Human interpretation required

Week ending 2026-08-27

# Weekly Evidence Pack — 2026-08-27

## Executive Summary

## What Changed This Week
- Project Perception documents human sign-off for every high-impact action, with defender-set objectives and guardrails.
- Project Perception documents a red/blue/green multi-agent architecture coordinated by orchestrated workflows and an orchestration harness.
- Project Perception assigns work execution to agents while reserving judgment to humans.
- Project Perception is in preview, initially delivered through Microsoft Defender, with broader Microsoft Security expansion planned.
- Codename MDASH is a private-preview agentic code scanner that surfaces code-level weaknesses across connected repositories.
- MDASH uses AI confidence and severity for triage while directing uncertain high-severity findings to human investigation before action.
- MDASH accepts Defender CLI and connector-triggered remote scans and labels their origin for provenance.
- MDASH exports validated findings to CSV for existing remediation workflows.
- MDASH is in private preview and its documentation/access path requires authorization.
- The MDASH portal view surfaces only the most recent 90 days of scan activity.
- Microsoft Learn identifies Project Perception as Limited Public Preview.
- Project Perception combines signals, context, models, and red/blue/green agents through coordinated playbooks.
- Project Perception supports autonomous execution initiated through reusable playbooks.
- Operators can approve or reject requested agent actions, stop sessions, and provide alternative guidance.
- Microsoft AI Code Security documents a multistage prepare/scan/validate/deduplicate pipeline using risk ranking, taint analysis, LSP type resolution, and multi-model debate.
- The scanning stage documents more than 100 specialized AI agents targeting vulnerability classes, including injection, memory-safety, and auth-bypass auditors.
- The Defender CLI can generate and apply code fixes directly from agentic scan results.
- Agentic code-scanning findings are published to Microsoft Security Exposure Management for organization-wide triage.
- Microsoft AI Code Security is in preview across listed Azure commercial regions, with UAE limited to MDASH CLI scans.
- The scanner claims broad language support with specially tuned expertise for C, C++, Java, and C#.
- Open Security has released ISPM Enterprise SQL v1 as its first autonomous cyber-defense benchmark.
- ISPM Enterprise SQL v1 uses a frozen synthetic enterprise and common questions, reporting 95% compatibility intervals across 127 tasks.
- The benchmark supports local runs with user-owned model keys before submission for an official run.
- Open Security labels the benchmark service as beta.

## Evidence Conflicts

## Freshness Alerts

## Trend Primitives
- preview_to_ga_days: {}

## Architecture/Control Pattern

## Independent Perspective

## What Remains Unknown

## Implications

## What to Watch Next

## Methodology

## Sources

Interpretation sections remain human-authored.