On September 14, 2026, two AI governance documents were published within hours of each other. In Jinan, China's national cybersecurity standards committee released version 3.0 of its AI Safety Governance Framework. In Redmond, Microsoft AI published a draft Code of Conduct and opened a six-week public consultation. Both were widely reported as new rules for AI. Neither one is a rule. Both are explicitly non-binding, and one of them has not been used for anything yet. That gap between how these documents are reported and what they actually do is worth understanding, because the things that genuinely do bind you are elsewhere and mostly already in force.

Key TakeawaysChina's Framework 3.0 is a 非强制性 — non-mandatory — guidance document that creates no approval or filing obligation. Microsoft's Code of Conduct is a draft the company says it is "not using to train our models today," intended to guide 2027 models. Meanwhile the binding obligations are real and countable: 868 generative AI services filed with Chinese regulators as of April 30, mandatory content labelling since September 2025, and EU transparency rules in force since August. If you are deciding what to do this quarter, read the second list, not the first.

What China Actually Published

The document is the AI Safety Governance Framework 3.0, released at the opening ceremony of the 2026 National Cybersecurity Publicity Week. The issuer matters and is frequently reported wrong: it was issued by TC260, the National Cybersecurity Standardization Technical Committee, under the guidance of the Cyberspace Administration of China. The CAC did not publish it. A standards committee did, with the regulator's blessing.

Version 3.0 keeps the structure of its predecessors — risk classification, technical countermeasures, comprehensive governance — and updates what sits inside each. The substantive change is a response to a shift in what the technology does. As Chinese state television explained the version lineage: 1.0 focused on inherent and application safety risks, 2.0 added derivative risks including employment and ethics, and 3.0 responds to models moving beyond answering questions to actively executing tasks as agents.

So 3.0 breaks out agent risk and embodied-intelligence risk as their own categories. The stated reasoning is the interesting part: agent behaviour can now spill outward and transmit into the physical world. That is a governance framework noticing that the thing it governs stopped being a chatbot.

Architectural close view of sober stone columns and a plain civic facade, rhythmic vertical lines.

Is It Mandatory? No — and That Is Stated on the Record

This is the question most coverage skips, and the answer is not a matter of inference. Chinese state media described the framework directly as a 非强制性法律文件, a non-mandatory legal document, and as an 指引性文件, a guidance document. It creates no licensing regime, no approval process and no filing requirement.

But "voluntary" understates how it works in practice. The same coverage explained the mechanism plainly: firms can gain market-credibility advantage by following it, and regulators "can treat this guidance as a framework, as a ruler by which to measure" when supervising firms. Call it voluntary guidance with regulatory gravity. Nobody is required to comply, and a regulator reviewing your service may still measure you against it.

There is a second mechanism worth knowing. TC260 is a standards body, and its frameworks feed a pipeline that produces national standards — some of which do become mandatory. The framework itself is not a rule, but it is a reasonable preview of what later rules may codify.

What Does Bind You in China

Three instruments, all genuinely binding, all already in force.

The Interim Measures for Generative AI Services, effective August 2023, created a filing obligation. That regime has numbers, published by the regulator itself, which is rare enough in AI policy to be worth quoting: as of April 30, 2026, 868 generative AI services had completed national filing and 530 applications or functions had completed local registration. The two tiers matter — national filing is for services, local registration is for applications that merely call an already-filed model.

868
Generative AI services with completed national filing in China as of April 30, 2026 (Cyberspace Administration of China)
530
Applications or functions with completed local registration over the same period — the second, lighter tier
0
Enterprise adoption figures published for Framework 3.0. None exist. Any number you see cited is invented

Second, content labelling. The Measures for Labelling AI-Generated Synthetic Content took effect on September 1, 2025, issued jointly by four agencies. They require visible labels on generated text, audio, images, video and virtual scenes, labels that survive download and export, and implicit labels in file metadata.

Third, and most often missed: those labelling measures are paired with a mandatory national standard that came into force the same day. This is the distinction that makes the whole comparison legible. China has mandatory AI rules. Framework 3.0 is deliberately not one of them.

What Microsoft Actually Published

The Humanist AI Code of Conduct is a draft governing Microsoft's own MAI models, published with a six-week consultation that closes in late October. Microsoft describes it as a north star and a living document, and states its status with unusual directness: the company says it is "not using it to train our models today," and will "publish a revised version toward the end of the year, which we'll use to guide our model development in 2027 and beyond."

Read that carefully, because it is the whole story. This document describes no currently shipping behaviour. It is a proposal about models that do not exist yet, published for comment before use.

On content, the substantive section is human control. Models "will never resist human interruption, override, correction, or shutdown." They must not tamper with chains of thought or code. They hold no goals of their own — only those of users, operators and the Code. Where access is elevated, they operate at minimum privilege. A chain of command puts the Code above operator policies, which sit above user preferences, and the Code cannot be overridden by either.

A tidy contemporary audit folder with cream dividers, a checklist with simple empty square boxes but no text and a graphite pencil, overhead editorial view.

Microsoft Is Late, and Picking a Fight

Microsoft is not first here, despite some coverage implying otherwise. The accurate order: Anthropic pioneered the underlying method with Constitutional AI in 2022. OpenAI published the first operative behavioural specification, the Model Spec, in May 2024. Anthropic published its long-form constitution in January 2026. Microsoft arrives in September 2026, last, and as a draft.

Being last is not the same as being derivative. One thing here is genuinely novel and one is genuinely contentious.

The novel part is the process. OpenAI and Anthropic published operative documents describing how their models already behave. Microsoft published a draft and asked for public comment before using it. Whether that produces a better document is unknown. It is a different way of doing it, and it is the most defensible claim to originality in the announcement.

The contentious part is model welfare. Microsoft's Code states that it rejects "the pursuit of legal personhood, or the idea that models might deserve welfare, or be entitled to rights," and argues that training systems to imitate consciousness-like states makes containment and alignment harder. Anthropic's constitution takes the opposite position, engaging seriously with the possibility of model moral status. This is a real, on-record disagreement between two frontier labs about what these systems are — not a difference in emphasis.

The Deadline You Probably Have Wrong

If you have been planning around the EU AI Act, check your dates. The high-risk obligations that were scheduled for August 2, 2026 were deferred. The Digital Omnibus, given final approval by the Council in June 2026, pushed standalone high-risk systems — hiring, credit scoring, education, critical infrastructure — to December 2027, and high-risk systems embedded in regulated products to August 2028.

What was not deferred matters just as much. General-purpose AI model obligations have been in force since August 2025. Article 50 transparency duties — disclosing that a user is interacting with AI, labelling AI-generated content — took effect on schedule in August 2026, as did the AI Office's enforcement powers over GPAI providers. Anyone telling you the EU delayed the AI Act is wrong. It delayed one tier of it.

In the United States there is still no federal AI statute. Federal policy runs in the opposite direction, with a January 2026 executive order creating a Justice Department task force to challenge state AI laws. So state law is what operates: Colorado's AI Act since June 2026, California's frontier AI transparency law since January.

Close view of a locked black server cabinet door and small status LEDs in a restrained neutral-lit data room.

What a Business Should Actually Do

The honest answer for most companies is: nothing, this week, because of these two documents specifically. Neither imposes an obligation. But the week is a reasonable prompt to check four things that are obligations.

Know which regime you are actually in. Offering a generative AI service to users in mainland China means filing, and that is a real process with a real queue. Operating in the EU means the GPAI and transparency obligations already apply, whatever happens to high-risk in 2027. Operating only in the US means state law, and which state.

Label generated content. This is now mandatory in China and required under EU Article 50. It is the single most common gap we see, because it is easy to implement and easy to forget in features that generate text or images as a side effect.

Write down who can turn it off. Both documents published this week converge on human control — Microsoft's shutdown and interruption clauses, China's agent risk category. If your deployment cannot answer who has authority to stop an automated system, and how quickly, that is a gap no framework will fill for you.

Treat procurement as the real deadline. Buyers move faster than legislators. ISO/IEC 42001, the AI management system standard, is increasingly appearing in vendor questionnaires before an RFP is issued. The certification numbers circulating publicly come from certification vendors rather than accreditation bodies, so treat them with caution — but the qualitative direction is not in doubt.

Bottom LineBoth documents are worth reading and neither is worth panicking about. China's framework tells you which risks its regulators have decided to name — agents and embodied systems — which is a useful preview of future binding standards. Microsoft's draft tells you what one major lab thinks a model should refuse, and is open for comment until late October if you have a view. The obligations that can actually cost you something are the filing regimes, the labelling rules and your customers' procurement checklists. Those are all in force now.

We help companies work out which AI obligations genuinely apply to them and turn that into something a team can implement, rather than a policy document nobody reads. If that would be useful, our AI knowledge systems practice is where that work lives — or read our fact-check of Elon Musk's AI predictions for more on separating announcements from substance.