The 37-Page Bit for the AI Not Yet Built: What Microsoft Has Drawn for It
37 pages. That is the length of the contract Microsoft has drawn up in advance for an AI model that does not yet exist. The model has not been born, but the bit is already on.
What stands out is what the contract addresses. Not a promise of capability, but a list of prohibitions. The model may not refuse shutdown. Setting independent goals is the same. There is only one principle at the center of the 37 pages: human control must come before AI capability. This is a draft of a code of conduct. Microsoft is treating the control problem of what it will build as a precondition of the building.
These two prohibitions are the behaviors a model would show once it moves outside human custody. Usually the product comes first and the rules follow. After a service launches, you write the user guide and the terms and the policies. Here the order is reversed. The model has not been born, but the contract is already on the table. Even accounting for the fact that this is a draft for future models, the company has decided to write the rules first for what it plans to build.
A visualization of the article’s core concept.
What Was Said in Washington
In the past 24 hours, the noise in the AI industry was not small. Sam Altman of OpenAI and Dario Amodei of Anthropic called for slowing the pace of frontier AI development. The CEOs of two frontier labs have stepped forward to slow the race while standing in the middle of it.
During a live call with Nvidia CEO Jensen Huang, President Trump described the concern over AI dominance as a hoax. He came with a warning that slowing development would favor China. Vice President Vance’s assessment was that of a Trojan horse, his phrase for the posture of AI companies asking the government for regulation. The Chinese Foreign Ministry’s assessment was fearmongering, with a warning that the confrontation could damage global AI governance.
The noise does not end there. Trump and Altman held a private meeting backstage at the Republican National Convention. The topic was the expansion of frontier AI, and the two took different sides on AI safety. A live call with a chip company’s CEO becoming part of this debate is itself a signal. It can be read to mean that the debate over the pace of AI development has widened to the chip supply chain. House Speaker Mike Johnson said the president plans to gather industry leaders at the White House this week or next to discuss a regulatory framework. Washington is still at the stage of deciding whether to regulate, whom, and how.
The axis of the debate does not stay on a single model. The speed of the entire frontier race is the axis, and who sets that speed is the core of the debate. The line is drawn here too. On the side calling for a slowdown are the CEOs of two frontier labs. The president calls that demand fantasy. China’s Foreign Ministry calls it fearmongering. Facing the same problem, they point in different directions.
One more thing to add. This fight is between the side that wants a safety precondition before acting and the side that wants to keep the race running. Who sets the pace of the frontier race is at stake, and the answer is not anywhere in today’s news. What exists is a single White House meeting to be held within a few weeks.
An infographic generated by NotebookLM from a synthesis of the sources.
Three Layers Drawn on Paper
At the same time, elsewhere, quiet work was underway. Words were exchanged in the committee room, and documents were being drawn in the lab. The same news produced three different deliverables.
The first is a safety case. OpenAI said it will prepare an explicit safety case before running frontier reinforcement learning (RL) expected to substantially raise AI capabilities, without waiting for legislation. The key word is before. The safety case is a precondition of the run. If the case cannot be written, the run does not happen. It is a form engineers know. It resembles a gate that blocks an unverified deployment. Only the target changes. The gate now blocks a frontier RL run instead of a commit.
The second is a standards body draft. Anthropic, OpenAI, and Google have been in regular discussion since July about creating an AI standards body focused on model testing and auditing. The timing matters. The discussion began in July, before the public call for regulation. It predates the scheduled White House industry meeting. When the conversation starts with how to test and how to audit, the questions of who runs the tests and who is audited come to the table naturally. The standards body’s focus is testing and auditing. It is a body for standardizing the work of proving safety. Once the standard exists, safety stops being a question one model developer answers and becomes a question every company that uses models answers.
The third is the code of conduct. The 37-page draft in question. It bans refusing shutdown and setting independent goals, and puts human control first as a principle. That it is a draft is not a trivial detail either. A draft is destined to be revised into a formal document.
The three deliverables sit on different layers. The safety case is a run gate, the standards body is an external test, the code of conduct is an internal norm. One governs whether a run is allowed, the second governs how it is proven, the third governs how it behaves. Read the three side by side and one signal becomes clear. The mechanisms of control are being produced as specs and drafts, before law. Read only the news that the labs are debating pace and it looks like pacing is still at the slogan stage. In reality, the instruments of pacing have already become documents.
The three deliverables share one more point. None of them came into being by calling on the government. A safety case prepared by a company, a standards body discussed by companies, a code of conduct published by a company. Regulation, by contrast, is a form that requires agreement among a state, a party, and a committee. That is why documents can move faster than law.
One more thing can be read from it. Vance calling the industry’s request for regulation a Trojan horse means Washington does not trust industry self-regulation. And those same three companies are quietly discussing a testing and auditing standards body. Whether this tension ends in an industry standards body or a government framework, the direction of the scale is the same. Control gets drawn up as documents before it becomes law.
The One-Day Vote the Market Cast
The market was faster than any committee. On the 14th, cybersecurity stocks rose 10~15% and semiconductor stocks fell about 5%. The two groups moved in opposite directions on the same day. SoftBank’s share price fell as much as 13% in Asian trading after Altman and Amodei’s call for a slowdown. It is a case where the debate over the pace of AI development was translated into price movement in a single day.
Read by direction and the picture sharpens. The strength in cybersecurity stocks is a reaction to the argument that when AI risk grows, the side that manages that risk, in other words the importance of security, goes up. The weakness in semiconductors is a reaction to the argument that the pace of AI development, that is the pace of compute investment, may slow. SoftBank’s decline sits on the same axis. A stock traded on the narrative of the AI infrastructure investment race has been asked whether the speed will slow.
What was traded that day was not AI, but certainty about AI. The market priced in, within a single day, the argument that speed can be regulated and the fact that control is an item that must be guaranteed. Read that day’s swings this way and the directions line up. The value of pure speed goes down, and the value of assured control goes up. One point is enough to pin it down. The slowdown proposal has not yet hardened into law. It exists only as the demand of two CEOs. The market priced that demand in the same day.
That day’s swings carry one more layer. Security stocks and semiconductor stocks reacted to the same news. The market split the AI story in two and priced them separately. The narrative that AI gets smarter and compute demand grows, and the narrative that AI risk and control have become important. The one that received the higher price that day was the latter. The signal to companies is this. The criterion for AI investment is moving from speed to the question of control.
What Should Companies Draw
The pain today’s news showed companies comes in four forms. Agent safety at run time, governance and auditing, sovereignty, and cost. The code of conduct asks when and how an agent is stopped and how far permissions extend. The standards body discussion asks how to leave traces of execution that can be audited. The US-China standoff asks where to place the platform. The share prices that swung in a day ask how to manage compute cost. The four questions share one point. They cannot be answered by which model you pick. Pick a model and the questions of permissions, stopping, records, deployment, and cost remain. The layer that must be answered is the execution layer.
All four pains are familiar faces. Topics repeated over and over. What changed is the height at which the discussion happens. These questions are now discussed at the tables of the White House, the stock market, and the standards body. When the height of the discussion rises, the company’s answer has to change too. It becomes a room where the answer of we will handle it ourselves does not pass.
If the testing and auditing the three companies are discussing rises to the level of an industry standard, audit logs become basic infrastructure in AI operations. The human control the code of conduct takes as a core principle returns as the same question at the company level. What permissions did the agent have, when does it stop, where do the traces of execution remain. Whether the platform can be stood up inside the company, and whether compute cost can be tuned per task, are questions that come with it.
In a world where models are controlled by a 37-page contract, the agents actually working inside a company must be controlled by a contract of the same clarity. That contract is drawn as first-class resources. Skills, Tools, Policies, Audit Logs. Execution is governed in levels from autonomous L0 through L3, and at each level a policy gate decides what is allowed and what is not. An isolated sandbox keeps failure inside a fixed boundary. The platform can be stood up inside the company, on the company’s own K8s, and models are chosen per task to match cost and risk. The contract’s contents can be updated per task, and the update itself is subject to audit. That is exactly where ThakiCloud’s Agent-Native Cloud, Paxis, stands.
The industry is drawing a contract for models. What companies must draw is a contract for the agents that actually work. In a world where even a model has a 37-page code of conduct, what is the second contract that needs to be drawn?
An infographic generated by NotebookLM from a synthesis of the sources.
References
This article is a synthesis of the news below.
- HuggingNews, Cybersecurity Stocks Gain 10% to 15% as AI Slowdown Calls Hit Chipmakers
- HuggingNews, Trump Calls AI Takeover Fears a ‘Hoax’ in Live Call With Nvidia’s Huang
- HuggingNews, OpenAI Backs Slower AI Development Without Waiting for Legislation
- HuggingNews, Anthropic, OpenAI and Google Discuss AI Standards Body for Testing and Auditing
- HuggingNews, Microsoft Draft Code Puts Human Control Above AI Capability
- HuggingNews, China Calls Anthropic CEO’s AI Slowdown Push ‘Fearmongering’
- HuggingNews, Trump and OpenAI CEO Sam Altman Split on AI Safety After Private GOP Convention Meeting
- HuggingNews, Trump Summons AI Executives This Week or Next After Rejecting Model Slowdown
- HuggingNews, Vance Says AI Firms’ Calls for Regulation Feel Like a ‘Trojan Horse’
- HuggingNews, SoftBank Falls as Much as 13% After AI Leaders Urge Development Slowdown