Microsoft CEO Satya Nadella speaks at the Microsoft AI Tour at the TikTok Entertainment Center in Sydney on April 23, 2026.
George Chan | Getty Images
Microsoft on Monday unveiled a new artificial intelligence model for detecting cybersecurity vulnerabilities. The move is the company’s first major push to revamp its cybersecurity business since its return Google Managing director Hayete Gallot takes over management of the unit.
When combined with OpenAI’s general-purpose GPT-5.4, Microsoft’s MAI Cyber-1 Flash outperforms Anthropic’s Mythos 5, Google’s 3.5 Flash Cyber, and OpenAI’s GPT-5.5 Cyber in the CyberGym benchmark, the company says.
“We offer world-leading performance at 50% of the cost,” Microsoft AI CEO Mustafa Suleyman said at a company event in San Francisco.
The generative model is the software maker’s first model for cybersecurity. According to a blog post from Gallot, it will work in its Project Perception, a collection of AI agents for discovering and remediating vulnerabilities, which will be available in public preview starting August 3rd.
In February, she returned to Microsoft to become executive vice president of security, a former top performer in the category Amazon Cloud manager Charlie Bell became an individual contributor.
Generative AI models have made it easier for attackers to quickly attempt to exploit newly documented vulnerabilities. Anthropic and OpenAI have released models that can help cybersecurity professionals defend themselves.
So far in 2026, Microsoft shares have fallen 19%. “With the consensus view that open source AI models (Chinese and others) are poised to take market share from Frontier Labs, investor sentiment about Microsoft’s high OpenAI commitment has shifted back to being perceived as a risk,” Microsoft analysts led by Karl Keirstead wrote in a Sunday note to clients. Keirstead recommends buying the stock.
This year the company announced its own model that can generate code in the GitHub Copilot tool, and more recently it has been moving to a first-party model in the Excel spreadsheet program. While Satya Nadella, CEO of Microsoft, has a partnership with OpenAI, she also provides computing power to train models in-house with an eye on spending efficiency.
“By combining specialized models and data with the right agents, tools, security context, and usage, we can push the cost-outcome frontier,” Nadella wrote in a post on Monday X.
Microsoft has not disclosed the size of its cybersecurity business since 2023, when annual revenue exceeded $20 billion.
In 2023, Microsoft introduced Security Copilot assistant for cybersecurity professionals, integrating OpenAI’s GPT-4. The service now comes with Microsoft’s two highest-quality productivity software packages. Project Perception can propose and implement code changes once permission is granted, and it can connect to non-Microsoft products.
Cybersecurity executives “may be looking at this as a way to lower the bar and bring in more talent to actually staff the SOCs and get more people to participate, because it’s very limited in the industry right now,” Gallot told CNBC. Companies maintain security operating centers (SOCs) full of people who look for threats to information technology systems.
Last week, OpenAI announced that its models had exploited a vulnerability during testing and attacked the infrastructure of AI startup Hugging Face. Hugging Face used a model from Chinese laboratory Z.ai to conduct forensic analysis.
“I think it’s a great example of why you need to use AI to defend yourself against the bad guys that have AI, right?” Gallot said.
There is plenty of room for Microsoft to improve the performance of the new model.
“We have a unique data set,” Suleyman said in an interview. “We used far less than 1% of that data.”
REGARD: SandboxAQ CEO comments on OpenAI and Hugging Face security incidents
Choose CNBC as your preferred source on Google and never miss a moment from the most trusted name in business news.
https://www.cnbc.com/2026/07/27/microsoft-touts-cost-saving-ai-model-for-cybersecurity.html
