Microsoft has introduced its first AI model purpose-built for cybersecurity, along with a new agentic security platform, at a small gathering held in San Francisco on Monday. The announcements position the company as a direct competitor to Anthropic, Google, and OpenAI in the rapidly expanding AI-driven security market.
The cybersecurity-focused model, called MAI-Cyber-1-Flash, is designed specifically to locate difficult vulnerabilities within complex software codebases. According to Microsoft, the model serves as the driving intelligence behind MDASH, the company's internal framework dedicated to identifying and fixing software security flaws.
A New Agentic Security Platform Called Perception
Alongside MAI-Cyber-1-Flash, Microsoft unveiled a new security platform named Perception. The platform is built around the concept of deploying coordinated teams of AI agents that can assist security professionals in automating workflows - ranging from spotting vulnerabilities to implementing fixes. Perception is also capable of integrating directly with MDASH, giving organizations a more unified approach to software security management.
Microsoft is claiming that MAI-Cyber-1-Flash outperforms competing models in both capability and cost-efficiency, citing results from an established AI cybersecurity benchmark as evidence.
Mustafa Suleyman, co-founder of DeepMind and current CEO of Microsoft AI, spoke enthusiastically about the results at the event. "We're very very excited to announce our results," he said. "We have MAI-1 Cyber Flash binded with GPT 5.4 inside of the MDASH harness - which beats out Gemini, GPT 5.5 Cyber, GPT 5.6 Sol, and Mythos 5 on Cyber Gym, which is the primary benchmark that we all use. The golden benchmark." He added that the company would be "shipping this into production immediately."
Defending Against AI-Powered Threats
Hayete Gallot, Microsoft's vice president for security, framed Perception as a direct response to the growing use of AI by cybercriminals. With attackers increasingly leveraging artificial intelligence to conduct more sophisticated intrusions, Gallot described the platform as a means for enterprise defenders to "defend against AI with AI at the scale and speed that the attackers have."
Perception operates through three distinct types of AI agent teams, each serving a different function within the security lifecycle. Red teams are responsible for running detailed simulations of potential attacks, providing context about likely threat actors and the specific vulnerabilities they might target. Blue teams focus on detecting and triaging bugs that already exist within a system. Green teams then take what Microsoft describes as "corrective actions" to address those identified issues.
Dave Weston, the lead engineer behind Perception, highlighted the platform's potential to dramatically reduce the time and personnel required to handle security incidents. "We've gone from this taking hours and hours of manual work from multiple specialized folks across the security organization - appsec hunters, remediation engineers, you name it - and in minutes, we have a fix for all of this," he said. "Not only do we discover the issues and prioritize them, but we have detection, posture fixing, and even a code fix."
An Increasingly Competitive Landscape
While AI has opened up powerful new defensive tools for organizations, it has simultaneously given cybercriminals access to capabilities that have broadened and intensified the threat landscape. The dual-use nature of the technology has made AI-driven security solutions a growing priority across the industry.
Microsoft said both MAI-Cyber-1-Flash and Perception will be available in preview starting November 3. The launch places Microsoft squarely in a field that has grown notably more competitive in recent months. Earlier this year, Anthropic introduced its own security-focused platform called Mythos, which was made available to a limited group of partner organizations through a program known as Glasswing. OpenAI similarly entered the space in May with its own security offering, launched through a program called Daybreak.
With major AI developers now competing directly in the cybersecurity sector, the race to provide enterprise-grade, AI-powered protection tools is accelerating - and Microsoft's latest announcements signal that the company intends to be a central player in shaping where that market heads next.



