KEEP IN MIND

Microsoft security agents can go from alert to action

Project Perception coordinates AI agents that look for avenues of attack, assess risks and can strengthen protections. The system will enter public preview on August 3, but automated actions still require limited permissions and clear human responsibility.

Publicerad 29 July 2026, 17.07

AI-generated illustration of a security officer reviewing three color-coded agent flows and a clear control point over an abstract network map.

Microsoft has presented Project Perception, a system where several AI agents collaborate in the company's security products. The agents can search for possible avenues of attack, assess which risks are important and propose or implement measures.

Microsoft divides work into three colors. Red agents try to find routes that an attacker could use. Blue agents investigate the signals and assess the risk. Green agents can then correct deficiencies and strengthen protection.

The last step makes the permissions crucial. An agent who is only allowed to read a report can cause less damage than an agent who is allowed to change accounts, programs, or network rules. The same automation that can shorten the response time can also magnify an error if the assignment or the document goes wrong.

Project Perception goes into public preview on August 3rd. Preview means customers get to try an early version that can still be changed. Microsoft writes that the system connects to the company's security products, but does not publish a full price list or a detailed country and plan list in the launch post.

Microsoft states that its own security model reaches 96 percent in the CyberGym test and costs almost half as much as the current configuration. An early customer also says that four weeks of analysis could be done in four hours. It is Microsoft's test and a customer example, not independent evidence of the same results in other businesses.

The UK cyber security agency NCSC recommends that organizations start with clearly delineated, low-risk tasks. The agency also emphasizes ongoing monitoring, human control and a plan for what should happen when an agent makes a mistake or goes beyond its assigned task.

A security agent does not take responsibility for a decision. The business still needs to decide who authorizes access, who monitors agent behavior, who reviews incidents, and who can stop the system.

Därför spelar det roll

Security work involves many recurring checks where faster analysis can be valuable. But when an AI agent is allowed to move from analysis to change, its permissions become part of the security risk. Swedish businesses therefore need to review access, logging and responsibility before a preview is allowed to work in production systems.

Det här kan du göra

  1. Start with a bounded task and test data in an environment where the agent's actions can be recovered.
  2. Give the agent the minimum possible authority and differentiate between proposing an action and executing it.
  3. Require human approval for changes that may affect accounts, data, applications, or networks.
  4. Log the agent's background, decisions and actions and decide in advance who can stop it.