Microsoft has introduced Project Perception, a new agentic cybersecurity system designed to detect risks, investigate threats and coordinate defensive actions at machine speed.

The company also announced MAI-Cyber-1-Flash, its first AI model developed specifically for cybersecurity. The compact model was built to identify difficult vulnerabilities hidden inside large and complex software codebases.

Project Perception brings together security data, AI models and teams of specialized software agents. Rather than relying on a single model or producing more security alerts, the platform is designed to continuously assess risks, determine which threats require attention and initiate corrective actions while keeping human security teams in control.

Red, blue and green AI agents

Microsoft has divided the system’s autonomous agents into three groups.

Red-team agents examine digital environments from an attacker’s perspective and search for potential routes into a system. Blue-team agents investigate suspicious activity and evaluate whether it represents a meaningful risk. Green-team agents then take corrective action and strengthen the organization’s defenses.

Together, these agents create a closed-loop security system that can discover vulnerabilities, assess their severity and improve protections continuously.

MAI-Cyber-1-Flash will initially operate inside MDASH, Microsoft’s multi-agent framework for identifying, validating and repairing software vulnerabilities. MDASH includes more than 100 specialized agents and can assign different models to different stages of a security task.

Microsoft claims 96 percent benchmark performance

According to Microsoft, an MDASH configuration combining MAI-Cyber-1-Flash with GPT-5.4 achieved a 96 percent success rate on CyberGym, a benchmark based on finding real vulnerabilities in large codebases.

The company said the result was 12 percentage points higher than Mythos. Microsoft also reported that the configuration reduced costs by approximately 50 percent compared with its current MDASH setup.

MAI-Cyber-1-Flash handles as much as 90 percent of the system’s workload, while more powerful and expensive models are reserved for the most difficult tasks. This multi-model approach is intended to balance accuracy, speed and operating costs. The performance and cost figures were published by Microsoft and have not yet been widely confirmed through independent testing.

Project Perception is scheduled to enter public preview on August 3, 2026. Microsoft says the platform will eventually use MAI-Cyber-1-Flash across a broader range of cybersecurity operations beyond software vulnerability management.