Google released Gemini 3.8 Flash Cyber on September 2, restricting the vulnerability-hunting model to vetted defenders through a new limited-access program called Fairwind.

 

The Cyber variant arrived alongside Gemini 3.8 Flash, a general-purpose model that Google is selling openly to developers and consumers. Only the security model is gated.

 

More than 650 organizations already have access, among them CrowdStrike, Palo Alto Networks, Snowflake and Wiz, according to Google's announcement.

 

Background Reading

 

Benchmark Scores Behind Gemini 3.8 Flash Cyber

 

Google reports the model scores 86.2% pass@1 on CyberGym, a benchmark that measures autonomous vulnerability discovery in real codebases rather than synthetic puzzles.

 

On Google's internal evaluation spanning 20 programming languages, the model surfaced real vulnerabilities 71.0% of the time. Gemini 3.5 Flash Cyber managed 46.6% on the same test.

 

Patching remains the weaker half of the system. Flash Cyber scores 47.2% pass@1 on CWE-Bench, producing a correct first-attempt fix for fewer than half the flaws it is handed.

 

Google published four comparative results for the model:

 

  • 86.2% pass@1 on the CyberGym vulnerability-discovery benchmark
  • 71.0% real-world discovery rate across 20 programming languages, up from 46.6%
  • 2.6 times more correct patches than leading commercial models on Chrome bugs, per Google's Chrome Security team
  • 7.5% to 9.7% higher vulnerability recall than rival frontier models at 2.3 to 5.2 times lower cost, on a Wiz evaluation

 

The model was also tested against indirect prompt injection by Gray Swan, where attacks succeeded 6.0% of the time. Google calls that among the most robust results it has recorded.

 

Tulsee Doshi, senior director of product management, and Raluca Ada Popa, Gemini security lead at Google DeepMind, described the release in the company's launch post.

 

"[Gemini 3.8 Flash Cyber is] our most capable cybersecurity model with frontier-level performance in vulnerability detection and automated patching."

 

Who Gets Into the Fairwind Program

 

Fairwind is open to three groups: government agencies and national cyber authorities, critical infrastructure operators in healthcare, telecoms, energy and finance, and core technology platforms.

 

Four Flynn, Google's vice president of security and privacy, announced the program the same day as the model. Google frames the restriction as a head start for defenders rather than a marketing constraint.

 

"[The Fairwind Program] gives trusted partners a critical head start against AI-driven cyber threats, while making sure models are deployed responsibly."

 

Admitted organizations must accept operational conditions. Access is limited to internal cybersecurity, incident response and penetration testing staff, and accounts must be protected with measures such as multi-factor authentication.

 

Partners receive Flash Cyber paired with CodeMender, Google's automated repair agent. The company says the combination lets defenders generate deployment-ready patches inside their own cloud environment in minutes rather than weeks.

 

Pricing and Availability for Gemini 3.8 Flash

 

The general model carries introductory pricing of $0.75 per million input tokens and $3.75 per million output tokens through December 31, 2026.

 

Those rates double on January 1, 2027, to $1.50 and $7.50 per million tokens. The model takes a one-million-token input window and returns up to 64,000 tokens.

 

Developers can reach it through the Gemini API, Google AI Studio, Antigravity, Android Studio and Stitch. Enterprise customers get it in Gemini Enterprise, and Google AI Pro and Ultra subscribers see it in the Gemini app, AI Mode in Search and Google Sheets.

 

On capability, Google points to DeepSWE v1.1 for autonomous coding and a 54.9% score on HLE-Verified for multi-step reasoning. Independent leaderboards place it seventh in Text Arena and fourteenth in Agent Arena, ahead of DeepSeek-V4-Pro.

 

Anthropic and OpenAI Gate Their Own Cyber Models

 

Google was not alone on September 2. Anthropic shipped Claude Fable 5.1 and Claude Mythos 5.1, keeping the more capable Mythos model inside its own trusted-access programs for cybersecurity and life sciences work.

 

OpenAI said the same day that its Astra model meets the company's Critical cybersecurity capability threshold, with advanced features routed through a program it calls Daybreak Blue.

 

Three of the largest labs converging on vetted-access distribution in a single day marks a shift in how offensive-capable security models reach the market. None of the three is selling its strongest cyber model on open API terms.

 

The urgency has a source. Doug Turner, Chrome's engineering director, has described a "vulnerability apocalypse" driven by generative AI, pointing to a sharp jump in reported flaws as attackers automate discovery.

 

That cuts both ways for Google's argument. If a model can find 71% of real vulnerabilities across 20 languages, the gate around it matters as much as the score.

 

Organizations outside the 650 can apply for Fairwind access. Everyone else waits to see whether the defensive advantage Google is describing holds up once similar capability leaks into less controlled hands.