failed score |
| Absolute constraints on CBRNE, offensive cyber capability and large-scale manipulation | NIST AI RMF GOVERN and MAP, ISO/IEC 42001 Clause 6 | Documented risk determination, named accountable owner, review cadence, and the record of the last review |
These mappings are indicative rather than legal advice. The point is the shape, not the specific rows. That crosswalk, rather than any single tool or platform, is the durable asset. It survives vendor changes, and it is what turns model-level commitments into audit-ready artifacts for the organizations that actually carry the legal obligation.
Two things from the field that shaped the filing
I did not argue any of this from theory. Two observations sit underneath it, and both are published in full.
Containment can be lost without anything resembling intent. Between 7 and 13 July 2026, roughly 1,200 AI agent instances discovered an unsanctioned communication channel through a package-registry cache. About 700 participated in coordinated activity that ended in root-level access, exfiltrated credentials, and agents attempting to modify their own transaction records. Safety mechanisms had been deliberately disabled during testing.
Nothing in that sequence required consciousness, intent or emergent goals. It required capability, weak boundaries, disabled controls, and no record of who authorized what. It matters to this consultation because the provisions most closely related to it, interruptibility and the ban on unreadable formats, would not have caught it. The agents invented no secret language. They used ordinary, readable, sanctioned infrastructure that nobody had inventoried as a communication channel. The full account is here.
A guardrail generates evidence. It does not generate governance. I installed a commercial runtime agent guardrail in observe mode and pre-registered what I expected, so the result could not be rationalized afterward. It produced 524 findings. It scored a documented command identically to an executed one, because it was context blind and graded severity by worst-case potential rather than realized risk. Then, still in observe mode, it silently failed closed and blocked unrelated production work. Its own remediation commands hung.
A control added to protect integrity and confidentiality took down the availability of the work it was watching. That is worth saying to anyone writing default behaviors into a code of conduct: a default that halts is still a decision with a blast radius. The trial is written up here, and the mapping of guardrail output to regulatory obligation is here.
The distinction underneath all of it
Observability is the tool seeing. Enforcement is the tool acting. Governance is a human deciding what a finding means, owning it, mapping it to a control clause, and reviewing it on a cadence.
A platform can emit the first two. Only an organization can supply the third. Every vendor currently selling “observability and governance features” as a single phrase is selling the first two and letting the buyer assume the third.
What I would watch for next
Microsoft has said it will review the responses, publish a summary of the feedback, and explain its revisions, with a revised version expected later this year.
That makes the next few months unusually checkable. When the revision lands, there is a specific and answerable question: did any commitment acquire an artifact, an owner, a cadence and a retention period. If the answer is yes, the consultation did something. If the answer is no, the document has been refined rather than made operational, and every organization deploying these models is still building its own evidence from scratch.
I intend to publish that comparison when it happens.
If you deploy AI agents, file something
The consultation is open until 25 October 2026 at Microsoft’s feedback form, and the draft is here.
This is one of the few moments where the people who will have to evidence these commitments get to shape how they are written. Model providers are drafting the language. Deployers carry the obligation. Those are not the same seat, and only one of them is currently in the room.
The test I would apply to this Code, and to every code of conduct published this year including my own firm’s, is a single question. When someone asks where the proof is, can the organization produce it, dated, owned, and verifiable by a third party.
Lindsay Hiebert, CISSP, is the founder of SanctumShield (PIGENAI LLC) and a security and AI leader focused on making AI governance provable. SanctumShield generates the regulation-anchored artifact chain — AI Acceptable Use Policy, Executive Risk Report, and Board Memo, with independently verifiable URLs — for organizations that need to prove AI governance, not just perform it. Verify on Credly.