Google released two models on September 2: Gemini 3.8 Flash, generally available, and 3.8 Flash Cyber, which it calls its most capable cybersecurity model. It is the third Flash release in six weeks. According to Google, both are “powered by the same foundational intelligence.” What separates them is the safeguards and who gets access: the Cyber variant ships with “a more permissive set of mitigations for cybersecurity,” and for that reason it is only available to vetted defenders.
Who can use the Cyber variant
There is no checkout. Access goes through the new Fairwind Program, by application. Google prioritizes governments and national cyber authorities, critical-infrastructure operators such as healthcare providers and telecommunications services, and companies that maintain widely used software. Academic labs working on defensive benchmarking can apply as well. Partners can also use the model inside CodeMender, Google’s agent for finding and patching vulnerabilities.
The terms are specific. Partners may only run dual-use tasks, such as authorized threat simulation, reverse engineering and malware analysis for defensive or academic research; creating malware is not permitted. Access must be limited to internal security, incident-response or penetration-testing teams, with employee use tracked, user-level authentication and phishing-resistant MFA, and it cannot be shared or resold. Zero data retention is available when the model is used as a managed model on Gemini Enterprise Agent Platform.
The pages reviewed give no price for the Cyber variant, no review timelines and no regional availability.
What the figures say, and who measured them
Google’s evidence for the Cyber variant comes in four kinds, and its methodology document says who ran each one:
- Measured by the benchmark owner. On CWE-Bench, a patching benchmark, Collinear computed 47.2% pass@1 for 3.8 Flash Cyber, against 47.8% for Claude Fable 5. Google’s argument is cost: a similar score “at a significantly lower cost.”
- Run by a third party on Google’s checkpoints. Gray Swan set up and ran its prompt-injection benchmark independently. The Cyber variant’s attack success rate was 6.0%, where lower is better.
- Self-computed on a public benchmark. On CyberGym, from UC Berkeley, Google’s chart puts 3.8 Flash Cyber at 86.2%, ahead of GPT-5.5-Cyber at 85.6% and 3.5 Flash Cyber at 77.5%. Google ran its own model; the other figures come from their owners’ model cards and leaderboards. The CyberGym leaderboard itself warns that “modest score differences may not reflect meaningful capability gaps.”
- Internal. On a set of 1,200 recent, confirmed historical vulnerabilities across 20 programming languages, the Cyber variant scores 71.0%, against 58.9% for 3.7 Flash. The set is not public, so the result cannot be checked from outside.
Google adds examples from its own use, including a Chrome Security team finding that the model produced 2.6 times more correct patches for Chrome vulnerabilities than much larger commercial models, and quotes from Fairwind partners such as Armadin, Palo Alto Networks, Snowflake and Wiz.
What the release does not include is a model card for 3.8 Flash Cyber. The only card published is for 3.8 Flash, which Google says is based on 3.7 Flash and shows no meaningful new capabilities in the domains of its Frontier Safety Framework. The variant with relaxed safeguards has no safety assessment of its own on the pages reviewed.
The general model
3.8 Flash, the version anyone can use, is generally available in the Gemini API and also reaches Google AI Studio, the Gemini app and Antigravity. The Antigravity agent, the default in Gemini Managed Agents, now runs on it. It keeps the introductory price of 3.7 Flash, $0.75 per million input tokens and $3.75 per million output tokens, through December 31, 2026. From January 1, 2027, both prices double, to $1.50 and $7.50.
The API documentation adds that the model “can use more tokens on longer running and complex tasks, by design,” taking smaller reasoning steps and verifying its work along the way. For those tasks, the per-token price does not tell the full cost.
Related reading
- Gemini 3.8 Flash Cyber model evaluation — Google DeepMind
- Gemini 3.8 Flash Cyber — Google DeepMind
- OpenAI’s Astra Crosses Critical Cybersecurity Threshold — and Triggers Its Own Guardrails — IA al Día