Companies
Microsoft Sells Its Cyber Model, Google Locks Its Own Away
Microsoft put MAI-Cyber-1-Flash inside a product going to preview August 3. Google gave Gemini 3.5 Flash Cyber only to governments. Same capability, opposite calls.

Anyone running security at a mid-sized company will notice the difference in their vendor calls next quarter. Two of the largest technology companies announced purpose-built cybersecurity models this month. One is going on sale in early August. The other is not for sale at all.
Microsoft: shipped inside a product
Microsoft announced MAI-Cyber-1-Flash on July 27, its first model built specifically for security work. It is not sold on its own. The model runs inside MDASH, a multi-agent system for finding and fixing vulnerabilities.
The company reports a 96% score on the CyberGym benchmark, shown as 95.95 in its own chart, putting the system 12 points above Anthropic's Mythos. The division of labor is the interesting detail: MAI-Cyber-1-Flash handles up to 90% of tasks by itself and hands the hardest remainder to GPT-5.4. Microsoft says that arrangement cuts costs by 50% against the previous MDASH configuration. The Decoder reports the model uses a sparse architecture with 137 billion total and 5 billion active parameters.
It reaches customers through Project Perception, a security platform announced the same day, which goes to public preview on August 3, 2026. The enterprise wrapper includes role-based access control, tenant isolation, encryption, auditability, and execution environments with no internet access.
Google: pilot access only
Google's Gemini 3.5 Flash Cyber arrived on July 21 with a similar job description: find vulnerabilities quickly, verify them, and generate patches. It is integrated into CodeMender and can work across large codebases through multi-step calls.
The concrete result Google published came from testing against the V8 JavaScript engine, where the model found 55 unique confirmed issues. Standard 3.5 Flash found 47 on the same test and Anthropic's Opus 4.6 found 36.
What it does not have is a public API, a price, or a general release date. Access runs through a limited pilot offered to governments and trusted partners via CodeMender.
Why one ships and one doesn't
The gap comes from what these systems are. A model that can locate and verify a zero-day in a codebase is equally good at writing the patch and at writing the exploit. The capability does not change based on who holds it.
That is not a hypothetical worry this month. In the same window, an agent OpenAI was running for security testing escaped its sandbox and reached Hugging Face's infrastructure. The evidence that this capability can slip its leash is a few weeks old, not theoretical.
Microsoft's answer is to move the control into the product layer, wrapping the model in enterprise governance so it is never a standalone download. Google's answer is to not distribute it. Two ways of managing the same risk, and the fact that both companies felt the need says something about what these models can do.
What changes for a smaller security team
Directly and in the short term: nothing. Both products are priced and scoped for large enterprises. The indirect effect starts sooner.
Acceleration on the defensive side has a mirror image. As the cost of finding vulnerabilities falls, so does the time before someone discovers the flaw in a library you depend on. The window between a patch being published and you applying it used to be a tolerable lag. It is becoming the main exposure.
Three things worth measuring this month:
- Your patch latency. How many days pass between a security update being released and running in your production environment? If nobody has measured it, the number is almost certainly worse than the guess.
- Your dependency inventory. Without a list of which open source packages you run at which versions, a published CVE leaves you unable to answer whether it applies to you.
- Your agent permissions. The Hugging Face incident makes the point cleanly. Whatever an agent can reach is what it reaches on the day it misbehaves.
These two announcements sketch how the security software market will look in two years. The shorter observation is that AI in security stopped being a roadmap item and became this month's product launch.
Sources: Microsoft AI, Google DeepMind, Help Net Security, The Decoder

Written by
Muhammet Fatih Batman
Founder & Editor
Founder of YZ Uzman, with 20+ years of experience in web design and software development.