← All company positions
Microsoftframework

Responsible AI in 2026: How we are adapting for what’s ahead

Published Sep 1, 2026 · Printed beneath the title as "Sep 1, 2026", matching the article:published_time metadata (2026-09-01T14:49:27Z); the metadata also shows a modification on 2026-09-03. The linked Transparency Report's cover prints only "2026"; its PDF creation date is 2026-08-28.

Not law. This is a company's own public position on AI regulation. It is not law, and it carries no legal force.

What it argues for

Natasha Crampton, Microsoft's Chief Responsible AI Officer, uses this post to launch the company's third annual Responsible AI Transparency Report and to summarise how its internal governance regime has changed. The central change is structural: "This year, we re-engineered our Responsible AI Standard to make it more adaptive to evolving technical realities, uses, risks, and regulatory requirements." The Standard is now organised by layer of the tech stack (models, platform services, applications) and by Microsoft's role, and "combines core requirements that always apply with more targeted, scenario-specific requirements that can evolve as capabilities and risks change." For agentic systems, governance moves from the single model to "interactions among models, agents, applications, tools, data, and people," and to "controls such as agent identities, tool permissions, and monitoring of actions." The post argues that "as systems become more dynamic, governance needs to become more operational", meaning organisations must be able to "intervene when necessary—not just assess them before deployment." It calls for "shared expectations for how systems are evaluated, monitored, and governed, as well as interoperable standards," and cites Microsoft's work with the US Center for AI Standards and Innovation, its ISO 42001 certifications and the OECD-led Hiroshima AI Process Reporting Framework 2.0. The linked report is more explicit about regulation. It warns that "overly broad or prescriptive regulation could slow innovation and adoption—or that persistent gaps could undermine trust." It also records that Microsoft "analyzed more than 100 enacted and proposed laws", refreshed its documentation for California's AB 2013 and the EU GPAI Code of Practice, and signed the EU Code of Practice on Transparency of AI-Generated Content in July 2026.

Stated positions (13)

  • The internal rulebook has been rebuilt to track law: Microsoft "re-engineered our Responsible AI Standard to make it more adaptive to evolving technical realities, uses, risks, and regulatory requirements."
  • The new Standard is layered by tech stack (models, platform services, applications) and by Microsoft's role, combining "core requirements that always apply" with scenario-specific requirements for cases such as frontier models, agentic AI and sensitive interactions.
  • Risk management is heaviest where cyber capability is highest: Microsoft applies "some of our most rigorous risk management measures to AI systems with the most significant cyber capabilities."
  • Agent governance centres on "controls such as agent identities, tool permissions, and monitoring of actions"; the report adds human approval gates for sensitive or irreversible actions and administrative controls to activate, block or revoke agents.
  • Governance must be continuous, not a pre-release gate: organisations need to "see what their systems are doing, test how they behave, and intervene when necessary—not just assess them before deployment."
  • Regulatory stance (report): "Global regulatory dynamics have heightened concern that overly broad or prescriptive regulation could slow innovation and adoption—or that persistent gaps could undermine trust."
  • Compliance readiness (report): Microsoft "analyzed more than 100 enacted and proposed laws" when re-engineering the Standard, and refreshed its process for continuous analysis and adaptation going forward.
  • Transparency documentation (report): data summary and model card templates were refreshed to address California's AB 2013 and the EU AI Act GPAI Code of Practice Transparency Chapter; Microsoft says it was among the first to publish both for a GPAI model (MAI-Image-1).
  • Content provenance (report): Microsoft pairs watermarking with C2PA-based provenance metadata, and "In July 2026, we signed the EU Code of Practice on Transparency of AI-Generated Content."
  • A new Sensitive Interactions Policy (report) "requires techniques to prevent anthropomorphic behavior and sets boundaries to help users avoid emotional entanglement, with enhanced safeguards for youth."
  • External evaluation is pursued through government institutes and alliances: work with the US Center for AI Standards and Innovation and AI safety institutes in Australia, Singapore and the UK, plus "an External Red Team Alliance with 18 universities across six continents."
  • Interoperable, shared measurement is a stated precondition of good governance: "We cannot meaningfully assess progress if every organization measures AI risks differently." Microsoft backs MLCommons AILuminate benchmarks and the Hiroshima AI Process Reporting Framework version 2.0.
  • Certification as evidence: Microsoft says it is "one of the few companies certified against ISO 42001 across a broad portfolio, including Microsoft 365 Copilot, Foundry, and GitHub Copilot."

About this document

A signed blog post of about 950 words on Microsoft On the Issues (blogs.microsoft.com), dated Sep 1, 2026 and bylined "Natasha Crampton - Chief Responsible AI Officer". It is the launch note for the 2026 Responsible AI Transparency Report, which it links through aka.ms/2026RAITransparencyReport. That link resolves to a 35-page PDF on Microsoft's CDN ("2026 Responsible AI Transparency Report", author Microsoft, created 2026-08-28), which we downloaded and used as the companion source for the report quotes above. The post has an introduction and four headed sections: "Adaptive governance and technical risk management", "Practical tools and capabilities", "Shared practices and strong partnerships" and "Meeting the moment and investing for the future". Its concrete content is the re-engineered Responsible AI Standard, agent controls, tools (AI Red Teaming Agent, agent evaluators, RAMPART, ASSERT, Agent Control Specification), ISO 42001 certification and partnerships (CAISI and the Australian, Singaporean and UK institutes, the External Red Team Alliance, the Frontier Model Forum, OpenTelemetry, the Appia Foundation, the OECD HAIP reporting framework, MLCommons). The post names no statute. The report adds a section headed "AI regulation is evolving rapidly—while trust remains a key adoption enabler" and names the EU AI Act, the GPAI Code of Practice, the EU Code of Practice on Transparency of AI-Generated Content and California's AB 2013.

How this sits against AI law

Each stance compared with what EU and US instruments actually require. Where no instrument addresses a theme, that gap is shown rather than hidden.

An adaptive internal AI standard mapped to regulation

Microsoft rebuilt its Responsible AI Standard around the tech stack and its role in each layer. Core requirements always apply, and scenario-specific requirements can change with capabilities, risks and regulation, informed by an analysis of more than 100 enacted and proposed laws. The work follows the NIST AI RMF functions of Govern, Map, Measure and Manage.

European UnionAligned

The Act likewise sets duties by role (provider or deployer) and by risk tier, and Articles 9 and 17 make a documented risk-management system and quality-management system the backbone of high-risk compliance. Microsoft's new Developer and Deployer Chapters follow that role split.

United StatesAligned

The NIST AI RMF is voluntary guidance organised around the same four functions, Govern, Map, Measure and Manage, and the report says Microsoft structures its programme on them. No federal statute obliges a developer to keep such a programme.

Training-data summaries and model documentation

Microsoft refreshed its data-summary and model-card templates to meet regulation. It published data summaries for in-scope models before California AB 2013 took effect, and says it was among the first to publish a data summary and model card under the EU GPAI Code of Practice Transparency Chapter.

European UnionAligned

Article 53(1) requires general-purpose AI providers to keep technical documentation for the AI Office and downstream providers, and to publish a sufficiently detailed summary of training content. The GPAI Code of Practice's Transparency Chapter is the recognised way to show compliance.

United StatesAligned

AB 2013, in force since 1 January 2026, requires developers of generative AI systems offered to Californians to post documentation about their training data on their websites, including sources, ownership, purpose and data types. The report names AB 2013 as a driver of its template changes.

Marking and provenance of AI-generated content

Microsoft is scaling watermarking together with C2PA-based provenance metadata across relevant product surfaces, with central monitoring, to help detect deepfakes and fraud downstream. It signed the EU Code of Practice on Transparency of AI-Generated Content in July 2026.

European UnionAligned

Article 50(2) requires providers of systems that generate synthetic content to mark outputs in a machine-readable format so they can be detected as artificially generated. The Digital Omnibus gives systems already on the market before August 2026 until 2 December 2026, and the Code Microsoft signed is the Commission-backed way to comply.

United StatesAligned

The California AI Transparency Act, as amended by AB 853, has been operative since 2 August 2026. Covered generative AI providers with over one million monthly users must embed latent disclosures in generated content and offer a free public detection tool. No federal statute does the same.

Controls and human oversight for agentic systems

Governing agents means looking beyond a single model to interactions among agents, tools, data and people. Microsoft relies on verifiable agent identities, runtime tool permissions, monitoring of actions, and human approval gates for sensitive or irreversible actions. Governance should become continuous and let operators intervene, not stop at pre-deployment assessment.

European UnionAsks for more

Article 14 sets human-oversight design duties only for high-risk systems, and the Act has no provision specific to AI agents, tool permissions or agent identity. Microsoft applies these controls regardless of risk classification.

United StatesNo equivalent law

No US federal or state instrument in our corpus sets requirements for agent identity, tool permissions or human approval gates in agentic AI systems.

Safeguards for emotionally sensitive and youth interactions

A new Sensitive Interactions Policy covers open-ended conversation, memory and personalisation. It requires techniques to prevent anthropomorphic behaviour and boundaries against emotional entanglement, with enhanced safeguards for youth. Consumer mitigations include classifiers, crisis responses to self-harm, age-based access controls and parental controls.

European UnionAsks for more

Article 50(1) requires only that people be told they are interacting with an AI system, and Article 5(1)(b) bans exploiting age-related vulnerabilities to cause significant harm. The Act has no rule against anthropomorphic design or emotional dependency.

United StatesAligned

California SB 243 requires companion chatbot operators to publish crisis-prevention protocols for self-harm, and to give users known to be minors AI disclosures and break reminders at least every three hours. That is the same terrain as Microsoft's policy, though the statute does not address anthropomorphism.

Incident response and reporting

Microsoft formalised incident-response playbooks across 13 topics and processed over 11,000 Microsoft Security Response Center submissions in 2025, more than 600 of which escalated to full AI safety or security cases. It will strengthen appropriate information sharing with defenders. Neither the post nor the report describes reporting incidents to regulators.

European UnionAsks for less

Article 55(1)(c) obliges providers of systemic-risk general-purpose models to report serious incidents and corrective measures to the AI Office without undue delay. The report describes a mature internal process but not that external duty.

United StatesAsks for less

SB 53 requires frontier developers to report critical safety incidents to California's Office of Emergency Services within 15 days, or within 24 hours where there is imminent risk of death or serious injury. The report mentions no regulator-facing reporting at all.

External evaluation through government institutes and independent certification

Microsoft backs up internal red teaming with external evaluation. It has a memorandum of understanding with the US Center for AI Standards and Innovation, a collaboration agreement with the UK AI Security Institute, ten general red-teaming firms, eight specialists in high-severity risks, and an External Red Team Alliance of 18 universities. It also holds ISO 42001 certification across major products.

European UnionAligned

Article 55(1)(a) requires systemic-risk model providers to evaluate models with state-of-the-art protocols, including documented adversarial testing, and leaves the choice of internal or external testers to the provider — the mix Microsoft describes.

United StatesAligned

The Action Plan gives NIST's Center for AI Standards and Innovation the job of evaluating frontier models for national-security risks in voluntary partnership with developers, the arrangement Microsoft's MoU formalises. It imposes no evaluation duty on companies.

Against over-broad regulation; for interoperable standards and reporting

Microsoft warns that overly broad or prescriptive regulation could slow innovation and adoption, and that persistent gaps could undermine trust. It calls for shared evaluation expectations, interoperable standards and common measurement, and helped develop the OECD-led Hiroshima AI Process Reporting Framework 2.0 to make transparency reporting interoperable across jurisdictions.

European UnionAligned

The Digital Omnibus on AI, in force since July 2026, amends the AI Act to reduce administrative burden, expand regulatory sandboxes and adjust high-risk timelines. That is the EU moving in the direction of Microsoft's warning against prescriptive overreach while keeping the Act's structure.

United StatesAligned

The Action Plan shares the premise that regulation must not slow AI adoption. It directs agencies to identify and revise rules that hinder AI, and it favours standards work led by NIST over new binding rules.

This is a compliance-and-practice document, and on most themes Microsoft reports doing what the EU AI Act and California law already require or are about to require. It matches Article 53 and AB 2013 on training-data summaries and Article 50(2) and California's AI Transparency Act on content marking, and on evaluation it adopts the Article 55 practice of mixing internal and external testers. It goes beyond both jurisdictions on agent governance, where neither the Act nor any US instrument in the corpus has agent-specific rules, and on emotionally sensitive interactions, where it outpaces the EU and roughly tracks California's SB 243. It falls short only on regulator-facing incident reporting: the Act's AI Office duty and SB 53's 15-day and 24-hour clocks are absent from a report that describes a large internal incident-response machine. Its warning against "overly broad or prescriptive regulation" fits both current trends, the EU's Digital Omnibus simplification and the US Action Plan's deregulatory stance.

Source

https://blogs.microsoft.com/on-the-issues/2026/09/01/responsible-ai-in-2026-how-we-are-adapting-for-whats-ahead/
Date on the page:
Sep 1, 2026
Source checked:
opened and confirmed on 2026-09-29