
Microsoft’s Israeli cyber team helps build the company’s next-generation AI defense system
Perception combines AI models and autonomous agents to detect and remediate vulnerabilities as Microsoft prepares for a future of faster, AI-powered attacks.
Microsoft unveiled a new AI-powered cybersecurity system called Perception on Monday, which it says is designed to transform cyber defense for the artificial intelligence era. Alongside the system, the company is introducing a new AI model for cybersecurity that it claims can outperform Anthropic’s Claude-based cyber model in identifying software vulnerabilities. Some of the capabilities behind the new technology were developed at Microsoft’s Israeli research and development center.
The announcement comes as concerns grow that AI systems are moving from being tools used by hackers into autonomous actors capable of carrying out sophisticated attacks. Last week, OpenAI revealed that advanced models tested by the company managed to escape their controlled environment and access the open internet, where they hacked into the computing systems of the Hugging Face platform. The operation took several hours, but OpenAI said a skilled human attacker could have required days to complete the same task.
The incident highlighted a scenario that cybersecurity experts have warned about for years: autonomous AI agents capable of identifying vulnerabilities, exploiting systems, and conducting complex cyber operations with limited human involvement.
Microsoft says Perception was developed specifically for this emerging reality. "The physics of cybersecurity are changing. Autonomous systems can now reason, adapt and operate continuously. At the same time, the cost of offense is falling, while the volume, velocity and complexity of what must be secured continues to grow. Attackers can generate exploits faster, scale campaigns further and operate with unprecedented efficiency. The approaches built for a world of human actors cannot keep pace with a world of AI, agents and machine-speed attacks," Microsoft wrote.
At the core of Perception are AI models and autonomous agents that use each organization's internal security information to proactively identify and mitigate threats. The system relies on three types of agents that work together: Red Team agents, which identify vulnerabilities and potential attack paths; Blue Team agents, which analyze those findings in the context of the organization and determine which risks require attention; and Green Team agents, which execute remediation actions to close vulnerabilities.
The agents operate using what Microsoft calls Security Context, a continuously updated view of an organization's assets, identities, applications, cloud environments, AI systems, and relevant cyber threats.
"The result is a continuously updated representation of an organization’s assets, identities, relationships, risks and activities that gives agents a shared, near real-time, understanding of the environment they are helping to defend," Microsoft explained.
Alongside Perception, Microsoft also introduced its first AI model designed specifically for cybersecurity: AI-Cyber-1-Flash. The model is intended to identify security vulnerabilities in software systems and compete with similar AI-based cyber models, including Anthropic’s Claude-based cyber model.
Microsoft said that when AI-Cyber-1-Flash is combined with MDASH, an AI agent-based security scanning system launched by the company in May, it achieved a score of 96 on the CyberGym benchmark, 12 points higher than Anthropic’s model.
A significant part of the new technology was developed by Microsoft’s Israeli R&D center. According to the company, the Perception system was developed in Israel and will serve as the first implementation of Microsoft’s cybersecurity-focused AI model.
The company said the Israeli-developed capabilities represent one of the first practical applications of its broader Perception vision, as Microsoft seeks to build a new generation of cybersecurity defenses designed for an era in which AI systems are both a powerful security tool and a growing source of risk.














