NewsStocksMicrosoft Launches Lower-Cost Cybersecurity Model to Challenge Mythos and GPT-5.6

Microsoft Launches Lower-Cost Cybersecurity Model to Challenge Mythos and GPT-5.6

Author: AI Business·

Key Takeaways

  • Microsoft said MAI-Cyber-1-Flash is designed to route security tasks to the lowest-cost appropriate model, reducing token usage costs compared with dedicated cyber models.
  • The model is embedded in Microsoft’s MDASH vulnerability identification and remediation platform, which was launched in May.
  • Microsoft also introduced Project Perception, which uses teams of agents to handle different security workflows and will later expand beyond software vulnerability identification.
  • Industry analysts said Microsoft’s approach benefits from its enterprise software security experience and from controlling more of the AI stack through vertical integration.
Microsoft Launches Lower-Cost Cybersecurity Model to Challenge Mythos and GPT-5.6

Microsoft has introduced a cybersecurity model and platform that it says cost half as much as rival systems, as enterprise demand for lower-cost generative AI services continues to rise.

The move comes as Microsoft looks to strengthen its AI strategy after its Copilot AI system received a lukewarm response from enterprises. It also follows a series of recent agentic AI releases and a broad effort to build and operate AI data centers worldwide, underscoring how the company is trying to pair infrastructure, software and models into a single enterprise offering.

Microsoft said its MAI-Cyber-1-Flash model, released on Monday, outperformed Anthropic's Mythos, OpenAI's GPT-5.6 Sol and Google's Gemini 3.5 Flash Cyber on a widely used benchmark.

A routing model

The cybersecurity model routes security vulnerability identification requests to three AI models from OpenAI and is embedded in Microsoft’s MDASH multi-agent vulnerability identification and remediation platform, which was released in May.

Alongside MAI-Cyber-1-Flash, Microsoft also launched Project Perception, an agentic security platform that provides teams of agents for different security workflows within MDASH to monitor and patch security vulnerabilities. Microsoft said it will soon add MAI-Cyber-1-Flash to Perception for many more security workflows beyond its initial software vulnerability identification use case.

Microsoft’s cybersecurity push follows controversy around Anthropic’s Mythos model, which the Trump administration initially deemed a national security threat and forced off the market. Anthropic later folded that model into Project Glasswing, launched in April, which restricted Mythos to select organizations. OpenAI’s main cyber model, GPT-5.6, followed a similar path. While it was not restricted by the government, OpenAI made it part of Project Daybreak in May, limiting access to approved users.

"Obviously, this is 'remains to be seen' territory. But I think the key here is that it's available to everybody, as opposed to Mythos [and GPT 5.6], which is not," said David Nicholson, an analyst at The Futurum Group. "And it's going to cost you a lot less because it's intelligently routing the consumption of tokens to appropriate models."

MAI-Cyber-1-Flash is currently built on OpenAI's GPT-5.4, GPT-5.4 and GPT-5.3-Codex — all of which provide cybersecurity capabilities in addition to generative AI features such as reasoning, coding and agentic workflows.

Nicholson said MAI-Cyber-1-Flash is essentially a routing model that selects the lowest-cost mode for specific security tasks, rather than functioning as a dedicated cybersecurity model like Mythos and GPT-5.6. He compared those systems to a high-end, ultra-expensive sports car.

"They're saying, 'We will do this arbitrage between models to pick the right model for the right job, so that you're not paying top dollar,'" he said.

Microsoft Security

Nicholson said Microsoft is also drawing on one of its long-standing strengths: enterprise software security. Because Microsoft is so deeply embedded in enterprise IT, its platforms have created a large attack surface and have long been a target for cyberattacks. At the same time, Microsoft has built substantial security mechanisms to protect its software, giving it a base of operational experience that newer entrants may not have.

Allie Mellen, a Forrester analyst, said Project Perception, with its red, blue and green team agents, provides a harness around the models that coordinates agents from different teams.

"It is handling the orchestration of these agents ..., the choice of model that best balances quality and cost and is able to provide the right context to the system to get the best outcome," she said. "The truly difficult part of building an agentic system is not the model itself; it's the harness around it. Microsoft is releasing that comprehensive system as a product, which can save users time, resources and architecting."

Mellen and Nicholson also said Microsoft’s approach benefits from vertical integration.

"Microsoft is launching its own model, so it has more control over the entire stack," Mellen said. "Its own model, based on its own data and expertise, ensures the model is best suited to reason over Microsoft data and best aligns to its products."