
Microsoft has introduced Project Perception, an artificial intelligence-based security system designed to defend against AI-powered cyberattacks by continuously perceiving, reasoning about, and acting on threats at machine speed. The system coordinates specialized AI agents that work together to identify attack paths, assess risk, and take corrective actions, and enters public preview on August 3. By using a multi-model architecture rather than relying on a single AI model, Project Perception achieves 96% accuracy on industry benchmarks while reducing costs by almost 50% compared to existing configurations.
Summaries like this, in your inbox every morning.
Sign up free →What happened
Microsoft unveiled Project Perception, a new security system that uses AI agents to continuously detect, evaluate, and counter threats at machine speed. The system enters public preview on August 3 and coordinates three classes of specialized agents—red team (identifying attack paths), blue team (assessing risk), and green team (taking corrective actions)—into a closed-loop defense loop.
Why it matters
Traditional security approaches built for human-speed attacks cannot keep pace with AI-powered threats that generate exploits faster and operate with unprecedented efficiency. Project Perception addresses this by applying specialized AI models to specific security tasks rather than relying on a single model, achieving 96% on CyberGym (an industry leading benchmark) for software vulnerability management while delivering almost 50% cost savings compared to the current configuration in market today.
What to watch
The system uses a multi-model architecture that selects the right AI model for each task, optimizing for quality and cost. Microsoft's specialized model MAI-Cyber-1-Flash, integrated into MDASH (a software vulnerability multi-model team of agents), scored 12 points above Mythos on CyberGym; the company plans to expand this model's use across additional security workflows beyond software vulnerability management.
Microsoft has introduced Project Perception, a new security system designed to defend organizations against threats in an AI-driven world. The company announced that Project Perception will enter public preview on August 3.
At its core, Project Perception is an "agentic security system"—one that coordinates multiple AI agents to work together in defending an organization's digital infrastructure. The system operates on the observation that the traditional model of cybersecurity, built around human defenders responding to alerts, cannot keep pace with modern threats. As the body notes, attackers can now generate exploits faster, scale campaigns further, and operate with unprecedented efficiency, while the volume, velocity and complexity of what must be secured continues to grow.
Project Perception addresses this challenge by coordinating three classes of specialized agents into a closed-loop system. Red team agents identify potential paths to compromise before an attacker can exploit them. Blue team agents investigate, reason over context and determine what represents meaningful risk. Green team agents take corrective actions and strengthen defenses across the environment. Working together, these agents continuously discover, evaluate and improve an organization's security posture.
The system is built on what Microsoft calls a "new Cyber Stack," which layers signals and sensors, security context, AI models, a coordination harness, specialized agents, and actuators (the mechanisms that translate decisions into actual protections). Security context—Microsoft's term for a continuously updated representation of an organization's assets, identities, relationships, risks and activities—is foundational. Rather than forcing agents to reconstruct understanding from raw signals, the context provides "immediate and token-efficient access" to information agents need to reason over risk and prioritize actions.
A key technical choice is Project Perception's multi-model architecture. Rather than relying on a single AI model for all security tasks, the system applies the right model to the right problem based on a combination of quality, reliability, latency and cost. This approach is demonstrated in the software vulnerability management use case, where Microsoft has integrated its specialized model MAI-Cyber-1-Flash into MDASH, a multi-model team of agents focused on software vulnerability discovery. MDASH with MAI-Cyber-1-Flash delivers 96% on CyberGym, an industry leading benchmark, scoring 12 points above Mythos. The same configuration achieves almost 50% cost savings compared to the current MDASH configuration in market today. Microsoft plans to expand MAI-Cyber-1-Flash's use across additional security workflows beyond software vulnerability management.
Project Perception is deeply integrated across Microsoft Security products, enabling agents to act on their reasoning. The body emphasizes that security teams do not need more information but better outcomes—a principle reflected in the "actuators" layer of the Cyber Stack, which connects insights directly to protective actions so organizations can continuously reduce risk rather than simply identify it. Throughout, the design places humans in control: defenders remain "firmly in control" and are "empowered with powerful new workflows" rather than replaced by automation.
The announcement reflects a fundamental shift in how organizations must approach cybersecurity as attackers increasingly leverage AI. The body makes clear that the traditional model—where human defenders respond to alerts and threats—breaks down when adversaries can operate at machine speed, scale campaigns globally, and generate new exploits faster than human teams can evaluate them. Microsoft's Project Perception is positioned as a response to this asymmetry: a system that mirrors the speed and scale of AI-driven attacks by deploying its own AI agents that operate continuously.
The technical approach centers on three key design choices evident in the body. First, visibility: Microsoft leverages its existing breadth of signals across identities, endpoints, applications, data, clouds and AI systems to provide what it calls "security context"—a continuously updated representation of an organization's assets, risks, and activities that agents can reason over without reconstructing context from raw signals. Second, specialization: rather than deploying a single frontier model to all tasks, Project Perception uses a multi-model architecture that selects the right model (quality, reliability, latency, cost) for each problem. The software vulnerability management example demonstrates this principle: the specialized model MAI-Cyber-1-Flash outperforms the previous configuration by 12 points on CyberGym while cutting costs by 50%, showing that domain-specific optimization beats generalization for security workflows. Third, human control: the body emphasizes that humans remain "firmly in control" and that agents "amplify defenders with better insights," positioning the system as augmentation rather than replacement.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
No comments yet. Be the first to share your thoughts!
Log in to join the discussion





Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.
Get Started FreeFree · takes 30 seconds · unsubscribe anytime