Microsoft Launches MAI-Cyber-1-Flash Model and Perception Security Platform
Microsoft unveiled its first purpose-built cybersecurity model, MAI-Cyber-1-Flash, and the Perception agentic platform at a San Francisco event. The system uses red, blue, and green AI teams to find and fix vulnerabilities in minutes, entering preview November 3.

Microsoft just dropped its first purpose-built cybersecurity model and a full agentic security platform at a San Francisco event on Monday — a direct challenge to Anthropic, Google, and OpenAI in the rapidly heating AI security race. The company says its new MAI-Cyber-1-Flash model, paired with the Perception platform, can find and fix complex code vulnerabilities in minutes instead of hours.
The Model: MAI-Cyber-1-Flash
Built specifically to "find challenging vulnerabilities in complex codebases," MAI-Cyber-1-Flash isn't a general-purpose model with a security coat of paint. It's designed to animate MDASH — Microsoft's dedicated harness for software vulnerability identification and remediation. Think of MDASH as the testing environment; MAI-Cyber-1-Flash is the engine running inside it.
Mustafa Suleyman, CEO of Microsoft AI and DeepMind co-founder, didn't mince words about performance: "We have MAI-1 Cyber Flash binded with GPT 5.4 inside of the MDASH harness — which beats out Gemini, GPT 5.5 Cyber, GPT 5.6 Sol, and Mythos 5 on Cyber Gym, which is the primary benchmark that we all use. The golden benchmark." He added the model is significantly more cost-effective than competitor offerings.
The Platform: Perception
If MAI-Cyber-1-Flash is the brain, Perception is the nervous system — an agentic platform that deploys teams of AI agents to automate security workflows end-to-end. It integrates directly with MDASH, creating a closed loop from discovery to fix.
Hayete Gallot, Microsoft's VP for security, framed the urgency bluntly: hackers are increasingly using AI in attacks, so defenders need to "defend against AI with AI at the scale and speed that the attackers have." Perception is Microsoft's answer to that asymmetry.
How Perception Works: Red, Blue, and Green Teams
Perception doesn't just run a single agent — it orchestrates three specialized agent types that mirror traditional security team structures:
- Red teams simulate detailed attacks, modeling specific threat actors and the vulnerabilities they'd likely exploit
- Blue teams detect and triage existing bugs in the codebase
- Green teams take "corrective actions" — actually writing and applying code fixes
Dave Weston, lead engineer for Perception, described the workflow shift: "We've gone from this taking hours and hours of manual work from multiple specialized folks across the security organization — appsec hunters, remediation engineers, you name it — and in minutes, we have a fix for all of this. Not only do we discover the issues and prioritize them, but we have detection, posture fixing, and even a code fix."
Competitive Landscape
Microsoft is entering a crowded field where every major AI player has staked a claim:
| Company | Security Platform | Access Program | Launch Timeline |
|---|---|---|---|
| Microsoft | Perception + MAI-Cyber-1-Flash | Preview (Nov 3) | Announced July 27, 2026 |
| Anthropic | Mythos | Glasswing (partner-only) | Earlier 2026 |
| OpenAI | Unnamed | Daybreak | May 2026 |
| Gemini (security variants) | General availability | Ongoing |
Anthropic's Mythos launched earlier this year through Glasswing, a selective partner program. OpenAI followed in May with its own security solution via Daybreak. Google's Gemini models have been benchmarked on Cyber Gym but lack a dedicated agentic platform comparable to Perception's red/blue/green team architecture.
Availability and What's Next
Both MAI-Cyber-1-Flash and Perception enter preview on November 3, 2026. Microsoft says it's "shipping this into production immediately" — suggesting the preview will be more than a tech demo. The real test will be how enterprises adopt agentic security workflows and whether the red/blue/green team model holds up against novel attack vectors that don't fit known patterns.
Key Takeaways
- MAI-Cyber-1-Flash is Microsoft's first cybersecurity-specialized model, built to run inside the MDASH vulnerability harness
- Perception deploys agentic red, blue, and green teams to automate the full vulnerability lifecycle
- Microsoft claims benchmark wins over Gemini, GPT 5.5 Cyber, GPT 5.6 Sol, and Mythos 5 on Cyber Gym
- Both tools enter preview November 3, 2026
- Direct response to AI-powered attacks — "defend against AI with AI"
The Bottom Line
Microsoft isn't just adding AI features to existing security tools — it's betting that fully agentic, team-based workflows will replace the current patchwork of scanners, triage queues, and manual remediation. If Perception delivers on the "minutes not hours" promise at scale, it could reset expectations for what enterprise security operations look like. The November preview will tell us whether the benchmark numbers translate to production reality.
Frequently Asked Questions
