
Microsoft this week detailed its most ambitious AI security initiative backed by a range of tools including its first specialized cybersecurity model, three layers of security agents, and an agentic harness that selects the best AI model for the security requirement at hand.
Like the broader cybersecurity industry, Microsoft’s Project Perception deploys AI to combat attackers who are exploiting the tech to breach corporate security protections and scale offensive attacks with high efficiency.
Microsoft and security industry competitors are pushing to realize what cybersecurity expert Chris Hughes labeled the “industrialization of vulnerability discovery” in a LinkedIn post, while noting there’s a quickly developing category that’s also populated by Cisco, Wiz, and Anthropic.
There are increasing indicators that those firms deploying AI for defensive purposes are making inroads against the expanding AI-powered threats. New IBM research finds those tapping AI and automation are reducing breach response time by 65 days and lowering the average cost of a breach by nearly $2 million.
Stronger Security Perception
Microsoft explains Project Perception as a defensive system bringing together signals, context, AI models, and specialized agents that can reason, prioritize, and act to keep pace with AI-powered attackers. At launch, Project Perception brings multi-agent defense into Microsoft’s Defender platform. Over time, Perception will extend across Microsoft security products, the company said.
Project Perception includes a new – the company’s first – dedicated cybersecurity model called MAI-Cyber-1-Flash which, when working with the company’s MDASH multi-agent security harness, delivers what the company characterizes as industry-leading scores on the CyberGym benchmark that is quickly emerging as the industry’s key performance measure.
MAI-Cyber-1-Flash in MDASH finds vulnerabilities in complex codebases, and it should handle up to 90% of all security tasks, said Mustafa Suleyman, CEO of Microsoft AI in a LinkedIn post. The agentic harness will tap larger and more costly models for the remaining 10% of tasks that require them.
Model options are central to Project Perception, which determines the right model based on the combination of quality, reliability, latency and cost – while optimizing for effectiveness and economics. The model flexibility in security is consistent with Microsoft’s overall approach to embracing third-party AI models while developing its own as well.
Another core element in Project Perception: specialized agents. The three agent classes work together to reason across security data, tools, and workflows to investigate and remediate threats. “Red team agents” identify potential paths to compromise before an attacker can exploit them. “Blue team agents” investigate, reason over context, and determine what represents meaningful risk that must be addressed. “Green team agents” take corrective actions and strengthen defenses across the data and agent estate.

Microsoft described Project Perception in the form of a new cybersecurity stack. In that stack, signals and sensors provide awareness across the digital estate spanning endpoints, identities, and clouds. Security context transforms signals into token-efficient understanding that agents can use. Models provide intelligence and reasoning as detailed above. The MDASH harness coordinates models and agents across workflows while agents apply intelligence across security workflows. “Actuators” are the mechanism an agent uses to take action, turning a conclusion into security protections. Each layer of that stack learns continuously for better security outcomes.
Project Perception enters public preview on Aug. 3. Costs are based on consumption measured in Security Compute Units (SCUs). As agents run scenarios in the portal, they consume SCUs, and more intensive tasks consume more SCUs.
In analyzing the broader “categorization” of AI-powered vulnerability management, security expert Chris Hughes noted that finding vulnerabilities with new platforms such as Project Perception is becoming cheaper and easier, while the real challenge remains what to do with all that data and insight. “Triaging, prioritizing, and actually burning down what these systems surface at scale is the part our industry still has not solved.”
With Project Perception, Microsoft is moving to deliver on that “burning down” requirement, and we’ll closely monitor future developments to update its progress.
More AI Security Insights:
- Purview, Entra Gain Real-Time Control Over AI and SaaS Data
- Customers Lack Confidence in Agents for Security
- Microsoft Tools Ensure AI Agents Play Within the Rules at Runtime
- Microsoft, Third-Party Agents Build Out Security Copilot Ecosystem



