Microsoft is launching Project Perception, an artificial intelligence security system that coordinates multiple agent teams to identify, investigate, and fix threats, entering public preview on August 3, according to a report published by AI Weekly. The system pairs Microsoft's multi-agent stack MDASH with a specialized cyber model called MAI-Cyber-1-Flash, achieving 96% on the CyberGym benchmark while cutting costs nearly in half compared to the current MDASH setup. The platform is built around red team agents that search for potential security breaches, blue team agents that evaluate which risks matter, and green team agents that execute fixes.

When running MAI-Cyber-1-Flash, MDASH scored 96% on CyberGym, an industry-recognized benchmark, outperforming Mythos by 12 percentage points while delivering cost savings of roughly 50% versus the existing MDASH configuration. The system connects directly to Microsoft's existing security infrastructure, including Defender for Endpoint, Entra ID, Sentinel, and Azure Resource Manager. Microsoft is using a multi-model approach rather than relying on a single large-scale model to handle every security function.

Hayete Gallot, Executive Vice President of Microsoft Security, stated that "no single model will be optimal for every security task," according to the company's announcement. The report emphasizes that "security teams do not need more information. They need better outcomes," though it doesn't reveal pricing details, identify preview customers, or explain how authorization works for the green-team agents making changes to identity and endpoint systems. The report notes the benchmark score warrants skepticism since it comes from a vendor, but calls the cost reduction "the more interesting" metric for potential buyers.

The report argues that if Microsoft can genuinely cut the inference cost of a security-agent platform it already sells by half, round-the-clock security coverage becomes financially viable for organizations that can't afford it today. The use of a purpose-built cyber model rather than general-purpose frontier models represents a bet that specialized models can outperform broader ones on specific security tasks while reducing expenses. The report suggests that if MAI-Cyber-1-Flash's pattern of beating general models at close to half the cost holds up in real security operations, competitors with security operations center platforms now have a blueprint to follow. The question for the coming weeks isn't whether Perception launches—it does on August 3—but whether rivals adopt the specialized-model strategy for their own security products. The absence of disclosed guardrails for automated corrective actions inside customer systems is where careful buyers will want clarity before turning agents loose. Every security platform vendor now faces a choice between investing in specialized models or watching Microsoft reshape customer expectations around both performance and price.