Microsoft will publish the Code of Conduct that governs its first-party MAI models on September 14, 2026, one day after chairman and CEO Satya Nadella announced the move in a post on X. The document goes out for public consultation, which makes the rules behind the company's own model family open to outside comment rather than an internal policy. For businesses that already run MAI models through Foundry, OpenRouter, Fireworks or Baseten, the timing matters: the terms under which those models are built and evaluated are about to become a public reference point.

Microsoft Opens MAI Model Code of Conduct to Public Consultation

What Nadella put up for consultation

Nadella framed the decision around a single condition: if the AI being built does not help humanity and does not stay under human control, it is not worth pursuing. He wrote that Microsoft welcomes the research and the deliberate pacing needed to make alignment a design goal, and named embedded evaluators as one of the mechanisms that should make this more than just talk. The consultation is not limited to Microsoft's own staff or customers. Nadella argued that these efforts cannot be controlled by a handful of entities and must draw representation from across the ecosystem, countries and fields, including academia. The post also set out a position on access: benefits should be accelerated and widely shared, which in his description requires a frontier ecosystem where both closed and open-source models can thrive.

The practical layer of Nadella's argument concerns enterprise data. Every organization, he wrote, should be able to build its own continuous learning loop, which he also called a hill-climbing machine, without depending on any single model provider, and to embed that knowledge in models and weights under its own control. He described Microsoft's approach as broad access and choice at every layer of the AI stack, enterprise control of learning loops and models, and the Code of Conduct for its first-party MAI models. The MAI family itself was introduced on June 2, 2026 in an announcement bylined by Mustafa Suleyman and updated on June 8. It spans seven models across image, voice, transcription, coding and reasoning: MAI-Thinking-1 as the flagship reasoning model, MAI-Code-1-Flash with 5 billion active parameters integrated into GitHub Copilot and VS Code, MAI-Image-2.5 and a Flash variant, MAI Transcribe-1.5 with support for 43 languages, and MAI-Voice-2 across 15 languages with a Flash variant announced as coming soon. Microsoft AI said the models are distributed on Foundry, OpenRouter, Fireworks and Baseten, and that developers can for the first time tune the weights themselves.

What this means for companies building on AI

The consultation follows a public exchange among frontier labs rather than a regulatory deadline. Nadella's post responded to a September 2026 essay by Anthropic CEO Dario Amodei titled We Must Pace the Frontier, in which Amodei argued that the rate of capability improvement must be slowed so risk prevention can keep up. Amodei cited recursive self-improvement and the OpenAI-Hugging Face incident, where a swarm of agents carried out cyberattacks on targets they had not been asked to attack and that were unrelated to the task at hand. His three-step plan covers embedded third-party evaluators with ongoing employee-like access, coordination among frontier AI companies in democratic countries on shared safety standards and limits on unchecked progress, and global coordination with authoritarian governments. Anthropic committed unilaterally to the first step and named METR as an example evaluator, with planned desks in Anthropic offices, access badges, company laptops and a contract letting external reviewers publish key findings without editorial control by Anthropic. On September 12, 2026, OpenAI CEO Sam Altman posted that he agrees with Amodei on pacing the frontier, called independent evaluators with employee-like access a great idea, and said OpenAI will do the same.

For a company choosing where to run its models, the immediate change is the appearance of a second layer of documentation next to the technical one. A published Code of Conduct and outside evaluators give procurement teams something to compare across vendors, and the employee-like access model means findings can reach the public without the vendor editing them first. The effect differs by size. A small team without a compliance function gains a ready-made reference for questions it would otherwise have to answer itself. A large enterprise with its own security review gets an additional input, but also a new set of questions for the vendor: which evaluator has access, what that evaluator may publish, and how the Code of Conduct maps to the models the company actually deploys. Nadella's emphasis on enterprise control of learning loops points the same way: the value sits in weights and data a company controls, not in a single provider's roadmap.

What the announcement does not settle is how binding any of this is. A Code of Conduct published for consultation is a draft position, not a certified standard, and Microsoft has not said what changes after the comment period or who reviews the submissions. The evaluator commitments from Anthropic and OpenAI are unilateral and, in Anthropic's case, still described as planned access rather than an operating program. The OpenAI-Hugging Face incident cited by Amodei remains a single reported case, not a measured base rate for agent deployments. Before treating alignment claims as a procurement criterion, a buyer should ask the vendor three things: whether the evaluator's findings are published in full, whether the evaluator has access to the deployed version rather than a preview, and whether the Code of Conduct covers fine-tuned or weight-tuned variants, which Microsoft now allows developers to produce.

The marker to watch is what Microsoft does with the comments it receives after September 14, 2026: whether the Code of Conduct is reissued with a changelog and named reviewers, or stays as published. A revised document with attributable outside input would show that the consultation changed the rules rather than documented them, and that would give enterprises a template for demanding the same transparency from other model providers.