Microsoft CEO Satya Nadella speaks at the Microsoft AI Tour at the TikTok Entertainment Center in Sydney on April 23, 2026.
George Chan | Getty Images
microsoft On Monday, we talked about new artificial intelligence models for finding cybersecurity vulnerabilities. The move marks the company’s first major effort since reviving its cybersecurity business. google The executive, Hiete Garot, will run the unit.
When combined with OpenAI’s general-purpose GPT-5.4, Microsoft’s MAI-Cyber-1-Flash outperforms Anthropic’s Mythos 5, Google’s 3.5 Flash Cyber, and OpenAI’s GPT-5.5 Cyber on the Cyber Gym benchmark, the company said.
“We’re delivering world-class performance at 50% of the cost,” Mustafa Suleiman, CEO of Microsoft AI, said at the company’s event in San Francisco.
This generative model is the software maker’s first for cybersecurity. It runs on Project Perception, a collection of AI agents to find and fix weaknesses, and will be available in public preview starting August 3, according to a blog post from Gallot.
She rejoined Microsoft in February as the company’s top security leader, serving as vice president of security. Amazon Cloud executive Charlie Bell has become an individual contributor.
Generative AI models have made it easier for attackers to quickly exploit newly documented vulnerabilities. Anthropic and OpenAI have released a model that can help cybersecurity personnel defend themselves.
As of 2026, Microsoft stock is down 19%. “Investor sentiment regarding Microsoft’s high exposure to OpenAI is shifting back toward being perceived as a risk, given the consensus view that open source (such as Chinese) AI models are poised to take market share from Frontier Labs,” Microsoft analysts led by Karl Keersted wrote in a note to clients on Sunday. Mr. Kiersted recommends buying the stock.
The company introduced its own model this year that can generate code with its GitHub Copilot tool, and recently leveraged a first-party model for its Excel spreadsheet program. Microsoft CEO Satya Nadella wants to maintain the partnership with OpenAI, but is allocating computing power to train models in-house for cost efficiency.
“By combining specialized models and data with the right agents, tools, security context, and harnesses, we can move forward on the cost and outcomes front,” Nadella wrote in a Monday X post.
Microsoft hasn’t disclosed the size of its cybersecurity business since 2023, when it announced annual revenue of more than $20 billion.
In 2023, Microsoft introduced the Security Copilot assistant for cybersecurity professionals, which incorporates OpenAI’s GPT-4. The service comes with two of Microsoft’s most high-end productivity software bundles. Project Perception can suggest and implement code changes if given permission, and can connect with non-Microsoft products.
Cybersecurity executives “think this is a way that we might be able to lower the bar and actually get more people to staff the SOC and get more people involved,” Garrott told CNBC. Companies maintain a security operating center (SOC) consisting of personnel who are alert to threats to information technology systems.
OpenAI announced last week that its model had exploited a vulnerability and attacked the infrastructure of AI startup Hugging Face during testing. Hugging Face conducted forensic analysis using a model from Chinese research institute Z.ai.
“I think this really illustrates why we need to use AI to defend against bad guys with AI, right?” Garot said.
Microsoft has plenty of room to improve the performance of the new model.
“We have our own dataset,” Suleiman said in an interview. “We used less than 1% of the data.”
WATCH: SandboxAQ CEO weighs in on security incident involving OpenAI and Hugging Face

