IT Brief Canada - Technology news for CIOs & IT decision-makers
Canada
Microsoft revamps responsible AI rules amid agentic risks

Microsoft revamps responsible AI rules amid agentic risks

Tue, 1st Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Microsoft has published its 2026 Responsible AI Transparency Report, outlining updates to its governance, tools and partnerships around artificial intelligence.

The report identifies three areas of investment over the past year: adaptive governance and technical risk management, practical tools, and shared practices with external partners. Microsoft said those efforts were shaped by five market trends: faster AI adoption, the spread of generative and agentic systems, growing public use of conversational AI, rising misuse, and rapid regulatory change.

It has revised its Responsible AI Standard to reflect changes in the AI technology stack and the different roles it plays in developing and deploying models, platform services and applications. The updated framework combines requirements that apply in all cases with more specific rules for particular scenarios.

The change comes as developers and policymakers focus more closely on systems that can retain memory, use tools, access data and take actions for users. Microsoft said this has pushed its internal work beyond reviewing individual models and applications toward monitoring interactions among models, agents, tools, data and people.

In practical terms, the group is placing greater emphasis on controls such as agent identities, tool permissions and action monitoring. It has also trained thousands of engineers and product managers on issues including agentic AI threat modelling and defences against prompt injection.

Governance changes

Some of Microsoft's strictest risk management measures now apply to AI systems with significant cyber uses. It said those controls are intended to ensure advances in AI support defenders responsible for securing digital infrastructure.

Microsoft also linked the governance overhaul to the emergence of agentic AI, which it described as a class of systems whose risks can change as they interact with users, environments and other systems. That, it said, requires more continuous oversight across a product's lifecycle rather than a single review before release.

A second strand of the report focuses on tools for developers and customers. Microsoft said organisations need ways to identify risks, evaluate systems, establish controls and monitor behaviour in live use as technical and regulatory demands become more complex.

Among the products highlighted are an AI Red Teaming Agent for identifying and testing risks, agent evaluators for measuring safety and quality in agent-based applications, and RAMPART, a tool designed to turn red team findings into repeatable tests. Microsoft also pointed to ASSERT and Agent Control Specification as tools for testing agents against internal policies, setting controls during workflows and monitoring behaviour.

The emphasis on operational oversight reflects a wider shift in the AI market. As businesses move from experimenting with chatbots to deploying systems that can carry out tasks across software tools and datasets, scrutiny is shifting to how those systems behave once they are running, not just how they perform in pre-release testing.

Microsoft also used the report to highlight external certification work. It said it is certified against ISO 42001 across products including Microsoft 365 Copilot, Foundry and GitHub Copilot, and has simplified the internal processes that support that certification.

External links

Beyond its own systems, Microsoft said responsible AI governance depends on shared standards and research across the sector. Increasingly interconnected AI products make collaboration necessary across borders and industries, it added.

Over the past year, Microsoft has worked with the US Centre for AI Standards and Innovation and AI Safety and Security Institutes in Australia, Singapore and the UK on AI evaluation. It also launched an External Red Team Alliance with 18 universities across six continents to expand research into priority risks.

It added that it is involved in work through the Frontier Model Forum, OpenTelemetry and the Appia Foundation on cyber benchmarks, observability for agentic systems and AI assurance across supply chains and sectors. Microsoft also said it has contributed to an OECD-led informal task force behind version 2.0 of the Hiroshima AI Process Reporting Framework.

Another area of focus is measurement. Microsoft said common benchmarks are needed because organisations cannot compare progress meaningfully if they assess AI risks in different ways. Through its work with MLCommons, it said it is helping expand AILuminate into a broader set of reliability benchmarks covering areas such as jailbreak resilience, multilingual performance and psychosocial risk in conversational AI.

Natasha Crampton, Chief Responsible AI Officer at Microsoft, said the company sees responsible AI as an ongoing operational task rather than a fixed compliance exercise. "Our experience over the past year has reinforced that responsible AI cannot be static. It has to be embedded in development processes, supported by practical tools, and continually informed by what we learn," Crampton said.

She said the company's work now spans internal development, customer-facing tools and industry collaboration. "That is why our responsible AI investments extend from the systems we build, to the tools we provide our customers, to the research, practices, and measurement approaches we help develop with the broader ecosystem," Crampton said.