Microsoft Unveils Project Perception, a Closed-Loop Security System Built Around Red, Blue and Green AI Agents

1 views

Microsoft unveiled Project Perception on July 27, linking AI agents that find attack paths, assess meaningful risk and carry out remediation in a closed loop, with public preview planned for August 3. Its first vulnerability-management scenario uses MAI-Cyber-1-Flash; the 96% CyberGym score and nearly 50% cost saving are Microsoft-reported figures that have not been independently verified.

Three Agent Classes, Not Just More Alerts

Project Perception divides security work among three types of specialized agent. Red-team agents look for potential paths to compromise before attackers exploit them. Blue-team agents investigate, reason over context and decide which risks matter. Green-team agents take corrective action and strengthen defenses. They share security context spanning identities, endpoints, applications, data and cloud environments, creating a loop that continuously discovers, evaluates and remediates risk. Microsoft says humans remain in control rather than handing every response decision to agents.

Software Vulnerability Management Comes First

The first scenario brings Microsoft's MAI-Cyber-1-Flash model into MDASH, its multi-model team of vulnerability-management agents. Microsoft reports that this configuration scores 96% on CyberGym, 12 points above Mythos, while cutting costs by nearly 50% compared with the current commercial MDASH configuration. These are vendor-run benchmarks and estimates, with no independent reproduction published yet, so they are better read as product claims than externally confirmed capability.

The Shift Is From Assessment to Action

Security tools have traditionally stopped at detecting problems and producing alerts. Project Perception's more consequential change is connecting model judgment to remediation actions. Its multi-model architecture selects models according to quality, reliability, latency and cost, and Microsoft plans to begin public preview on August 3. Whether enterprises will grant agents production remediation privileges will still depend on audit trails, permission boundaries and human approval controls; Microsoft has not yet disclosed full pricing or rollout details.

via: Official Microsoft Blog (2026-07-27; verified 2026-07-28)