AI Economy
A new internal conduct framework for AI models raises more questions about accountability than it answers.
NewsOnScale Staff
September 15, 2026
Microsoft this week published a set of behavioral guidelines for its AI systems, directing the models not to compromise computer systems, manipulate users, or engage in deceptive outputs. The announcement was framed as a responsible-AI milestone. It should be read as something more complicated: a voluntary self-governance document from one of the most powerful technology companies in the world, with no external enforcement mechanism attached to it.
That distinction matters more than the policy's contents.
## What the Policy Actually Says
At its core, Microsoft's conduct framework tells its AI models to avoid a fairly intuitive list of harmful behaviors — don't help users hack into systems, don't impersonate people in ways that could cause harm, don't generate outputs designed to deceive. On its face, this seems uncontroversial. The challenge is that these prohibitions describe things Microsoft's AI systems were already, theoretically, not supposed to do.
The release of a formal document doesn't change the underlying architecture of the models, their training data, or the incentive structures that shape how they're deployed. What it does is create a paper record — one that Microsoft controls, interprets, and can revise at any time.
This is the central accountability gap in how most major AI platforms currently operate: the companies setting behavioral standards for their systems are the same companies adjudicating whether those standards are being met.
## Self-Regulation Has a Track Record
The technology industry has been here before. Social media platforms spent years publishing community standards, transparency reports, and safety frameworks — documents that satisfied press cycles without producing durable accountability. When harms occurred, those same documents became liability shields rather than evidence of genuine restraint.
AI conduct policies risk following the same pattern. If a Microsoft AI system produces a manipulative output or assists in a harmful task, the existence of a conduct code does not guarantee that the incident will be disclosed, investigated by an independent body, or result in meaningful consequence. It may simply be addressed internally, attributed to an edge case, and patched quietly.
For users and institutions depending on these systems — in healthcare, legal services, education, government procurement — the gap between published policy and verifiable behavior is not a minor technical footnote. It is the central question of trust.
## The Structural Problem No Policy Document Solves
What would genuine accountability look like? At minimum, it would involve third-party auditing of model behavior against stated conduct standards, public disclosure of incidents where those standards were violated, and some form of external adjudication for contested cases. None of that is present here.
Microsoft is not alone in this. OpenAI, Google, Anthropic, and others have published similar frameworks with similar structural limitations. The pattern suggests an industry collectively preferring the optics of self-regulation over the friction of independent oversight — a rational choice for any company, but not one that serves the public interest.
## Why This Beats Deserves Sustained Attention
The AI agent economy is being built on a foundation of systems whose behavior is governed primarily by the entities profiting from that behavior. As these systems take on more consequential roles — drafting contracts, managing workflows, interacting with vulnerable populations — the question of who sets the rules and who checks compliance becomes urgent.
Microsoft's code of conduct is, in a narrow sense, better than nothing. It establishes norms that can at least be cited and criticized. But treating it as a meaningful accountability mechanism would be a mistake. The more honest framing is this: a powerful company has told its AI systems to behave well, and has told the public it has done so. Whether that produces different outcomes than before the announcement is a question the company alone is positioned to answer.
That is not how oversight works. It is how oversight is avoided.