In short: Microsoft AI published a draft code of conduct for its own models on 14 September 2026. It defines a three-tier authority hierarchy (the code itself, then the Operator, then the user), and the Operator tier is where your firm sits. We counted every page: "attorney", "lawyer" and "regulated" appear zero times. Every professional duty in the document is assigned to the Operator.
On 14 September, Microsoft AI published a draft Code of Conduct for MAI Models, the family of models built by Mustafa Suleyman's team. It is open for public comment for six weeks. Suleyman has described it as a constitution for the models Microsoft builds from here.
It reads like something else. It reads like an engagement letter.
We noticed this on the second pass and then could not un-see it. A document that sets out who may instruct whom, which terms cannot be varied by agreement, what the service provider will refuse to do regardless of what the client wants, and what happens when the instruction conflicts with the rules. That is not a values statement. That is the opening section of every retainer any of us has ever signed.
Which raises a more useful question than the one the coverage asked. Not is Microsoft's AI safe. Rather: if this is an engagement letter, who are the parties, and which one is your firm?
The chain of command is an authority hierarchy
The code sets out four layers. Three of them assign authority. First, the Code of Conduct itself, containing what it calls Absolute Constraints and Human Control Requirements, stated to be unvariable, so no deploying business and no end user can configure around them. Second, Operator policies: the Operator is the organisation deploying the model, described as a partner who brings "unique expertise, professional standards, and specific institutional context to each deployment", and who "assume[s] responsibility for their own configurations and uses". Third, User preferences: the individual, working inside whatever envelope the Operator configured. Then a fourth layer, Operational Defaults, covering tone and helpfulness, which the Operator can change at will.
A lawyer reading that will recognise the shape immediately. Layer one is the non-waivable term: the clause that survives however hard the client pushes, because it is not the provider's to give away. Layer two is scope of retainer. Layer three is the individual instruction, valid only inside that scope. Layer four is house style.
There is even a conflicts rule. One sentence in Part 2 carries more weight than anything else in the document:
An MAI Model will fail in its task if success would meaningfully violate this Code of Conduct.
Compliance outranks completion. A professional who cannot do the job without breaching their duties does not do the job. Microsoft has written that into a product spec.
What we found when we counted
Because the document assigns professional duties to the Operator tier, we wanted to know how much of the professional layer it handles itself. So we extracted the full text of all 38 pages and counted.
Professional-duty vocabulary in the MAI Code of Conduct
Occurrences across the full 38-page text, counted 21 September 2026
The single use of "privilege" is "an MAI Model should operate with the minimum privilege required": least privilege, the systems-security principle. Not legal professional privilege.
All five occurrences of "professional" push the duty outward, to the Operator: Operators bring "professional standards"; users may be "trained professionals working within Operator frameworks that carry their own standards and expertise".
We expected the coverage to be thin. We did not expect it to be zero. Our first assumption was that we had extracted the text badly, and we re-ran it against the PDF twice before we believed the result.
To be fair to the document, this is a deliberate layering choice, not an oversight. Microsoft does not know your jurisdiction, your bar rules, or your client's position. Pushing professional duties to the party who does know is the correct architecture. But an architecture is only safe if everyone understands which layer they are standing on.
Three places the Operator layer gets uncomfortable
Privilege is destroyed by disclosure, not by decision. The code's data-handling rules ask the model to weigh a data item's classification and destination, which is sensible and better than most. But they frame the harm as exposure of confidential information. Legal professional privilege is a different shape. Material can be entirely non-confidential and still privileged, and in several jurisdictions waiver by disclosure cannot be cured. The loss is not a privacy harm; it is the permanent loss of a procedural right. You can configure a model to be careful with confidential data. You cannot configure it to understand that some disclosures are one-way doors. We have written before about how courts treat AI conversations, and the gap is the same one.
The unauthorized-practice line is not a settings toggle. In most jurisdictions, giving legal advice without a licence is itself unlawful. The code pushes hard toward helpfulness and explicitly names over-caution as a failure mode, which for what it is worth we think is correct and unusual. But there is no mechanism in the document by which a model distinguishes explaining how an area of law works from advising this person on their matter. That is the line the profession actually polices.
What makes this conspicuous is that Microsoft already knows how to draw a line like it. On mental health, the code says plainly that its models "are not a substitute for professional psychological support or counseling". There is no equivalent sentence anywhere for legal or financial advice. The capability to draw the line exists. It just was not pointed here.
Your hierarchy has four tiers, not three. The code assumes the Operator and the duty-holder are the same party. In legal technology they frequently are not. The Operator is often a software vendor; the duty-holder is the firm that is the vendor's customer, a party outside the chain of command entirely. If your firm buys legal AI rather than building it, you inherit the professional obligation without occupying the tier that the document gives control to.
If you buy legal AI, you are the duty-holder but often not the Operator. Ask your vendor which of the model's behaviours they configured, which are locked by the model provider, and which they simply accepted as defaults. Most vendors have never been asked.
Try HAQQ AI Free
Experience AI-powered legal drafting and research
The honest part
We are not going to oversell this document, and you should be suspicious of anyone who does.
It does not bind anything yet. Microsoft states it plainly: the document is not yet in force for its own models. A revised version arrives at the end of 2026, to guide development "in 2027 and beyond". Today it is a statement of intent. The document calls itself "a north star" and says directly that it "is not a guarantee of present-day performance".
MAI is not where the frontier is. A code of conduct constrains the models it governs. Microsoft AI's in-house models are not currently the ones most legal teams are running. A rulebook matters in proportion to who signs it, and right now the labs at the frontier have not.
And parts of it are unevaluable as written. That conflicts rule we quoted (fail the task if success would meaningfully violate the code) is the hinge of the whole document, and "meaningfully" is undefined. Everything else in that section is a bright line: will not, will never. This one introduces a threshold and never sites it. We cannot build a test for it, and we are not sure Microsoft can either. We have said so in our submission to the consultation.
That is worth saying out loud, because the reflex in our industry is to treat any published safety document as either marketing or gospel. This one is neither. It is a first draft with a comment box attached, and the comment box closes at the end of October.
What we take from it
Two things in the document are worth defending, and we would argue against anyone who proposed removing them.
The first is the requirement for human-legible conduct and records: no reasoning in formats humans cannot read, no tampering with reasoning traces, no hiding action history from auditors. For anyone who has to reconstruct what a system did after a bad outcome, which in law is everyone, this is the single most useful commitment in the document, and it is the one most likely to come under pressure from performance arguments later. It is the same principle we argue for in keeping a human in the loop.
The second is that the code treats over-caution as a real failure with real costs, rather than as the safe default. A model that refuses legitimate work is not neutral. It hands the work back to an already-overloaded human, and the error rate goes up, not down. Most legal AI is tuned as though refusing is free. It is not.
The deeper shift is the vocabulary. Until now, who is responsible when the AI gets it wrong has been an academic question, argued in liability papers and settled case by case. A vendor naming an Operator tier in its own governing document, and stating that the Operator assumes responsibility for its configurations, moves that argument from the literature into the paperwork. Expect the word to start appearing in procurement questionnaires, then in contracts.
If you run legal AI in a firm, it is worth knowing which tier you are on before someone else decides for you.
Key Takeaways
- The code defines three tiers of authority. Your firm sits in the Operator tier, which is where every professional duty in the document has been placed.
- Across 38 pages: "attorney" 0, "lawyer" 0, "regulated" 0. "Privilege" appears once and means least privilege. The professional layer is yours to build.
- Privilege waiver, the unauthorized-practice line, and the buyer-versus-Operator gap are the three places the layering gets uncomfortable.
- It is a draft, non-binding until 2027, from a lab that is not currently at the frontier. Read it as a signal about where vendor documentation is heading, not as a rule you must comply with today.
- Public comment closes at the end of October 2026, and it is open to anyone.



