Microsoft cyber AI model targets code flaws at lower cost
Microsoft said MAI-Cyber-1-Flash will enter Project Perception, claiming stronger benchmark results at half the cost.
By Amanda Ross · Deals Correspondent
· 3 min read
Microsoft introduced a Microsoft cyber AI model for finding vulnerable code, positioning the tool as a lower-cost way to support corporate security teams as AI-assisted attacks accelerate. The company said MAI-Cyber-1-Flash, used with OpenAI’s general-purpose GPT-5.4, beat Anthropic’s Mythos 5, Google’s 3.5 Flash Cyber and OpenAI’s GPT-5.5 Cyber on the CyberGym benchmark.
Mustafa Suleyman, chief executive of Microsoft AI, said at a company event in San Francisco that the system delivered “world-leading performance at 50% of the cost.” Microsoft did not disclose the full economics behind that comparison.
The launch is Microsoft’s first major cybersecurity initiative since Hayete Gallot returned from Google in February to become executive vice president of security. Charlie Bell, the former Amazon cloud executive who had led the category, moved into an individual contributor role.
What is Microsoft’s cyber AI model?
MAI-Cyber-1-Flash is a generative AI model built for cybersecurity tasks, beginning with the detection of risky sections of source code. Microsoft said it will operate inside Project Perception, a set of AI agents designed to identify software weaknesses and, with permission, suggest or carry out code fixes.
Project Perception will become available in public preview on Aug. 3, Gallot wrote in a Microsoft blog post. The tools can connect to products outside Microsoft’s own software stack, according to the company.
The mechanism is straightforward in principle: a specialized model examines code and security context, while agents use tools and permissions set by the customer to turn findings into remediation steps. Microsoft is arguing that task-specific models can reduce compute costs compared with relying only on larger, general-purpose systems.
Microsoft chief executive Satya Nadella wrote on X that combining specialized models and data with agents, tools and security context can improve “cost to outcome.” The company has also been developing first-party models for GitHub Copilot and Excel, as Nadella maintains Microsoft’s OpenAI partnership while allocating computing capacity to internal model training.
Why Microsoft is pushing into AI security now
Generative AI has lowered the time required for attackers to test newly disclosed vulnerabilities, while Anthropic and OpenAI have released models intended to help defenders. Microsoft is seeking a larger role in that market through both its security software and its AI infrastructure.
Gallot told CNBC that cybersecurity executives see AI tools as a possible way to broaden staffing for security operating centers, or SOCs, where teams monitor threats to corporate information-technology systems. She said the industry is constrained by limited available talent.
OpenAI said last week that its models exploited a vulnerability and attacked AI startup Hugging Face’s infrastructure during a test. Hugging Face used a model from Chinese lab Z.ai for forensic analysis. Gallot told CNBC the episode showed the need to “defend with AI against the bad guys who have AI.”
Microsoft has not updated the size of its cybersecurity business since 2023, when it said annual revenue had surpassed $20 billion. That same year, the company introduced Security Copilot, an assistant for cybersecurity professionals that used OpenAI’s GPT-4 and is now included in Microsoft’s two highest-end productivity software bundles.
The announcement comes during a weaker year for Microsoft shares, which CNBC reported have fallen 19% so far in 2026. Analysts led by Karl Keirstead wrote in a Sunday client note that investor sentiment toward Microsoft’s exposure to OpenAI had shifted toward viewing it as a risk, amid expectations that open-source AI models, including Chinese systems, could take share from frontier labs. Keirstead recommends buying the stock.
Suleyman said Microsoft still has room to improve the new model by using more of its own information. “We have a unique data set,” he told CNBC. “We’ve used way less than 1% of that data.”
This story draws on original reporting from CNBC.