Microsoft entered the AI cybersecurity arena on July 27 with MAI-Cyber-1-Flash, a specialized model designed to uncover vulnerabilities in complex codebases.
That is not enough though: they also launched Perception, an agentic platform that deploys teams of AI agents to identify, prioritize, and fix security flaws at machine speed.
The model itself targets a real problem that has plagued security teams for decades. Finding dangerous vulnerabilities in thousands of lines of code requires specialized human expertise, patience, and time. Security teams spend hours manually hunting for exploitable gaps, often working nights and weekends during vulnerability discovery cycles.
MAI-Cyber-1-Flash automates that exhausting hunt by understanding code architecture and threat patterns that expose systems to attack. For the first time, security teams have a partner that doesn’t tire.
But the bigger innovation sits in Perception, the platform that orchestrates responses across three types of AI agent teams. Red teams simulate realistic attack scenarios, modeling the behavior and targeting patterns of potential threat actors.
This simulation work surfaces which vulnerabilities a particular attacker would most likely exploit. Blue teams then detect and triage existing bugs within the organization’s systems, prioritizing based on real risk rather than requiring humans to make judgment calls under time pressure. Green teams execute corrective actions, generating and implementing code fixes to close the gaps. The entire workflow transforms what was once a fragmented, exhausting process into a coordinated operation where each component reinforces the others.
Dave Weston, the lead engineer for Perception, told the launch event that work consuming hours across multiple specialized security roles now completes in minutes. Discovery, prioritization, detection, posture fixing, and code remediation all collapse into a compressed timeline. That efficiency matters enormously because the threat landscape has inverted.
Hackers are already using AI to automate their attacks. Defenders who are still hunting vulnerabilities manually are falling behind. More importantly, smaller organizations and enterprises without massive security budgets can now compete with well-resourced teams. A startup with two security engineers can deploy Perception and achieve coverage that previously required a team of ten.
Microsoft claims MAI-Cyber-1-Flash outperforms competitors on Cyber Gym, an established benchmark for AI cybersecurity models. The company’s benchmarking shows it defeating OpenAI’s offerings, Google’s Gemini, and Anthropic’s Mythos 5.
“We’re very very excited to announce our results,” said Mustafa Suleyman, the co-founder of DeepMind and current CEO of Microsoft AI. “We have MAI-1 Cyber Flash binded [sic] with GPT 5.4 inside of the MDASH harness — which beats out Gemini, GPT 5.5 Cyber, GPT 5.6 Sol, and Mythos 5 on Cyber Gym, which is the primary benchmark that we all use. The golden benchmark. We’re shipping this into production immediately.”
Security teams working with Perception shift from reactive firefighting to strategic thinking. Instead of spending their days on repetitive vulnerability hunting, analysts can focus on understanding business risk. It would also help them understand threat actor motivation, and organizational vulnerabilities that technology alone cannot address. The platform elevates human judgment by handling the computational overhead, freeing specialists to do the work only humans can do effectively.
Perception enters public preview on November 3 as Microsoft competes directly with Anthropic’s Glasswing program and OpenAI’s Daybreak initiative.
