Microsoft Launches Project Perception, an Agentic Security Platform to Fight AI-Operated Attacks
Red, blue, and green team AI agents work together to find and fix vulnerabilities before attackers do, alongside a new MAI-Cyber-1-Flash model that replicates 95% of Microsoft's vulnerability-hunting system.
Microsoft unveiled Project Perception on July 27 at a San Francisco event — an agentic security platform built to counter attacks that are increasingly generated and operated by AI rather than humans. The system coordinates three classes of specialized agents: red team agents that probe for exploitable vulnerabilities before attackers find them, blue team agents that triage what actually represents meaningful risk, and green team agents that take corrective action to close the gaps automatically.
“We’re now in a world where we’ve moved from AI-assisted attacks to AI-operated attacks to now autonomous AI attacking customers,” said Hayete Gallot, EVP of Microsoft Security. “The physics of cyber have fundamentally changed.” That’s not marketing hyperbole in 2026 — Google’s Threat Intelligence Group documented AI-generated working zero-day exploits back in May, and defenders have been racing to match attacker automation with automation of their own ever since.
Alongside Project Perception, Microsoft introduced MAI-Cyber-1-Flash, a purpose-built model that plugs into the company’s MDASH code-scanning harness to identify and remediate vulnerabilities. Microsoft claims the model performs roughly 95% of the work its full MDASH vulnerability-hunting system does, at a fraction of the cost — a deliberate positioning against both open-weight security models and rival AI vendors’ general-purpose models applied to security tasks. The pitch is that a smaller model trained specifically on Microsoft’s own telemetry and trillions of collected threat signals beats a bigger general model bolted onto a security workflow.
The bet underlying all of this: static, signature-based defense can’t keep pace with attackers who now use AI to generate novel exploit chains in hours instead of weeks. An autonomous red-team agent finding your own zero-days before an attacker does is a genuinely different security posture than periodic pen tests and CVE patching cycles — but it also means organizations are now trusting AI agents with privileged access to probe and modify production security controls, which is its own new attack surface if Microsoft’s agent orchestration has flaws of its own. Microsoft hasn’t published pricing or a general-availability date for Project Perception; expect a phased rollout starting with Security Copilot customers.
Sources
Related reading
- Cybersecurity JADEPUFFER: The First Documented Ransomware Attack Run End-to-End by an AI Agent
- Cybersecurity Federal Agencies Have Until Tomorrow to Patch an Actively Exploited AD FS Zero-Day
- Cybersecurity Critical SharePoint RCE (CVE-2026-50522, CVSS 9.8) Under Active Exploitation — Attackers Are Stealing Machine Keys