2 min read AI-generated

Microsoft Pushes Project Perception Into Public Preview — With Claude on Board

Copy article as Markdown

Microsoft's agentic security platform is publicly testable as of August 3. It orchestrates models from Microsoft, OpenAI, and Anthropic — but the real surprise is a homegrown mini-model that does most of the work.

Featured image for "Microsoft Pushes Project Perception Into Public Preview — With Claude on Board"

Microsoft first showed off Project Perception in late July — now it’s getting real. The public preview went live on August 3, starting inside Microsoft Defender. And for those of us watching the Claude ecosystem, it’s interesting for two reasons.

What Project Perception is

Project Perception is an agentic security platform. When a task comes in — find a vulnerability, assess a threat, patch a hole — the system decides which AI model is best suited to handle it. Three agent classes mirror real security roles: Red hunts for attack paths and weaknesses, Blue reads the context and decides what’s truly dangerous, and Green performs the fixes.

The interesting part for us: the platform orchestrates models from Microsoft, OpenAI, and Anthropic at the same time. So Claude is one of the engines under the hood — depending on the task, the best-fit model gets picked. That very multi-model idea was the standout at the unveiling.

The real surprise

More remarkable than the frontier models, though, is what Microsoft built itself: MAI-Cyber-1-Flash, a small in-house model. According to Microsoft, it now carries about 90 percent of the load in its vulnerability-scanning system — and beats larger frontier models at roughly half the cost.

That’s a statement. It shows where things are heading: not every problem needs the biggest, most expensive model. For narrow, repetitive tasks, a specialized mini-model can be cheaper and faster — and the big models only step in when things get genuinely tricky.

My take

Two things stick with me. First: the fact that Claude sits alongside GPT and Microsoft’s own models inside a security platform underlines that the big providers are no longer thought of as go-it-alone. If you want the best result, you mix. That’s good for us as users — and a little uncomfortable for any provider betting its model has to do everything on its own.

Second: the rise of small, specialized models is the real story here. MAI-Cyber-1-Flash is a sign of things to come. If an in-house Flash model handles 90 percent of the work at a lower cost, every company has to ask: where do I actually need frontier power — and where does a lean, specialized model do the job? The answer will shape a lot of architecture decisions in the months ahead.


Sources: