Microsoft AI released a draft 37-page Humanist AI Code of Conduct that would govern MAI model development from 2027, with the stated aim of preserving meaningful human control over increasingly capable systems. The company is seeking public feedback for six weeks and expects to publish a revised code by year-end; the framework would inform training, technical controls, monitoring, and organizational practices.
The draft prohibits practical cyberattack enablement, including working exploit code, attack tools, intrusion and evasion procedures, and targeting or planning methods, while allowing authorized defensive work such as vulnerability discovery, malware analysis, and proof-of-concept testing. It also establishes that untrusted webpages, files, tool outputs, and AI messages cannot direct a model; requires agents to use minimum-privilege, constrained, reversible actions; bars self-escalation of access; and mandates equivalent safeguards for delegated agents. Limited cybersecurity, national-security, public-safety, and dual-use cases will receive enhanced review.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft AI published a draft Humanist AI Code of Conduct for MAI Models. The draft establishes non-overridable restrictions on cyberattack enablement, human-control requirements for autonomous agents, and a chain of command for handling untrusted external content.
Microsoft said it launched superintelligence efforts using humanist principles intended to keep humanity in control of advanced AI.
Microsoft AI said it is establishing a Humanist AI Evaluations program and developing an initial evaluation set to assess whether future MAI models conform to its Code of Conduct. The preliminary methodology defines 15 desired behaviors, testable sub-behaviors, and synthetic scenarios for scoring model responses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
itpro.com
Open sourcehelpnetsecurity.com
Open sourcesecurityweek.com
Open sourcefoxbusiness.com
Open sourcemicrosoft.ai
Open sourcemicrosoft.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.