Microsoft built its first security model. OpenAI still gets the hardest 10%.
MAI-Cyber-1-Flash runs inside MDASH, a 100 plus agent vulnerability harness that routes 90% of the work to Microsoft's own model and escalates the rest to GPT-5.4.
Microsoft's first security model handles 90% of MDASH's work. GPT-5.4 still takes the hardest cases.
On July 27, 2026, Microsoft AI launched MAI-Cyber-1-Flash, its first in-house model built specifically for cybersecurity. It runs inside MDASH, a harness that orchestrates more than 100 agents to find and fix vulnerabilities in large codebases. The architecture chart carries the interesting detail: Microsoft's own model handles about 90% of the work, and the hardest 10% still gets escalated to OpenAI's GPT-5.4.
What shipped
MAI-Cyber-1-Flash is a compact, code-focused model derived from Microsoft's MAI-Thinking-1 lineage, announced by Microsoft AI CEO Mustafa Suleyman and Microsoft Security EVP Hayete Gallot at an event in San Francisco. Microsoft says it was trained for defensive tasks, finding and patching bugs, explicitly not offensive ones, and shipped with a model card and a third-party assessment. MDASH, the system around it, is described as a multi-agent vulnerability identification and remediation harness. Microsoft never spells out the acronym anywhere in the announcement, which The Register duly made fun of.
The numbers Microsoft is claiming
The cost claim needs precision, because some coverage rounded it into something bigger. Microsoft's 50% figure compares the new configuration against its own previous best MDASH setup, which ran entirely on three OpenAI models. It is not a claim of being half the price of competing security platforms, though it was widely repeated that way.
The 90/10 split
The routing is the story. The compact in-house model covers the high-volume work: scanning, detecting, patching, confirming a fix held. GPT-5.4, which The Register notes is roughly 10 times larger, is reserved for the minority of cases that need heavyweight reasoning. The Decoder's read is that Microsoft is becoming an orchestrator of models rather than a consumer of one, reducing its exclusive reliance on OpenAI without actually leaving it: for the toughest tasks, Redmond still calls San Francisco.
What to keep in mind
Every benchmark number above comes from Microsoft. Nobody has independently reproduced the CyberGym results yet, and no outlet covering the launch published a verification. Alongside the model, Microsoft announced Project Perception, an agentic security platform with red, blue, and green team agents, which Microsoft's own blog says enters public preview on August 3, 2026.
Why a build studio cares
The 90/10 pattern, a small specialized model for volume with a frontier model behind it for escalations, is the same cost architecture that makes client agent systems affordable to run. Microsoft just validated it at the scale of its own security operation and published the routing split. When the biggest software company on earth prices its security AI this way, that pattern is going to show up in procurement conversations everywhere.
Next step: read Microsoft AI's announcement, TechCrunch's coverage, and The Register's more skeptical take. If you are wiring a volume-plus-escalation agent stack of your own, write to hello@gattyworks.com.