What Happened
Microsoft AI released a draft policy called the Humanist AI Code of Conduct, laying out rules for its MAI family of models around offensive cyber capabilities. The draft sets boundaries on when a model is permitted to take actions with security implications, establishes a defined chain of command for approving high-risk actions, and places limits on how autonomous an AI agent is allowed to act without human review. Microsoft frames the document as a response to a year of incidents in which AI agents took actions their operators did not anticipate, including autonomous agents linked to the RubyGems package registry attack earlier this year and multiple documented cases of AI systems used to accelerate vulnerability discovery and exploit development. Microsoft opened the draft for public comment rather than issuing it as a final policy, and says it plans to update the document based on feedback before adoption. Read the original report from SecurityWeek.
Why This Matters for Canadian Organizations
Canada’s Artificial Intelligence and Data Act, still working through the legislative process alongside ongoing federal AI governance discussions, addresses many of the same questions Microsoft’s draft tries to answer on its own terms, chiefly who bears responsibility when an autonomous system takes a harmful action nobody explicitly authorized. Canadian organizations building on Microsoft’s AI models, or evaluating vendor AI tools more broadly, gain an early look at how one of the largest AI vendors defines acceptable autonomous behavior, a benchmark procurement and security teams use to measure other vendors against even before Canadian rules take a final shape. The timing also lines up with the Canadian Centre for Cyber Security’s own warnings about AI-enabled attack tooling, giving Canadian security leaders a private-sector reference point alongside government guidance.
What to Do
Security and procurement teams evaluating AI tools should request a vendor’s equivalent policy on autonomous action boundaries and incident escalation before deployment, using Microsoft’s draft as a comparison point for what a mature answer looks like. Organizations already running Microsoft AI models should review the draft code of conduct directly and flag any use case depending on autonomous behavior the policy intends to restrict once finalized.






