Rethinking security for the age of AI
July 27, 2026 · Microsoft Security · Severity: MEDIUM
Microsoft has introduced Project Perception, a new AI-driven cybersecurity system designed to address the evolving threat landscape shaped by AI and machine-speed attacks. The initiative aims to create a "Cyber Stack" that continuously perceives risk, reasons across vast contexts, and takes action at machine speed while empowering human defenders with enhanced insights and workflows. Project Perception integrates specialized agents—Red Team agents to identify vulnerabilities, Blue Team agents to assess risks, and Green Team agents to strengthen defenses—forming a closed-loop system that continuously improves an organization’s security posture. The system leverages Microsoft’s extensive security research, threat intelligence, and operational experience to provide broad visibility and actionable insights across identities, endpoints, applications, data, and cloud environments. Project Perception employs a multi-model architecture, combining frontier and specialized cyber models to optimize effectiveness and cost efficiency. Its first application focuses on software vulnerability management, utilizing MAI-Cyber-1-Flash within the MDASH framework, which achieves a 96% benchmark score on CyberGym, outperforming Mythos by 12 points while reducing costs by nearly 50%. Microsoft plans to expand Project Perception’s capabilities to additional security workflows, with the system entering public preview on August 3. This initiative underscores the need for a new cybersecurity paradigm to counter increasingly sophisticated AI-driven threats, ensuring organizations can defend against attacks at scale while maintaining affordability and continuous protection.
Why security needs a new Cyber Stack — Introducing Project Perception
The physics of cybersecurity are changing. Autonomous systems can now reason, adapt and operate continuously. At the same time, the cost of offense is falling, while the volume, velocity and complexity of what must be secured continues to grow. Attackers can generate exploits faster, scale campaigns further and operate with unprecedented efficiency. The approaches built for a world of human actors cannot keep pace with a world of AI, agents and machine-speed attacks.
Security needs a new Cyber Stack. A new Cyber Stack must continuously perceive risk across the entire digital estate, reason across vast amounts of context and take action at machine speed. It must learn and adapt as environments evolve, helping organizations stay ahead of threats. And because security is ultimately a human mission, it must amplify defenders with better insights and more powerful ways to act. The defining characteristic of the next generation of security systems will not be their ability to generate more alerts. It will be their ability to continuously perceive, reason and act.
That vision led us to build Project Perception. A new agentic security system designed for the realities of AI. It turns signals into real-time protections using AI to defend against AI.
Project Perception brings together signals, context, models and specialized agents into a continuously learning system of defense. It can reason, prioritize and act at machine speed while keeping humans firmly in control and empowering them with powerful new workflows.
Project Perception is based on a simple idea: effective defense requires continuous understanding of how an attacker sees the world, how a defender evaluates risk and how protections are improved over time. To accomplish this, Perception coordinates three classes of specialized agents. Red team agents identify potential paths to compromise before an attacker can exploit them. Blue team agents investigate, reason over context and determine what represents meaningful risk. Green team agents take corrective actions and strengthen defenses across the environment. Working together, these agents form a closed-loop system that continuously discovers, evaluates and improves an organization’s security posture.

A system like Project Perception is only as effective as the visibility it has, the actions it can take, the experience of the teams building it and the models it can use. Microsoft brings together all four.
We see across identities, endpoints, applications, data, clouds and AI systems, providing broad visibility across the digital estate. Equally important, we can help customers take action across those environments. Combined with decades of security research, threat intelligence and real-world operational experience defending organizations, these capabilities shape how Project Perception reasons, prioritizes and responds.
Security is a 24/7 mission. Organizations need protection that is highly effective, continuously available and affordable at scale. That requires more than access to the most capable model. It requires applying the right model to the right task. Project Perception adopts a multi-model architecture that combines frontier and specialized cyber models, optimizing for both quality and cost.
As part of this multi-model strategy, we are committed to bringing customers the best models for each security task, including innovating with our own specialized models. The first scenario is software vulnerability management, bringing MAI-Cyber-1-Flash inside MDASH, our software vulnerability multi-model team of agents. MDASH with MAI-Cyber-1-Flash delivers 96% on CyberGym, an industry leading benchmark, +12 points above Mythos. And this same configuration delivers almost 50% of cost savings vs. the current MDASH configuration in market today. That’s the power of a well-tuned, multi-model system with access to uniquely rich historical training data. Next, Project Perception will take advantage of MAI-Cyber-1-Flash for many more security workflows, beyond the software vulnerability scenario.
We are bringing this vision to customers around the world through Project Perception, which enters public preview on August 3.
YouTube Video
A Cyber Stack built for agentic security
Delivering agentic security requires more than adding agents to existing workflows. It requires a new Cyber Stack, designed from the ground up.
The stack begins with signals and sensors that provide awareness across the digital estate. Security context transforms those signals into token-efficient understanding that agents can use. Models provide intelligence and reasoning. A harness coordinates models and agents across security workflows. Agents apply that intelligence across security workflows and actuators translate decisions into protection. Together, these layers create a continuous learning system that can understand risk, adapt to changing conditions and improve security outcomes over time.

While each layer provides important capabilities, the power of Project Perception comes from how they work together.
Security context built for AI
Effective reasoning requires more than raw signals. Agents need context.
Microsoft transforms its breadth of visibility, threat intelligence and security expertise into a security context that connects security data, knowledge and semantics across the digital estate. The result is a continuously updated representation of an organization’s assets, identities, relationships, risks and activities that gives agents a shared, near real-time, understanding of the environment they are helping to defend.

Key Takeaways
- Autonomous systems change cybersecurity physics; offense cost falling, volume increasing.
- New Cyber Stack needed to continuously perceive, reason, and act at machine speed.
- Microsoft introduces Project Perception to amplify defenders with better insights.