
Microsoft cut the cost of AI vulnerability discovery in half. The company built Project Perception, an AI security system to drive down expenses. Microsoft launched the system earlier in the year.
However, the move signals a broader shift across the cybersecurity industry. Rivals like GitHub have already followed with similar price cuts. Together, these changes reveal how AI reshapes vulnerability research economics.
Microsoft Halves the Cost of Finding Vulnerabilities
Microsoft built Project Perception, an AI security system to cut its research costs. Perception runs on MAI-Cyber-1-Flash, a specialized in-house model built just for this work. Now, the model handles 90% of Microsoft’s AI vulnerability discovery workload. Engineers route only the hardest cases to OpenAI’s GPT-5.4.
Consequently, the routing change cut Microsoft’s compute costs in half. Red, blue, and green agent teams run the scanning process. Red agents probe systems, and blue agents assess the risks. Then, green agents write fixes, pending human approval.
Security chief Hayete Gallot said Perception can reason, prioritize, and act at machine speed. In addition, the system scored 95.95% on the CyberGym benchmark. The score beat results Microsoft reported for Anthropic’s rival model and has set a new industry benchmark.
The Economics Behind the Price Cut
AI has flooded bug bounty programs with low-quality reports. Researchers now submit findings faster than teams can verify them. Consequently, validation costs rose even as report numbers grew.
As a result, Microsoft chose to address the imbalance with its own specialized model. Their engineers used decades of exploit data from 1.6 million customers. No outside AI lab can access such proprietary data.
Because of this, Microsoft gained a lasting cost advantage. GitHub faced identical pressure and cut its public payouts too. Starting on the 27th of July, GitHub reduced critical rewards to $10,000. The figure fell from a prior range of $20,000 to $30,000. GitHub said researchers will earn more when they submit better work.
A New Baseline for the Bug Bounty Market
Cheaper AI security research means less money for many researchers. In addition, independent researchers who search for bugs now earn smaller rewards. Instead, companies benefit since lower costs let firms like Microsoft scan systems continuously rather than occasionally.
Constant scanning helps companies protect large systems more effectively. However, this same change is pushing skilled researchers out of the job. Some experts call this shift a “vulnpocalypse” warning it will hurt smaller researchers the most. As a result, many researchers are now turning to higher-paying private programs instead.
What Comes Next
Companies will likely copy Microsoft’s pricing move soon, since the cost benefits are hard to ignore. Google has already released a similar AI security tool and Cisco followed with its own, called Antares.
Overall, the industry is moving toward cheaper, specialized AI tools. Bounty programs will likely get stricter as more reports pour in. Fixing problems, not finding them, may become the next big challenge. The push to make AI security cheaper has only just begun.
