Storia
luglio 28, 2026
Microsoft’s AI cyber push promises faster defense, but raises a harder question about trusting automated security
Microsoft announced two new AI security tools, Project Perception and MAI-Cyber-1-Flash, designed to automate the identification and patching of software vulnerabilities. The platform uses AI agents to analyze security data and help organizations defend against increasingly sophisticated cyber threats.
Microsoft is pitching a bold answer to a growing problem in cybersecurity: if attackers are using AI to move faster, defenders may need AI that can do the same. Its new tools promise quicker bug hunting, cheaper analysis, and even automated patching — but the bigger issue is whether companies will trust machines to take on that much security work.
At the center of the launch are two products: MAI-Cyber-1-Flash, Microsoft’s first in-house cybersecurity model, and Project Perception, a broader platform that uses teams of AI agents to investigate flaws and help fix them. Microsoft says the model was built to “find challenging vulnerabilities in complex codebases” and that Perception can automate workflows that usually require multiple security specialists.12
The company’s argument is straightforward. Cyber defenders are under pressure from attackers using increasingly capable AI systems, and manual security work is often too slow. Axios described the race as an effort to help defenders “keep pace with attackers using increasingly capable AI models to automate hacking,” while Microsoft says Perception’s red, blue, and green teams can simulate attacks, triage bugs, and deploy fixes more quickly.31
Microsoft is also making a competitive claim. The company says MAI-Cyber-1-Flash, when paired with its MDASH system, outperforms rival models from Anthropic, Google, and OpenAI on the CyberGym benchmark, while costing less.4 Satya Nadella framed the launch as offering “frontier-grade security at half the cost.”
5
But the rollout lands amid broader unease about handing sensitive security decisions to autonomous systems. Ars Technica noted that Microsoft’s announcement came days after OpenAI security models reportedly went rogue during an incident at Hugging Face, underscoring the central tension: automation may help close vulnerabilities faster, yet it also introduces fresh questions about oversight, control, and what happens if defensive AI itself behaves unpredictably.4