Microsoft deploys its AI army

What if the best defense against AI were another AI?
Microsoft just made that a reality this August.
For years, security teams have fought automated threats with manual tools. The speed of attackers outpaced any reasonable human response.
Now Microsoft has unveiled a complete arsenal: proprietary models, offensive labs, and university partnerships, all aimed at having AI defend where AI attacks.

The battlefield changed, and Microsoft knows it.
On July 27, Microsoft introduced Project Perception, an agent-based security system where agents work as a team to continuously identify, assess, and reduce risk. Three classes of specialized agents coordinate to improve security posture over time. The company processes roughly 100 trillion signals daily and connects that information to create context that agents consume efficiently.
Project Perception opens its Preview on August 3.
Alongside it, Microsoft introduced MAI-Cyber-1-Flash, a generative model designed for software vulnerability analysis integrated into MDASH. Powered by GPT-5.4, the combination achieved 95.95% on the CyberGym benchmark, outperforming OpenAI’s GPT-5.5 Cyber, Anthropic’s Mythos, and Google’s Gemini 3.5 Flash Cyber, all of which scored above 83% but clearly fell short.
And all of that at approximately 50% less cost than the alternatives.
Within MDASH, MAI-Cyber-1-Flash handles 90% of queries: detecting vulnerabilities, applying patches, and verifying they work. The more complex 10% is passed to GPT-5.4, which is roughly ten times larger. The combination delivers superior performance at lower cost, according to Mustafa Suleyman, CEO of Microsoft AI.

But Microsoft didn’t stop at models.
It also announced the FORGE Lab, led by Team Atlanta, winners of DARPA’s AI Cyber Challenge at DEFCON 2025.
Its mission is to accelerate the transition toward fully autonomous and scalable security research.
The FORGE Lab connects DARPA-level advances with Azure and GitHub defenses, platforms with hundreds of millions of users.
And there was still one more piece.
Microsoft also launched EXTRA, an external red team initiative with two pillars: no-strings-attached funding for 18 university labs across six continents, and a distributed network of experts specialized in attack methods, languages, and cultural contexts where internal teams have blind spots.
The race between attackers and defenders is accelerating.
What Microsoft unveiled is not just a product: it is a response architecture where each layer reinforces the next. Project Perception observes and acts in real time. MAI-Cyber-1-Flash detects and patches vulnerabilities before anyone can exploit them. The FORGE Lab researches the threats of the future. And EXTRA extends reach into territories no internal team can cover alone.
The smaller model outperforms the larger rivals.
MAI-Cyber-1-Flash proves that size isn’t everything: being ten times smaller than GPT-5.4, it handles 90% of the workload with better benchmark results than models from OpenAI, Anthropic, and Google. The key lies in specialization and in how the models hand work off to one another.

Universities enter the global security equation.
The 18 university labs funded by EXTRA are not accountable to Microsoft, nor are they required to direct their research toward specific products. The idea is that academic freedom will produce the discoveries that internal teams cannot generate.
Agents that attack, agents that defend.
David Weston, Corporate VP of AI Security at Microsoft, put it plainly: you need agents to fight agents. That’s not marketing. It’s the logic behind every announcement that day: if attackers automate with AI, the only viable response is to also automate defense with more context and better models.
AI no longer just attacks — it also protects.
The question is whether the rest of the industry can keep up with this pace, or whether Microsoft is building an advantage that is impossible to close.
What you can do
- ✓Enable Project Perception in Preview starting August 3.
- ✓Review whether your stack integrates specialized AI models.
- ✓Follow the FORGE Lab to anticipate emerging autonomous threats.
Are you ready for a world where AI attacks and defends at the same time?
Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.
Related articles
Nacata Security, reach out to us anytime
We are Nacata Security, get to know us
web: nacata.io
email: info@nacata.io
Phone: 919930793
LinkedIn: Nacata Security
The intersection of artificial intelligence and cybersecurity: attacks that use AI to deceive or impersonate, security of models and conversational assistants, and new AI-based threat detection tools.
RATING
9.7
Who are we?
At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.
We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.
We’d be glad to get in touch with you for whatever you need.




