Microsoft has unveiled Project Perception, a new agentic cybersecurity system, alongside MAI-Cyber-1-Flash, its first AI model built specifically for software vulnerability analysis. The company claims that the new cybersecurity model outperforms Gemini and GPT on vulnerability-detection benchmarks while reducing operational costs by 50%.The announcements come as Microsoft says AI is changing the pace and scale of cyberattacks, requiring security teams to move beyond traditional approaches. According to the company, MAI-Cyber-1-Flash, when integrated into its multi-agent vulnerability identification and remediation system (MDASH), achieved 96% on the CyberGym benchmark, outperforming Mythos, Gemini and GPT-based configurations while lowering costs compared with its current deployment.
Project Perception brings AI agents together for cyber defence
Project Perception is Microsoft’s new agentic security system designed to help organisations continuously identify, assess and reduce cyber risks across their digital environments.The platform coordinates three specialised categories of AI agents:
- Red agents, which identify potential attack paths and software vulnerabilities before they are exploited.
- Blue agents which investigate findings, analyse security context and determine which risks require attention.
- Green agents, which take corrective actions and strengthen an organisation’s security posture.
Microsoft said the system combines security signals, threat intelligence, AI models and autonomous agents into a continuous workflow that helps organisations move from reactive incident response to ongoing risk reduction.
MAI-Cyber-1-Flash focuses on software vulnerabilities
Alongside Project Perception, Microsoft introduced MAI-Cyber-1-Flash, describing it as its first cybersecurity-specialised AI model. The compact model has been developed for software vulnerability analysis and forms part of Microsoft’s broader multi-model strategy, which combines specialised AI models with larger frontier models depending on the security task.According to Microsoft, MAI-Cyber-1-Flash handles approximately 90% of software vulnerability analysis tasks, allowing larger AI models to be reserved for more complex cases.The company said the combined MDASH with MAI-Cyber-1-Flash configuration achieved 96% on CyberGym, which it described as an industry benchmark for evaluating how AI systems identify vulnerabilities across large software codebases. Microsoft added that the result was 12 percentage points higher than Mythos and ahead of Gemini and GPT-based systems while delivering 50% lower costs than its current MDASH configuration.
New Cyber Stack built around AI
Microsoft said Project Perception is built on what it calls a New Cyber Stack, consisting of six layers:
- Signals and sensors
- Security context
- AI models
- Harness
- Agents
- Actuators
According to the company, these layers work together to collect security signals across identities, endpoints, cloud services, applications, data and AI systems before transforming them into context that AI agents can use to identify risks and recommend or take corrective actions.Microsoft said the system uses a multi-model architecture that selects different AI models based on factors including quality, reliability, latency and cost instead of relying on a single model for every cybersecurity task.
Public preview starts next month
Microsoft said Project Perception will enter public preview on August 3. The company also said MAI-Cyber-1-Flash will initially be used inside MDASH for software vulnerability management before expanding to additional security workflows within Project Perception.Microsoft said the cybersecurity model has been evaluated by its AI Red Team, tested through automated and expert-led adversarial exercises, and assessed by an independent third party. The company added that MDASH includes enterprise controls such as role-based access controls, tenant isolation, encryption, audit logging and sandboxed execution environments without internet access.Explaining the motivation behind the announcements, Microsoft said, “The physics of cybersecurity are changing. Autonomous systems can now reason, adapt and operate continuously. At the same time, the cost of offence is falling, while the volume, velocity and complexity of what must be secured continues to grow.”
