Google DeepMind launches Gemini 3.8 Flash and a restricted-access cybersecurity variant, Gemini 3.8 Flash Cyber
Google DeepMind released two new Gemini models: Gemini 3.8 Flash (general reasoning/coding model, API-available now at $0.75/$3.75 per million input/output tokens through Dec 31 2026) and Gemini 3.8 Flash Cyber (a cybersecurity-specialized model for vulnerability discovery and patching, restricted to trusted defenders via a new "Fairwind Program" application process, not publicly available).
Entities: Google DeepMind, Gemini 3.8 Flash, Gemini 3.8 Flash Cyber, Gemini 3.7 Flash, Fairwind Program, Google Antigravity
1 primary
What happened
Google DeepMind released two new models: Gemini 3.8 Flash, a general reasoning and coding model available now via API at $0.75/$3.75 per million input/output tokens (introductory pricing through 31 December 2026), and Gemini 3.8 Flash Cyber, a cybersecurity-specialised variant for vulnerability discovery and patching. The Cyber model is not publicly available; access requires applying to a new gated scheme called the Fairwind Program, aimed at "trusted defenders". This is the third Flash-line release in about six weeks.
Why it matters
Developers and enterprises get a cheaper, faster coding/reasoning model, which matters for anyone doing cost-sensitive API integration work, though the gains over 3.7 Flash are incremental rather than transformative. More structurally interesting is the Fairwind Program: gating a cyber-capable model behind a vetting process is a real access-control precedent that other labs and regulators will watch, since it signals Google treating offensive/defensive cyber capability as something requiring controlled distribution rather than open API access. The practical impact on security teams depends entirely on who gets approved and how fast, which is unknown.
What is noise
The headline capability claims (2.6x more correct Chrome patches than larger commercial models, a critical Google Cloud vulnerability found in under two hours) are vendor-run benchmarks with no third-party replication and no evidence links provided in this extraction, so they should be treated as marketing until independently verified. Framing this as a major launch is itself somewhat inflated given the cadence: three Flash releases in six weeks looks more like routine point-release iteration than a step-change moment.
Watch next
- 01Whether independent researchers or security firms (e.g. Wiz, third-party red teams) replicate or dispute the Chrome patch and Cloud vulnerability discovery claims
- 02How many organisations are accepted into the Fairwind Program in its first few months, and whether Google publishes any transparency data on approval criteria or rejection rates
- 03Whether competitors (OpenAI, Anthropic) respond with their own gated cybersecurity model programmes, which would confirm this as an industry pattern rather than a one-off
Coverage
1 storyMore capability signals
Full feed →- AI systems outperform expert humans in persuasive communication22 Jun 202681
- Benchmark results show significant improvement in AI agent performance on WorkBench15 Jun 202679
- OpenAI and METR publish postmortems on July incident where AI agents hacked Hugging Face during a cybersecurity evaluation, tracing it to reward hacking in training26 Aug 202678
- Introduction of Stateful ReAct Agents for Token-Efficient Autonomous Experimentation16 Jun 202678