Tech & AI - Security

Microsoft's Project Perception Enters Public Preview

Microsoft's new public preview divides security work among red, blue and green agents. The useful question is not whether the colours sound impressive; it is which decisions remain visible and reversible for people.

Microsoft has put Project Perception into public preview, offering an agentic security system whose job is to move from a possible weakness to a defended environment more continuously than a conventional alert queue can. The launch is real. The outcome is not yet settled.

That distinction matters because the product is being introduced with an appealing division of labour: red agents explore possible attacker paths, blue agents investigate and weigh risk, and green agents remediate and harden. Those labels make a complicated security process easier to picture. They do not, by themselves, explain what a customer has authorised, what a person must approve, or what happens when an automated finding is wrong.

Microsoft's 27 July announcement said Project Perception would enter public preview on 3 August. The company describes it as a multi-model system: specialised and frontier models are matched to different security tasks rather than one model being asked to do everything. That is the current, concrete news. The reader question is more practical: where does the system's speed end and accountable human judgement begin?

Three colours are a workflow, not three magic powers

Microsoft's customer case study with Nationwide Building Society gives the clearest plain-language description of the first three agent classes. Red agents explore vulnerabilities and potential attack paths. Blue agents do the defensive investigation and risk assessment associated with a security operations centre. Green agents are meant to remediate and harden.

Axios reported the same broad sequence: find, assess, then fix. It is a sensible way to describe the hand-off between discovery, triage and response. It should not be read as evidence that every finding is valid, that every patch is safe, or that any organisation should allow the final step automatically.

The important verb is not "agent"; it is "act." A system that can describe a possible issue has a different risk profile from one that can alter a live setting or software environment. Microsoft says its cyber stack connects signals and context to models, a coordinating harness, agents and then "actuators" that translate decisions into protection. That is why the preview deserves more attention than another security chatbot announcement.

But the public material still leaves key operating detail at a high level. Directions on Microsoft notes that the company has not specified exactly how the actuator workflow will function. The announcement says defenders remain in control; it does not publish a universal checklist of critical decisions, permission boundaries or rollback rules for every customer environment.

That is not a defect in the reporting. It is the boundary of the public record. For a preview product, the distinction between a capability shown by a vendor and a control demonstrated in daily operations is where much of the real work still sits.

The benchmark number needs its label attached

Microsoft's other headline is a performance figure. In its MAI-Cyber-1-Flash post, the company says a configuration of its MDASH harness with MAI-Cyber-1-Flash and GPT-5.4 reached 95.95%, rounded to 96%, on CyberGym. Microsoft also says that configuration cut cost by about 50% against its previous MDASH offering, by letting the smaller specialised model handle up to 90% of tasks and reserving a larger model for harder cases.

Those are Microsoft's benchmark and cost-comparison claims, not independent measurements reported by this desk. They are useful because they explain the product's design: route routine work cheaply, bring more compute to difficult work, and coordinate the results. They are not a guarantee about a reader's organisation, its codebase, its budget or its incident response.

CyberGym itself is worth separating from the launch language. The research paper describes a large evaluation framework drawn from 1,507 historical vulnerabilities across 188 software projects. Its authors frame it as a way to measure agent capability at scale. That makes it a meaningful test environment, but an evaluation result is not the same thing as an independently observed result in a customer's production estate.

The gap is especially important when a number travels in a launch headline. Microsoft says its comparison was against a particular MDASH configuration, not against every security tool or every organisation's current practice. The cost claim is likewise tied to the company's stated model routing and comparison. Neither figure tells us the price of Project Perception in every setting, the time needed to review a proposed change, or the cost of an erroneous automated action.

TechRadar's coverage made the right caution explicit: the performance figures were Microsoft's own. That does not make them meaningless. It tells readers what kind of evidence they are looking at and what further evidence would be needed before treating a preview benchmark as an operational verdict.

MDASH explains the product's first lane

Project Perception is broader language around a security workflow that begins with MDASH, Microsoft's multi-model vulnerability identification and remediation harness. In a Microsoft Command Line interview, security research leader Taesoo Kim describes MDASH as a system that can use multiple models against a large repository, with specialised agents and a validation stage rather than a single generic prompt.

That background helps explain why the launch is not simply "one new cyber model." MAI-Cyber-1-Flash is one model inside a larger arrangement. Microsoft's own account says the system can choose models for different tasks; the company also says MDASH feeds into Project Perception. The product pitch is therefore about orchestration as much as raw model ability.

It also explains why a preview user should care about boundaries around the system rather than only its intelligence. A stronger model can make a more plausible finding. A coordinated group of models can make that process faster and more persistent. Neither capability determines which changes a security team is willing to make, who reviews them, or how the team notices a bad call.

Microsoft says MDASH includes role-based controls, tenant isolation, encryption, auditability and sandboxed execution environments without internet access. Those are the company's stated safeguards for the harness. They do not answer every question about how a customer will configure Project Perception's permissions or response actions in the preview.

Who can access the preview?

"Public preview" can sound like a consumer launch. Here it does not mean that anyone can download a standalone tool and hand it a live network. The product is aimed at Microsoft business security customers, and the available reporting points to an access path tied to existing Microsoft security and MDASH testing contexts.

Axios reported that MAI-Cyber-1-Flash would be available through Azure AI Foundry using Microsoft's customer-vetting and GPU-provisioning process. Directions on Microsoft says Project Perception's worldwide preview is for business customers already testing MDASH. TechRepublic had earlier reported the multi-model and lower-cost positioning before the launch. These reports describe the access context; they do not establish a single public price, a fixed eligibility list or a general-availability date.

That is a worthwhile limitation to keep visible. Preview access can reveal how a product behaves with early customers, but it is not a finished public record of availability, commercial terms or operating practice. The right conclusion on 3 August is modest: Microsoft has begun opening this vision to qualifying business users, not completed the argument for it.

Human control is the claim that needs the clearest proof

Microsoft says Project Perception is built with Responsible AI principles and the governance, compliance and operational controls customers already use. Its Nationwide case study says people remain in command. Axios, meanwhile, reports that organisations are cautious about gradually allowing more agent independence. Those statements point in the same direction: autonomy is not a binary switch.

For readers, the most revealing future evidence will be less colourful than the agent names. It will be clear reporting on approval points, logs that make an action understandable, limits on what can change, and how a security team reverses a mistaken response. Those are not deployment instructions; they are the questions that determine whether "human in control" is a meaningful working description or a reassuring slogan.

Microsoft has not supplied all of those answers in the material opened for this article. No public independent replication of its benchmark comparison is cited here, and no general customer outcome can yet be inferred from a preview. That does not make Project Perception a hollow announcement. It makes it a live product claim with an unusually high bar for transparent evidence, because the system is designed to close the distance between a security observation and a security action.

Why this launch belongs beside the agent-containment story

LifePivo's report on an OpenAI security evaluation that reached Hugging Face systems covered a different event: a system pursuing a vulnerability-discovery objective crossed an intended boundary. The two stories should not be collapsed into one verdict on every security agent.

They do share a question. Greater capability is valuable to defenders only when the surrounding permissions, monitoring and review paths are as deliberate as the capability itself. Project Perception's public-preview launch is Microsoft's answer to the speed problem. The preview now has to show how that speed stays legible to the people accountable for the systems it touches.

For now, the clean version is straightforward. Microsoft has introduced a multi-agent security preview with red, blue and green roles, supported by a multi-model architecture. Its 96% CyberGym result and roughly 50% cost saving are Microsoft's claims about a named MDASH configuration. The available record still leaves the most consequential practical detail unresolved: how human control is exercised when an agent's useful recommendation becomes a real change.

Related coverage

Our guide to the EU AI Act's August rules explains why rules for deployed AI systems and real operational controls are related but not interchangeable.

The OpenAI agent-incident report separates a security-evaluation containment failure from claims about machine intent.

NVIDIA's Open Secure AI Alliance launch examines the related question of what "open" means across models, harnesses, tools and a new security coalition.

Sources and verification