The “loss of control” of the OpenAI model is a wake-up call Microsoft (MSFT.US) quickly launches a low-cost cybersecurity model

Zhitongcaijing · 2d ago

The Zhitong Finance App learned that Microsoft (MSFT.US) launched a new artificial intelligence (AI) model to discover cybersecurity vulnerabilities on Monday at a time when the “loss of control” of the OpenAI model sparked a buzz. This is the first time that Microsoft has launched a major product to revive the cybersecurity business since reinstating former Google executive Haite Gallot in charge of the security department.

Microsoft said that when used with OpenAI's GPT-5.4 general model, its MAI-Cyber-1-Flash model performed better than Anthropic's Mythos 5, Google's 3.5 Flash Cyber, and OpenAI's GPT-5.5 Cyber in CyberGym benchmarks.

Mustafa Suleiman, CEO of Microsoft's AI division, said at a corporate event held in San Francisco: “Our model performance is at the leading level in the world, and the cost is only half that of the competition.”

This generation model is the first model introduced by Microsoft for cybersecurity scenarios. Gallot explained in a blog post that the model will be integrated into Microsoft's Project Perception (Project Perception). The plan integrates a variety of AI agents to identify and fix system security vulnerabilities, and will be open for public preview on August 3.

She returned to Microsoft in February as the executive vice president of the security business, while Charlie Bell, a former Amazon Cloud Services executive who was responsible for the business, became an independent technology developer.

Generative AI has drastically lowered the threshold for hackers to launch attacks using the latest public vulnerabilities. To this end, both Anthropic and OpenAI have launched defense AI models for cybersecurity practitioners.

Microsoft's stock price has dropped 19% since this year. A team of UBS analysts led by Carl Kilstead wrote in a Sunday report: “Given that the market generally believes that the open source AI model will seize market share from cutting-edge laboratories, investors are now re-examining Microsoft's deep binding OpenAI layout and viewing it as a potential risk.” However, Kirsted maintained Microsoft's “buy” rating.

This year, Microsoft launched a number of self-developed big models: first, a model that can generate code in the GitHub Copilot tool, and recently incorporated self-developed native AI models into the Excel table software. Microsoft CEO Satya Nadella maintains a partnership with OpenAI, but he is also investing in computing power resources to train self-developed models to improve operational efficiency.

“By combining dedicated models and industry data with adapted agents, tools, security environments and systems, we can improve cost efficiency,” Nadella wrote on social platform X on Monday.

Microsoft has not disclosed the revenue scale of its cybersecurity business since 2023. In that year, the sector's annual revenue exceeded 20 billion US dollars.

In 2023, Microsoft launched the “Security Copilot” (Security Copilot) for cybersecurity practitioners, which integrates OpenAI's GPT-4. Currently, the service has been pre-installed in Microsoft's two high-end office software suites. Project Perception can suggest and implement code changes when authorized, and can connect to non-Microsoft products.

In an interview, Gallot said that cybersecurity industry executives regard this tool as the key to breaking the game: it can lower the entry threshold for security operation personnel and attract more personnel to the security operation center (SOC), because currently such talents are very limited in the industry. Businesses often have a security operations center (SOC), which is staffed with a large number of personnel to monitor threats to information technology systems.

An uncontrolled attack on the OpenAI model revealed hidden dangers in the industry, and AI security fence construction equipment received attention

Last week, OpenAI said its model exploited a vulnerability to attack the infrastructure of AI startup Hugging Face. The incident revealed the potential risks of leading edge models under independent decision-making, and drew strong industry attention to AI security fences.

Based on this, members of the US Congress proposed the “AI Kill Switch Act” (AI Kill Switch Act), which aims to give federal agencies the power to suspend the operation of AI models when necessary. Currently, it is still in the congressional proposal stage and has not officially come into effect.

Also, according to reports, OpenAI CEO Sam Ultrman and Nvidia CEO Hwang In-hoon will meet with Democratic Chief Representative Mark Warner of the US Senate Intelligence Committee this week to discuss AI development and security issues.

Microsoft AI chief Suleiman described the OpenAI cyber attack as a “wake-up call” in the field of cybersecurity. Suleiman pointed out that this is an important sign of the rise of AI cyber attacks. “As the model becomes more powerful, the precautionary principle becomes very important.”

Garlot also commented, “This case fully confirms that in the face of cyber attackers with AI tools, we must rely on AI technology to build a defense system.”

Microsoft's new cybersecurity model still has plenty of room for performance optimization.

Suleiman revealed in an interview: “We have a unique massive safety data set, and currently the training model uses less than 1% of the data reserve.”