- What: Microsoft announces AI security initiatives including Project Perception
- Impact: Introduces new security agents for threat detection and response
You need agents to fight agents. At least thatâs what David Weston, corporate VP for AI security at Microsoft told his audience during a Microsoft Security launch preview on July 27. During the event, the Redmond-based company announced a flurry of new AI and security products and initiatives. First, Microsoft launched Project Perception , a new agentic security system designed to help cyber defenders continuously identify, evaluate and reduce security risk. Microsoftâs Perception coordinates three classes of specialized agents that work together to improve security posture over time: Red agents identify potential attack paths and vulnerabilities before they can be exploited Blue agents investigate findings, apply security context and determine what represents meaningful risk Green agents take corrective action and strengthen defenses across the environment This is akin to Googleâs AI Threat Defense platform, powered by Wizâs Red, Blue and Green agents, released in May 2026. Speaking at Microsoftâs launch event, Hayete Gallot, executive VP at Microsoft Security, explained that the global reach of Microsoft means the company see about 100 trillion signals a day. âWe sit at your identity, data, cloud, code and even AI level. If you add our security research, threat intelligence and red teaming efforts, you end up with even more signals,â she said. âHowever, if you were to apply an agent to that raw data, it would be very slow and you would get terrible results. Thatâs why we are connecting and correlating all those signals so we can provide a âsecurity context,â which is organized efficiently for our agents.â Weston added that Project Perception will be multi-model and demonstrated to the audience several âplaybooksâ based on a set of operations a security operations center (SOC) could face. âWe believe fundamentally you need agents to fight agents,â he said. Perception will be available in Preview mode for all Microsoft customers from August 3. Read more: Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses Microsoftâs First Cyber-Focused AI Model: MAI-Cyber-1-Flash Gallot also announced the launch of a new Microsoft-made generative AI model specifically designed for cybersecurity use cases, especially software vulnerability analysis. Developed by Microsoft AI (MAI), the model, named MAI-Cyber-1-Flash , is based on the companyâs internally developed MAI-Thinking-1 reasoning model. It has been integrated into Microsoft Securityâs multi-model agentic scanning harness (MDASH). According to Mustafa Suleyman, CEO at Microsoft AI, the system is further enhanced by GPT-5.4 and has outperformed competing solutions from Anthropic, OpenAI and Google in CyberGym benchmarking. The MAI-Cyber-1-Flash and GPT4.5 enhancement have achieved a 95.95% success rate according to the CyberGym benchmark. By comparison, OpenAIâs GPT-5.5 Cyber scored 85.6%, GPT-5.6 Sol achieved 83.6%, Anthropicâs Mythos recorded 83.8%, and Googleâs Gemini 3.5 Flash Cyber reached 83.2%. Source: Microsoft Security Within MDASH, MAI-Cyber-1-Flash handles approximately 90% of queries, identifying and patching software vulnerabilities before verifying that the fixes work. The remaining 10% of more complex tasks are passed to the larger GPT-5.4 model. Suleyman said GPT-5.4 is around ten times larger than MAI-Cyber-1-Flash and can resolve the queries handed off to it. He claimed that the collaboration between the two models delivers stronger performance than competing systems while costing roughly 50% less. From DARPA AIxCC Winners to Microsoft Security FORGE Lab The tech firm also announced the launch of the Microsoft Security Frontier Offensive Research and Generative Exploration (FORGE) Lab. The lab will be led by Team Atlanta,, the group of cybersecurity researchers that won the US Defense Advanced Research Projects Agencyâs (DARPA) AI Cyber Challenge (AIxCC) at DEFCON in the summer 2025, after Microsoft hired the team to head the new initiative, Gallot said. The FORGE Lab will be headed by Taesoo Kim , who also led Team Atlanta. During the Microsoft launch event, Kim described the DARPA competition as a âreal world AI cyber challengeâ and said the winning teams combined cuttingâedge research with practical engineering. He reported that DARPAâs process encouraged teams to âstrike the balance between engineering and highârisk, highâreturn research throughout the competition,â and that Microsoft provided the ideal environment to translate those advances into production given its scale across Azure and GitHub. Kim added that the labâs mission is to âadvance the frontier of offensive security research and accelerate the evolution from AIâassisted vulnerability discovery to autonomous security research,â positioning FORGE as the bridge from DARPAâlevel breakthroughs to enterprise defenses. Launch of the External Red Team Alliance Finally, Microsoft announced the External Red Team Alliance (EXTRA), a two-pronged initiative designed to broaden the scope of AI safety research. The first piece involves Microsoft's in-house AI red team distributing "unrestricted gifts" to 18 university labs spread across six continents, all in support of AI safety-related research. Ram Shankar Siva Kumar, Microsoft's head of the AI red team, explained in a blog post published on July 17 that the funding comes with no strings attached because the goal isn't to steer research toward specific products or predetermined outcomes. He noted that while some of these universities are digging into the cybersecurity risks posed by AI systems themselves â looking at how such models might be exploited, manipulated or misused in real-world settings â others are tackling the flip side and explore how AI can actually be leveraged to strengthen defenses and enhance cyber operations. The initiative's second component focuses on assembling a distributed network of specialized experts who can contribute to red teaming efforts in niche areas. According to Siva Kumar, this network will draw on researchers, practitioners, and regional specialists with knowledge of particular attack methods, languages, cultural nuances, or technical fields, areas where Microsoft's internal teams may lack complete coverage on their own. Image credits: Tada Images / Mijansk786 / Shutterstock.com