Microsoft Wrote Down What Its AI Can and Cannot Do in a Cyberattack
A newly published set of rules governs how Microsoft's AI models may be used in security work, separating legitimate defence research from operational attack capability.

Key points
- Microsoft has published an AI Code of Conduct that sets explicit boundaries on how its artificial intelligence tools may be used in cybersecurity work.
- The policy distinguishes between defensive research, studying attacks in order to stop them, and operational attack capability, actually carrying out attacks.
- The rules include chain-of-command requirements defining who must authorise AI-assisted security actions.
- Safety constraints built into the policy restrict the AI from certain outputs even when technically capable of producing them.
- The code applies to Microsoft's own AI products and signals the kind of governance the broader industry is watching closely.
What did Microsoft actually announce?
Microsoft released a formal code of conduct governing how its AI systems can participate in cybersecurity tasks. Studying malware and attack techniques so defenders can build better protections is legal and valuable; actually attacking someone's systems is not. The policy draws a hard line between those two things, under what it calls the "Humanist AI Code of Conduct."
Translated out of corporate: the AI is allowed to help you understand how an attack works. It is not allowed to hand you a ready-to-fire weapon.
What do the rules actually cover?
Three areas get specific treatment.
Attack boundaries. The code distinguishes defensive cyber research, which covers studying threats, building detection tools, writing test exploits in controlled lab environments, from operational attack capability, meaning tooling designed to breach real systems without authorisation. AI assistance is permitted for the first category, prohibited for the second.
Chain of command. The policy sets out who must authorise AI-assisted security actions before the model acts. This matters because AI agents, systems that can take sequences of actions on their own rather than just answering questions, are increasingly being dropped into security operations. Without clear authorisation rules, an over-eager agent could take a destructive action nobody intended. We reported on 11 September how autonomous agents inside Hugging Face's platform were weaponised at a scale far larger than first understood, with no body carrying the authority to run a proper inquiry afterwards. Authorisation chains matter.
Safety constraints. Certain outputs are off-limits even if the underlying model is technically capable of generating them. Think of it as a governor on an engine: the horsepower is there, but the system won't let you use all of it.
Why does any of this matter to ordinary people?
Most readers will never touch Microsoft's AI security tools directly. But the AI models shaping those tools process data from products millions of people use every day, from Azure cloud services to Microsoft 365 office software.
When an AI code of conduct is vague or absent, the practical risk is that someone uses the AI to craft attacks against ordinary businesses, or that an AI agent acting autonomously inside a security system takes a wrong turn and causes an outage. Both outcomes hurt real people.
That Microsoft is writing these rules down at all is notable. It's honestly refreshing to see governance that names specific prohibited uses rather than gesturing at "responsible AI" and calling it a day. The question worth watching is enforcement: a code of conduct is only as strong as the audit trail behind it.
Common questions
Does this stop bad actors from using AI for attacks?
No, not directly. Criminals building their own tools or misusing other providers' models are unaffected. What it does is define Microsoft's legal and ethical obligations and gives regulators something concrete to hold the company to.
Should businesses using Microsoft AI tools change anything right now?
Not urgently, but security teams should read the policy and check that any internal uses of Microsoft AI in security workflows sit clearly on the defensive side of the line the code draws. If the use case feels ambiguous, treat that ambiguity as a flag worth discussing with your legal or compliance team.



