
It’s no surprise that after the spate of recent high-profile security lapses carried out by ‘friendly’ AI agents, many of the Cloud Wars Top 10 companies have begun to pivot their messaging to cybersecurity. Over the coming weeks, I’ll be surfacing the methods and intentions of these AI innovators to give you a full view of how the industry is tightening its security and governance efforts.
Today, we’re starting with Microsoft and Project Perception, a cybersecurity system designed to help organizations defend against AI-powered attacks. It taps AI to combat these threats, and in doing so, presents a massive opportunity for Microsoft to create the autonomous security layer that every enterprise will need to protect itself against such attacks.
Project Perception
Project Perception utilizes AI agents that continuously observe, analyze, and remediate security threats across the organization. Currently in preview, the system includes a workforce of specialized red, blue, and green agents that carry out various parts of this holistic security process.
With Project Perception, Microsoft acknowledges that AI has fundamentally changed the attack surface, and the industry must adapt by moving beyond reactive defense to autonomous systems that are constantly working.
“The physics of cybersecurity are changing,” said Hayete Gallot, Executive Vice President, Microsoft Security. “The approaches built for a world of human actors cannot keep pace with a world of AI, agents and machine-speed attacks … The defining characteristic of the next generation of security systems will not be their ability to generate more alerts.
“It will be their ability to continuously perceive, reason and act.”
So how does Project Perception work in practice? To continuously address and act on security threats, the system coordinates three teams of specialized agents:
Red team agents identify possible vulnerabilities that could be exploited by an attacker before they have the chance to act.
Blue team agents investigate, analyze the context, and identify meaningful risks.
Green team agents implement corrective measures and enhance defenses throughout an enterprise’s environment.
When combined, this multi-agent architecture creates what Microsoft describes as “a closed-loop system that continuously discovers, evaluates and improves an organization’s security posture.”
A Multi-Model Approach
“Organizations need protection that is highly effective, continuously available and affordable at scale,” said Gallot. “That requires more than access to the most capable model. It requires applying the right model to the right task.
“Project Perception adopts a multi-model architecture that combines frontier and specialized cyber models, optimizing for both quality and cost.”
Microsoft is leveraging its embedded access to multi-model systems to allow users to utilize the best models for specific security tasks, including its own specialized models. The company says that for effective agentic cyber defense, it’s crucial to apply the right model to the right problem at the right time.
Project Perception evaluates which model to use based on factors such as quality, reliability, latency, and cost. “Our security researchers continuously assess models against real-world security workflows, enabling us to match each task with the model that delivers the best outcome,” said Gallot. “This allows customers to benefit from advances in AI without being tied to any single model.”
Final Thoughts
With news feeds full of major AI missteps, the race to advance AI technology will inevitably push security to the forefront. This, I believe, could become one of Microsoft’s biggest differentiators in the space. Microsoft has taken some pretty hefty blows to its standing in secure infrastructure rankings in recent years, but those setbacks made a difference: the company rectified past discrepancies on a massive, public scale.
Now, with its position at the center of the AI technology stack, Microsoft can position security as more than just a defensive layer. Instead, it can present security as a constantly evolving system that learns from new threats, adapts in real time, and improves over time — tapping into the widespread expectation of continuous AI improvement.

Community Summit North America is the largest independent innovation, education, and training event for Microsoft business applications delivered by Expert Users, Microsoft Leaders, MVPs, and Partners. Register now to attend Community Summit in Nashville, TN from October 11-15.



