Microsoft has launched its first custom cybersecurity model, MAI-Cyber-1-Flash, alongside Project Perception, an autonomous defense system designed to autonomously scan, evaluate, patch, and deploy system fixes. According to Microsoft, MAI-Cyber-1-Flash features 137 milliárd total parameters, 5 milliárd active parameters, and a 256 ezer-token context window.
How Microsoft MAI-Cyber-1-Flash Operates Within MDASH
The MAI-Cyber-1-Flash model currently runs exclusively inside the Multi-Model Agentic Scanning Harness (MDASH) platform. According to Microsoft, the model is available through a closed beta test in Azure AI Foundry strictly for approved MDASH customers, and it does not feature a standalone API.
With 137 milliárd total parameters and a massive 256 ezer-token context window, the model processes large chunks of code and system telemetry simultaneously.
Project Perception and Multi-Agent Defense Architecture
Project Perception acts as the overarching framework connecting Microsoft’s custom security models with foundational architectures like GPT-5.4. According to Microsoft disclosures, the system divides defensive workflows among three distinct types of AI agents.
- Red agents: Map out potential attack paths that malicious actors could traverse within a network.
- Blue agents: Investigate flagged issues and determine whether they constitute an active, substantive risk.
- Green agents: Remediate verified problems and reinforce system defenses automatically.
Pro Tip: Autonomous remediation workflows require strict environment boundaries. Always verify your staging environments match the network isolation parameters used during initial deployment testing.
Managing Risk in Autonomous Patch Deployment
Allowing AI agents to directly modify and patch production systems introduces inherent operational risks. To mitigate potential disruptions, Microsoft stated that all performance tests for Project Perception and MAI-Cyber-1-Flash took place under complete network isolation.
According to the company, these testing environments operated without access to production systems, the public internet, or external third-party services. This isolated sandbox approach allows green agents to draft and deploy fixes without exposing live enterprise infrastructure to unvetted automated changes.
Frequently Asked Questions
Can developers access MAI-Cyber-1-Flash via a public API?
No. According to Microsoft, the model has no standalone API and is exclusively accessible inside the MDASH platform through the Azure AI Foundry closed beta for approved clients.
What role do red agents play in Project Perception?
Were production systems exposed during Project Perception testing?
No. Microsoft confirmed that every performance test was conducted under strict network isolation, entirely cut off from the public internet, external services, and live production systems.
Stay Ahead of Enterprise Cybersecurity Trends
Subscribe to our newsletter for deep dives into autonomous defense frameworks, emerging AI security models, and infrastructure updates.
Keep reading