Jul 28, 2026
Enterprise

Microsoft Project Perception targets autonomous AI attacks

Microsoft launched Project Perception and MAI-Cyber-1-Flash as security teams face faster AI-enabled exploitation.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

Microsoft Project Perception targets autonomous AI attacks
Photo: CIO Dive

Microsoft Project Perception, an agentic security platform, was launched Monday to help defenders counter AI-enabled attacks that Microsoft says are moving from assisted activity toward autonomous operations. The company also introduced MAI-Cyber-1-Flash, an AI model tied to its MDASH code-scanning harness to help identify and fix software vulnerabilities.

Microsoft announced the products at a San Francisco event on July 27, 2026. The company did not disclose pricing, customer counts, or deployment timelines beyond the launch, but said the system is intended for organizations trying to find weaknesses before attackers do.

The release fits a broader security industry push to use AI against AI-assisted attackers. Microsoft and other vendors are trying to sell security teams on systems that can work at machine speed, because criminal and state-backed hackers have begun using AI to accelerate vulnerability discovery and exploit development.

What is Microsoft Project Perception?

Project Perception combines red team, blue team and green team agents inside a security system. Microsoft says those agents are designed to simulate attacks, detect risks and support remediation across an organization’s environment before malicious actors identify the same attack routes.

Agentic security refers to systems that can take a sequence of actions with limited human input, rather than only producing alerts or recommendations. In this case, Microsoft is applying that approach to vulnerability discovery, defensive testing and response workflows.

Hayete Gallot, executive vice president of Microsoft Security, said at the launch event that attackers have progressed from AI-assisted campaigns to AI-operated activity and now to autonomous AI attacks against customers. “The physics of cyber have fundamentally changed,” Gallot said.

That framing is useful for Microsoft, but it also raises the same questions security buyers ask of any automated defense product: how much autonomy it gets, how decisions are audited, and where humans remain in the loop. Microsoft’s announcement focused on the system’s defensive role and its access to Microsoft’s security data, not on those operational limits.

How MAI-Cyber-1-Flash fits into Microsoft’s security push

Alongside Project Perception, Microsoft introduced MAI-Cyber-1-Flash, a model built for cybersecurity tasks. Microsoft says the model helps users find and remediate vulnerabilities through integration with MDASH, the company’s code-scanning harness.

Microsoft argues it has an advantage because it collects trillions of security signals that can be used to detect potential threat activity. The company also said its system offers cost savings compared with rival models, though it did not provide figures in the announcement.

Allie Mellen, principal analyst at Forrester, told Cybersecurity Dive that Microsoft’s decision to build its own model on its own data and expertise should make it better suited to reason over Microsoft data and align with Microsoft products.

The market context is getting less theoretical. In May, Google Threat Intelligence Group reported that hackers had used AI to create a working zero-day exploit as part of an attempted mass event. Researchers warned the affected developer and helped prevent a broader attack, according to that report.

For enterprise security teams, Microsoft’s launch signals where large platform vendors are taking cyber products next: toward automated systems that test, detect and remediate in the same workflow. The unanswered part is how reliably those agents perform outside Microsoft-controlled environments, and how much trust buyers will place in autonomous tools defending systems that are already difficult to secure manually.

This story draws on original reporting from CIO Dive.

More from Enterprise

All Enterprise →