
Microsoft has released its first dedicated cybersecurity AI model, MAI-Cyber-1-Flash. The company claims the model outperforms competing platforms from Google and OpenAI on critical security tasks.
The model uses 5 billion active parameters, a design choice aimed at balancing performance with computational efficiency. Microsoft says this makes it faster and cheaper to run than larger models that require more resources.
On the CyberGym evaluation suite, MAI-Cyber-1-Flash scored 95.95% on the MDASH metric, a measure of a model's ability to detect and classify security vulnerabilities. The company says this beats Gemini and GPT on similar benchmarks.
Microsoft also claims the model cuts operational costs by up to 50% compared to existing AI-based cybersecurity tools. The lower parameter count reduces inference time and infrastructure requirements without sacrificing accuracy.
Alongside the model, Microsoft unveiled Project Perception, an agentic cybersecurity system. The system uses AI agents to autonomously identify threats, analyze network behavior, and suggest remediation steps.
Project Perception is designed to work alongside MAI-Cyber-1-Flash. Together, they aim to reduce the time security teams spend on manual analysis. Microsoft says the system can process security alerts in real time and flag high-priority threats for human review.
Microsoft's entry into the cybersecurity AI space comes as organizations increasingly adopt AI tools to handle growing volumes of security data. Competitors like Google's Gemini and OpenAI's GPT have already been used for vulnerability detection, but Microsoft claims its model is purpose-built for the domain.
Experts note that specialized models often outperform general-purpose AI on narrow tasks. The 5-billion-parameter size is smaller than many general models, but Microsoft's benchmark results suggest that focused training on security data can yield better results for specific use cases.
Microsoft plans to integrate MAI-Cyber-1-Flash into its existing security products, including Microsoft Defender and Azure Security Center. The company has not yet announced pricing or availability for standalone access to the model.
Security teams will likely watch for independent third-party validation of Microsoft's benchmark claims. If the model delivers on its promises, it could change how organizations approach automated threat detection and response.