Microsoft is reported to be preparing a new security product that sits inside a company's IT environment, hunts for software vulnerabilities, and proposes fixes. The internal name is Project Perception. Its purpose is straightforward: to deliver what Anthropic's Mythos already does, at a far lower price. Here is what has been reported, and why the pricing strategy could work.
A New Market for Vulnerability-Hunting AI
Finding software vulnerabilities has traditionally been slow, specialist work carried out by security researchers. AI models entered the field in earnest over the past year or so. Anthropic offers Mythos, which is strong at this task, to vetted partners, and has described it as capable of finding flaws across major operating systems and web browsers. This is not limited to Mythos: the Government of Alberta used Claude Code with Opus and Sonnet to scan 466 million lines of code in 20 hours[1], a case that shows inspection at a scale no human team could match has already begun.
There is a structural risk built into this class of model. If it can find a flaw before a patch ships, an attacker with the same tool can locate targets with the same accuracy. That danger is the reason access to Mythos has been kept to a narrow set of partners.
The Price Gap Project Perception Targets
According to reports, Project Perception will combine models from Anthropic, OpenAI, and Microsoft itself to handle scanning, flaw identification, and fix suggestions end to end. The headline pitch is operating cost relative to Mythos. Mythos API pricing has been estimated at roughly twice that of Opus and about 1.8 times that of GPT, both among the most expensive publicly available models, which makes continuous operation an expensive proposition.
The mechanism Microsoft is said to be using to cut costs is model routing. Rather than handing everything to a single expensive model, queries are directed to whichever model suits the task. Use one model that reads source code well, another that is strong at spotting unusual behavior, and a third suited to generating patches, and the blended cost per query falls. Routing routine work to cheaper models to compress spending is a pattern spreading across AI services generally.
Vulnerability scanning is not a one-off job. It pays off when it runs every time the code changes. Because a lower unit cost makes continuous operation practical, price here means more than a number on a quote.
Microsoft Shifting Its Weight Toward Enterprise
Project Perception fits the AI strategy Microsoft has been signaling lately. Mustafa Suleyman, who leads its AI operations, has said the company intends to launch frontier models of its own without distilling from other providers, and Microsoft is also rolling out hardware built specifically for AI workloads. Moving AI processing in Excel and Outlook to in-house models points the same direction.
Its stance toward former partners OpenAI and Anthropic has hardened at the same time. Satya Nadella has argued that those AI models use customer data to improve themselves, and claimed Microsoft has controls in place to prevent the same thing. The pitch to enterprise buyers is twofold: stronger on security and governance, and cheaper. The foothold Microsoft holds inside companies through Windows and Office is an asset that keeps working even where its models rank behind on their own merits.
Regulation as a Moving Variable
The regulatory picture matters too. On June 12, 2026, the US government applied export controls to Anthropic's Fable 5, a model trained along similar lines to Mythos but shipped with additional guardrails. With no way to verify user nationality in real time, Anthropic suspended access to both Fable 5 and Mythos 5 for all users. Those controls were lifted on June 30, however, and Fable 5 returned for users worldwide on July 1[2]. Mythos 5 was also restored for a set of US organizations following government approval on June 26, and access via AWS, Google Cloud, and Microsoft Foundry is being re-enabled.
The restrictions have therefore already been unwound, so export controls are not a straightforward tailwind for Microsoft. What remains is the precedent that a frontier model can become the subject of a national security review. OpenAI cleared a US Commerce Department review before launching GPT-5.6, and Microsoft would not be exempt from a comparable process when shipping a security product. Given that several US agencies continue to use Mythos and that European governments and financial institutions have been seeking access, how convincingly a vendor can promise continuity of supply remains a selling point.
Summary
Project Perception looks like Microsoft entering the vulnerability-hunting AI market on terms that favor it. Instead of fielding the single strongest model, it blends models from several providers to cut the unit cost and land in a price band where continuous operation is viable. The competition is on running cost rather than novelty. For now this remains at the reporting stage, with no official announcement, pricing, or detection accuracy figures. In an era where attackers hold the same tools, how far the cost of defense can fall is worth watching.
References
- Anthropic, "Government of Alberta uses Claude to find and fix cybersecurity vulnerabilities" https://www.anthropic.com/news/alberta-government-claude-cybersecurity
- Anthropic, "Redeploying Claude Fable 5" https://www.anthropic.com/news/redeploying-fable-5
