Microsoft Launches its First Cybersecurity AI Model, MAI-Cyber-1-Flash

MAI-Cyber-1-Flash paired with MDASH and GPT-5.4 outperformed Google's newly launched 3.5 Flash Cyber, OpenAI's GPT-5.6 Sol, and Anthropic's Mythos 5 in finding vulnerabilities.

Updated on Jul 29, 2026 02:49 PM
Microsoft Launches its First Cybersecurity AI Model, MAI-Cyber-1-Flash - feature image

San Francisco: Microsoft unveiled its first cybersecurity-focused AI model, MAI-Cyber-1-Flash at an event in San Francisco. The launch also included a new agentic security platform called Project Perception.

The model does not work as a standalone product. It is built to power MDASH, Microsoft’s harness dedicated to identifying and fixing software vulnerabilities. Access is limited to select customers through an Azure AI Foundry private preview, and requires extra approval, since tools that find vulnerabilities can be misused by attackers too.

Strong benchmark results

Microsoft says the results are notable. In testing on the CyberGym cybersecurity evaluation framework, MAI-Cyber-1-Flash paired with MDASH and GPT-5.4 outperformed Google’s newly launched 3.5 Flash Cyber, OpenAI’s GPT-5.6 Sol, and Anthropic’s Mythos 5 in finding vulnerabilities. The MDASH system scored 95.95 percent on CyberGym using this combination.

Mustafa Suleyman, CEO of Microsoft AI, called the results a major milestone. He said the combined system “beats out Gemini, GPT 5.5 Cyber, GPT 5.6 Sol, and Mythos 5 on Cyber Gym, which is the primary benchmark.”

Built for cost savings, not just performance

A key part of the pitch is affordability. Microsoft says MAI-Cyber-1-Flash is designed to handle up to 90 percent of MDASH’s tasks, while GPT-5.4 is reserved only for the hardest 10 percent. This routing approach is claimed to cost 50 percent less than the company’s current best MDASH setup, which uses a combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex.

Technically, the new model is a sparse mixture-of-experts fine-tune of MAI-Code-1-Flash, carrying 137 billion total parameters with 5 billion active at a time, and supports a 256k context window. It was trained only for defensive work such as patching bugs, not offensive tasks, which is why it scores zero by design on ExploitGym, a benchmark for writing exploits.

Independent scrutiny

Some outlets have flagged caveats. The 95.95 percent figure wasn’t reflected on CyberGym’s public leaderboard as of July 28, which still showed lower scores for competing systems. Details like token usage, call volume, and compute allocation behind the cost claim haven’t been disclosed, making the comparison hard to independently verify.

Part of a bigger industry trend

The launch comes just days after Google Cloud rolled out its own tool, CodeMender, with AWS, Nvidia, and others also racing to defend against AI-driven cyberthreats. Analysts note the emerging theme is that cybersecurity increasingly needs a multi-model approach, and Microsoft’s move also reflects its broader push to build its own AI model family and reduce reliance on costlier frontier models from partners like OpenAI.

Microsoft also signed on to Nvidia’s newly launched Open Secure AI Alliance, aimed at sharing security tools across the industry.

Published on July 29, 2026

Shobhit Kalra

Chief Sub Editor

Shobhit Kalra is the Chief Sub Editor at Tea4Tech, with over 12 years of experience across digital media, digital marketing, and health technology. He is responsible for editorial review, content structuring, and quality control of articles covering software, SaaS products, and developments across the technology ecosystem. At Tea4Tech, Shobhit over...

View Bio