Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints
The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability. The post Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints appeared first on SecurityWeek.
Microsoft AI has published a draft “Humanist AI Code of Conduct” for its MAI Models, spelling out safety rules for offensive cyber capabilities, limits on autonomous AI agents, and a dedicated review track for cybersecurity and other specialized uses.
According to the code of conduct, models are blocked from producing working exploit code, attack tooling, planning and targeting methodologies, intrusion procedures, evasion techniques, operational guidance, or other assistance that would enable or improve a cyberattack. Microsoft says these restrictions apply regardless of how a request is framed.
The rule falls under what Microsoft calls Absolute Constraints, safeguards that neither the companies deploying its models nor their end users can override. The tech giant draws the line between understanding an attack, or working to defend against one, and gaining the practical means to carry it out.
Related breach coverage
- Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows2026-09-17
Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek.
- Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard2026-09-17
The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution. The post Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard appeared first on SecurityWeek.
- UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure2026-09-02
Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify. The post UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure appeared first on SecurityWeek.
- Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars2026-09-01
Forescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models. The post Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars appeared first on SecurityWeek.