Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News Breaking Product

Microsoft Ships MDASH, Its First AI Cybersecurity Platform

Microsoft unveiled its first custom cybersecurity AI model and a multi-agent defence platform that cuts security costs by 50% versus leading models.

Enterprise DNA | | via TechCrunch
Microsoft Ships MDASH, Its First AI Cybersecurity Platform

Microsoft announced MAI-Cyber-1-Flash and MDASH on July 27, 2026, marking the company’s first purpose-built cybersecurity AI model and a fully integrated agentic defence platform designed for enterprise security teams.

The announcement lands as businesses are running more AI agents in production than ever before, often with less visibility into what those agents are doing. Microsoft is betting that specialised models, not general-purpose ones, are the answer to keeping those deployments secure.

What Microsoft Actually Shipped

MAI-Cyber-1-Flash is Microsoft’s first AI model designed specifically for cybersecurity work. It comes from the same MAI-Thinking-1 model family as Microsoft’s other in-house models, but was purpose-trained on security-specific data and optimised for code-heavy tasks that security teams face daily, including vulnerability identification, patch analysis, and threat remediation.

The model lives inside MDASH, which stands for Microsoft’s multi-agent vulnerability identification and remediation system. MDASH routes work intelligently across its model fleet: MAI-Cyber-1-Flash handles roughly 90% of tasks where it is capable and fast enough. The remaining 10%, the genuinely hard problems, escalate automatically to OpenAI’s GPT-5.4.

According to Microsoft, this tiered routing is what delivers the cost savings. Running MAI-Cyber-1-Flash for the bulk of work, with GPT-5.4 reserved for the edge cases, cuts costs by 50% compared to using leading frontier models across the board.

On the CyberGym benchmark, the combined MDASH system scores 95.95%. Microsoft also noted that MDASH outperforms Anthropic’s Claude Mythos 5 on this benchmark.

The Enterprise Security Stack

Beyond the model, MDASH ships with a full set of enterprise controls that security teams expect from Microsoft:

  • Role-based access controls (RBAC) so only the right people trigger the right agents
  • Tenant isolation to keep enterprise environments separated
  • Encryption at rest and in transit
  • Full audit trails for compliance and incident review
  • Sandboxed execution environments with no outbound internet access, meaning the agents cannot be used as a pivot point for external attacks

Microsoft has called this initiative Project Perception. The public preview opens on August 3, 2026.

What This Means for Business

Most enterprise security teams are dealing with the same underlying problem: they have too many alerts, too many vulnerabilities in the backlog, and not enough engineers to triage and patch them at the speed threats move. AI agents promise to help, but general-purpose models were not built for the specific syntax and reasoning patterns that security work demands.

A purpose-built cybersecurity model changes the economics. If MAI-Cyber-1-Flash can reliably handle 90% of the routine triage and patch work, that frees security engineers for the 10% that genuinely needs human judgement. At half the cost of running frontier models everywhere, it also makes continuous, automated security monitoring financially viable for organisations that could not justify it before.

The sandboxed execution with no internet access is a meaningful design choice. It directly addresses one of the main concerns enterprises have raised about AI agents in security contexts: that a compromised or manipulated agent could become the attack surface itself. Running agents without outbound access closes that vector for the most sensitive workflows.

For organisations already in the Microsoft 365 and Azure ecosystem, MDASH fits into existing identity and compliance infrastructure rather than requiring a parallel stack. That lowers the integration cost considerably.

Two broader signals worth watching here. First, Microsoft is now building its own specialised AI models rather than relying entirely on OpenAI. Second, the tiered model routing approach, where a cheaper specialist handles the bulk of work and a frontier model handles the tail, is likely to become a standard cost-control pattern across enterprise AI deployments in every function, not just security.

If your business is building or buying AI agents, this architecture deserves attention as a template for keeping total cost of ownership manageable as agent workloads scale.

Talk to Enterprise DNA about building AI agent workflows for your business.

Working With Claude field guide cover

Free Resource

Going deeper with Claude?

Get the free 32-page implementation guide for ANZ teams.

No spam. Unsubscribe any time.