With Project Perception, Microsoft has introduced a new agentic security system built specifically for the AI era. The underlying idea: when attacks run at machine speed, a defence designed around human reaction times is no longer enough. The public preview starts on 3 August 2026.
What is Project Perception?
Project Perception brings signals, context, AI models, and specialised agents together in a system that keeps learning. It observes the digital estate, reasons about what it sees, and applies protective measures – while people remain in control of the decisions. Microsoft describes this as a new “cyber stack”: security is not simply topped up with a few agents, it is rebuilt from the ground up for agentic work. The stated goal is not to produce even more alerts, but to continuously observe, assess, and remediate risk.
The layers of the cyber stack
- Signals and sensors: Identities, endpoints, applications, data, clouds, and AI systems provide visibility across the entire digital estate.
- Security context: Raw signals become a continuously updated picture of assets, identities, relationships, risks, and activities – the shared basis for every agent.
- Models: Frontier models and specialised cyber models supply the ability to reason about that context.
- Harness: A control layer that orchestrates models and agents across the individual security workflows.
- Agents: Specialised agents apply the analysis to concrete tasks – from finding vulnerabilities to responding to incidents.
- Actuators: The connection into Microsoft security products that turns an insight into an actual protective measure.
Red, blue, and green: three classes of agents
- Red team agents look for possible attack paths before an attacker finds them.
- Blue team agents analyse in the context of your own environment and decide what constitutes a real risk.
- Green team agents apply corrective measures and harden the environment afterwards.
Together the three classes form a closed loop: observe, assess, improve – not as a project, but in continuous operation.
Why Microsoft is betting on multiple models
No single model is the best choice for every security task. Project Perception therefore uses a multi-model architecture and selects per task based on quality, reliability, latency, and cost. That is not a side note: security runs around the clock, and only economically sustainable operations can be maintained at scale over time. An early example is vulnerability management – there, the multi-agent system MDASH with the specialised model MAI-Cyber-1-Flash reaches 96 percent on the industry benchmark CyberGym while also saving close to half the cost compared with today’s MDASH configuration.
What this means for companies
Project Perception is a preview for now, not a product to be rolled out at short notice. The direction, however, is clear – and it has one practical consequence: a system that reasons from context is only as good as the data underneath it. If your signals from Microsoft Defender are incomplete today, if identities in Entra ID are inconsistent, or if data classification in Purview is unresolved, agentic defence will do little for you tomorrow. If, on the other hand, you have already governed the use of AI tooling with Microsoft Security Copilot and your own agents with Microsoft Agent 365, you are well prepared.
What companies should do now
- Check how complete your security signals really are – gaps in endpoints, identities, or data feed directly into every later AI-assisted analysis.
- Decide in advance which measures a system may carry out automatically and where human approval must remain mandatory.
- Follow the public preview deliberately, but without rushing: a test in your own tenant only pays off once the baseline configuration is sound.
We are happy to clarify how robust your signal and data foundation for agentic security is today, and which steps sensibly come first, as part of a Microsoft Security Assessment – get in touch with us.
