MAI-Cyber-1-Flash
Microsoft AI · United States · 2026
Microsoft's first model built specifically for cyber defence — a 137-billion-parameter sparse mixture of experts with only 5 billion active, running inside the MDASH vulnerability-hunting harness.
MAI-Cyber-1-Flash, announced on 28 July 2026, is the first model Microsoft AI has built for a single security purpose: finding and fixing software vulnerabilities. Architecturally it is a sparse mixture-of-experts transformer with 137 billion parameters in total, of which about five billion are active for any one token, and a context window of 256,000 tokens — wide enough to hold a substantial codebase while reasoning about it. Inputs and outputs are text only. The model is a security fine-tune of MAI-Code-1-Flash, which was itself grown from a mid-training checkpoint of MAI-Thinking-1. It is not sold as a model. It works inside MDASH, Microsoft's multi-agent harness for vulnerability identification and remediation, which the company says now coordinates more than a hundred specialised agents. The design goal was economic rather than headline-grabbing: MAI-Cyber-1-Flash is meant to absorb up to 90% of MDASH's workload cheaply, leaving the hardest tenth to a larger frontier model. That framing matters for reading the headline number. Microsoft reports 95.95% on CyberGym Level 1, but the score belongs to MDASH running MAI-Cyber-1-Flash alongside GPT-5.4 — not to the new model on its own. GPT-5.4 has not been retired from the pipeline; it has been demoted to the difficult remainder. Microsoft's cost claim, that the pairing runs 50% cheaper than its previous combination of GPT-5.4, GPT-5.4 mini and GPT-5.3 Codex, was published without token counts or task-allocation figures, so it cannot be checked from outside. As of the announcement the result was not listed on the public CyberGym leaderboard. Access is deliberately narrow. There is no public API and no standalone product; the model is offered through an Azure AI Foundry private preview to approved MDASH customers, whom Microsoft calls verified defenders. For a model trained to locate exploitable flaws at scale, that gate is the safety measure.
▸News
▸Videos
No videos yet.
▸Reviews
No reviews yet. Be the first!