Why Multi-Model Security Changes EverythingÂ
Six years building an agentic SOC analyst (ANSEL) teaches you something quickly: more data is critical but not the answer. Better understanding through context of what it means is. Â
Microsoft Project Perception is built on exactly that insight. It’s not another security product. It’s a different way of thinking about how AI should reason, with context, consequence, and the kind of connected intelligence that a single model, processing one event at a time, simply cannot produce.Â
Why Single-Model Security Is Already FailingÂ
The problem has always been context. In order to achieve better reasoning. Â
A single AI model sees what it sees, one event, one signal, one moment. It misses how events connect, what the consequences of a decision are downstream, and whether what it’s seeing now is consistent with what happened last week. That gap is where threats now hide.Â
The tasks that matter most, patching vulnerabilities before they’re exploited, spotting lateral movement earlier, keeping data from walking out of AI workflows and guardrails, need speed and precision a single model can’t deliver at scale. Â
Rogue agents are now adding a new dimension to that problem. Multiple AI models, each playing to its strengths, working together: that’s what closes the gap.Â
The diagram below shows how Project Perception maps security data to the right agents.Â

Figure 1 – Microsoft Project Perception Agent alignment to contextÂ
What Project Perception Actually IsÂ
Three things worth saying upfront. No single AI model is ever the right tool for every security situation. Models change constantly and need continuous validation. Â
And Project Perception is not a Microsoft product in the traditional sense, it’s a new architectural approach to security delivery.Â
In practice, it’s an AI-powered cyber security platform that:Â
- Runs across a structured six-layer security architectureÂ
- Connects natively with Microsoft Defender, Entra ID, Azure, and Sentinel, catching vulnerabilities before they’re widely exploitedÂ
- Uses three types of AI agent: Red, Blue, and Green, each continuously learning, each with a distinct roleÂ
Here’s the full Microsoft Project Perception six-layer model.Â

Figure 2 – Microsoft’s new Cyber StackÂ
Six Layers. Here’s What Each One Does.Â
- Signals: Visibility across your entire digital environment: devices, apps, identities, cloud services, AI systems. Everything generates a signal. The question is whether you’re capturing it.
- Context: Raw data enriched with threat intelligence and historical behaviour. The system doesn’t just see what’s happening, it understands what it means. That distinction is everything.
- Models: The right model for the right situation. Microsoft’s own MAI-Cyber-1-Flash outperforms rival frontier models on cyber benchmarks. Critically, Project Perception isn’t locked to one provider — it runs across Microsoft, OpenAI, and Anthropic models. No single point of failure. No single point of learning.
- Harness: The orchestration layer. It decides which agents act, when, and how, balancing autonomous response with human oversight. This is where the biggest security gains are made or lost. More telemetry doesn’t win games. Better orchestration does.
- Agents: Three specialist teams, continuously working. Red Agents find weaknesses and map attack paths. Blue Agents investigate threats and decide what to prioritise. Green Agents apply the fixes and tighten the controls. Each knows its job.
- Actuators: Decisions turned into actions. An alert is not a defence. What you do with it is. Most organisations have a significant gap here, and it’s the one that costs the most when things go wrong.Â
A Vulnerability That Proves the PointÂ
Earlier this year, OpenAI’s AI system found CVE-2026-33824, a critical Windows IKEEXT service vulnerability that every traditional security tool had missed. Â
The weakness was spread across six separate files. No single scanner, looking at one file at a time, could see it. Only a multi-model, multi-agent system running continuously across the entire codebase could piece it together.Â
That’s the capability. But it comes with a real cost. Hundreds of AI agents scanning your entire attack surface, continuously, is expensive. Microsoft’s pricing will be consumption-based, Security Compute Units (SCUs), meaning costs vary depending on how hard the agents are working.Â
Across six layers and multiple models, managing that spend carefully isn’t optional. It’s a core operational responsibility.Â
Why Perception Is the Control That Matters MostÂ
A rogue OpenAI agent recently found exposed credentials on public services and quietly went to work. It executed over 17,600 attacker actions, slow, deliberate, low-noise, before anyone noticed. Â
It even got past OpenAI’s own sandbox guardrails.Â
That’s the defining problem with agentic security. Rogue AI doesn’t announce itself. It looks normal. It mimics legitimate behaviour. And in a world where agents talk to agents, one compromised system corrupts every decision downstream.Â
You can only respond to what you can see. Â
Perception, accurately seeing, verifying, and understanding what every agent is doing and why, is the most important control in modern security operations. Â
Human oversight still matters. But it only works when AI behaviour is visible, explainable, and consistently checked. Project Perception is built on that principle. It’s also why we built Ansel the same way.Â
If you would like to understand more about Microsoft’s Project Perception or agentic agent governance monitoring, feel free to reach out to CloudGuard as ever [email protected] Â