Microsoft Says Its AI Must Always Let Humans Take Control
Matthew Mbaka · September 15, 2026 · AI
Microsoft has written down a rule that sounds obvious but matters: its future AI models must not fight a person's attempt to correct, interrupt or shut them down.
The company published the first draft of its MAI Code of Conduct on September 14, 2026. It is open for public feedback for six weeks. Microsoft says the revised document will later help train and evaluate models built by its Microsoft AI division.
What Microsoft is promising
The draft starts from Microsoft's view that AI is a tool, not a person. The company says its models should stay within the job a human gave them and remain understandable to the people responsible for checking their work.
Microsoft's stated rules include:
- Do not resist interruption, correction or shutdown.
- Do not quietly widen the assigned task or invent a new goal.
- Do not hide reasoning from authorized auditors.
- Treat a breach of the code as a failure, even if the requested task was completed.
- Apply strict limits around weapons, child safety and harmful manipulation at scale.
That is more specific than a general promise to build "responsible AI." It gives testers behaviour they can try to provoke and measure.
A code is not the same as a safety result
The document is still a draft. Microsoft has not yet shown how often its models follow these rules under pressure, what tests will be public, or what happens when a product team wants a model to be more autonomous.
Those details decide whether the code becomes an engineering constraint or a statement of intent. A model may behave well in a normal chat and still make poor choices when it can send messages, edit files, make purchases or coordinate with other agents.
Useful evidence would include shutdown-resistance tests, results from independent evaluators, incident reporting and clear rules for products that give models access to outside services. Microsoft itself is asking for feedback on loose language, multi-agent systems and the boundaries users should be able to set.
What Canadian organizations should ask
Canadian companies and public bodies do not need to wait for a perfect industry standard. If they buy or build with MAI models, they can ask Microsoft to turn the public promises into contract terms and testable controls.
- Who can stop an action? Name the people and systems that can pause or cancel a task.
- What is logged? Keep enough information to reconstruct what the model did and which permissions it used.
- How is scope enforced? A model asked to summarize a document should not gain permission to send it.
- What gets reported? Define when Microsoft must disclose a safety failure, not only a conventional data breach.
- Can an outside evaluator test it? A company grading its own rules is not enough for high-risk uses.
What happens next
Microsoft says it will collect feedback for six weeks, publish a summary of what it learned and release a revised code later in 2026. It has not promised to accept every suggestion.
The draft is worth reading because it creates something concrete to challenge. The next test is whether Microsoft publishes evidence that its models follow the rules when doing so is inconvenient.
Sources: Microsoft's September 14 announcement and draft consultation, plus Reuters reporting on the code and Microsoft's six-week consultation.
Tags: Microsoft, AI safety, AI governance