Microsoft Shifts Security Workload to In-House AI, Cuts Costs by Half
Microsoft has shifted most of its security workload to an in-house AI model called MAI-Cyber-1-Flash, reducing its compute bill by roughly half. This move was announced on July 27 by Microsoft Security chief Hayete Gallot and is part of the company's Project Perception.
The system uses three teams of AI agents: Red agents probe customer systems for potential paths an attacker could take, Blue agents investigate signals and decide which risks matter, and Green agents write and deploy fixes. Human approval is required for high-impact actions.
Until now, Microsoft's MDASH vulnerability-finding harness relied heavily on rented intelligence from OpenAI. However, the new release replaces most of this capacity with MAI-Cyber-1-Flash, a code-heavy specialist trained on Microsoft's own record of real exploits and remediations. This model is significantly smaller than those used by OpenAI but has achieved impressive results.
The full MDASH harness scored 95.95% on the CyberGym benchmark, surpassing Anthropic's Mythos model. However, it's essential to note that this score belongs to the multi-stage system, not just the small model alone.
Microsoft's move has significant implications for the industry. By building its own specialist models and controlling the routing of tasks between them, the company can reduce costs while improving performance. This approach is being replicated by other platform owners like Google and Cisco.