IT Brief Ireland - Technology news for CIOs & IT decision-makers
Ireland
Microsoft launches AI cyber model to cut security costs

Microsoft launches AI cyber model to cut security costs

Wed, 29th Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Microsoft has introduced MAI-Cyber-1-Flash in its MDASH security system, saying the model halves operating costs compared with its current top-tier MDASH setup.

MAI-Cyber-1-Flash sits within MDASH, a multi-agent system for identifying and fixing software vulnerabilities. It is designed to handle most security analysis tasks, with larger models reserved for the hardest cases.

Microsoft said the combined MDASH and MAI-Cyber-1-Flash system scored 96% on CyberGym, a benchmark for testing how systems analyse large codebases and identify real vulnerabilities. It said that score is 12 percentage points above Mythos and ahead of Gemini and GPT models on the same benchmark.

The launch reflects a broader push by major technology groups to build AI tools for cyber defence as automated attacks become more frequent and cheaper to carry out. Microsoft argued that the falling cost of finding software flaws has made periodic scanning and delayed patching less effective.

Model choice

Microsoft said MAI-Cyber-1-Flash was built to carry out up to 90% of tasks in the workflow. MDASH then calls on larger models, including GPT-5.4, for the remaining 10% that require more intensive analysis.

The approach lowers token costs, which Microsoft identified as a major limiting factor for security teams processing high volumes of potential threats. The current benchmark compares the new setup with an existing MDASH mix of GPT-5.4, GPT-5.4 mini and GPT-5.3 codex.

Alongside the model release, Microsoft also launched Perception, an agentic security system within MDASH. It uses teams of agents for workflows including monitoring, patching and blocking emerging threat paths.

Perception is also expected to use MAI-Cyber-1-Flash across a broader set of security tasks beyond software vulnerability work. Microsoft said agent-based code scanning is now a core function in the Security Operations Centre and feeds into the Perception system.

Data advantage

Microsoft tied the launch to the scale of its security operations, saying it sees more than 100 trillion security signals a day and draws operational insight from 1.6 million customers across identity, endpoint, cloud, data, browser and application environments.

It said that historical record gives it a large body of examples covering real exploits and remediations. Microsoft said this data is central to training and tuning both the model and the broader MDASH system, which includes more than 100 agents built to find, validate and fix vulnerabilities.

It added that MAI-Cyber-1-Flash comes from the MAI-Thinking-1 lineage and was developed in-house on code-focused training data. Microsoft also described cybersecurity as a reinforcement learning environment because defenders can link actions to outcomes, such as whether a threat was blocked, contained or left exploitable.

Safety measures

Because this is Microsoft's first cyber model, the company put heavy emphasis on safeguards around training and deployment. It said the model was calibrated with a security-first approach, reviewed by its AI red team, tested through automated and expert-led adversarial exercises, and assessed by an independent third party.

Microsoft also outlined the controls available to customers through MDASH, including role-based controls, tenant isolation, encryption, auditability and sandboxed execution environments with no internet access.

The launch comes as software suppliers, cloud providers and security companies race to show that AI can do more than generate code and text. In cyber defence, the immediate test is whether these systems can find and fix weaknesses at a pace that matches automated probing by attackers.

Microsoft framed the release as a step towards that goal, arguing that security tools must move from periodic reviews to continuous monitoring and remediation. It said its broader aim is to build systems that improve through day-to-day defensive operations across its security estate.

"Cybersecurity is not just a data-rich domain; it is a live reinforcement learning loop."