Microsoft Launches Cybersecurity AI Model, Claims 50% Lower Costs
Microsoft aims to combat hackers without incurring excessive AI costs. On Monday, the company introduced MAI-Cyber-1-Flash, its first cybersecurity-focused AI model designed to identify and help fix software vulnerabilities. Microsoft claims its new, smaller, and specialized model outperforms Anthropic’s Mythos 5 in the CyberGym performance test, while also cutting vulnerability detection costs by close to 50%.

This announcement comes at a time when cyberattacks are becoming increasingly rapid and sophisticated. Microsoft notes that hackers are increasingly using AI to automate attacks and discover software vulnerabilities, making it difficult for traditional security tools to keep pace. To counter this trend, the company is focusing on smaller, specialized AI models built specifically for cyber defense.
What is MAI-Cyber-1-Flash?
The centerpiece of Microsoft’s announcement is MAI-Cyber-1-Flash, a smaller AI model developed specifically to identify and resolve software vulnerabilities. It operates as part of MDASH, Microsoft’s AI-powered system for detecting and remediating security flaws. Instead of relying on a massive AI model for every task, Microsoft explains that MAI-Cyber-1-Flash handles the bulk of the work, reserving the processing of the most complex cases for OpenAI’s GPT-5.4 model. Microsoft claims that this approach achieves a score of 95.95% on the CyberGym test—about 12 percentage points higher than Anthropic’s Mythos 5—and reduces operating costs by nearly 50%.
According to the company, MAI-Cyber-1-Flash handles around 90% of security tasks, including vulnerability detection, patch generation, and verifying that fixes work correctly. Only the remaining complex tasks are routed to GPT-5.4. David Weston, Corporate Vice President of AI Security at Microsoft, stated that the model performs approximately 95% of the work currently handled by MDASH. Microsoft believes that using multiple specialized AI models, rather than a single large model, yields better performance at a lower cost. Each model is designed to handle the task for which it is best suited.
Microsoft Unveils Project Perception
Alongside MAI-Cyber-1-Flash, Microsoft has also introduced Project Perception, a new AI-powered cybersecurity platform that continuously scans an organization’s systems for security risks.
“Autonomous systems are already capable of reasoning, adapting, and operating continuously. At the same time, the cost of attacks is dropping, while the volume, speed, and complexity of the assets requiring protection continue to grow. Attackers can generate exploits faster, expand the reach of their campaigns, and operate with unprecedented efficiency,” says Hayete Gallot, Executive Vice President of Microsoft Security.
Project Perception employs three specialised AI agents, each with a distinct role. “Red team” agents hunt for security vulnerabilities before hackers can detect them. “Blue team” agents analyse security alerts and identify which threats require immediate attention. “Green team” agents recommend solutions or—subject to client approval—implement them to strengthen the organisation’s security. According to Microsoft, these AI agents collaborate to continuously monitor and improve security across devices, applications, cloud services, data, and AI systems, while keeping humans in control of key decisions.
The company notes that Project Perception can also suggest code modifications and—once approved by customers—apply them automatically. It is also designed to integrate with third-party security tools, allowing organisations to use it alongside their existing cybersecurity software.
Availability
Project Perception will enter public preview on August 3, while MAI-Cyber-1-Flash will be available AI Foundry. Initially, the platform will focus on detecting and remediating vulnerabilities in software capabilities, to subsequently expand their scope to other cybersecurity tasks.
