Microsoft's Project Perception security agents open to the public Monday
Unveiled last Monday, Microsoft's three-color agent security platform and its first in-house cyber model reach the public inside Defender on August 3. The benchmark claims are all Microsoft's own.
Microsoft's bet that security agents can work like a security team gets its first public test Monday. Project Perception, the agentic security platform the company unveiled last Monday, July 27, opens in public preview inside Microsoft Defender on August 3, putting a coordinated fleet of attack-mapping and patch-writing agents in front of ordinary enterprise customers for the first time.
Three colors, one platform
Project Perception ships with three initial agent types, organized the way human security organizations are. Red agents map attack paths and hunt for vulnerabilities. Blue agents investigate and prioritize risk. Green agents take corrective action, up to and including writing and deploying patches. The agents share intelligence with each other, a design Microsoft describes as mirroring how human red and blue teams hand off work, as reported by TechCrunch.
Underneath sits MAI-Cyber-1-Flash, Microsoft's first in-house cybersecurity model. It is compact, trained heavily on code, and derived from the company's MAI-Thinking-1 lineage. Shipping its own model rather than routing everything through OpenAI is a notable step in Microsoft's slow separation from its most famous partner, and security is a shrewd place to start: the domain rewards a small, fast, specialized model over a general-purpose giant, and Microsoft owns more security telemetry than any company alive.
Vendor math, vendor benchmarks
The performance claims deserve the usual discount applied to launch-day numbers, because every one of them comes from Microsoft. The company says the new model does roughly 95 percent of the work of MDASH, its internal vulnerability-finding system. Paired with GPT-5.4, Microsoft says the combination scores about 96 percent on the CyberGym benchmark, which the company claims is 12 points above Anthropic's Mythos, at half the cost of the current MDASH configuration. CEO Satya Nadella framed it as 'world-class performance at 50 percent of the cost of leading models,' per Axios. None of these figures has been independently verified, and CyberGym scores in particular have become a marketing currency that labs quote selectively.
A rough month for agent security
The timing is either shrewd or awkward, depending on your view. July has been a parade of agent security failures. OpenAI paused a model after repeated sandbox escapes. UK government testers breached a corporate network using Opus 5 in eight of ten attempts. Researchers showed that four separate agent attack techniques exploit the same underlying flaw. Microsoft's answer to agents behaving badly is, in effect, more agents, ones with write access to production systems via those patch-deploying green agents. Enterprises will want to look hard at the approval gates before letting an agent push a patch on a Friday afternoon. Microsoft has not yet published detail on what human sign-off, if any, sits between a green agent's proposed fix and a live deployment, and that document will matter more to security teams than any benchmark score.
For the agentic AI as a service market, Monday matters more than last week's announcement did. A public preview inside Defender puts agentic security in front of the largest enterprise security install base on earth, at bundle pricing that standalone agentic security startups cannot match. If Project Perception works even close to Microsoft's numbers, it resets the baseline for what a security agent product must do and what it can charge. If the green agents misfire in the wild, it will hand every rival, and every regulator, the case study they have been waiting for.