Please ensure Javascript is enabled for purposes of website accessibility
Microsoft Unveils AI Cybersecurity Tools
d8a347b41db1ddee634e2d67d08798c102ef09ac
By The New York Times
Published 1 hour ago on
July 27, 2026

A Microsoft logo is seen on an office building in New York City in this July 28, 2015 file photo. (Reuters File)

Share

Getting your Trinity Audio player ready...

SAN FRANCISCO — OpenAI sent shock waves across Silicon Valley last week when it revealed that two of its artificial intelligence technologies had gone rogue and hacked into a popular internet library.

The incident showed the unpredictable power of new AI systems and the growing importance of technology that can be used against AI attacks.

On Monday, Microsoft added to the widening assortment of AI security tools with the release of systems designed to help businesses protect their computer networks.

It is among a number of companies racing to take the same kind of advanced systems used to commit attacks and instead harness their power to prevent hacks. They are hoping to capitalize on rising concerns that AI presents a serious threat to computer infrastructure that security experts are just starting to come to grips with.

Microsoft executives are among the many voices in tech arguing that powerful cybersecurity systems should be more widely distributed so that more organizations can better defend themselves.

That viewpoint runs counter to growing concerns among some tech executives and officials in Washington that new AI systems need to be carefully monitored or kept away from the public because they can be such effective hacking tools.

“The cat is out of the bag,” said Hayete Gallot, an executive vice president at Microsoft who oversees the company’s security efforts.

Microsoft’s new AI model, MAI-Cyber-1-Flash, has been trained specifically for cybersecurity, the company said. The system learned its skills partly by analyzing decades of data that Microsoft collected when responding to hacking incidents experienced by its customers.

Microsoft has unusual access to security data, because its products, such as the Windows operating system, Outlook email and Azure cloud computing, are so widely used and are frequent targets of cyberattacks, said Mustafa Suleyman, who oversees the development of Microsoft’s AI models.

Unlike other leading AI companies, Microsoft did not share the new model with independent testers for evaluation before releasing the technology. But the company said it expected that the model integrated into its security tools would top the leaderboard for a standard benchmark test called CyberGYM after it was released Monday, surpassing offerings from OpenAI and Anthropic.

Microsoft said the price of using the new system was about half the price of other leading technologies, which are more expensive partly because they were developed to do many things, not just cybersecurity work. The company said it effectively handled 90% of queries, meaning the more expensive models would be necessary only 10% of the time. Suleyman said Microsoft had focused on lowering the costs so that the model could be deployed more quickly and more widely.

MAI-Cyber-1-Flash will feed into another new Microsoft tool, Project Perception. It transforms various AI models into teams of “agents” designed to find and repair network vulnerabilities. AI agents are digital assistants that can use other software to perform various tasks largely on their own. In some cases, Microsoft’s agents will be able to imitate hackers.

The AI security threat has emerged over the past year or so as AI companies have built systems that are particularly good at writing computer code. When Anthropic, for example, introduced an AI system in April, the company said it had used the technology to find thousands of security holes that had gone undetected in popular software systems for years.

Arguing that the AI system was too dangerous for wide release, Anthropic limited the release of this enormously expensive technology to a small number of organizations so that they could use the technology to defend the internet’s vital infrastructure.

Not long after, OpenAI and Google said they, too, were sharing similar technology with only a group of partners. The White House also started to explore government oversight of such technologies. Among the possible plans was a formal government review process for new AI models.

The field and norms are rapidly evolving. In an interview July 16, Microsoft’s corporate vice president, David Weston, said it was “really important for us to make sure everyone has the capability.” But when the product was announced Monday, the company limited the initial release to businesses and individuals who used a third Microsoft security tool, MDASH, which is designed for finding and closing security holes in software.

As companies try to control the use of their latest models, experts have shown that other technologies could help drive malicious attacks on computer networks.

Last month, researchers at the University of Toronto said they had found a way to use freely available AI technologies to create a dangerous computer “worm” capable of targeting any known flaw in the world’s computers.

“A lot of these models are getting better,” Weston said. “What concerns me is not the model du jour but that the capability is more widespread.”

In the weeks since, two Chinese startups have released technologies that are nearly as powerful as leading systems from Anthropic and OpenAI.

(The New York Times has sued OpenAI and Microsoft, claiming copyright infringement of news content related to AI systems. The two companies have denied those claims.)

This article originally appeared in The New York Times.

By Cade Metz and Karen Weise
c. 2026 The New York Times Company

RELATED TOPICS:

Send this to a friend