A Cyber Stack built for agentic security
Delivering agentic security requires more than adding agents to existing workflows. It requires a new Cyber Stack, designed from the ground up.
The stack begins with signals and sensors that provide awareness across the digital estate. Security context transforms those signals into token-efficient understanding that agents can use. Models provide intelligence and reasoning. A harness coordinates models and agents across security workflows. Agents apply that intelligence across security workflows and actuators translate decisions into protection. Together, these layers create a continuous learning system that can understand risk, adapt to changing conditions and improve security outcomes over time.
While each layer provides important capabilities, the power of Project Perception comes from how they work together.
Security context built for AI
Effective reasoning requires more than raw signals. Agents need context.
Microsoft transforms its breadth of visibility, threat intelligence and security expertise into a security context that connects security data, knowledge and semantics across the digital estate. The result is a continuously updated representation of an organisation’s assets, identities, relationships, risks and activities that gives agents a shared, near real-time, understanding of the environment they are helping to defend.
This shared understanding is foundational to how Project Perception operates. Rather than forcing agents to continuously gather, correlate and reconstruct context from raw signals, it provides them with immediate and token-efficient access to the information they need to reason over risk, prioritise actions and make decisions. By grounding every interaction in this rich security context, Project Perception improves the accuracy and consistency of reasoning while reducing the time, compute and cost required to operate at scale.
A multi-model architecture built for security
No single model will be optimal for every security task. Effective cyber defense requires applying the right model to the right problem at the right time.
For Project Perception, the right model is determined by the combination of quality, reliability, latency and cost. Rather than relying on a single model, Project Perception adopts a multi-model architecture that continuously selects the capabilities best suited to the task, optimising for both effectiveness and economics. Because security is an always-on mission, sustainable economics are essential to operating protection at scale.
This approach is shaped by ongoing research, benchmarking and evaluation across frontier and specialized models. Microsoft’s security researchers continuously assess models against real-world security workflows, enabling us to match each task with the model that delivers the best outcome. This allows customers to benefit from advances in AI without being tied to any single model.
Actuators — insights to actions
Security teams do not need more information. They need better outcomes.
That is why actuators are a critical part of the Cyber Stack. Project Perception is deeply integrated across Microsoft Security products, enabling agents to connect insights to actions. Organisations can continuously reduce risk rather than simply identify it, helping defenders strengthen security while remaining in control.
Built with safety first
Underpinning every layer of the Cyber Stack is a foundation of trust. Project Perception is built in alignment with Microsoft’s Responsible AI principles and inherits the security, compliance, governance and operational controls our customers already rely on. This ensures these capabilities are delivered with the same rigor, accountability and enterprise readiness that customers expect.
The future of security
Security has always been a race between attackers and defenders. AI changes the speed, scale and economics of that race. Defenders need systems that can continuously perceive, reason and act alongside them.