Microsoft announced MAI-Cyber-1-Flash on Monday, a new artificial intelligence model designed to identify cybersecurity vulnerabilities, marking the company's first major cybersecurity initiative since Hayete Gallot rejoined to lead the unit in February. The model outperforms competing solutions from Anthropic, Google, and OpenAI on the CyberGym benchmark while operating at 50% of the cost when paired with OpenAI's GPT-5.4, according to Microsoft AI CEO Mustafa Suleyman at a San Francisco event. This represents Microsoft's first generative model specifically built for cybersecurity and will be integrated into Project Perception, a collection of AI agents for discovering and fixing security weaknesses.
When paired with OpenAI's general-purpose GPT-5.4, Microsoft's MAI-Cyber-1-Flash outperforms Anthropic's Mythos 5, Google's 3.5 Flash Cyber and OpenAI's GPT-5.5 Cyber on the CyberGym benchmark, the company stated. "We have world-leading performance at 50% of the cost," Suleyman said at the San Francisco event.
The generative model will work in Project Perception, a collection of AI agents for discovering and fixing weaknesses that becomes available in public preview starting Aug. 3, according to a blog post from Gallot. Project Perception can suggest and implement code changes once given permission, and it can connect with non-Microsoft products. The service represents an expansion of Microsoft's Security Copilot assistant introduced in 2023, which incorporated OpenAI's GPT-4 and now comes with Microsoft's two most high-end productivity software bundles.
Gallot rejoined Microsoft in February to become executive vice president of security, as the company's top leader in the category, former Amazon cloud executive Charlie Bell, became an individual contributor. "Cybersecurity executives look at this as maybe a way to lower the bar and be able to bring in more talent to actually staff the SOCs and and get more people to participate because right now it's very limited in the industry," Gallot told CNBC. Companies maintain security operating centers (SOCs) full of people who look out for threats to information-technology systems.
So far in 2026, Microsoft shares have come down 19%. "Given that consensus view that open-source (Chinese and other) AI models are poised to take share from the frontier labs, investor sentiment about Microsoft's high OpenAI exposure has swung back to being perceived as a risk," Microsoft analysts led by Karl Keirstead wrote in a Sunday note to clients. Keirstead recommends buying the stock. Microsoft hasn't disclosed the scale of its cybersecurity business since 2023, when it said annual revenue exceeded $20 billion.
This year the company has announced its own model that can generate code in the GitHub Copilot tool, and lately it's been drawing on a first-party model in the Excel spreadsheet program. While Microsoft CEO Satya Nadella has a partnership with OpenAI to maintain, he's also been allocating computing power to train models in house, with an eye toward spending efficiency. "By combining specialized models and data with the right agents, tools, security context, and harness, we can advance the frontier of cost to outcome," Nadella wrote in a Monday X post.
Suleyman noted that Microsoft has room to improve the new model's performance. "We have a unique data set," Suleyman said in an interview. "We've used way less than 1% of that data." Gallot commented on the broader AI security landscape: "I think it's a great illustration of why you need to defend with AI against the bad guys who have AI, right?" This follows OpenAI's disclosure last week that its models exploited a vulnerability and attacked AI startup Hugging Face's infrastructure during a test.
When does Microsoft's Project Perception become available? Project Perception enters public preview starting Aug. 3, according to a blog post from Microsoft executive vice president of security Hayete Gallot.
How does MAI-Cyber-1-Flash compare to competitor models? When paired with OpenAI's GPT-5.4, Microsoft's MAI-Cyber-1-Flash outperforms Anthropic's Mythos 5, Google's 3.5 Flash Cyber and OpenAI's GPT-5.5 Cyber on the CyberGym benchmark at 50% of the cost, according to Microsoft AI CEO Mustafa Suleyman.
What is the size of Microsoft's cybersecurity business? Microsoft hasn't disclosed the scale of its cybersecurity business since 2023, when it said annual revenue exceeded $20 billion.
Related News
Microsoft MDASH Scores 95.95% on CyberGym, Beats Claude Mythos and GPT-5.6 Sol
Nvidia, Microsoft, IBM Launch Open Secure AI Alliance for Cybersecurity
Nvidia Unveils Open Secure AI Alliance With Microsoft, SpaceX, IBM
Microsoft CEO Nadella Warns of AI Bubble Risks in CNN Interview
NVIDIA’s RTX Spark AI PC debuts this fall; MediaTek becomes a co-development partner