Per an exclusive in The Information (July 17, 2026), Microsoft is preparing to launch Project Perception before the end of the month: an AI security platform that scans enterprise codebases for exploitable vulnerabilities, positioned squarely against Anthropic’s Claude Mythos — the restricted-access tier widely described in coverage as the most capable vulnerability-hunting AI available, and one most organizations cannot currently use.
Here’s the sentence that earns this Signal its “peak 2026” title, per the reporting: Perception routes security-analysis tasks across models from Microsoft, OpenAI — and Anthropic. Microsoft’s product for competing with Anthropic’s security AI has Anthropic’s models inside it.
Everything in this column is second-hand — The Information’s report is paywalled, the product unreleased, the figures estimates. Labeled accordingly throughout. But the architecture being described matters more than the launch, because it’s the clearest statement yet of where enterprise AI buying is heading.
Peak 2026:
the router is the product.
Reported by The Information (Jul 17): Microsoft’s Project Perception — an AI bug-hunter built to undercut Anthropic’s restricted, premium Mythos — routes tasks across Microsoft, OpenAI and Anthropic models. The competitor is in the mix.
The architecture, as reported
per-task cost decision
the ten million ordinary functions
the ten suspicious functions
Routing is how the cost wall comes down — and it’s the week’s thesis again: right-shaped models per task, assembled into a system, beating one giant model applied indiscriminately.
Target, per the reporting: Claude Mythos Preview — described as the most capable vulnerability-hunting AI, with estimated API cost ~100% above Opus, ~82% above GPT-class, and access most organizations don’t have. Microsoft’s pitch: the strongest tool has the narrowest door — sell a wider one.
What routing does to the market
- Everything here is second-hand: The Information’s exclusive is paywalled, the product unannounced by Microsoft, cost deltas are estimates.
- “Before end of July” is a reported date — this column has spent the week watching what launch dates are worth.
- A router owned by a party that also sells models has a thumb available for the scale. Watch where the traffic actually goes.
enterprise AI vulnerability scanning software
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
The pitch: routing beats flagship
Per the coverage of The Information’s reporting: Mythos’s estimated API cost runs roughly 100% above Claude Opus and 82% above GPT-class pricing — already two of the most expensive models available — and its access is restricted enough that Microsoft’s pitch practically writes itself: wider availability (including international markets constrained by US export considerations) at far lower cost.
The cost mechanism is the interesting part. Perception’s model-selection layer reportedly reserves expensive frontier calls for the steps where they create real value and assigns cheaper, distilled models to the high-volume scan passes. That single design choice is what makes continuous AI security auditing economically plausible at all — running a frontier model across an entire enterprise codebase, continuously, was the cost wall that kept the idea theoretical. Routing is how the wall comes down: the expensive model reads the ten suspicious functions, not the ten million ordinary ones.
Regular readers will recognize the shape. It’s this week’s thesis wearing yet another badge: the right-shaped model for each task, assembled into a system, beating one giant model applied indiscriminately. Tuesday it was 0.9B OCR specialists; Saturday it was a two-pass local pipeline; today it’s Microsoft applying the same logic to vulnerability hunting — with the twist that its “specialists” are other companies’ frontiers, metered per request.
AI security platform for code analysis
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
What routing does to the market
Three consequences for buyers, each worth internalizing before the sales calls start.
Model choice becomes a per-request cost decision, not a vendor allegiance. When the orchestration layer picks the model call-by-call, “which lab do we standardize on” quietly dissolves as a question. What remains is: who controls the router? That layer — not the models under it — is where the durable margin and the durable lock-in live. Microsoft, with no frontier lead of its own to protect, has every incentive to commoditize the layer everyone else’s valuation sits on. Distribution plus routing versus capability plus restriction is the actual contest.
The asymmetry from Thursday’s dispatch gets a commercial answer. Hugging Face’s incident showed the most security-capable models are wrapped in the tightest usage constraints — defenders locked out mid-forensics. Mythos is that pattern at the access level: the strongest tool, the narrowest door. Perception’s entire premise is arbitraging that gap — packaging governed, wider access to security capability the raw model providers ration. Whether a routed, mediated version delivers the capability that made Mythos worth restricting is exactly the open question; a router can only route to what it’s allowed to call.
The pattern already runs in the other direction too. The same coverage notes companies increasingly routing day-to-day workloads to cheaper Chinese open-weight models — the floor this week keeps documenting. Routing doesn’t just discipline frontier pricing from below; it makes the whole stack liquid. For a local fleet, the takeaway is direct: the router pattern is exactly as available to a Mac cluster as to Azure — cheap local models for volume, one expensive call (local or API) for the moments that justify it. Saturday’s Stage 2/Stage 4 split is a two-rung router.
The honest caveats: unreleased product, paywalled primary source, vendor-estimated cost deltas, and a “before end of July” date that may slip — this column has spent the week watching what launch dates are worth. And Microsoft’s neutrality has limits: a router owned by a party that also sells models is an orchestration layer with a thumb available for the scale. Watch where Perception’s traffic actually goes once it ships.
Monday’s thesis piece closes the week, and this story hands it the final exhibit: when even the company with the deepest enterprise distribution on Earth decides the winning move is assembling other people’s right-shaped models, the argument about where value migrated is no longer an argument.
AI model routing and selection tools
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Sources
- The Information (exclusive, July 17, 2026, paywalled) via TechTimes, “Microsoft Project Perception: AI Bug Hunter Set to Rival Mythos” (July 19, 2026) — platform description, multi-model routing across Microsoft/OpenAI/Anthropic, frontier-calls-reserved design, cost-and-access positioning vs Claude Mythos Preview, end-of-July debut expectation
- TechRepublic, “Microsoft’s ‘Project Perception’ Could Challenge Anthropic’s Mythos in AI Security” (July 18, 2026) — estimated Mythos API cost deltas (~100% above Opus, ~82% above GPT-class); scan-identify-fix scope; routing-to-cheaper-models pattern including Chinese open-weight adoption; Microsoft’s enterprise-distribution framing
- Microsoft Learn, “Anthropic models in Microsoft Online Services” (July 2026) — standing context: Anthropic models in Microsoft 365 Copilot surfaces, EU/EFTA/UK setting (April 3, 2026), GCC non-federal rollout (July 15, 2026), subprocessor terms noting processing outside Microsoft-managed environments
- ThorstenMeyerAI.com, “When the Cloud Says No” (July 23, 2026) and “The Local Document Pipeline, End to End” (July 25, 2026) — the asymmetry and router-pattern context
All Project Perception details are as reported by outlets summarizing The Information’s paywalled exclusive; the product is unannounced by Microsoft and unreleased at publication. Cost figures are estimates from that reporting.

The Developer's Playbook for Large Language Model Security: Building Secure AI Applications
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.