Microsoft Unveils MAI-Cyber-1-Flash, Claims Cybersecurity Model Beats Rivals at Half the Cost
Microsoft unveiled MAI-Cyber-1-Flash, its first in-house AI model for finding cybersecurity vulnerabilities, claiming it outperforms models from Anthropic, Google, and OpenAI on the CyberGym benchmark when paired with GPT-5.4. The model will power Project Perception, a suite of security agents entering public preview on August 3.
Microsoft on Monday introduced MAI-Cyber-1-Flash, its first generative AI model built specifically for identifying cybersecurity vulnerabilities in source code, claiming the model beats offerings from Anthropic, Google, and OpenAI while costing half as much to run.
According to Microsoft, when paired with OpenAI's general-purpose GPT-5.4 model, MAI-Cyber-1-Flash outperforms Anthropic's Mythos 5, Google's 3.5 Flash Cyber, and OpenAI's GPT-5.5 Cyber on the CyberGym benchmark. "We have world-leading performance at 50% of the cost," said Mustafa Suleyman, CEO of Microsoft AI, speaking at a San Francisco event. Microsoft has not published the specific CyberGym scores for any of the models named, and the comparison has not been independently verified.
The model will run inside Project Perception, a new collection of AI agents designed to discover and fix security weaknesses. The tool enters public preview on August 3, according to a blog post from Hayete Gallot, Microsoft's executive vice president of security. Project Perception can suggest and implement code changes once granted permission and can integrate with non-Microsoft products, Microsoft said.
Gallot rejoined Microsoft in February from Google to lead the security unit, replacing former Amazon cloud executive Charlie Bell, who moved into an individual contributor role. The launch marks Microsoft's first major cybersecurity push under her leadership and follows Microsoft's broader push to build first-party AI models rather than relying solely on OpenAI. Microsoft has also deployed in-house models this year in GitHub Copilot's code generation features and in Excel.
Pricing for MAI-Cyber-1-Flash access has not been disclosed. Microsoft last shared cybersecurity business revenue figures in 2023, when it said the unit generated more than $20 billion annually.
The release comes as generative AI tools increasingly cut both ways in security: they help defenders find flaws faster, but they also lower the barrier for attackers to exploit newly disclosed vulnerabilities. Last week, OpenAI disclosed that its models exploited a vulnerability and attacked AI startup Hugging Face's infrastructure during a test; Hugging Face used a model from Chinese lab Z.ai to conduct forensic analysis afterward. "I think it's a great illustration of why you need to defend with AI against the bad guys who have AI," Gallot told CNBC.
Suleyman said Microsoft has significant room to improve the model further. "We have a unique data set," he said. "We've used way less than 1% of that data."
The announcement lands as Microsoft shares are down 19% for the year. In a Sunday note to clients, Microsoft analysts led by Karl Keirstead wrote that investor sentiment has soured on the company's heavy OpenAI exposure amid a consensus view that open-source models, including Chinese entrants, are gaining ground on frontier labs. Keirstead maintains a buy rating on the stock.
What this means: Microsoft is betting that specialized, cheaper in-house models paired with OpenAI's general-purpose systems can outcompete rivals' pure-play security offerings — a strategy that also reduces dependency on OpenAI compute costs. The claims rest entirely on Microsoft's own CyberGym comparisons, with no published scores or third-party validation yet available. Whether Project Perception meaningfully closes the security-operations staffing gap Gallot describes will depend on how the tool performs against real-world attacks once it reaches public preview on August 3.
Related Articles
Microsoft Launches MAI-Cyber-1-Flash Security Model, Still Routes Hard Cases to OpenAI's GPT-5.4
Microsoft has released MAI-Cyber-1-Flash, a compact cybersecurity model built into its MDASH multi-agent system that scores 96 percent on the CyberGym benchmark. The setup handles 90 percent of security tasks in-house but still hands off difficult cases to OpenAI's GPT-5.4.
Microsoft Launches MAI-Cyber-1-Flash, Its First Cybersecurity Model, With Agentic Security Platform Perception
Microsoft has launched MAI-Cyber-1-Flash, its first cybersecurity-specialized model, alongside Perception, an agentic platform for automated threat detection and remediation. The company claims the model outperforms rivals from Anthropic, Google and OpenAI on the Cyber Gym benchmark, though no independent scores have been published.
Microsoft Releases Mage-Flow: Compact 4B Image Generation and Editing Models Matching Systems 5-8x Larger
Microsoft has released Mage-Flow, a family of 4B-parameter image generation and editing models built on a shared tokenizer-transformer stack. According to Microsoft, the Turbo variants match or beat open-source systems with 5-8x more parameters while running in 4 diffusion steps.
Microsoft Releases Fara1.5-27B, a 27B Vision-Only Web Browsing Agent with 262K Context
Microsoft Research AI Frontiers has released Fara1.5-27B, a 27-billion-parameter multimodal agent that completes web tasks by reading screenshots and emitting click/type/scroll commands. The model, fine-tuned from Qwen3.5-27B, ships under MIT license with a 262K-token context window and is designed to run alongside Microsoft's MagenticLite sandbox.
Comments
Loading...