AI Strategy · 6 min read
Project Perception: Microsoft Just Showed Us What an AI Agent Workforce Looks Like
By James Wilkinson 1 August 2026
Microsoft's Project Perception puts a coordinated team of AI agents to work on security. Here's what the launch signals for every UK firm, not just security teams.
TL;DR
- Project Perception puts red, blue and green AI agents to work as a team inside Microsoft Defender: red probes like an attacker, blue investigates what matters and green fixes what they find. Public preview starts on 3 August.
- The pattern is the story: specialist agents, automatic handoffs, humans approving consequential actions and consumption pricing are the blueprint for agent workforces in every department, not just security.
- Nothing here needs buying today unless you run a security function. The sensible moves are picking one looped process, sorting the context an agent would need and piloting one narrow agent with human sign-off.
On 27 July, Microsoft announced Project Perception at a launch event in San Francisco. It goes into public preview on 3 August, inside Microsoft Defender.
Most of the coverage has filed it under security news, and fair enough: it is a security product. But if you run a business that will never own a security operations centre, Project Perception is still worth ten minutes of your attention. It is the clearest picture Microsoft has given us yet of how it thinks AI agents should work: not one assistant answering questions, but a coordinated team doing a job.
That pattern will not stay in security.
What Microsoft actually announced
Project Perception is what Microsoft calls an agentic system: a workforce of specialised AI agents that operate across security data, tools and workflows to find weaknesses, investigate threats and fix them, continuously.
There are three types of agent, named after the colours security teams use:
- Red agents think like an attacker. They probe the environment to find the paths a real attacker could take, before one does.
- Blue agents investigate. They take what the red agents surface, add context and work out which risks actually matter.
- Green agents fix. They remediate issues and harden the environment so the same gap does not reopen.
The important part is not any single agent. It is that they hand off to each other automatically, in a closed loop. A finding becomes an investigation becomes a fix without a human carrying it between tools at every step.
Under the hood, a few things stand out:
- Purpose-built models. Microsoft introduced MAI-Cyber-1-Flash, its first in-house model built specifically for cyber security. It sits inside a multi-model setup, with an orchestration layer choosing the best model for each task based on quality, reliability, latency and cost. In Microsoft’s benchmarking, its vulnerability-scanning harness running MAI-Cyber-1-Flash scored 96% on the CyberGym benchmark.
- Context as the starting point. The agents do not begin from a blank page. They begin from a continuously updated picture of the organisation: its assets, identities, relationships, risks and activity across endpoints, applications, clouds and AI systems. Microsoft says it distils around 100 trillion daily signals into a graph the agents can navigate.
- Humans stay in charge. Defenders set the objectives and guardrails, and high-impact actions need human sign-off. Decisions are scoped, traceable and replayable, and Microsoft has been open that it expects organisations to grant more autonomy gradually as trust builds.
- Consumption pricing. There is no per-seat licence. Usage is measured in Security Compute Units, so you pay for the work the agents actually perform, with heavier tasks costing more.
Availability is narrow for now: public preview inside Microsoft Defender, with plans to extend across the wider Microsoft Security stack over time. Nobody should be rushing to switch this on next week.
Hayete Gallot, the executive vice president who runs Microsoft Security, summed up the reasoning at the launch: “The physics of cyber have fundamentally changed.” Attackers are already using AI at machine speed. Microsoft’s answer is a defence that runs at machine speed too, with people setting the strategy.
Five things worth stealing from the design
Here is why this matters even if you never touch a firewall. Strip away the security context and Perception is a blueprint for how agent workforces will be built everywhere. Five design choices stand out.
1. Agents are specialists with defined roles. There is no single genius agent trying to do everything. Red finds, blue assesses, green fixes. Each has a narrow job it can be measured on. That is exactly how agents should be scoped in any department: one agent that chases overdue invoices, one that triages the shared inbox, one that assembles a new starter pack. Narrow beats clever.
2. The value lives in the handoffs. Most business processes do not fail because people are slow at their bit. They fail in the gaps: the finding that never becomes a ticket, the approval that sits in an inbox, the fix nobody confirms. Perception’s whole pitch is closing that loop automatically. That is an operations idea wearing a security badge.
3. Humans keep the judgement. Microsoft did not remove people. It moved them up a level: set the objectives, define the guardrails, approve the consequential actions, review a traceable record afterwards. That is the governance model to copy on day one of any agent project, and it is why “the AI will run wild” is the wrong fear for a well-designed rollout.
4. You pay for work done, not seats. Consumption pricing means the bill reflects what the agents actually did, and Copilot Studio agents are already billed on a similar consumption basis. The direction of travel is clear: software pricing is shifting from licences per person towards cost per outcome. That changes how you build a business case. You stop asking “how many users” and start asking “what is this process worth”.
5. Context is the fuel. Perception’s agents start from organisational knowledge. Without it they would be guessing. The same is true of any agent you deploy in your firm: if your processes live in people’s heads and your documents are scattered across inboxes, an agent has nothing solid to stand on. Getting your data estate in order is no longer an IT chore. It is the runway.
The quiet second announcement
Alongside Perception, Microsoft also announced real-time protection and threat detection for business agents governed through Agent 365, its management layer for the agents companies build and buy themselves.
Read that back. Microsoft is building the security tooling for a world where ordinary businesses run fleets of their own agents. Vendors do not build the seatbelts unless the cars are coming.
What a mid-sized firm should do now
There is nothing here to buy today unless you run a security function, and even then it is preview software. But there are three sensible moves while the pattern is still early:
- Pick one looped process. Find the workflows in your business that are really a cycle of find, assess and act: credit control, complaints triage, supplier onboarding, quality checks. Write down how one of them actually runs today, including the gaps.
- Sort the context. Gather the documents, data and policies an agent would need into one governed place. In a Microsoft 365 business that usually means well-structured SharePoint rather than a shared drive archaeology dig.
- Pilot one narrow agent with human sign-off. Build small, keep a person approving anything consequential, measure the time saved and expand from there. That is the shape of a good first Copilot Studio agent.
Firms that practise this pattern on small, low-stakes processes now will find the bigger shift routine rather than disruptive. The ones that wait will be learning governance, data hygiene and agent design all at once, under pressure.
If you want a clear map of where an agent workforce fits your firm, and just as importantly where it does not, that is exactly what our Discover engagement produces. It is a fixed £1,500, credited back in full once follow-on work passes £3,500. Book a consultation and we will start from the processes you already run.
Sources checked
Last checked: 1 August 2026.
- Rethinking security for the age of AI
- Project Perception product page
- Securing AI agents at runtime with Microsoft Agent 365
- Microsoft launches agentic security platform designed to combat AI-based attacks
- Microsoft escalates the AI security race with ‘Project Perception’ and a new in-house model
- Microsoft’s Project Perception bets on agents that act, not just alert
Related reading
More on ai strategy
Common questions