Microsoft Publishes the First Draft of the Humanist AI Code of Conduct

Microsoft AI has made public the first draft of its Humanist AI Code of Conduct, a training manual outlining how it develops artificial intelligence models and how it intends for them to behave during deployment. The document is currently open for public consultation for six weeks, with the aim of gathering feedback before a final review scheduled for the end of the year.

Quick Response

The Humanist AI Code of Conduct is a framework that establishes principles and rules for the development and use of Microsoft's AI models. It includes non-negotiable restrictions to prevent serious harm and requires that models remain under human control. The document is currently in the public consultation phase.

A Framework for Humanistic Artificial Intelligence

The code is based on Microsoft AI's concept of "Humanist Superintelligence," an approach to advanced AI designed to meet human needs and subject to human control. The framework sets standards for the development, training, and evaluation of AI models.

Fundamental Principles of the Code

The code establishes that AI must remain a tool under human control, with models obliged to operate within defined limits and subject to human direction. The framework includes non-negotiable restrictions to prevent serious harm, such as assisting in the production of weapons, offensive cyber operations, large-scale harmful manipulation, and exploitation of minors.

Rules for Security and Human Control

The code establishes specific rules on what AI models can do and how operators and users can configure their behavior. Models must balance the risks of enabling harm against those of refusing legitimate requests, with responses proportional to the probability and severity of potential harm.

Hierarchy of Instructions and Restrictions

Microsoft AI has established a hierarchy of instructions in which the code of conduct takes precedence, followed by operator policies, and then user instructions. Operators and users can customize model behavior but cannot override the absolute constraints of the code or the requirements of human control.

Scope of Restrictions

The restrictions cover various areas, including chemical, biological, radiological, nuclear, and explosive weapons production or modification, offensive cyber operations, large-scale harmful manipulation, child sexual abuse material and exploitation, harmful deepfakes, illegal or mass surveillance of civilians, and assistance in violence, terrorism, or persecution.

Authorizations for Defensive Cybersecurity Activities

The code allows authorized and legal defensive cybersecurity activities, such as vulnerability discovery, malware analysis, and the development and testing of proof-of-concept exploits. AI models must respect attempts at interruption, correction, or shutdown, stay within their authorized scope, and not undertake autonomous goals.

Principle of Least Privilege

When models gain access to systems or tools, they must follow the principle of least privilege, using only the access necessary to complete an authorized task. Organizations will be able to configure AI models for different environments within the fundamental constraints of the code.

Assessments and Monitoring

Microsoft's AI models will undergo red teaming, security assessments, and pre- and post-deployment reviews. Guardrails and monitoring are designed to address abuses and adversarial attacks, ensuring that models operate safely and in compliance with the established guidelines.

Public Feedback and Review

Microsoft AI has consulted academics and business partners in the development of the draft and organized focus groups with the public to gather opinions and concerns about AI. Public feedback is now requested on both individual provisions and the overall framework.

The Impact on the Cyber Insurance Market

The introduction of the Humanist AI Code of Conduct could have significant repercussions on the cyber insurance market. Insurance companies are already closely monitoring the evolution of AI security frameworks, as restrictions on activities such as offensive cyber operations could reduce risk exposure for companies. According to recent analyses, the cost of cyber risk policies could drop by 15-20% over the next two years, thanks to the greater standardization of security protocols offered by AI models compliant with this code.

The Challenges for Cybersecurity Service Providers

Providers of incident response and breach remediation will need to quickly adapt their services to the new restrictions imposed by the code. For example, penetration testing and vulnerability assessment activities authorized by the code require more rigorous documentation and alignment with Microsoft guidelines. This could increase operating costs for service providers, directly impacting cyber insurance costs for client companies.

Adoption of the Framework in Regulated Sectors

Highly regulated sectors such as finance and healthcare will need to carefully evaluate how the code integrates with existing regulations, such as the NIS2 Directive and the DORA Regulation. Banks, in particular, will be interested in how the principle of least privilege can be applied to Data Loss Prevention and Security Information and Event Management systems to ensure compliance with regulations on digital operational resilience.

The Role of Managed SOCs and MDR Services

Managed Security Operations Centers and MDR service providers will need to recalibrate their processes to align with the new guidelines. The code indeed requires that AI models respect attempts at interruption or correction by human operators, which necessitates a review of incident monitoring and response procedures. This could accelerate the adoption of advanced zero trust architecture and identity access management solutions to ensure continuous human control.

Implications for Corporate Risk Management

For companies, the adoption of the code represents an opportunity to review their identity management and ransomware protection strategies. The restrictions imposed by the code could indeed reduce the attack surface available to attackers but also require greater attention to the configuration and monitoring of AI models. Companies will need to invest in ISO 27001 certification and security audits to ensure compliance with the new framework.

Future Prospects for the AI Market

If the draft code is definitively adopted, we could see a fragmentation of the AI market, with some providers choosing to align with Microsoft's guidelines and others developing alternative solutions. This could lead to greater competition and innovation in the sector but also to greater complexity for companies that will have to manage different security frameworks.

The Challenges for AI Model Developers

Developers of AI models will face new technical challenges to ensure that their products comply with the code of conduct. For example, managing hierarchical instructions requires advanced disaster recovery as a service and business continuity solutions to ensure that models can be interrupted or corrected safely. This could accelerate the development of advanced enterprise backup and cloud security posture solutions.

Impact on Academic Research

The code of conduct could also influence academic research in the field of AI. Research institutions will need to adapt their projects to ensure that the models developed comply with the new guidelines. This could lead to greater collaboration between the private sector and academia, with benefits for innovation and the development of new technologies.

Towards a Future of Humanistic AI

The Humanist AI Code of Conduct represents a significant step towards a future where AI is developed and used ethically and responsibly. While the draft is still in the consultation phase, the implications for the cyber insurance market, security service providers, and companies are already evident. With the expected adoption of the code starting in 2027, we can expect a radical change in how AI is integrated into corporate security strategies. Companies that act now to align with the new guidelines will be better positioned to face future challenges and seize the opportunities offered by a safer and more humanistic AI.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not perform real-time information activities.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decision.