Microsoft introduced MAI-Cyber-1-Flash on July 27, its first cybersecurity-specialized AI model, alongside Project Perception, a new agentic system built to defend networks at machine speed, the company said.

Paired with OpenAI’s GPT-5.4 inside Microsoft’s MDASH vulnerability-management system, the combination scored 96% on the CyberGym benchmark for finding flaws in large codebases — 12 points above Anthropic’s Mythos model, according to Microsoft — while cutting the cost of running MDASH by roughly half compared with its earlier GPT-5.4-only setup.

A Model Built to Handle the Routine Work

MAI-Cyber-1-Flash descends from Microsoft’s MAI-Thinking-1 model family and was trained in-house on what the company describes as more than 100 trillion daily security signals drawn from identity, endpoint, cloud and network telemetry across its products. Inside MDASH, it is designed to resolve about 90% of routine vulnerability-hunting tasks on its own, leaving the costlier GPT-5.4 to handle only the hardest cases. Microsoft frames the split as a response to attack volumes growing faster than security teams can hire to match.

Project Perception Adds Autonomous Response

Project Perception organizes AI agents into three roles: red-team agents that simulate how an attacker might move through a network, blue-team agents that investigate and prioritize the risks those simulations surface, and green-team agents that carry out the fixes. “The defining characteristic of the next generation of security systems will not be their ability to generate more alerts,” Microsoft Security executive vice president Hayete Gallot wrote in the announcement. “It will be their ability to continuously perceive, reason and act.” The platform enters public preview on August 3.

The launch puts Microsoft in more direct competition with rivals that have shipped their own security-focused AI tools this year, including Anthropic’s Claude Security plugin. It also lands amid growing scrutiny of AI-agent security generally, after a sandbox-escape flaw was recently found in a rival AI coding tool — the kind of failure Microsoft’s red-team-blue-team design is meant to catch before real attackers do.