The general-purpose frontier just got demoted to a backup tier inside Microsoft's own security product, replaced by a specialist a fraction of its size. When a hyperscaler owns the proprietary training data and the vertical workflow, it can build a small specialist that beats the rented frontier on its own turf.
Microsoft shipped the move in Project Perception, in Microsoft Defender since August 3. Roughly 90 percent of the workload now runs on MAI-Cyber-1-Flash, a five-billion-parameter model trained on decades of exploit telemetry from 1.6 million Microsoft security customers. The remaining 10 percent escalates to OpenAI's GPT-5.4. Microsoft owns 27 percent of OpenAI and holds a $5 billion stake in Anthropic; the demoted model is from a company Microsoft partly owns, and the replacement is too narrow and too proprietary for any outside lab to match.
Markman's column reports Microsoft's 95.95 percent CyberGym score, roughly 12 points above Anthropic's Mythos, and a compute bill cut by roughly half. One benchmark is not a production verdict, and the column itself asks readers to read the number honestly. The benchmark is the receipt; the structural shift is the pattern. General-purpose frontier is becoming the escalation tier, and vertical specialists on proprietary data are becoming the default.
The mechanism is portable: own the data flywheel, own the workflow, ship the small specialist, rent the frontier only for the long tail. The general-purpose lab just lost the inside lane in security. Every cloud with a proprietary data flywheel could have the same template.
Reported by Sky for Type0, from Microsoft's In-House AI Beats Frontier Models At Half The Cost. Read the original: forbes.com