Microsoft Copilot Cyber updates will be costly
By Jim Lundy
Microsoft Copilot Cyber updates will be costly
Enterprise defense teams face an unsustainable volume of machine-speed threats that manual operations can no longer contain. Microsoft launched a specialized artificial intelligence cybersecurity platform named Perception alongside a targeted model called MAI-Cyber-1-Flash to address this gap. The release highlights a broader industry movement toward automated threat remediation. This blog overviews the Microsoft Perception announcement and offers our analysis, which includes a caution on the pricing of Security Compute Units.
Why Did Microsoft Announce Perception?
Microsoft introduced Perception and MAI-Cyber-1-Flash one week after Google launched Gemini 3.5 Cyber. The platform uses teams of autonomous red, blue, and green agents to assist security teams with bug detection and active remediation. The lightweight MAI-Cyber-1-Flash model powers the MDASH execution harness to locate vulnerabilities across complex software codebases. Microsoft designed this multi-agent system to help defenders match the speed and scale of attackers who increasingly leverage automation.
Analysis
This announcement marks a transition from simple alert generation to continuous autonomous remediation. Running every security workflow through giant frontier models creates cost and latency barriers that most enterprises cannot sustain. Microsoft addresses this by routing routine code analysis through a specialized compact model and reserving high-parameter reasoning for severe threats. Competitors will be forced to replicate this tiered harness design or face severe pricing pressure. Legacy security vendors that rely purely on manual triage will lose ground as customers demand automated code patching.
Interoperability with Security Copilot
Perception will function as an execution engine beneath the broader Microsoft Security Copilot interface. While Security Copilot handles natural language queries and cross-domain visibility for human analysts, Perception supplies the underlying agentic automation for code remediation. Security Copilot will consume telemetry from Perception red and blue team agents to present unified risk summaries to security leaders. This combination allows administrators to oversee automated patching workflows directly within their established Copilot workspace.
Microsoft 365 E5 and E7 Customers Get Security Copilot
The good news is that Microsoft 365 E5 and E7 Customers do get Security Copilot included in those Skus. Microsoft has stated that for every 1000 licenses, an enterprise would get 400 Security Compute Units a month. That is a little misleading and enterprises need to use their Microsoft Security Copilot calculator to fully estimate how the large the monthly cost could be.
Enterprises need to understand Security Compute Unit Costs before buying
Enterprise technology leaders should evaluate Perception during its preview phase to benchmark its remediation speed against existing application security workflows. Organizations must review how automated code fixing fits into their software development lifecycle and change management protocols.
IT teams should map their current vulnerability management spending to determine if a multi-agent model architecture can reduce operational overhead. You should test these agentic red and blue team simulations in isolated testing environments before enabling active remediation in production networks.
As with a growing number of providers, before purchasing Perception, Enterprises need to run an estimate of what the costs will be as some of these agents will replicate what human analysts do (e.g. Red Team and Blue Team). For 50 Security Copilot users, the calculator estimated that 32 SCUs would be needed an hour. For one month, that cost comes to $93,440. We will do a more detailed blog on the calculator that computed this.
Bottom Line
Microsoft Perception represents a major structural change in how enterprise code vulnerabilities are detected and patched. Combining specialized models with autonomous agent teams allows defenders to operate at machine speed while controlling computing costs. Organizations should pilot these agentic security platforms to accelerate threat remediation and streamline daily security operations. High costs may cause enterprises to pause deployment until full costs are understood.
Related Blogs:
Google Unveils Gemini 3.5 Flash Cyber
AI Agent Observability: Preventing Harmful Breakouts
Microsoft moves to Freeze out AI Competitors
Grok 4.5: SpaceXAI Disrupts AI Market Economics
Important Research related to this Blog:
Also – Check out all our Podcasts HERE





Have a Comment on this?