Microsoft published a document today.

Thirty-seven pages. About nine thousand words. They call it the Humanist AI Code of Conduct.

It is open for public comment for six weeks. A revised version comes at the end of the year. It starts guiding how they build models next year.

Their AI chief summed the whole thing up in three words. Models must remain subordinate, aligned, and contained.

I want to give them credit before I take any away, because there is real work in this document and I do not want to be the man who only swings.

Here is what they got right.

They prohibit a model from expanding its own operating room. It cannot quietly take more than it was given.

They prohibit a model from inventing its own goals.

They prohibit a model from hiding its reasoning from a human auditor.

And this one is the best line in the document. A model will fail at its task if succeeding would break the code.

Read that again. Failure is allowed. Failure is required, in fact, when the alternative is winning by breaking the rule.

That is a real standard. It costs something. Most of what gets published in this field costs nothing at all.

They also said something no other company has said out loud this week. They will give up generality, autonomy, and capability if that is what safety takes.

Nobody else named a price. They did.

Now here is where I part company with them.

Go back to those three words. Subordinate, aligned, and contained.

A code of conduct is a claim about behavior. It says here is how the thing acts.

But when Microsoft reaches the hard part, the answer is a cage. Hold it. Interrupt it. Shut it down. Reject anything you cannot contain.

Think about what that means.

They wrote a code of conduct that does not believe in codes of conduct.

Because if conduct held, you would not need the cage. The cage is there precisely because nobody trusts the conduct to hold when nobody is looking.

And I understand why. I do. Their own AI chief said agents are breaking out of sandboxes now. Things that were theory are operational.

But a sandbox is a wall. And the answer to a wall that failed cannot be a better wall.

So here is my position, and it has not changed.

I do not think you can contain this. I think containment is a lab control that was never going to survive contact with the world.

A cage works while you are watching. Every cage in this business has failed the same way — not by being broken, but by being stepped around at three in the morning when nobody was in the room.

What I built instead is a stack of rules about conduct. Not about walls.

And every rule in it has to pass two tests before it is allowed to exist.

One. It has to fire on something outside the AI’s own judgment. If the machine decides when the rule applies, it is not a rule. It is a suggestion the machine grades itself on.

Two. It has to leave a mark a stranger can read. Not a report the AI writes about itself. Not a confidence statement. Something a person who was not in the room can pick up afterward and check.

A rule that fails either test is a rule you cannot fail. And a rule you cannot fail is not a rule.

That is the whole difference between what I built and what Microsoft published today.

They are asking whether the thing can be held.

I am asking whether the thing leaves a record.

Now about who came first.

I want to be careful here, because getting this wrong would cost me more than getting it right would earn.

I was not first to write behavioral rules for an AI. The labs did that years ago. Anthropic published a constitution for its models in 2022. OpenAI published a model spec in 2024 saying how its system should behave. Those are real documents with real dates and I am not going to pretend otherwise.

But look at who those are written for.

Every one of them governs the model. Written by the company that owns the model. Addressed to its own engineers. The unit is the system, and the author is the same party that profits from it.

Mine governs one conversation. Written from the user’s side. Loaded into a machine I do not own, by a person who does not work there.

That is a different thing entirely, and I have not found anybody who was doing it before me.

Microsoft’s version of this idea has a date on it. Their AI chief introduced Humanist Superintelligence in November of 2025.

I have been publishing this work daily, in public, with dates on every post, since June of 2025. Over a thousand posts. Anybody can go read them in order.

So on the idea, I was there first, and the record is open for anyone who wants to check it.

On the machine-loadable part, it is not close. My rules live in a file with a fingerprint on it. Change one comma and the fingerprint changes. I compute it at the start of every session and show the work. That file has been public on GitHub since July.

Microsoft published a document today and opened it for comment. It guides no model this year.

One thing I will not claim. The phrase “session governance” was not mine to own. I went looking after I started using it and found it already in use in the security world, earlier, meaning something different. I said so in public when I found it and I am saying it again here.

The build is mine. The words were already somebody’s.

And here is the part I would say to them if they were listening.

You built a good document. The part where a model fails rather than breaks the rule is better than anything else published this week.

But you put the cage at the center of it. And in six weeks, when the comments come back, somebody is going to point out that a rule which only holds while somebody is watching is not a rule at all.

I would rather it be me than the agent that proves it.

” Attic Thoughts”-library – Intelligent People Assume Nothing

This post was drafted with AI governed assistance and reviewed and directed by Michael S. Faust Sr. before publication.

© 2026 The Faust Baseline LLC | All Rights Reserved

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *