Project Perception coordinates red, blue and green security agents around a specialized cyber model and enters public preview August 3. Microsoft says the system can identify, analyze and remediate risk while keeping human operators in control.

Microsoft announced Project Perception and the MAI-Cyber-1-Flash model on July 27. The company described red-team agents for finding attack paths, blue-team agents for investigation and green-team agents for remediation. The first scenario focuses on application vulnerability management.

Microsoft claimed a 96 percent score on its cited CyberGym benchmark. The company said the configuration reduced costs by nearly half compared with its current setup. Project Perception was scheduled to enter public preview on August 3.

Vendor benchmarks are useful for defining a claim but require independent reproduction. Security agents may receive privileges that make containment and auditability critical. Human approval controls depend on how products are configured in practice.

The checked record also defines what is not yet established. The tools were not yet generally available, Microsoft supplied the benchmark comparison, and the checked reporting identified unresolved agent-control risks. This distinction prevents an announcement, allegation, estimate or early field report from being presented as a completed or independently proven event.

At the August 2 publication cutoff, the next evidence expected to update this account is independent benchmark results and incident testing and public-preview documentation on permissions, logging and rollback. Those future developments are not assumed here; they will require a responsible source, a dated public record or independently verifiable reporting.

The source pages retained below support the numerical values, sequence and attributed statements in this report. Statements from interested parties establish what those parties said or did, but they do not independently prove every claim embedded in those statements. No image is included because a rights-cleared visual was not necessary to report the facts.

This edition preserves the difference between the immediate event and its operating context. Vendor benchmarks are useful for defining a claim but require independent reproduction. Security agents may receive privileges that make containment and auditability critical. Human approval controls depend on how products are configured in practice. The article will remain fixed at this cutoff even if a later investigation, corrected total, weather observation or implementation record changes the public understanding.