Microsoft is putting an army of artificial intelligence agents to work hunting for vulnerabilities in software used by the U.S. government.
The company has deployed Codename MDASH, its multi-model agentic security scanning system, to Azure Government. Preview access is now available to select U.S. government customers and authorized partners.
Rather than relying primarily on traditional scanners looking for known patterns, MDASH uses more than 100 specialized AI agents working against the same body of source code. Each agent is trained to recognize a different category of weakness.
Finding something suspicious is only the beginning. Microsoft says another group of AI agents then examines the findings and argues for and against whether a potential vulnerability is actually reachable and dangerous.
That approach could help address one of the biggest annoyances with automated security scanning: false positives. Instead of dumping a massive collection of warnings on security teams, MDASH attempts to validate vulnerabilities, remove duplicate findings, and prioritize the problems that deserve attention. When possible, it can even demonstrate a vulnerability rather than simply claiming one exists.
Microsoft says MDASH scored 96.55 on CyberGym, a public benchmark based on real-world vulnerabilities. The company has also been using the technology to examine its own software for months.
There is another reason Microsoft wants government agencies using AI to search their code. Attackers can use similar technology.
An AI system capable of finding vulnerabilities for defenders could potentially find those same vulnerabilities for someone looking to exploit them. Microsoft says threat actors are investing in AI capabilities, making the time between discovering a weakness and patching it increasingly important.
That creates something of an AI security arms race. If attackers are going to use AI to hunt for weaknesses, defenders have a strong incentive to get there first.
For government agencies, there is also the question of what happens to sensitive source code during all this AI analysis. MDASH is available through Microsoft Defender inside Azure Government and works with models available through the FedRAMP High-authorized Microsoft Foundry service. According to Microsoft, that means an agency’s source code and information the system learns from analyzing it can remain inside an approved government boundary.
The multi-model architecture is interesting too. Microsoft isn’t betting MDASH on one particular AI model. Its harness can direct different models toward different jobs and incorporate newer models as they become available.
Microsoft says its own MAI model family also plays a role in bringing down scanning costs. The company expects its newest addition to reduce the cost of an individual scan by roughly half, potentially allowing agencies to analyze more code without requiring additional budget.
Of course, giving more than 100 AI agents access to government source code sounds like the beginning of a science-fiction thriller when described without context. In reality, these agents aren’t autonomous hackers wandering around federal networks. They are specialized components coordinated by Microsoft’s security system to analyze code and validate potential vulnerabilities.
Still, the underlying race is very real. AI is getting better at understanding software, and that ability isn’t reserved for defenders. The question may soon be less about whether AI can discover the next serious vulnerability and more about whose AI finds it first.
Support independent tech journalism
NERDS.xyz is independently owned and operated. If you enjoy my coverage of Linux, AI, hardware, cybersecurity, and tech culture, consider supporting the site on Ko-fi.
Support NERDS.xyz