Microsoft has expanded its growing portfolio of AI systems with the launch of MAI-Cyber-1-Flash, a model designed specifically to help businesses protect their computer networks. The new AI model has been trained exclusively for cybersecurity by analyzing decades of data Microsoft has gathered while responding to hacking incidents affecting its customers.
With a broad portfolio of products spanning enterprise software, cloud services, and operating systems, Microsoft has amassed extensive data on a wide range of cyberattacks, giving the model deep expertise in identifying security threats. Unlike some rivals, however, Microsoft did not share the model with independent testers for evaluation ahead of its release. Instead, the company claimed that the model, when integrated into its security tools, would top the leaderboard on the standard Cyber Gym benchmark after its launch on Monday, outperforming offerings from OpenAI and Anthropic.
STORY CONTINUES BELOW THIS AD
According to Microsoft, MAI-Cyber-1-Flash will cost roughly half as much as competing technologies. Those alternatives are more expensive partly because they are designed for a broad range of tasks rather than cybersecurity alone. Mustafa Suleyman said Microsoft deliberately focused on lowering costs so the model could be deployed more quickly and at a wider scale.
The new model will also power another Microsoft offering, Project Perception, which transforms various AI models into teams of autonomous agents designed to detect and remediate network vulnerabilities. These AI agents can use other software to perform tasks largely on their own, and in some cases, Microsoft’s agents will be capable of imitating hackers to identify and patch security weaknesses.
Project Perception
introduces agentic security systems that deploy teams of AI agents within MDASH to continuously monitor, identify, patch, and close emerging security threats. Microsoft said Project Perception will soon integrate MAI-Cyber-1-Flash across a broader range of security workflows beyond software vulnerability detection.
According to Microsoft, MAI-Cyber-1-Flash is trained on data from its extensive cybersecurity ecosystem, including the Microsoft Security Response Center, more than 100 trillion security signals processed daily, and insights from 1.6 million customers. The company also uses a reinforcement learning feedback loop that continuously improves the model based on real-world attack, defense, and remediation outcomes.
STORY CONTINUES BELOW THIS AD
Microsoft describes MAI-Cyber-1-Flash as a compact, code-focused cybersecurity model derived from the MAI Thinking-1 lineage. It has been trained using data from Microsoft’s security infrastructure, which spans identity, endpoint, cloud, and network environments, along with a vast repository of real-world exploits and remediation efforts.
Threat identification power of more than 100 AI agents
The company said MDASH, its multi-agent vulnerability identification and remediation framework, has been fine-tuned by leading cybersecurity experts. The platform uses more than 100 AI agents powered by multiple frontier models to identify, validate, and remediate software vulnerabilities. Agentic code scanning serves as a core function within the Security Operations Center and powers Project Perception.
Microsoft added that, as its first AI model built specifically for cybersecurity, MAI-Cyber-1-Flash has been designed with a security-first approach. The model includes enterprise-grade safeguards such as role-based access controls, tenant isolation, encryption, auditability, and sandboxed execution environments with no internet access, enabling organizations to deploy advanced AI-powered cyber defenses while maintaining governance, security, and operational control.
AI-powered coding models have emerged as a major cybersecurity concern due to their ability to discover software vulnerabilities. Anthropic, OpenAI, Google, and Microsoft have restricted access to their most advanced security-focused models over fears they could be misused for cyberattacks, while the White House has explored oversight of such systems. Despite these safeguards, researchers have demonstrated that publicly available AI models can already be used to create dangerous malware, and the rapid release of powerful open models by Chinese startups suggests these capabilities are becoming increasingly widespread.
STORY CONTINUES BELOW THIS AD