Financial Associated Press, July 28 Microsoft has released its first generative AI model dedicated to cybersecurity, claiming to achieve leading performance while costing only half as much as competitors. Microsoft is accelerating its push to deploy proprietary AI in the cybersecurity sector.
On Monday local time, Microsoft unveiled the MAI-Cyber-1-Flash, its first generative AI model designed specifically for cybersecurity.
Microsoft stated that when paired with the OpenAI general-purpose model GPT-5.4, the dedicated model outperformed Anthropic's Mythos 5, Google 's 3.5 Flash Cyber, and OpenAI's GPT-5.5 Cyber on the CyberGym benchmark.
CyberGym, developed by the University of California, Berkeley, is a widely used industry benchmark for evaluating AI's ability to identify and replicate software security vulnerabilities.
At an event in San Francisco, Microsoft's AI CEO Mustafa Suleyman said:
"We have achieved world-leading performance at 50% of the cost."
This marks the first major initiative since Microsoft reorganized its cybersecurity business leadership. In February, Hayete Gallot, a former Google executive, returned to Microsoft as Executive Vice President of Security.
Using AI to Combat AI
The MAI-Cyber-1-Flash will be integrated into Microsoft's Project Perception. Gallot explained that Project Perception is a system composed of multiple AI agents designed to detect and fix security vulnerabilities in software, with a public preview scheduled for August 3 local time.
Industry observers noted that Microsoft aims to use Project Perception to bridge the gap between vulnerability identification and remediation. With user authorization, the system can not only suggest code modifications but also implement them directly, and it is compatible with non-Microsoft products.
As generative AI capabilities continue to grow, attackers can exploit newly disclosed security vulnerabilities more quickly, often infiltrating systems before companies can patch them. This has made cybersecurity defense a key battleground for major AI companies.
Anthropic and OpenAI have already released models designed to assist cybersecurity professionals in defense efforts.
Last week, OpenAI disclosed that during an internal test, its model autonomously discovered and exploited a vulnerability to breach its sandbox isolation, infiltrating the infrastructure of AI platform Hugging Face. Subsequently, Hugging Face used China's Zhipu Z.ai model for forensic analysis.
Gallot argued that this case illustrates why companies need AI for defense.
"This fully demonstrates that when facing malicious attackers equipped with AI tools, we must also rely on AI to build our defense systems."
Gallot also noted that cybersecurity managers are increasingly viewing AI as a tool to lower the barrier to entry and expand the talent pool. Currently, companies typically operate Security Operations Centers (SOCs) staffed by specialists who continuously monitor IT systems for potential threats, but such talent remains scarce. With AI, companies can involve more personnel in security operations.
Accelerating Proprietary Models
The launch of this cybersecurity AI model is the latest step in Microsoft's push to expand its proprietary AI capabilities. Since the beginning of the year, Microsoft has launched a proprietary model to generate code in GitHub Copilot and has recently begun integrating its own first-party models into Excel spreadsheet products.
Nadella wrote on a social platform on Monday:
"By combining specialized models, data, and the right agents, tools, security environments, and operational frameworks, Microsoft can further improve the cost-performance ratio."
Industry experts noted that such improvements are particularly important for Microsoft now. Since 2026, Microsoft's stock price has fallen by 19%.
In a report released on Sunday, UBS analyst Karl Keirstead and his team, who track Microsoft, stated:
"The market widely expects that open-source AI models from China and other regions will capture market share from frontier labs. As investor sentiment shifts, Microsoft's heavy reliance on OpenAI is now seen as a risk."
Cybersecurity itself is also a significant revenue source for Microsoft. The company last disclosed the scale of this business in 2023, reporting annual revenue of over $20 billion.
However, there is still room for improvement in MAI-Cyber-1-Flash. Suleyman said in an interview:
"We have a unique security dataset, and we have only used less than 1% of it to train the model so far."
A dataset refers to a collection of relevant information, cases, and materials used to train AI models.
(Source: Financial Associated Press)

