Microsoft’s Answer to AI Threats? More AI
David Weston, Microsoft’s corporate VP for AI security, put it plainly during a July 27 security launch preview: you need agents to fight agents. That single idea drove nearly everything the company announced that day.
The Redmond giant rolled out a batch of new products and initiatives aimed at defending against AI-enabled attacks. The lineup includes a new agentic security system, a custom cyber-focused AI model, a research lab staffed by DARPA competition winners, and a global red teaming alliance.
Here’s a breakdown of what Microsoft announced and why it matters for security teams.
Project Perception: Red, Blue, and Green Agents Working Together
The centerpiece is Project Perception, an agentic security system designed to continuously identify, evaluate, and reduce security risk. It coordinates three types of specialized agents that work in tandem to improve security posture over time:
- Red agents probe for potential attack paths and vulnerabilities before they can be exploited.
- Blue agents investigate findings, apply security context, and determine what constitutes meaningful risk.
- Green agents take corrective action and strengthen defenses across the environment.
This approach mirrors Google’s AI Threat Defense platform, powered by Wiz’s Red, Blue, and Green agents, which launched in May 2026.
Hayete Gallot, executive VP at Microsoft Security, explained why this matters at scale. Microsoft sees about 100 trillion signals a day. That’s an overwhelming amount of raw data.
“We sit at your identity, data, cloud, code and even AI level,” she said. “If you add our security research, threat intelligence and red teaming efforts, you end up with even more signals.”
But raw data alone isn’t useful. “If you were to apply an agent to that raw data, it would be very slow and you would get terrible results,” Gallot added. “That’s why we are connecting and correlating all those signals so we can provide a ‘security context,’ which is organized efficiently for our agents.”
Weston noted that Project Perception will be multi-model. He demonstrated several “playbooks” based on operations a security operations center (SOC) might face. Perception enters Preview mode for all Microsoft customers on August 3.
MAI-Cyber-1-Flash: Microsoft’s First Cyber-Focused AI Model
Gallot also unveiled MAI-Cyber-1-Flash, a generative AI model built specifically for cybersecurity use cases, particularly software vulnerability analysis.
Developed by Microsoft AI (MAI), the model builds on the company’s internally developed MAI-Thinking-1 reasoning model. It’s integrated into Microsoft Security’s multi-model agentic scanning harness (MDASH).
Mustafa Suleyman, CEO at Microsoft AI, said the system is further enhanced by GPT-5.4. In CyberGym benchmarking, it outperformed competing solutions from Anthropic, OpenAI, and Google.
The numbers are striking. MAI-Cyber-1-Flash, combined with the GPT-4.5 enhancement, achieved a 95.95% success rate on the CyberGym benchmark. For comparison:
- OpenAI’s GPT-5.5 Cyber scored 85.6%
- GPT-5.6 Sol achieved 83.6%
- Anthropic’s Mythos recorded 83.8%
- Google’s Gemini 3.5 Flash Cyber reached 83.2%
Within MDASH, MAI-Cyber-1-Flash handles roughly 90% of queries, identifying and patching software vulnerabilities before verifying the fixes work. The remaining 10% of more complex tasks go to the larger GPT-5.4 model.
Suleyman said GPT-5.4 is about ten times larger than MAI-Cyber-1-Flash and can resolve the queries handed off to it. He also claimed the collaboration delivers stronger performance than competing systems while costing roughly 50% less.
From DARPA AIxCC Winners to the Microsoft Security FORGE Lab
Microsoft also announced the launch of the Security Frontier Offensive Research and Generative Exploration (FORGE) Lab.
The lab will be led by Team Atlanta, the cybersecurity researchers who won DARPA’s AI Cyber Challenge (AIxCC) at DEFCON in summer 2025. Microsoft hired the team to head the initiative, Gallot said.
Taesoo Kim, who led Team Atlanta, will head the FORGE Lab. He described the DARPA competition as a “real world AI cyber challenge” and said the winning teams combined cutting-edge research with practical engineering.
DARPA’s process encouraged teams to “strike the balance between engineering and high-risk, high-return research throughout the competition,” Kim reported. Microsoft, he said, provided the ideal environment to translate those advances into production given its scale across Azure and GitHub.
The lab’s mission, Kim explained, is to “advance the frontier of offensive security research and accelerate the evolution from AI-assisted vulnerability discovery to autonomous security research.” In other words, FORGE is meant to be the bridge from DARPA-level breakthroughs to enterprise defenses.
External Red Team Alliance: Spreading AI Safety Research Worldwide
Finally, Microsoft announced the External Red Team Alliance (EXTRA), a two-pronged initiative to broaden AI safety research.
The first piece involves Microsoft’s in-house AI red team distributing “unrestricted gifts” to 18 university labs across six continents, all in support of AI safety-related research.
Ram Shankar Siva Kumar, Microsoft’s head of the AI red team, explained in a blog post published July 17 that the funding comes with no strings attached. The goal isn’t to steer research toward specific products or predetermined outcomes.
Some of these universities are digging into the cybersecurity risks posed by AI systems themselves, looking at how models might be exploited, manipulated, or misused in real-world settings. Others are tackling the flip side: how AI can be leveraged to strengthen defenses and enhance cyber operations.
The initiative’s second component focuses on assembling a distributed network of specialized experts who can contribute to red teaming efforts in niche areas. According to Siva Kumar, this network will draw on researchers, practitioners, and regional specialists with knowledge of particular attack methods, languages, cultural nuances, or technical fields, areas where Microsoft’s internal teams may lack complete coverage.
For security teams watching the AI arms race, Microsoft’s message is clear: the defenders need the same weapons as the attackers. Whether that bet pays off will depend on execution, but the company is certainly not sitting still.