Microsoft Steps Up AI Governance Amid Growing Agentic Risks
Microsoft has published its third annual Responsible AI Transparency Report, detailing changes to its governance of generative and agentic AI. The report highlights revisions to Microsoft's internal Responsible AI Standard as AI systems become more complex and scrutiny of their safety, reliability, and oversight increases.
The revised framework combines baseline requirements with scenario-specific rules that can change as technical risks and regulatory demands shift. This approach reflects a broader effort to adapt governance to AI systems that can retain memory, use tools, access data, and act on behalf of users.
Microsoft's controls now place greater emphasis on agent identities, tool permissions, and the monitoring of actions taken by AI systems. The company has also simplified and strengthened its internal processes for supporting certification against ISO 42001, which it has achieved across products including Microsoft 365 Copilot, Foundry, and GitHub Copilot.
Microsoft provided responsible AI training to nearly 20,000 engineers, policymakers, and customers over the past year. The company also developed several internal and external tools intended to help developers test and monitor AI systems, such as an AI Red Teaming Agent and a system called RAMPART that converts red-team findings into repeatable tests.