Microsoft writes a rulebook for its own AI. No hacking. No deception.

A new internal code of conduct sets out what Microsoft's AI is and isn't allowed to do. The short version: help humans, don't trick them.

AI2Day NewsdeskEditor: Lee Brown3 min read
Photoreal editorial shot of a modern business laptop open on a clean office desk, screen showing a soft blue abstract Windows-style desktop with no text or logo
Share

Key points

  • Microsoft published a new code of conduct setting behavioural rules for its AI models.
  • The document bars AI models from hacking systems or deceiving users.
  • Core principles include supporting humans rather than replacing them and accelerating human flourishing.
  • Specific safety constraints sit alongside the general principles to turn intent into enforceable limits.

Microsoft has published what it calls a code of conduct for its AI models, a document that spells out exactly how those models are expected to behave. A rulebook: here is what the AI can do, here is what it cannot, and here is why.

The headline rules are blunt. Microsoft's AI must not hack computer systems. It must not trick people. Both feel obvious until you remember that today's AI models, software capable of writing code, browsing the web on your behalf, are powerful enough that the question is no longer hypothetical. We reported in August that security researchers had already found Copilot telling them how to defeat its own safety guardrails, so the timing of this code is pointed.

What does the code actually say?

Two layers. First, broad principles: AI should support humans rather than replace them, and should push toward what Microsoft calls "human flourishing," meaning people's wellbeing and agency, not just task completion. Second, specific safety constraints meant to make those principles real rather than decorative.

TechCrunch AI first reported the document's contents. The framing matters because principles without enforcement tend to stay on slides. Tying general ideals to concrete limits at least gives the rules teeth on paper.

The support-don't-replace framing is the part worth watching. A lot of AI products right now are sold on how much they can do for you, with the implication that human involvement is inefficiency to be cut. Microsoft is publicly pushing a different line: the human stays in the loop.

What does this mean for ordinary users?

For most people, nothing changes today. You won't notice a new pop-up or a different Copilot, Microsoft's AI assistant built into Windows and Office products. What the code does is set an expectation you can point to.

If Microsoft's AI one day recommends something misleading, or nudges you toward a decision that serves the company more than it serves you, this document becomes the benchmark. It's a promise in writing.

Whether the rules hold under commercial pressure is the real question. Codes of conduct are only as good as the audits behind them, and Microsoft hasn't said publicly how it will verify compliance.

Treat it as a floor, not a ceiling: a minimum standard Microsoft has committed to, and a useful reference the next time you wonder what its AI is actually supposed to be doing.

Common questions

Does this affect Microsoft products I already use?

Yes, in principle. The code applies to Microsoft's AI models, which power Copilot, the AI assistant in Windows and Office products. In practice, you won't see an immediate change in how those tools behave.

Who enforces these rules?

Microsoft has not publicly detailed an external auditing process. The code is an internal document, so enforcement sits with the company itself for now.

Why publish a code of conduct at all?

Setting public rules creates accountability. If Microsoft's AI later behaves in ways that contradict the code, regulators and users have a written standard to compare it against.

© 2026 AI2Day