Why Security Needs a New Cyber Stack: Introducing Project Perception
- Microsoft is launching Project Perception, an agentic security system designed to counter AI-driven threats, with a public preview scheduled for August 3.
- The system operates through a closed-loop defense mechanism coordinating three distinct classes of specialized agents, according to Microsoft.
- Microsoft describes this as a new "cyber stack" built from the ground up.
Microsoft is launching Project Perception, an agentic security system designed to counter AI-driven threats, with a public preview scheduled for August 3. According to The Official Microsoft Blog, the system replaces traditional alert-based security with a “cyber stack” that uses specialized AI agents to perceive risk, reason across digital estates, and execute protections at machine speed.
Project Perception’s Agentic Architecture
The system operates through a closed-loop defense mechanism coordinating three distinct classes of specialized agents, according to Microsoft. Red team agents identify potential compromise paths before attackers can exploit them, while blue team agents investigate context to determine meaningful risk. Green team agents execute corrective actions to strengthen the environment’s defenses.
Microsoft describes this as a new “cyber stack” built from the ground up. This stack consists of signals and sensors for awareness, security context for token-efficient understanding, intelligence models for reasoning, a harness to coordinate workflows, and actuators that translate AI decisions into active protections.
Multi-Model Strategy and Performance Benchmarks
Project Perception utilizes a multi-model architecture rather than a single AI model to balance quality, latency, and cost. Microsoft states this approach allows the system to apply the most effective model to a specific security task based on ongoing research and real-world workflow assessments.
The company is implementing this strategy first within software vulnerability management via MDASH, a multi-model team of agents. According to Microsoft, integrating the MAI-Cyber-1-Flash model into MDASH resulted in a 96% score on the CyberGym industry benchmark, which is 12 points higher than Mythos. Microsoft further claims this specific configuration provides nearly 50% in cost savings compared to the current MDASH version in the market.
Security Context and the Role of Actuators
To avoid forcing agents to reconstruct context from raw signals, Project Perception uses a shared security context. Microsoft explains that this is a continuously updated representation of an organization’s assets, identities, relationships, and risks, which reduces the compute and cost required to operate at scale.
The system connects these insights to actions through actuators integrated across Microsoft Security products. This integration is intended to allow organizations to reduce risk continuously rather than simply identifying it, while keeping human defenders in control of the workflows.
Microsoft stated that Project Perception is built in alignment with the company’s Responsible AI principles and utilizes existing security, compliance, and governance controls.
Related reading
