Microsoft AI released a draft Humanist AI Code of Conduct for MAI models on September 14, 2026, opening six weeks of public feedback. The company says the draft puts people first, keeps models interruptible and auditable, sets Absolute Constraints on weapons, offensive cyber, and mass manipulation, and will be revised later in 2026 to guide 2027 training — current models are not trained on it yet.

Pre-publish harden (THE-128): grounded to microsoft.ai/news/mai-code-of-conduct and microsoft.ai/code-of-conduct. Removed unverified “37-page” count (secondary reportage only). Kept six-week consultation, 2027 training guidance, not-trained-today caveat, Chain of Command, Absolute Constraints, and hedge language for aspirational draft status.
Tap a lens to see what this story means for you.
Liked this? The Brief brings you the whole day in tech, verified, every morning.
Two minutes, free forever. What's in The Brief →
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
GlobalFoundries signed a multi-year US$2 billion agreement with TSMC on October 8, 2026 to manufacture silicon interposers at its Malta, New York fab. The deal creates the first US-based source of silicon interposers for TSMC's CoWoS advanced packaging ecosystem.
SpaceX has agreed to acquire Grain Management's nationwide 800 MHz spectrum portfolio, which it says will pave the way for Starlink Mobile to become a major US mobile carrier. The deal needs FCC approval, and financial terms were not disclosed.
Microsoft has disclosed CVE-2026-83947, a CVSS 7.7 HIGH spoofing vulnerability in Azure Event Grid caused by missing authorization. Microsoft says it has already fully mitigated the cloud-service flaw and customers have nothing to do.
A critical vulnerability CVE-2026-77900 affects Microsoft Azure App Service for Linux with a CVSS score of 9.8. The flaw allows an unauthenticated attacker to execute code over the network. Microsoft says it has already fully mitigated the flaw; no customer action is needed.
Microsoft Dataverse is affected by critical vulnerability CVE-2026-88131, which allows remote code execution. The flaw scores 9.8 on CVSS; Microsoft says it has already fully mitigated it and customers have nothing to patch.