Microsoft has released a security system that lets AI agents investigate threats and fix them, not just surface findings. Project Perception, introduced July 27 and in public preview since August 3, runs on a new architecture.
The platform splits work across three agent types. Red team agents map attack paths and vulnerabilities, blue team agents triage what they find, and green team agents carry out corrective actions. To do this, the system pulls telemetry across identities, endpoints, applications, data, clouds and AI systems.
Microsoft also reported that its new MAI-Cyber-1-Flash model scored 96% on the CyberGym benchmark, 12 points above a model it names “Mythos,” at roughly half the cost of its current setup. These vendor-reported figures lack independent verification.
The primary shift for security leaders is autonomous remediation via green team agents. Before piloting, press Microsoft on which remediation steps run without human sign-off and how false positives are contained. Secondary coverage from the Times of India cites enterprise controls such as role-based access and audit logging, but no source yet details approval gates or telemetry retention limits.
This architecture introduces concentration risk. One vendor’s reasoning layer would sit on top of identity, endpoint, cloud and AI data, increasing governance and lock-in risks. Demand independent benchmarking before trusting autonomous decisions in production.



Leave a Reply