Skip to content
All news
Gemini|Briefing··Abhishek Kapoor

Google launched Gemini 3.8 Flash generally, and Gemini 3.8 Flash Cyber only through Fairwind

On September 2, 2026 Google shipped two Gemini 3.8 Flash SKUs that share a core and split on safety. Flash is generally available at $0.75 / $3.75 per 1M tokens through December 31, 2026. Flash Cyber stays behind the Fairwind Program for trusted defenders.

Dark briefing graphic pairing a public Gemini 3.8 Flash label with a restricted Fairwind Flash Cyber label
Summarize this page with AI

On September 2, 2026 Google launched Gemini 3.8 Flash for general use and Gemini 3.8 Flash Cyber for a closed defender program. In the launch post, Tulsee Doshi and Raluca Ada Popa say both SKUs share the same foundational intelligence. The safety envelope and the access list are what change.

Flash is the public workhorse. Flash Cyber is that core with a more permissive cyber mitigation set, and Google does not put that SKU on the public Gemini API. If you are shortlisting Gemini against ChatGPT or Claude, score the two Flash SKUs separately.

Flash is on the public surfaces. Cyber is an access program.

Google lists Gemini 3.8 Flash across developer, enterprise, and consumer surfaces. Google offers Gemini 3.8 Flash Cyber only through the Fairwind Program, which it describes as limited access for trusted government authorities, critical infrastructure operators, and software maintainers. Google says more than 650 organizations participate globally.

  • Developers: Gemini API, Google AI Studio, Google Antigravity, Android Studio, and Stitch.
  • Enterprises: Gemini Enterprise.
  • Consumers on Google AI Pro and Ultra: the Gemini app, AI Mode in Google Search, and Gemini in Google Sheets.
  • Cyber: Fairwind partners only. DeepMind hosts the program page and application form.

Google prices Flash at the same introductory rate it used for Gemini 3.7 Flash: $0.75 per million input tokens and $3.75 per million output tokens. That introductory price expires on December 31, 2026. From January 1, 2027, Google says $1.50 per million input tokens and $7.50 per million output tokens apply. The launch post also says 3.7 Flash remains fully supported for efficiency-first workloads.

Same core, two safety envelopes

Google's stated design is one shared core, then two mitigation packages. Flash ships safeguards against misuse in chemical, biological, radiological, and nuclear (CBRN) work and against cyber offense, under Google's Frontier Safety Framework. Flash Cyber ships a more permissive cyber mitigation set. Google limits that SKU to trusted defenders who, in its wording, require a more comprehensive set of cyber capabilities.

The DeepMind model card, published September 2, 2026, treats Gemini 3.8 Flash as the next iteration on Gemini 3.7 Flash. It lists a 1M-token context window, 64K-token text output, and customizable effort levels. The card dates the knowledge cutoff to March 2026, with some domains limited to January 2025. DeepMind says 3.8 Flash did not add meaningful new Frontier Safety capabilities versus 3.7 Flash, and it treats 3.8 Flash as unlikely to reach a Tracked or Critical Capability Level on that basis.

  • Flash: public SKU, tighter cyber-offense and CBRN safeguards, Gemini API and consumer surfaces.
  • Flash Cyber: Fairwind-only SKU, more permissive cyber mitigations, paired with Google's CodeMender for find-and-fix workflows.
  • Google's stated priority for Cyber: vulnerability fixing first, offensive capabilities such as exploitation second.
  • DeepMind's published Fairwind rules: permitted dual-use work is authorized threat simulation, reverse engineering, and malware analysis for defensive and academic research. Partners may not share, redistribute, or sell model access.

Four Flynn's Fairwind launch note says the first offering pairs Gemini 3.8 Flash Cyber with CodeMender so defenders can find, verify, and generate patches inside an organization's secure cloud environment. Google says participating organizations must limit access to internal cybersecurity, incident response, or penetration-testing teams, and must deploy protections such as phishing-resistant multi-factor authentication. Google Cloud customers outside Fairwind can still run CodeMender on publicly available models hosted on the Gemini Enterprise Agent Platform.

What Google reports for Gemini 3.8 Flash as a workhorse

The launch post presents 3.8 Flash as a coding and agent workhorse at 3.7 Flash speed and introductory price. Google says the model "works harder" on complex tasks: extra reasoning steps, iterative tool calls, and more tokens at higher effort levels. Teams that need to cap token spend can drop the effort level or keep 3.7 Flash.

Every score below is Google-reported or DeepMind-reported. Treat it as vendor evidence, not an independent audit.

  • HLE-Verified: Google reports 54.9 percent. DeepMind's evals methodology says Gemini HLE-Verified numbers are self-computed on the 1,811-item verified set.
  • DeepSWE v1.1 (long-horizon software engineering): Google says 3.8 Flash outperforms most larger frontier models. DeepMind's methodology says the Gemini score is self-computed with a mini-SWE agent setup at high thinking.
  • Vals Finance Agent V2 and Harvey's Legal Agent Benchmark: Google says 3.8 Flash outperforms 3.7 Flash and other frontier models. DeepMind points at Vals.AI as the source for those two suites.
  • Prompt injection: Google reports a gain on Gray Swan's IPI (indirect prompt injection) benchmark for the 3.8 Flash family.

Google points developers at Antigravity for agent-first coding loops. Antigravity is a separate product surface (manager, IDE, CLI, and SDK), not the model. When you compare coding agents, put Google Antigravity next to Claude Code and run the same repository job on both, rather than reading one lab's DeepSWE slide as a purchase decision.

What Google and DeepMind report for Flash Cyber

Google frames Flash Cyber as a defender SKU: autonomous vulnerability discovery plus automated patching, at Flash speed and cost. Google does not publish a public API path for Cyber. The numbers in this section are company-reported. Several sit on internal benches or partner benches that you cannot rerun.

  • CWE-Bench (Collinear, patching, pass@1): Google reports 47.2 percent for Gemini 3.8 Flash Cyber against 47.8 percent for a leading frontier model, at what Google calls a significantly lower cost. DeepMind's Fairwind page names that comparison model as Fable 5.
  • Chrome Security (Google-stated, internal): Google says Flash Cyber produced 2.6 times more correct Chrome patches than the larger commercial models the Chrome Security team compared.
  • Internal 20-language discovery (Google-stated): Google reports a success rate exceeding 70 percent on an internal benchmark that asks the model to find vulnerabilities across complex codebases in 20 programming languages.
  • CyberGym: Google describes Flash Cyber as frontier-level on this public vulnerability-discovery suite and says it surpasses Gemini 3.5 Flash Cyber and larger frontier models. The launch post does not publish a CyberGym pass@1 number.
  • Wiz (as reported by Google): Google says Wiz measured 7.5 to 9.7 percent higher recall on Wiz's internal penetration-testing benchmark, at 2.3 to 5.2 times lower cost than other leading frontier models.

Google also says its Cloud Vulnerability Research team used Flash Cyber to find a critical foundational vulnerability in less than two hours. Google says that class of research usually takes months. That is a Google-stated internal anecdote, not a public reproduction. This briefing does not describe vulnerability-finding methods or exploit steps.

Gray Swan's prompt-injection result still matters on the Cyber SKU, because a more permissive cyber envelope does not remove indirect injection as a failure mode. The mechanism is the same one we mapped for agentic browsers and the same-origin policy: retrieved text becomes an instruction unless the agent treats it as untrusted. A CodeMender-style agent that reads tickets, diffs, and tool output inherits that problem. So does any MCP connector you bolt on. Read MCP tool poisoning and supply-chain risk before you treat a find-and-fix agent as a sealed box.

How to evaluate the launch without adopting the press numbers

Vendor benches decide marketing order. They do not decide whether Flash replaces your current default, or whether Fairwind is even available to you. Use the 2026 agent-evaluation framework for the job spec, the failure modes you will accept, and the cost model under retries.

  1. Split the SKUs on the shortlist. Write "Gemini 3.8 Flash" and "Gemini 3.8 Flash Cyber" as two rows. If you cannot join Fairwind, the Cyber row is not a product you can buy.
  2. Price the introductory window through December 31, 2026, then the January 1, 2027 rate. Google says higher effort uses more tokens, so a $0.75 input sticker can still miss your unit cost if the model loops.
  3. Re-run your own coding job on Gemini 3.8 Flash, your current ChatGPT default, and Claude or Claude Code. Keep the repo, the tests, and the time box identical.
  4. If you evaluate Antigravity, score approvals, logs, and workspace isolation as well as the model. Compare that checklist to Claude Code.
  5. If you are a Fairwind candidate, ask Google which dual-use tasks your tenant may run, who inside your company can hold credentials, and whether CodeMender patches require a human merge gate.
  6. If you are not a Fairwind candidate, test CodeMender only on the public Gemini models Google already hosts for Cloud customers. Do not plan a Cyber rollout you cannot access.
  7. Add an injection case that puts instructions in a file, a ticket, or a tool description. A Gray Swan gain that Google reports is not a substitute for that test.

Open the Gemini and Google Antigravity profiles, add ChatGPT, Claude, and Claude Code to the same shortlist, and attach the seven checks above before you change a default model.