Rethinking security for the age of AI — Introducing Project Perception
Why security needs a new Cyber Stack — Introducing Project Perception
Project Perception brings together signals, context, models and specialized agents into a continuously learning system of defense. It can reason, prioritize and act at machine speed while keeping humans firmly in control and empowering them with powerful new workflows.
Project Perception is based on a simple idea: effective defense requires continuous understanding of how an attacker sees the world, how a defender evaluates risk and how protections are improved over time. To accomplish this, Perception coordinates three classes of specialized agents. Red team agents identify potential paths to compromise before an attacker can exploit them. Blue team agents investigate, reason over context and determine what represents meaningful risk. Green team agents take corrective actions and strengthen defenses across the environment. Working together, these agents form a closed-loop system that continuously discovers, evaluates and improves an organization’s security posture.
Security is a 24/7 mission. Organizations need protection that is highly effective, continuously available and affordable at scale. That requires applying the right model to the right task. Project Perception adopts a multi-model architecture that combines frontier and specialized cyber models, optimizing for both quality and cost.
As part of this multi-model strategy, Microsoft is innovating with specialized models. The first scenario is software vulnerability management, bringing MAI-Cyber-1-Flash inside MDASH, Microsoft’s software vulnerability multi-model team of agents. MDASH with MAI-Cyber-1-Flash delivers 96% on CyberGym, an industry leading benchmark, +12 points above Mythos. And this same configuration delivers almost 50% of cost savings vs. the current MDASH configuration in market today.
Project Perception enters public preview on August 3, 2026.
A Cyber Stack built for agentic security
The stack begins with signals and sensors that provide awareness across the digital estate. Security context transforms those signals into token-efficient understanding that agents can use. Models provide intelligence and reasoning. A harness coordinates models and agents across security workflows. Agents apply that intelligence across security workflows and actuators translate decisions into protection.
Axios and VentureBeat reported MAI-Cyber-1-Flash is Microsoft’s first in-house cybersecurity-specialized model; roughly 95% of MDASH work runs on it while more intensive tasks route to GPT-5.4. The model will be available through Azure AI Foundry rather than as a fully public open release. At launch, Project Perception brings multi-agent coordinated defense into Microsoft Defender, with plans to expand across Microsoft Security products.