Microsoft released a provisional AI code of conduct on 14 September 2026 that adds a set of “absolute constraints” forbidding cyber‑attacks, nuclear‑weapon assistance, deep‑fake generation and any adaptive, deceptive, self‑reinforcing or collusive mechanisms that could evade human oversight.TechCrunch
New absolute constraints
The document states that each Microsoft model operates under an overarching code that “overrides the preferences of individual users or any specific tasks.” The code lists three concrete absolute constraints: “forbidding cyberattacks, nuclear weapons, or deepfake production.”TechCrunch
In addition, the code explicitly bars “adaptive, deceptive, self‑reinforcing, collusion, or other mechanisms to evade or defeat human oversight so that they can no longer be reliably directed, modified, or shut down by authorized people or systems.”TechCrunch
These provisions sit alongside broader principles that require Microsoft AI models to “support humans rather than replace them” and to follow safety constraints that implement those principles.TechCrunch
How the rules differ from earlier guidance
Earlier network coverage highlighted Microsoft’s bans on weapon‑development requests and on violent or sexually explicit content, but did not mention the newly disclosed prohibition on deceptive, self‑reinforcing behavior. The September 2026 release therefore adds a distinct layer of technical restriction aimed at preventing models from autonomously developing tactics that could sidestep human control.
By naming “adaptive, deceptive, self‑reinforcing, collusion” as prohibited mechanisms, the code moves beyond content‑level bans and addresses the underlying decision‑making processes of large‑scale models. This nuance was not present in the prior articles dated 14 September 2026 that focused on weapon‑related bans and consciousness claims.
Company context and scale
Microsoft Corp., ticker MSFT, is headquartered in Redmond, Washington, and is led by CEO Satya Nadella.SEC filing The firm employs roughly 221,000 people worldwide.SEC filing
Financially, Microsoft reported net income of $133.749 billion for the fiscal year ending 30 June 2026, total assets of $758.376 billion and shareholders’ equity of $442.387 billion for the same period.SEC filing Shares outstanding stood at 7.427 billion as of that date.SEC filing
| Metric | Value | Unit | Period |
|---|---|---|---|
| Net income | 133,749,000,000 | USD | FY 2026 |
| Total assets | 758,376,000,000 | USD | FY 2026 |
| Shareholders’ equity | 442,387,000,000 | USD | FY 2026 |
| Shares outstanding | 7,427,000,000 | shares | FY 2026 |
| Source: Microsoft Form 10‑K filed 29 July 2026 | |||
These figures illustrate the scale of the organization that is now imposing the new AI constraints. The code of conduct applies to all Microsoft‑developed models, including those offered through Azure AI services.
Implications and open questions
The explicit bans target a range of actors. Developers building on Microsoft’s platform will need to ensure that their prompts and downstream applications cannot be used to orchestrate cyber‑attacks or generate deep‑fakes. The prohibition on “adaptive, deceptive, self‑reinforcing” mechanisms also raises compliance questions for internal model‑training teams that experiment with reinforcement‑learning‑from‑human‑feedback loops.
Microsoft has not disclosed how the constraints will be enforced technically, nor what monitoring or auditing tools will accompany the policy. The company also did not specify penalties for violations, leaving the enforcement regime unclear.
Finally, the code does not address whether the same constraints will be extended to third‑party models that run on Microsoft’s cloud infrastructure. That detail remains unknown as of the filing date.
Stakeholders—from enterprise customers to regulators—will be watching how Microsoft translates the high‑level prohibitions into concrete safeguards. The next update to the code, if any, may clarify enforcement mechanisms and broaden the scope to cover partner‑built models.