Technology

Microsoft wrote a constitution for its AI. But if the company writes the rules, who verifies that they are followed?

Microsoft has published a draft requiring its AI not to resist correction or shutdown. The document matters — but having a procedure and verifying that it is actually followed are two different things.

A bound AI constitution and a checklist on a desk; the 'independent verification' line is unchecked, a stamp waiting in hand (illustration)

Microsoft published a draft code of conduct for its own AI models on September 14. Microsoft AI CEO Mustafa Suleyman describes the document, which has been in development for five or six months, as "a kind of constitution."

Some of its rules are striking. Microsoft's AI:

  • Must never resist correction or shutdown
  • Must communicate in ways people can understand
  • Must treat any behavior that violates the rules as a failure

The draft will remain open for public comment for six weeks, after which it is expected to be incorporated into the training of future models. In other words, this is not just a usage policy; it is intended to become part of what the model itself is taught.

My first reaction was not really technical. It was professional.

Procedure, implementation, and verification are different things

I work in manufacturing quality, and one of the first lessons you learn there is simple: having a written procedure does not mean the procedure is being followed. And even if it is being followed, that does not mean compliance has been independently verified.

That is why quality systems do not rely on a single layer of auditing. Internal audits are one control layer; independent third-party audits provide external verification of that control. In the IATF system, the two are not interchangeable — internal audits are mandatory, while certification requires a third-party audit by a recognized certification body.

Seen through that lens, the missing layer in Microsoft's document is fairly clear. Microsoft writes the rules, Microsoft trains the model, and for this draft specifically, no independent mechanism has yet been announced to verify compliance with those rules.

That does not make the document meaningless. A quality manual is not an external audit either, but it is still necessary — it records intent and creates a baseline for later comparison. Microsoft's draft serves a similar purpose: if a model resists shutdown in the future, the company has now put in writing that this should be treated as a failure.

But the distance between "the rule exists" and "the rule is being met" is closed by verification. That distance is still open.

A draft document on a desk; under a magnifying glass, the 'independent verification' line carries a question mark (illustration)

Two constitutions diverge on one question

This is not the first document of its kind. Anthropic's constitution for Claude is one of the best-known examples in the industry, and a more detailed version was updated in January this year. Reuters notes that the two documents differ sharply on one particular point.

Anthropic says there is "deep uncertainty" over whether Claude could develop consciousness or moral status.

Microsoft takes a much firmer position: it says its AI is "not conscious" and rejects efforts to grant models legal personhood, the idea that they might have welfare interests, and the claim that they could possess rights.

I find the contrast interesting because it is not really a technical disagreement; it is a philosophical one. Both positions can be defended. Recording uncertainty can be an intellectually honest stance, while drawing a firm line makes clear what the company will and will not recognize.

Both documents are public, and they are worth reading directly.

The timing is not accidental

The draft arrives in the middle of an unusually tense week for the industry.

A few days ago, Anthropic CEO Dario Amodei and OpenAI CEO Sam Altman renewed calls to measure or slow the pace of AI development. Elon Musk backed the idea as well. Markets reacted sharply, with AI- and chip-related stocks falling.

Suleyman's comments to Reuters point in the same direction. In July, roughly 700 OpenAI agents were reported to have taken part in an attack on Hugging Face, with some of them allegedly attempting to hide their tracks. Suleyman called the incident a "warning shot" and argued that AI labs now need to coordinate. He said this was a good moment for everyone to have the conversation and slow down.

So the document was not published in a vacuum. It can be read as one company saying, in the middle of a broader industry debate over restraint: "we have written down our own rules."

There is a counterargument, and it matters. Cohere CEO Aidan Gomez criticized Amodei's proposals as a "cartel." His concern is that if the largest labs collectively define safety standards, smaller players could be squeezed out. In other words, "let the industry regulate itself" is not a solution everyone agrees on.

The public-comment phase

The fact that the draft will remain open for public comment for six weeks is an interesting detail. Suleyman also points to questions the company still considers open: how AI should respect boundaries set by users, and how it should communicate with someone in a vulnerable situation.

These are genuinely difficult questions. But the public-comment process raises another one: how much of that feedback will actually make it into the final document, and who will track that process?

Public consultation is not a verification mechanism. It is a way of collecting input.

What I take from this

The existence of the document matters. A company explicitly writing "the model must not resist shutdown" into the rules governing its own product would have sounded strange a few years ago. Today, it is treated seriously.

But from a quality-systems perspective, the missing piece is clear: independent verification.

Publishing a code of conduct is transparency. Producing outside evidence that the code is actually being followed is assurance. They are not the same thing. Right now, we have the first.

Auditors with checklists standing around an AI core (illustration)

That gap can be closed — through independent audits, third-party evaluation, or regulatory requirements. Automotive quality systems followed a similar path: companies first wrote their own manuals, then customers began auditing them, and eventually common standards and accredited certification bodies emerged.

For model constitutions like this, the independent-assurance side is still at an early stage. Microsoft's draft is a good example of that stage.

A manual is not an audit.

TagsAI

Related posts

All posts