Security
Microsoft Puts Project Perception Into Preview, Testing The Limits Of Agentic Defense
Microsoft's new Project Perception security system is entering public preview with specialized red, blue and green agents, putting human approval and rollback controls at the center of its machine-speed defense claim.
By Leo W ·

Microsoft's Project Perception enters public preview this week, bringing specialized AI agents into a continuous security workflow. The company describes red agents that search for attack paths, blue agents that assess real risk and green agents that help remediate and harden systems. The proposition is compelling because security teams are overwhelmed by volume. The challenge is whether an automated system can move faster without becoming another source of production risk.
Microsoft says the first use case is software vulnerability management, pairing its MAI-Cyber-1-Flash model with a multi-model agent system. Specialized models make sense here: the work has recognizable artifacts, including code, advisories, logs, tickets and asset inventories. But the moment an agent proposes a patch or changes a control, the boundary between assistance and autonomy becomes operationally significant.

The company emphasizes human control, and that is the right standard to test. Teams need to see why a path was judged dangerous, which systems a proposed remediation will touch and how they can stop or reverse it. A benchmark score is useful only if the resulting workflow is explainable enough to deploy under incident pressure.
The security market is now racing toward this model because attackers can use AI to accelerate reconnaissance and exploit development. Defenders do need more automation. The safest near-term advantage may come from triage, correlation and proposed remediation rather than fully autonomous change. Those uses reduce the work of finding the right decision without pretending the decision no longer belongs to a person.
Project Perception's preview will be more valuable than its launch claims because it exposes the product to real operations. The decisive evidence will be not how many agents it can orchestrate, but whether customers can patch faster, make fewer mistakes and retain a trustworthy record of every action taken.
Topics: Microsoft, cybersecurity, AI agents, vulnerabilities