'It delivers world-class performance at 50 percent of the cost of leading models': Microsoft unveils cut-price AI for security with latest in-house model launch

Pairing the MAI security model with GPT-5.4 gives benchmark leading results at half the cost, according to the tech giant

Microsoft logo and branding illuminated against a dark background at Mobile World Congress (MWC) in Barcelona, Spain.
(Image credit: Getty Images)

Microsoft has unveiled a new AI model for spotting security flaws in code, joining a growing crowd of companies targeting vulnerabilities with AI.

Part of a wider collection of AI agents designed to spot potential flaws in code, Microsoft’s MAI-Cyber-1-Flash works paired with OpenAI's GPT-5.4, and will be available via public preview beginning 3 August, the company said in a blog post.

The move follows a rush by AI companies into the security market, sparked by Anthropic's Claude Mythos with subsequent launches into the space by OpenAI.

As ITPro reported last week, Cisco made strides on this front with its Antares small language model (SLM) range, which the firm said is designed to run at a “fraction of the compute” expense of frontier security models.

Latest Videos FromIT Pro

Microsoft is taking a similar approach, saying that its MAI-Cyber-1-Flash model not only outperforms Mythos 5 and Google's 3.5 Flash Cyber on one specific benchmark, but that it'll also cost less to run.

Microsoft CEO Satya Nadella said the system would "give customers frontier-grade security at half the cost."

"This is the benefit of building the harness, context/signals, and action space separate from one model family,” he said in a post on X.

“By combining specialized models and data with the right agents, tools, security context, and harness, we can advance the frontier of cost to outcome."

This model is the first of Microsoft’s in-house range to focus specifically on cybersecurity and part of a wider push to promote the MAI range after launching in June.

Nadella in particular has been keen to push these models, with the Microsoft chief hailing their cost-efficiency compared to larger frontier models in a blog post last week.

Under the hood of MAI-Cyber-1-Flash

The MAI-Cyber-1-Flash model sits inside MDASH, Microsoft's Security multi-model agentic scanning harness. Multiple models can feed into the system, which then control more than 100 agents to spot bugs.

"MAI-Cyber-1-Flash is our first cybersecurity model, built ground up to find the most challenging vulnerabilities in complex code bases," Nadella said. "When combined with MDASH, it delivers world-class performance at 50 percent of the cost of leading models."

The system manages to top benchmarks at half the cost by using the cheaper MAI-Cyber-1-Flash model for 90% of tasks, with MDASH choosing to use the more costly GPT-5.4 only when necessary.

"That’s the power of a well-tuned, multi-model system with access to uniquely rich historical training data," added a blog post penned by Microsoft AI CEO Mustafa Suleyman and EVP for Microsoft Security Hayete Gallot. "It ensures you always have the best model at the best price for every task."

MAI-Cyber-1-Flash was unveiled alongside Project Perception, an agentic security product that pulls together "teams of specialized agents" into workflows to simulate attacks, detect and triage issues, and even patch them.

"Perception will also soon use MAI-Cyber-1-Flash for many more security workflows, beyond the software vulnerability work," the blog post added.

Microsoft is keen to stress that trust was built into all aspects of the system, saying it was tested by Microsoft's AI Red Team and includes encryption, auditability, and sandboxes with no internet access.

This, the company said, enables the "governance, security, and control enterprises expect”.

Microsoft’s safety focus here comes in the wake of a high-profile incident involving Hugging Face last week. OpenAI admitted that one of its security models slipped out of a testing environment and breached a Hugging Face production database.

"In this new environment, being able to go from identifying a new vulnerability to addressing it in real-time is critical," Suleyman and Gallot added in that blog post. "And while AI remediation of software vulnerabilities is now a key security workflow, there are many jobs to be done by Security practitioners themselves."

FOLLOW US ON SOCIAL MEDIA

Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.

You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Freelance journalist Nicole Kobie first started writing for ITPro in 2007, with bylines in New Scientist, Wired, PC Pro and many more.

Nicole the author of a book about the history of technology, The Long History of the Future.