Microsoft is making a bigger push into AI-powered cybersecurity.
At an event in San Francisco, the company unveiled MAI-Cyber-1-Flash, its first AI model built specifically for security work. Alongside it came Perception, a new platform where AI agents help security teams hunt down threats, dig into vulnerabilities, and patch problems faster than before.
The move puts Microsoft squarely in competition with OpenAI, Anthropic, and Google, all of which have been ramping up their own cybersecurity efforts lately.
Built to Find Hard-to-Spot Security Flaws
MAI-Cyber-1-Flash isn’t meant to be a chatbot you’d casually ask questions.
Microsoft designed it to comb through large codebases and catch security weaknesses that are easy for developers to miss. It works alongside MDASH, Microsoft’s internal system for tracking down and fixing software vulnerabilities.
Rather than just dumping a list of flagged issues on a team, the system tries to help them figure out which problems actually matter and how to go about fixing them. Microsoft bets that this cuts down on the manual grunt work security engineers deal with day to day.
Microsoft Says It Beats Rival Models
Microsoft also came armed with benchmark numbers.
The company says MAI-Cyber-1-Flash outperformed several rival AI models on Cyber Gym, a benchmark widely used in the cybersecurity world.
Mustafa Suleyman, who leads Microsoft AI, said the team paired the new model with GPT-5.4 inside the MDASH framework—and claimed the combo beat out competing systems from Google, OpenAI, and Anthropic in Microsoft’s own internal tests.
The technology is already being used in production, according to the company.
You may also like to read: Trust Matters More Than Cost in the US-China AI Battle, Says Microsoft CEO
A Team of AI Agents
The second big reveal was Perception.
Instead of leaning on one model to do everything, Perception splits the work across multiple AI agents, each handling a different stage of a security investigation.
Some agents act like attackers — running real-world hacking simulations to find weak spots before actual criminals do. Others play defense, digging into alerts, ranking risks, and flagging what needs attention right away. A third group focuses on fixing things: suggesting code changes, tightening security settings, and helping developers close holes faster.
The idea, Microsoft says, is to speed things up without cutting human experts out of the loop.
From Hours to Minutes
Dave Weston, who leads engineering at Perception, says the platform can dramatically cut investigation time—work that used to take a team of security specialists can now be done in minutes.
Instead of a task bouncing among app security teams, remediation engineers, and analysts, the AI system keeps things moving on its own from the moment a problem is found until it’s fixed.
According to Weston, the platform doesn’t just spot vulnerabilities — it also prioritizes them, builds detection rules, suggests improvements, and can even write the code fixes itself.
Why Microsoft Is Investing in AI Security
The threat landscape is shifting fast.
Hackers aren’t just relying on old-school tools anymore — more of them are turning to AI to write malicious code, run phishing campaigns at scale, and find software vulnerabilities faster than ever.
Microsoft’s argument is simple: security teams need AI too, just to keep up.
Hayete Gallot, the company’s VP for Security, put it this way—defenders need to be able to move at the same speed and scale attackers now have.
Basically, Microsoft’s stance is that the best defense against AI-powered attacks is AI-powered defense.
You may also like to read: Microsoft Launches New AI Deployment Company with $2.5 Billion Investment
Looking Ahead
AI is becoming a bigger piece of how companies handle security.
Businesses want tools that cut down on repetitive work, react faster to threats, and free up security teams to focus on what actually matters most.
With MAI-Cyber-1-Flash and Perception, Microsoft is wagering that AI agents are going to become a standard part of security operations going forward.
Whether the claims hold up once they’re tested outside Microsoft’s own labs is still an open question. But one thing’s for sure—the race to build AI-driven cybersecurity tools is heating up, and Microsoft clearly wants to be leading it.






