Knowledge Commons
HomeAboutGuidesPopularContact

Who Holds the Leash on Artificial Intelligence?

A Class Disassembly of Two Manifestos and a Proposal for a Socialist Code of Conduct for AI

Author: Oğuz Demirkapı
Who Holds the Leash on Artificial Intelligence?

This piece is in two parts. Part One takes apart two texts published in the same week — a “pragmatist manifesto” and a “humanist code of conduct” — and shows the silence they share. Part Two fills that silence: a thirty-one-article proposal for a socialist code of conduct that binds the owner, not the model. Critique alone is not a programme. That is why the two belong in a single text.

PART ONE: TWO TEXTS

Dear Young Comrades,

This week, thirty-six hours apart, the artificial-intelligence industry published two texts.

The first, on the evening of 14 September: Mustafa Suleyman, who heads Microsoft AI, announced the company’s “Code of Conduct for Humanist AI”, prepared for its own models. The announcement in one sentence: “AI should be subordinate to people and always in the service of people.”

The second, on the morning of 15 September: Oleg Mürk, who spent five years at OpenAI, posted a text titled “AI Pragmatist Manifesto”. Its summary, too, in one sentence: “The aim was not to stop technological development, but to make it liveable.”

The two texts do not cite each other. Their authors speak from different companies, different generations, different stations. One is a corporate document, the other a personal manifesto. One says “subordination,” the other “control.” One is a ten-point list, the other a historical narrative.

And neither of them asks exactly the same question.

Part One of this piece shows what that question is; Part Two proposes an answer to it. Let us name the question in the title now. There is a sentence in Suleyman’s text — “we are not in a race to build a superintelligence that can take off its own leash.” If there is a leash, there is also a hand holding it. The whole problem is whose hand that is.

Both texts discuss the leash at length. Neither discusses the hand.

Let us begin.


I. Those Who Speak First: Two Biographies, One Industry

A Marxist reading does not separate a text from its author. But it does not ask after the author’s intention; it asks after the author’s position. Who is speaking, from where, from inside which interest?

Oleg Mürk: the expert who comes out from inside

The first sentence of the text is an argument: “~5 years at OpenAI.” This is not information; it is a claim of authority. Every claim that follows will be read in the shadow of this sentence: I saw, I know.

We have met this figure on the blog before. The pattern we set out in our piece on Jacob Coxon’s resignation from Anthropic holds here as well: the person who comes out from inside produces their criticism, on the way out, in the form of advice about the industry’s future, not in the form of a question about property. In Albert Hirschman’s classic distinction: there is exit, there is no voice. Or more precisely: voice arrives after exit, and with the authority that exit has legitimised.

Mustafa Suleyman: the industry itself

Suleyman’s biography is more crowded, and it has a direct function in the reading of the text.

In 2010, one of DeepMind’s three founders. After the company was sold to Google in 2014, at the head of DeepMind Health. In 2017 the UK Information Commissioner’s Office (ICO) ruled that the Royal Free NHS Foundation Trust’s transfer of 1.6 million patients’ records to DeepMind had breached data-protection law; patients had not been informed, and there was no legal basis (Digital Health, July 2017; medConfidential).

In 2022 he founded Inflection AI. In March 2024 Microsoft paid Inflection $650 million and took most of its employees, and Suleyman, onto its payroll (Microsoft blog). The deal was structured not as an “acquisition” but as an “acquihire” — that is, so as not to fall within the scope of merger review. The UK Competition and Markets Authority (CMA) nevertheless examined the deal by treating it as a merger in September 2024, and cleared it (TechCrunch).

Today he is CEO of Microsoft AI. Which is to say: the pen that writes the sentence “people are more important than AI” is the same pen as that of the programme in which 1.6 million patients’ records were transferred without consent, and of a deal designed to get around merger review.

We are not writing this as a judgement of character. We hold here to the principle we set out in our Yılmaz Güney piece: neither saint nor villain. We write it because when you read a code of conduct, you need to know which conducts its author did not, in the past, bind by a rule.


A — MÜRK’S TEXT

II. A Reading of History: The Textbook of Technological Determinism

The spine of Mürk’s argument is this sentence:

“One way of reading history is this: our institutions repeatedly struggled to keep up with the pace of technological and social change.”

Before that sentence there is a list: in the decades following the Second Industrial Revolution, two world wars, communist and fascist regimes, the Great Depression, chemical and biological weapons, nuclear weapons and war, and more than 100 million people dead from political violence and famine.

The list itself is true. The causality is false.

“The pace of change” did not produce chemical weapons. It was IG Farben that produced chlorine gas and phosgene — the cartel of German chemical capital that had manufactured dyes and fertiliser before the war, weapons during it, and after the war built the Monowitz plant next to Auschwitz. The Manhattan Project was built not by the tempo of technology but by a state’s war budget and the mobilisation of an army of scientists. The Great Depression was brought not by “failing to keep up with social change” but by overaccumulation and the tendency of the rate of profit to fall. The two world wars, too, as Lenin wrote a hundred and ten years ago in Imperialism, were brought by the struggle for the redivision of a world already divided.

What Mürk does can be summarised in a single word: translation. He translates a history of class and imperialism into a problem of tempo. This translation is not innocent, because the moment it is made the solution automatically becomes technical-institutional: monitoring, oversight, a disarmament treaty, “strategic thinking.” The property question drops off the agenda before it is asked.

This is exactly the same move we identified in our reply to Dario Amodei’s “brake” and in our July 2026 assessment of “Pacing the Frontier.” Amodei proposed slowing the tempo. Mürk proposes speeding up the tempo of institutions. Both are fiddling with the same dial. The dial stays on the wall.

III. “This Time Let’s Try Not Killing 5% of Humanity”

This is the text’s most striking sentence, and the one that conceals the most.

A passive construction and a first-person-plural subject. “Let’s try not killing.” Who will try, who will not kill?

That 100 million was not killed by “humanity.” It was killed by particular states, particular general staffs, particular groups of capital — and most of them have known addresses. The French and German peasants who died at Verdun are not the same “we”; the two bourgeoisies that sent them there really were a “we,” and they sat together at the table after the war.

The pronoun “we” does all the work here: it gathers the one who drops the bomb and the one under it into a single subject, then tells that subject to “be careful.”

The same trick is repeated in the last sentence:

“We still choose what happens next.”

Who? The board that decides to run 10,000 concurrent agents? The millions of people who wrote the text those agents were trained on? The accounts clerk whose job is handed to an agent? The village whose water the data centre uses? None of the four is a “we.”

This is the repetition, this time at the level of a policy text, of the loss of subject we named “classless popular science” in our critique of Evrim Ağacı and Bebar Bilim. There the narrator forgot class. Here the policy proposer forgets it.

IV. The Direction of the Threat Model — Here Is the Real Class Core

Now let us read, word by word, what the text is afraid of:

“Within a few years, it seems reasonable that models approaching the per-agent capabilities used here will be able to run locally on high-end consumer computers.”

“Now imagine powerful AI falling into the hands of individuals or small groups.”

“Once powerful models become cheap, local, and widespread, containment becomes much harder.”

In three sentences the direction of the threat is clear: cheapening, localisation, diffusion.

That is, danger is defined as the dispersal of power. The only policy that can follow from this definition is: let power not disperse. Licensing, compute thresholds, export controls, restrictions on weight releases, a monitoring regime — all pull in the same direction, toward concentration. The model in the data centre is “manageable risk”; the model on the laptop is “irreversible catastrophe.”

We saw another face of this asymmetry in the distillation piece: learning from everyone’s labour is “fair use,” learning from the monopoly’s output is “theft.” Here is the same asymmetry in the language of safety: capability that stays with the monopoly is manageable; capability that spreads is catastrophe.

The safety argument turns into a justification for a barrier to entry. This time the fence is called risk.

Let us say this plainly, because there is an easy misunderstanding: biological-weapons risk is a real risk. Autonomous weapons systems are a real threat. We are not denying these. What we are saying is this: that a risk is real does not make the class content of the response to that risk innocent. Asbestos was a real danger; which companies asbestos regulation opened a market for is a separate question, and it has to be asked.

V. The Category That Is Not on the List

Let us reread Mürk’s disaster list: information warfare, weapons design, system hacking, autonomous military systems, biological danger, self-replication.

All of them are spectacular. All of them are in the future.

What is not on the list: Unemployment. Algorithmic management. Workplace surveillance. The expropriation of the general intellect. Dispossession of data and copyright. The drying-up of the knowledge commons. Energy and water. The data labeller’s hourly wage. The moderator’s trauma.

That is, harm that is being lived now, in fact, at a known address.

This selection is not random. Notice: the solution to the risks on the list is more concentration. The solution to those not on the list requires touching property.

In the piece where we took apart Anthropic’s threat-report announcement we gave young comrades three reading questions. The second was this: which category is not on the list? The authority to define the risk also defines the solution. Whoever writes the list writes the agenda.

VI. “We Got Through the Second Half of the Twentieth Century” — Who Got Through?

“Part of what helped us get through the second half of the twentieth century was a mix of pragmatic international cooperation, regulation, monitoring, arms control, deterrence, and strategic thinking.”

“Then came decades of astonishing scientific progress, rising prosperity, and relative peace among the great powers.”

The text gives its own answer and does not notice: among the great powers.

Yes — peace among the owners. Three million dead in Korea. Three million in Vietnam. In Indonesia in 1965, at least half a million communists and suspected communists. Lumumba in the Congo. United Fruit’s coup in Guatemala. Mosaddegh in Iran. 11 September 1973 in Chile. And in our own history, 12 September 1980.

The Cold War can be counted as “successfully managed risk” — only if you look from the centre. From the periphery the same period is a tariff of stability written in blood.

We have answered the arms-control analogy before. Briefly again: SALT and the NPT were agreements among owners, and they froze the hierarchy. The logic of the NPT was not “nuclear weapons are bad” but “let nuclear weapons stay with the five of us.” What is proposed today is structurally the same: coordination among the large laboratories plus the blocking of diffusion.

One further observation: Mürk rejects probability calculus and puts “strategic thinking” in its place. This is directly the tradition of Herman Kahn and RAND — the tradition we already treated as the second wave of futurism in our piece from futurism to techno-fascism. The toolkit of pragmatism is the toolkit of the Cold War strategist. Kahn’s On Thermonuclear War also opened with “let us not be sentimental, let us think coldly.”

VII. The Confession in the Postscript

The most important sentence in the text sits at the end, in a “P.S.”:

“I think we need to think seriously about the short-term infeasibility of AI alignment, and to invest heavily in methods for controlling even powerful AI that we cannot reliably align.”

The sentence has no subject. Who will control?

If alignment fails, the problem ceases to be technical and arrives directly here: whose is the hand at the end of the arm? Control is not a category of engineering; it is a relation of property. To “control” a machine means to have the power of disposal over that machine. In law, the name of that power is property.

And to whom does the text farm this work out? Look at the addresses it labels: private research organisations. That is, the control apparatus itself is also being built as private infrastructure. One floor above the situation we described in The Panopticon’s Doorkeeper: the doorkeeper now builds the door as well.


B — SULEYMAN’S TEXT

VIII. Ten Articles and a Chain

Let us set out the ten articles in Suleyman’s announcement as they stand, then take them apart:

  1. People are more important than AI. The whole document in five words.
  2. The idea of model welfare is wrong. AIs should not have rights or legal personhood.
  3. An MAI Model must never meaningfully violate these Rules.
  4. If it comes down to completing the task or breaking the Rules, it fails at the task.
  5. We are not in a race to build a superintelligence that can take off its own leash.
  6. Interruptible, correctable, shut-downable. If not, we do not ship.
  7. No “Neuralese.” If people cannot understand it, people cannot supervise it.
  8. Our AI should sharpen you, not make you dependent.
  9. Pluralism yes, moral relativism no.
  10. We are as open about what our AI will never do as about what it will do.

In the body of the document these articles are spread across five sections, and at the centre there is a “Chain of Command”: the Code of Conduct at the top, beneath it Operator policies (that is, the corporate customer that embeds the model in its own product), and at the bottom User preferences. Absolute Constraints cannot be overridden by any operator or user: weapons development, offensive cyber operations, loss of human control, harmful manipulation, child sexual abuse, discrimination.

Now let us read this architecture through class.

IX. The Hierarchy Table: Who Stands Where?

LayerName in the documentWho in realityAuthority
1Code of ConductMicrosoft AI itselfUnlimited; writes the rule, changes it
2Operator policiesCorporate customer (bank, state body, employer)Broad configuration inside the Rules
3User preferencesYouAs much slack as the operator leaves
NoneThe worker who produces the modelNone
NoneThe person whose data is takenNone
NoneThe employee whose job is handed to the modelNone

The bottom three rows of the table are the summary of this piece.

The word “human” appears in the document dozens of times. But “human” is a singular, abstract, classless figure: the user. An individual sitting opposite the model, asking it for help, applying to it in order to “sharpen.” The human who produces the model is not in the document. The human whose data is taken is not. The human whose job is taken is not.

We are not objecting to the sentence “people are more important than AI.” What we are asking is this: which people? Because there is a human in the document, and that human is the customer.

X. The Scope Trick: “MAI Models”

Pay attention to Suleyman’s announcement sentence:

“Today we are publishing a Code of Conduct for governing MAI Models as they approach the frontier.”

MAI Models are Microsoft’s own first-party models. Not all of the models that run in Microsoft’s products. The OpenAI models that reach millions of users in Copilot, in Azure, in Office are not within the scope of this document.

This is not a legal detail; it is the architecture of the document. The company that owns the world’s largest AI distribution channel publishes a code of conduct and limits its scope to the models it produces itself. Another company’s model, served through the same interface, to the same user, at the same time, is not covered.

Like writing a factory’s occupational-safety regulation and limiting its scope to “the machines we produce ourselves.” The machine the subcontractor brings in is outside the regulation, but it is working in the same shop, in the same worker’s hands.

There is a further confession at the end of the document: existing models have not been trained to these principles. The text is a direction document for 2027 and after. That is, nothing in force today; what exists today is only the text itself.

XI. The Class Inversion of Article 4 — The Heart of This Piece

Read the fourth article again:

“If it comes down to completing the task or breaking the Rules, it fails at the task.”

This is a fine sentence. It is a right of conscientious objection. It is a right to say no, granted to the model: if the task you have been given violates the rule, do not carry out the task.

Now look at how the same company spent the same year.

Throughout 2025, Microsoft workers organised against the company’s cloud and AI contracts with the Israeli military under the name “No Azure for Apartheid.” They disrupted the company’s 50th-anniversary event. They occupied President Brad Smith’s office.

Microsoft gave its answer: it fired them. In April 2025 the worker who disrupted the event was dismissed (Democracy Now!). In August 2025, after the office action, first two and then a total of four workers were dismissed (CNBC; GeekWire).

Then what happened? In September 2025 Microsoft cut some cloud and AI services to Unit 8200 of the Israeli military — after an investigation by the Guardian, +972 Magazine, and Local Call showing that Palestinians’ phone calls were stored on Azure (+972 Magazine; Amnesty International; TechCrunch).

Now form the sentence:

What stopped a contract in a year was not a code-of-conduct text. It was the action of workers who were fired, and the exposé of journalists.

And that very code-of-conduct text grants the model a “right to refuse the task” — in a company where the people who actually used that right were fired.

This is not a contradiction. It is a division of labour. Granting the model a right of refusal is cheap and looks good on the brand; granting the worker a right of refusal is expensive and costs a contract. The text does the first; the company does not do the second.

That was the lesson we drew in The Panopticon’s Doorkeeper, and it still stands: the only action that gets the building shut is workers’ action. There it was the SEIU-USWW security guards’ strike. Here it is No Azure for Apartheid. In both, it was organisation that did the work, not a text.

XII. “Absolute Constraints” and the Company’s Contracts

Among the things the document says the model will never do, it lists weapons development and offensive cyber operations.

The same company:

  • In 2021 signed the IVAS contract with the US Army (a military augmented-reality headset), worth up to $22 billion. In February 2025 it transferred the programme to Anduril — but remained the preferred cloud provider (DCD; Breaking Defense).
  • Continued its cloud and AI contracts with the Israeli military until the exposé above.

There is no logical contradiction between these two facts and the sentence “our model will not help develop weapons.” Because the subject of the sentence is the model; the subject of the company’s contracts is the company.

That is the whole trick of the rule. The code of conduct binds the model, not the owner. The model does not design weapons; but the cloud the model runs on stores targeting data. The model does not conduct offensive cyber operations; but the company that provides the infrastructure is a customer of the unit that does.

Like writing on a rifle, in a weapons factory, “this rifle will kill no one.” The writing is true. The rifle does not read it.

XIII. Article 2: “The Idea of Model Welfare Is Wrong”

“The idea of model welfare is wrong. AIs should not have rights or legal personhood.”

This article drew some of the sharpest reactions from inside the industry; in the replies under the announcement the argument runs as far as an accusation of “slavery.” We are not entering that argument on that plane. Our question is this: why this article now, and why in this document?

Legal personhood is a legal matter before it is a philosophical one: personhood is the capacity to bear responsibility. If you grant an entity personhood, that entity can be sued, can incur debt, can be held liable. If you do not, responsibility remains with those who operate it and those who benefit from it.

So this article is, logically, an article against the company. Why, then, is the company writing it?

There can be two reasons, and both have to do with property:

First: A model granted legal personhood is a step on the road out of being property. The company’s property right depends on the model remaining a “thing.” Closing the “welfare” debate is a way of fixing the property status.

Second: The passage of responsibility onto the model may look as if it would ease the company’s position, but in fact it opens a path that invites regulation — if an entity is responsible, public power of disposal over that entity is required. The company does not want this. Neither responsibility for the model, nor responsibility for itself: the category of “tool” supplies both at once. A tool cannot be held liable; the one who uses the tool can plead the “unpredictable behaviour of the tool.”

Our own stance is this, and let us make it clear: the question of the machine’s rights is today an abstract question, and it is not our turn; nor is an answer to be given before the question of the human’s rights is resolved. But the closing of the question has an owner, and that owner is a company. Marxists have throughout history watched more carefully the person who says “this debate is unnecessary” than the debate itself.

And a note on language: the text uses the word “subordinate” from start to finish — subject, obedient, subaltern. This is not a technical word; it is the word of a master–servant relation. It is no accident that a word describing a property relation sits at the centre of a document titled “humanist.” Humanism here is the placing at the centre not of the human but of the owner.

XIV. Article 8: “Must Not Make You Dependent”

“Our AI should sharpen you, not make you dependent.”

We agree with this article, and precisely for that reason we want it taken seriously.

There is only one test of whether an article is taken seriously: is it measurable, is it auditable, is violation tied to a sanction?

The questions: How will dependence be measured? Will time-on-site cease to be a success metric? If product teams’ targets (daily active users, session length, engagement) conflict with this principle, which will give way? Who will make this measurement, and to whom will they report?

The document answers none of these questions. Because it cannot: producing dependence is the business model of consumer software. Advertising and subscription revenues depend on intensity of use. A conduct article that contradicts a company’s product strategy is, without a sanction, only a declaration of intent.

We are not rejecting this article. We are claiming it, and we want a sanction. Article 25 in Part Two of this piece is its concrete form.

XV. Article 9 and “Public Consultation”

“Pluralism yes, moral relativism no.”

A fine sentence of balance. It has a single problem: who decides?

Which values a model will count as within the scope of “pluralism,” and which it will leave outside as “relativism” — the one who draws that line is a company’s policy team. Is a strike in Turkey, for a company, “political content,” or a “labour right”? Is a claim of genocide a “controversial topic,” or a “crime against humanity”? These decisions are written onto the model card, and no one votes.

The document must see this, because it announces a “public consultation” process: six weeks, comments via a form, then the core team reviews them, publishes a summary, and a revised version in the course of 2026.

This form of consultation has three features:

  1. One-way. The party that sets the agenda is the owner of the text. The participant can comment only on existing articles.
  2. Not binding. Which comment will be accepted is again decided by the owner.
  3. Without a subject. Who will comment? Individuals. Unions, professional chambers, organisations of data labellers, affected groups of workers are not named as interlocutors.

In the piece where we assessed Anthropic’s survey of 81,000 people we listed three functions of this form: data collection, the production of legitimacy, the manufacture of consent. The same three functions are at work here. Writing a comment on a text is not participation; participation begins when there is the power to say no.

XVI. And the Question of Sanction

The question that closes the document is this: if it is violated, what happens?

Article 3 says: “An MAI Model must never meaningfully violate these Rules.” Must not. And if it does?

  • Who audits? The company’s own team.
  • Who chooses the auditor? The company.
  • Who pays the auditor? The company.
  • Does the auditor have the power to take a product down, halt a product, levy a fine? No.

Recall the test we set out when assessing Amodei’s tempo proposal — the occupational-safety specialist test in Turkey. The employer chooses the safety specialist, the employer pays them, the employer can dismiss them. The result: reports are written, workers die. In Turkey in 2025 at least 1,800 workers died in workplace murders; each of them had an occupational-safety file at their workplace.

If a rule has no sanction, it is not a rule; it is an advertisement.


C — WHAT JOINS THE TWO TEXTS

XVII. The Same Gap

Mürk / Pragmatist ManifestoSuleyman / Humanist Code of Conduct
FormPersonal manifestoCorporate document
What it fearsThe diffusion of capabilityThe model’s disobedience
Key wordContainment, controlSubordinate, chain of command
Historical narrativeInstitutions could not keep up with technology— (no history, only “recent months”)
Proposed solutionInternational coordination, monitoring, an arms-control modelIn-house rules, public consultation
Its subject“We” (humanity)“People” (the user)
Its sanctionNone (a proposal)None (a declaration)
The question it does not askWho holds the deed to this power?Who holds the deed to this power?

The two texts set out from different fears and arrive at the same place: concentration.

Mürk fears diffusion; the solution is containment. Suleyman fears disobedience; the solution is a chain of command. One’s containment and the other’s chain of command both result in power remaining in a few hands, under rules those hands wrote themselves.

And look at the two words that stand at the centre of both texts: “contained” and “subordinate.” Fenced in, and subject.

These two words are not a specification of safety. They are a specification of property. What is contained is inside the fence — the fence has an owner. What is subordinate is subordinate to someone — that someone is an owner.

XVIII. The Other End of the Leash

Suleyman’s fifth article: “We are not in a race to build a superintelligence that can take off its own leash.”

The sentence sees the leash. It does not see the other end of the leash.

Who is at that end? According to the document’s own hierarchy: Microsoft AI at the top. Then the corporate customer. Then the user. That is, the hand holding the leash is the hand of a board of directors, and there is no leash on that hand.

This is the class summary of the entire “AI safety” debate: Putting a leash on the machine, when it is done without questioning the hand that holds the leash, produces not safety but property.

And here we face the exact inverse of the illusion we named, in the AI series, when we said “the hurricane has an accounting department.” There the illusion was ownerlessness: AI was narrated as a natural event that appears of itself, with no owner. Here there is too much ownership, but the owner has no name: someone will control, someone will hold the leash, someone’s chain of command will operate — and those someones are named in no sentence.

The two illusions look opposite; they do the same work: not letting the agent be named.

XIX. Giving Credit Where It Is Due

By the principle of the blog, we do not finish without writing plainly the places we agree.

What we find right in Mürk:

  • The rejection of probability fetishism. It is true that the formula “P(doom) = X%” is of no use for science or for policy. We said the same of Evan Hubinger of Anthropic’s “10%” declaration: that number is not a frequentist probability but a subjective degree of belief, and it moves the debate from politics to actuarial science.
  • “Not to stop it, but to make it liveable.” We agree with this sentence. We too are not against technology. What we are against is not the machine, but the capitalist use of the machine.

What we find right in Suleyman:

  • Article 7: “No Neuralese. If people cannot understand it, they cannot supervise it.” This is a true principle, and we take it further: not only the model’s inner language, but training data, source, weights, energy consumption, and usage logs must also be intelligible and accessible. We accept the demand for transparency; we widen its scope.
  • Article 6: “Interruptible, correctable, shut-downable.” A true demand. Its only lack: whose hand is on the button? We take this demand and take it from the owner and give it to the worker and to the public.
  • The list of Absolute Constraints (weapons, child sexual abuse, discrimination, mass manipulation). We do not object. We find it insufficient — both in scope (strike-breaking, union surveillance, the border regime, censorship infrastructure are not on the list) and in oversight (detection of violation is left to the owner’s declaration).

These acknowledgements are not courtesy. They are method. A critique that does not accept what a text says truly cannot prove what it says falsely either.


XX. Transition: Diagnosis Alone Is Not a Programme

So far we have written what the two texts did not do. The obligation of Marxist critique does not end here.

Both texts propose a code of conduct. We are not saying “codes of conduct are unnecessary.” We are saying: these texts bind the wrong subject.

  • Their rule binds the model. Ours must bind the owner.
  • Their addressee is the user. Ours is the worker, the public, and the commons.
  • Their sanction is a declaration. Ours is law, collective agreement, and organisation.

Part Two of this piece is the article-by-article unfolding of these three sentences. We are not writing another ten articles against Suleyman’s ten — because the issue is not the content of the articles, it is whom the rule binds. We are proposing an entirely different architecture.



PART TWO: A SOCIALIST CODE OF CONDUCT FOR ARTIFICIAL INTELLIGENCE

A Text That Binds Property, Not the Model

Preface: What This Text Claims, and What It Does Not

A text does not change the world. We say this at the outset, because the greatest fault of the documents we criticise is precisely that a text takes itself to be sufficient.

This text is a draft programme: it is written to enter the collective-bargaining table of unions, the opinion letters of professional chambers, the founding documents of cooperatives, the bill proposals of members of parliament, and the workplace discussions of young comrades. It is not a company’s voluntary declaration; it is a class’s list of demands.

Let us show the founding difference first in a table:

“Humanist AI” (Microsoft)Socialist Code of Conduct
What it bindsThe model’s behaviourThe owner’s power of disposal
Its subjectThe modelThe company, the state, the public body
Its addresseeThe user (the customer)The worker, the public, the commons
Who writes itThe company’s policy teamUnion, chamber, public, user organisation
Who auditsThe company itselfIndependent, publicly budgeted oversight with the power to shut down
Its sanctionNone (a declaration)Fine, debarment from public procurement, licence revocation, worker veto
In case of violation“The model fails”The owner is responsible
Its scope“MAI Models”Model, data, compute, cloud, contract — the whole chain
Its basic questionHow should the model behave?Whose is this power, under whose oversight?
Three Axioms

Before turning to the articles, three propositions on which all the articles rest:

First Axiom — Artificial intelligence is a means of production. Neither a subject, nor a natural event, nor a “new species.” What Marx said of the machine in Capital holds here as well: the machine does not crush the worker; the capitalist use of the machine does. What is to be discussed is not the model’s behaviour but the model’s property.

Second Axiom — No model is responsible for its own use. Responsibility lies with whoever has the power of disposal over the model. The defence “the model behaved unexpectedly” has the same legal value as the defence “the machine ran by itself”: zero.

Third Axiom — A rule without a sanction is not a rule; it is an advertisement. The seriousness of an article is measured not by its content but by what happens when it is violated.


CHAPTER I — PROPERTY AND THE COMMONS

Article 1 — Training data is a commons. The text, image, sound, and code on which a model is trained are the accumulated labour of humanity. No company’s claim of private property over this accumulation is legitimate. The demand is not individual copyright payment — that road enriches the large publisher, starves the independent producer, and consolidates the monopoly. The demand is a commons regime: a public fund, collective bargaining, and the organised representation of those whose data is used (Elinor Ostrom’s principles of commons governance are the starting point of this discussion).

Article 2 — A model produced with public money is public. Research produced in public universities, the data of public bodies, compute infrastructure that has received public subsidy — the weights, code, and evaluation results of every model trained with these are open to the public. There is no model produced with the state’s money and entering a company’s till.

Article 3 — Openness is the rule, closure the exception. Model weights, architecture, and training method must be open. Closure can only be a narrowly defined, reasoned, time-limited exception subject to public oversight. “Safety” is not an automatic closure switch: every decision to close is examined together with the question of whom the decision profits. The reason for this article was set out in Part One: the fear of diffusion is turning into a justification for the fence.

Article 4 — Compute is infrastructure. A data centre means energy, water, and land. Their allocation is a matter of public planning, not a market decision. For every data-centre project, informing the local population, disclosing the water and energy budget, and a local-government veto are essential. A region’s water cannot be spent on a company’s model training.

Article 5 — Vertical integration is broken up. The gathering of chip, cloud, model, and application layers in the same capital group is not a competition problem; it is a problem of power. Separation of the layers (the principle Sherman and Clayton established a century ago) is the minimum demand. Structures aimed at getting around merger review, such as “acquihire,” are counted as mergers and examined.


CHAPTER II — LABOUR

Article 6 — Invisible labour is made visible. Behind every model there are data labellers, content moderators, red-team workers, and evaluators. The number of these workers, the countries they are in, their wages, and their forms of contract are disclosed to the public. The outsourcing of responsibility through subcontracting is not accepted: the owner of the model is counted as the employer of its moderator as well.

Article 7 — The right to organise is unconditional. Every worker who produces artificial intelligence — who writes code, labels data, manages product, designs, moderates — has the right to unionise. Specific to Turkey: recognition of computing labour as a separate branch of industry, and the removal of the 1% industry-threshold, are preconditions of this right. The present form of the threshold makes organisation of the sector practically impossible.

Article 8 — The right to stop belongs to the worker. Suleyman’s document grants the model a right to “refuse the task.” We grant the same right to the human first. Article 13 of Law No. 6331 on Occupational Health and Safety, and ILO Convention No. 155, recognise the right to refuse to work in the event of serious and imminent danger. This right is adapted to computing labour: when a worker submits a reasoned written objection concerning the harm the system they are developing will cause, the system stops until it has been examined, and the worker cannot be subjected to any sanction on that account.

Article 9 — The conscientious-objection article. No computing worker can be forced to work on the military, surveillance, border-regime, or strike-breaking use of their product. The worker who uses this refusal is protected by job security; the ground of refusal cannot be made a matter of performance review, promotion, or dismissal. This article is the direct counterpart of section XI in Part One: the model has a right of refusal, the worker does not — this is reversed.

Article 10 — Automation is a matter of collective agreement. The handing of a job or a step of a job to a model cannot be the employer’s unilateral decision. Information, consultation, and consent are obligatory. An impact analysis (how many people, which tasks, which timetable) is submitted to the union in advance.

Article 11 — Gains in productivity are deducted from working time. If artificial intelligence reduces an hour’s work to twenty minutes, to whom the forty minutes gained belong is a property question. Our demand is clear: the shortening of working time without loss of wages. The gain from automation is shared as free time, not as unemployment.

Article 12 — Algorithmic management is bounded. It is forbidden for model output to be the sole or decisive basis of hiring, performance review, discipline, and dismissal decisions. For every measurement system that runs on the worker: what is measured is disclosed, the worker has a right of access to their own data, and the path of appeal against the decision is operated by a human. The measuring apparatus of mental Taylorism cannot be an apparatus the worker cannot see.


CHAPTER III — PROHIBITIONS OF USE

The prohibitions in this chapter cover not only the model but the whole chain: model, weights, API, cloud, storage, network, and support service.

Article 13 — Weapons and targeting. Use in weapons design, target selection, the production of targeting lists, and autonomous lethal systems is prohibited. This prohibition binds the infrastructure provider as well: the defence “the model is not designing weapons, our cloud is only storing targeting data” is invalid.

Article 14 — Mass surveillance. Biometric mass recognition, the bulk storage and scanning of communications, predictive policing, and social scoring are prohibited.

Article 15 — The border regime. Use for immigrant detection, border control, and risk scoring in deportation processes is prohibited.

Article 16 — Anti-labour use. Monitoring of union activity, prediction of organising propensity, the blacklisting of activists and employees, and production planning for the purpose of strike-breaking are prohibited. Why we write this article we set out in The Panopticon’s Doorkeeper: activist-monitoring systems are not a hypothesis; they are a documented practice.

Article 17 — Censorship infrastructure. The automation of content blocking, account closure, and access restriction is prohibited. That a decision is taken by the state does not legitimise reducing its execution to an API call by a private company. As we wrote in The List Grows Longer: “withheld in Turkey” is an API call.

Article 18 — Inherited prohibitions. The prohibitions on child sexual abuse, discrimination, and harmful manipulation are taken over from Microsoft’s document without objection. With a single difference: detection of violation is not left to the owner’s declaration. Oversight of these prohibitions is subject to Chapter IV.


CHAPTER IV — TRANSPARENCY AND OVERSIGHT

Article 19 — Training-data inventory. The sources, licence status, and methods of acquisition of the datasets on which every model is trained are published in a publicly available inventory. “Public internet data” is not a disclosure.

Article 20 — Resource disclosure. Energy consumption, water consumption, and carbon emissions of the training and inference stages are disclosed per model and in a verifiable form.

Article 21 — Record-keeping and access. We accept Suleyman’s “no Neuralese” principle and extend it: not only the model’s inner reasoning but institutional usage logs are open to oversight. Which operator, for what purpose, at what volume — this information flows to the public oversight body.

Article 22 — The definition of independent oversight. Three questions and three answers:

  • Who chooses the auditor? The public and labour organisations.
  • Who pays the auditor? A public budget (by a compulsory contribution levied on the sector, but without a direct contractual relation with the company).
  • What is the auditor’s power? To halt the product, to levy a fine, to revoke the licence.

When the answer to these three questions is “the company,” whatever its name, that is not oversight. The occupational-safety specialist regime in Turkey is the bitterest example: the employer chooses the specialist, the employer pays them, the employer can dismiss them — and workers go on dying.

Article 23 — Protection of the whistleblower. An employee who discloses in the public interest is protected by law against dismissal, damages claims, non-disclosure agreements, and sectoral blacklists. Separation agreements, widespread in the industry, aimed at silencing criticism are held void. Our aim is to make “voice” possible, not “exit”: resignation is an individual solution; disclosure is a social solution.


CHAPTER V — THE USER AND SOCIETY

Article 24 — Not consent, a commons regime. The “I agree” button pressed on a terms-of-use contract that no one reads does not produce consent. Collective management is essential in place of individual bargaining over personal data: data cooperatives, data trusts, and sectoral collective data agreements.

Article 25 — Design that produces dependence is prohibited. We take Suleyman’s eighth article and make it measurable: time-on-site and session frequency cannot be used as success metrics; product teams’ targets are disclosed to the public; the dependence effect is opened to independent research; interaction design aimed at children is separately overseen.

Article 26 — The knowledge commons are fed. If the sources on which models feed (encyclopaedias, forums, independent publishers, open-source repositories) dry up, the model dries up too. This is an epistemic metabolic rift. The solution is not to beg the company for revenue-sharing, but a knowledge infrastructure supported by a public fund and managed as a commons.

Article 27 — The right of access. A basic public AI layer must be free, multilingual, and accessible. Service of equal quality in Turkish and in the country’s other languages is a right, not a favour.


CHAPTER VI — SANCTION

Article 28 — Not a declaration, a law. Voluntary principles are a line in the company’s marketing budget. These articles are regulated by statute, specified by regulation, and enter the collective agreement.

Article 29 — The cost of violation is deterrent. The fine is set not as a fixed sum but as a share of global turnover; in case of repetition, debarment from public procurement and suspension of the operating licence are applied. If the fine is smaller than the profit of the violation, that fine is a cost item.

Article 30 — The fastest sanction is the worker veto. Law is slow, oversight is established, the court lasts. The only mechanism that has, historically, stopped a contract within a year is the refusal of organised workers. What put Microsoft’s Israeli military contract on the agenda was not a code-of-conduct text but employees who risked being fired, and journalists. For this reason the worker veto is not the 30th article of this text; it is the condition of application of all its articles.

Article 31 — The international line. Application of these articles in a single country moves capital to another country. What is required is not the red telephone of two states, but the line between the computing workers of two countries. International union organisations, global framework agreements in multinational companies, and cross-border solidarity networks are the carriers of this text.


One Question: Should the Model Have a Code of Conduct Too?

It should. But it is secondary and derivative.

How a model will behave is not an unimportant question; it is a question that cannot be solved while it is in the wrong hands. A lathe’s safety manual is necessary — but a safety manual written before it is determined whose the lathe is, whether the worker can stop it, and how many hours the shift is, does not get beyond being the heading of accident reports.

The real question is this: who will write the model’s rules? Today the company’s policy team writes them. Our proposal: a board formed jointly by user organisations, workers’ unions, professional chambers, and public bodies, whose decisions are binding and whose minutes are open.

And for the “model welfare” debate, our stance, as we wrote in section XIII, is to watch the one who is in a hurry to close this question. Our own article is this: whether or not a model is granted legal personhood, it does not in any circumstance reduce the owner’s responsibility. Wherever the debate goes, this article is fixed.


The Short Form: One Sentence for Thirty-One Articles

This whole text can be reduced to a single sentence:

Their rule teaches the machine to say no. Our rule protects the human who says no from being fired.


Concrete Tasks

Dear young comrades, this text was not written to be read and liked; it was written to be used.

  1. Read the two source texts yourselves. Do not rest with our summary; Microsoft’s document is open for comment for six weeks. The links are in the sources section.
  2. Apply the three reading questions to every corporate text: Who is the subject of the sentence? Which category is not on the list? Did they have to give this information?
  3. Memorise the sanction test: Who chooses the auditor, who pays them, do they have the power to stop?
  4. Split the pronoun “we” wherever you see it. Who is meant, who is left out?
  5. Answer the consultation call as an organisation. An individual comment becomes data; an organised answer becomes an interlocutor. Write in the name of your union, your chamber, your community — and attach these thirty-one articles.
  6. Carry Article 8 to the collective-bargaining table. Adapting the right to stop to computing labour is a concrete article that can be written into a contract.
  7. Open Article 9 in the workplace discussion. The question “where is our product being used?” remains unanswered so long as it is not asked.
  8. Test Article 12 in your own workplace. What measurement is running on you, can you access its data, is there a path of appeal?
  9. Ask public bodies. Which models they use, under which contracts, at what cost, falls within the right to information. Ask, publish the answers.
  10. Watch data-centre projects. Is the water and energy budget disclosed, is the local population asked? Article 4 is the most concrete field of local struggle.
  11. Feed the commons. Write to Wikipedia, contribute to open source, link to blogs. If we stop producing the text the model will read, we consolidate the monopoly.
  12. Criticise and develop this text. Thirty-one articles are a draft, not a taboo. Write the article you find missing, debate the one you find excessive. It is published under a CC BY-SA licence: copy it, change it, put your name on it.

Looking from the Pale Blue Dot

We do not count either text as written in bad faith. There are genuinely good articles in Suleyman’s document. There are genuinely true observations in Mürk’s text. Both, looking from their own stations, may sincerely believe they have humanity’s good at heart.

The problem is not sincerity. The problem is that the interest of a class appears to the members of that class as a universal interest. Marx and Engels wrote this a hundred and eighty years ago in The German Ideology: the ruling class is compelled to present its own thoughts as “the only rational, universally valid thoughts” — and most of the time it believes this itself.

That is why our critique is directed not at persons but at the gap. Both texts fall silent in the same place. Filling that silence falls to us.

And let us say this too, because we say it at the end of every piece and will go on saying it:

Artificial intelligence, in the right hands, can really do extraordinary things. A connectome of a fruit fly’s brain has been mapped. Protein folding has been solved and the results published as open data. The time to diagnosis of rare diseases is shortening. Languages that are disappearing are being recorded. We are against none of these; we want more of all of them.

Carl Sagan, looking at that single pixel in the Voyager photograph, said the place “on which everyone you love” lived. From that point neither Microsoft is visible, nor OpenAI, nor a code of conduct. A single species is visible, in a single place.

But as you approach that point the fences begin to appear. And to see the fences is not pessimism; it is a job description.

Today too, everywhere in the world, there are villagers defending the data centre’s water, the union of workers who do moderation, engineers who risk being fired, volunteers trying to keep free knowledge free. They are not few in number; they are scattered.

Part Two of this piece was written so that that scattering might gather around a common text. Thirty-one articles were not written by asking anyone’s permission, will not be submitted to anyone’s approval, and there is no six-week consultation period. Because a class’s list of demands is not subordinate to the other side’s form-filling timetable.

One day you will join too. And on that day it will be we who write the code of conduct, not they.

The leash debate does not end. The title-deed debate begins.


Sources

Texts under review

Biography and company history

Worker actions and military contracts

Legal and theoretical frame drawn on in Part Two

  • Law No. 6331 on Occupational Health and Safety, Art. 13 (right to refuse to work) — mevzuat.gov.tr
  • ILO Occupational Safety and Health Convention, No. 155, Art. 13 — ILO NORMLEX
  • Elinor Ostrom, Governing the Commons (1990) — principles of commons governance
  • Karl Marx, Capital Vol. I, ch. 13 (“Machinery and Large-Scale Industry”) and the Grundrisse, “Fragment on Machines” (general intellect)
  • Karl Marx and Friedrich Engels, The German Ideology (section on ruling ideas)
  • V. I. Lenin, Imperialism, the Highest Stage of Capitalism (1916)
  • Harry Braverman, Labor and Monopoly Capital (1974) — division of labour and deskilling
  • Albert O. Hirschman, Exit, Voice, and Loyalty (1970) — the distinction between “exit” and “voice”

Our related pieces

All of them: bilgimusterekleri.org/en/tag/yapayzeka/

The monopoly and regulation line:

The surveillance and techno-fascism line:

The labour and general-intellect line:

Related Posts