Microsoft Introduces Project Perception and MAI‑Cyber‑1‑Flash to Power Agentic Security

Microsoft has announced a sweeping evolution of its security strategy with the introduction of Project Perception, a next‑generation agentic security system built for the realities of AI‑accelerated cyber threats. Alongside it, the company unveiled MAI‑Cyber‑1‑Flash, a specialized cybersecurity model integrated into its multi‑agent vulnerability harness MDASH, delivering world‑class performance at half the cost of leading models. Together, these advancements signal a decisive shift toward autonomous, continuously learning defense systems designed to counter attackers operating at machine speed.

The announcement comes as organizations worldwide confront a new physics of cybersecurity. Autonomous systems can now reason, adapt, and operate continuously, while attackers leverage AI to generate exploits faster, scale campaigns further, and probe vast codebases with unprecedented efficiency. Traditional security approaches—built for human‑paced workflows—are no longer sufficient. “Security needs a new cyber stack,” Microsoft notes, one capable of perceiving risk across the digital estate, reasoning over massive context, and acting at machine speed while keeping humans firmly in control.

Project Perception is Microsoft’s answer to this new era. It is an agentic security system that unifies signals, context, models, and specialized agents into a continuously learning loop. Its core design is based on a simple but powerful idea: effective defense requires understanding how attackers see the world, how defenders evaluate risk, and how protections improve over time. To achieve this, Perception coordinates three classes of agents—Red, Blue, and Green—each performing specialized roles in discovery, investigation, and remediation.

Red team agents identify potential paths to compromise before attackers can exploit them. Blue team agents investigate and reason over context to determine meaningful risk. Green team agents take corrective actions and strengthen defenses across the environment. Together, they form a closed‑loop system that continuously discovers, evaluates, and improves an organization’s security posture.

The system’s effectiveness is rooted in Microsoft’s unparalleled visibility across identities, endpoints, applications, data, clouds, and AI systems. This breadth of signals feeds into a rich “security context”—a continuously updated representation of assets, identities, relationships, risks, and activities. This context gives agents immediate, token‑efficient access to the information they need to reason accurately and act consistently.

Project Perception also adopts a multi‑model architecture, selecting the right model for each security task based on quality, reliability, latency, and cost. This ensures sustainable, always‑on protection at scale. The system enters public preview on August 3.

Complementing Project Perception is MAI‑Cyber‑1‑Flash, Microsoft’s first specialized cybersecurity model. Integrated deeply into MDASH—its multi‑agent vulnerability identification and remediation harness—the model is designed to find challenging vulnerabilities in complex codebases with exceptional efficiency.

MAI‑Cyber‑1‑Flash delivers 96% performance on CyberGym, the industry’s gold‑standard benchmark for reasoning over large codebases, outperforming Mythos by 12 points. It also enables MDASH to operate at 50% of the cost of previous configurations by handling up to 90% of tasks, reserving larger frontier models like GPT‑5.4 for the most difficult 10%. This multi‑model optimization ensures defenders always have the best model at the best price.

The model is built on Microsoft’s unmatched historical training data—decades of real exploits, remediations, and trillions of daily signals across identity, endpoint, cloud, and network. It is hardened through rigorous AI Red Team evaluation, adversarial testing, and third‑party assessment, and deployed with enterprise‑grade controls including role‑based access, tenant isolation, encryption, and sandboxed execution environments.

The architecture behind MAI‑Cyber‑1‑Flash is further illuminated in an interview with Taesoo Kim, Microsoft’s VP of Security Research and leader of the new Microsoft Security FORGE Labs. Kim explains how MDASH orchestrates more than 100 specialized agents—each with fine‑grained scopes—to find, validate, and remediate vulnerabilities. Agents debate findings, validate exploitability, and generate proofs, ensuring high‑fidelity results before human review.

MDASH integrates traditional program analysis techniques with agentic reasoning, combining fast static tools with deep LLM‑based analysis. It also feeds high‑confidence signals into Project Perception, enabling the broader system to understand how vulnerabilities manifest in real environments.

Kim emphasizes that this is the first moment in his career where defenders may finally gain the upper hand. With systems like MDASH and Project Perception, organizations can identify and eliminate vulnerabilities before attackers ever see them—potentially reversing the long‑standing asymmetry of cybersecurity.

With Project Perception and MAI‑Cyber‑1‑Flash, Microsoft is redefining what modern cybersecurity looks like: autonomous, continuously learning, multi‑model, and deeply integrated across the digital estate. As AI accelerates both offense and defense, these systems aim to ensure defenders can perceive, reason, and act at machine speed—while maintaining the oversight, governance, and trust enterprises require.