Microsoft launched its first cybersecurity-specialised AI model and a new agentic security platform at a San Francisco event on Monday, extending the MDASH multi-agent security system already rolling out to South African customers and putting the company into direct competition with Anthropic, Google and OpenAI on the fastest-growing frontier of enterprise AI security.
The new model, MAI-Cyber-1-Flash, is designed to identify complex vulnerabilities in software codebases and is built to power MDASH — Microsoft’s harness dedicated to software vulnerability identification and remediation. The new platform, Perception, deploys agentic teams to help defenders identify and fix bugs, and integrates with MDASH. Both will be available in preview from November 3.
Microsoft chief of AI Mustafa Suleyman — a co-founder of DeepMind who now leads Microsoft’s AI division — pitched the launch around benchmark results. The company claims MAI-Cyber-1-Flash, paired with OpenAI’s GPT 5.4 inside the MDASH harness, outperforms Google’s Gemini, OpenAI’s GPT 5.5 Cyber and GPT 5.6 Sol, and Anthropic’s Mythos 5 on Cyber Gym — the benchmark Suleyman described as the “golden benchmark” for AI cybersecurity performance. Microsoft, he said, is “shipping this into production immediately.”
The pitch on Perception is different. Where MAI-Cyber-1-Flash is a model, Perception is a working defensive architecture. It operates through red teams — agents that simulate potential attacks by modelling threat actor behaviour and likely exploitation paths; blue teams — agents that detect and triage existing bugs; and green teams — agents that take corrective action against those bugs.
Microsoft VP for security Hayete Gallot framed the platform as a scale-and-speed response to what has become an AI-versus-AI environment on the attacker side. Enterprise defenders, she said, need to “defend against AI with AI at the scale and speed that the attackers have.” Dave Weston, Perception’s lead engineer, framed the value proposition as compression: work that previously took hours of manual effort across specialised roles inside a security organisation now runs in minutes, from discovery and prioritisation through to detection, posture fixing and code fix.
The launch lands directly on top of a South African cybersecurity picture iAfrica documented in detail last month. When Microsoft brought MDASH to South African customers in June, the accompanying Boston Consulting Group report — “AI Is Raising the Stakes in Cybersecurity” — found that nearly 60% of African companies had experienced AI-enabled cyberattacks in the past year, yet only half were prioritizing AI in their defences. Just 29% had implemented advanced AI-driven cybersecurity tools, and only 3% reported a significant increase in cybersecurity budgets in response to AI-driven threats. Microsoft’s own Digital Defence Report had already flagged AI-enabled phishing emails as 4.5 times more likely to be clicked than traditional attempts. On the workforce side, 82% of African organisations told BCG they were struggling to hire AI-cybersecurity talent — a shortfall Microsoft has been trying to address through its cybersecurity skills campaign, its Ikamva Digital delivery across all 50 South African TVET colleges, and its Secure Now initiative.
Perception, on paper, is designed for exactly the environment those figures describe. If defenders in African organisations can’t reasonably staff AI-native security teams, the argument runs, deploying agentic red, blue and green teams that automate the manual work of detection, triage and remediation is one of the more direct ways to close the exposure gap without waiting a decade for the talent pipeline to fill.
The launch also enters an increasingly crowded AI cybersecurity market. Anthropic launched Mythos earlier this year and released it to a small group of partner organisations through a programme called Glasswing. OpenAI launched its own security offering in May under a programme called Daybreak. Microsoft’s positioning is that it’s paired the most competitive coding model in the security-benchmark space (MAI-Cyber-1-Flash + GPT 5.4) with a production-ready agentic platform layered on top — a bundle its competitors have not yet fully matched.
The competitive framing sits interestingly against Microsoft CEO Satya Nadella’s own recent warning to enterprises. Nadella told CNN’s Fareed Zakaria earlier this month that firms wholly relying on proprietary AI labs will not survive, and specifically urged companies to keep their coding harnesses separate from the underlying models. Perception is, in effect, Microsoft’s commercial version of that architecture: a harness-plus-agentic-layer that customers can direct at multiple models, with MAI-Cyber-1-Flash bound to GPT 5.4 in Microsoft’s benchmark configuration. Nadella’s warning, and Microsoft’s product, are two sides of the same argument.
Whether Perception meaningfully compresses the AI-cybersecurity exposure gap that BCG’s African data documented, or reproduces the same dependence-on-a-single-vendor pattern that African AI strategies have been flagging as a sovereignty risk, will be the more interesting test once the November 3 preview lands with African enterprise customers already using MDASH.





