Google releases Gemini 3.8 Flash and Flash Cyber

Google releases Gemini 3.8 Flash and Flash Cyber

Google introduced two new AI models built on the same underlying core: Gemini 3.8 Flash, a general-purpose reasoning and coding model, and Gemini 3.8 Flash Cyber, a cybersecurity-focused variant for finding and patching vulnerabilities. This is Google's third Flash-line release in six weeks, following Gemini 3.7 Flash three weeks earlier. Gemini 3.8 Flash keeps 3.7 Flash's introductory price of $0.75 per million input tokens and $3.75 per million output tokens. Google says it outperforms most larger frontier models on the DeepSWE v1.1 long-horizon software engineering benchmark, solving complex engineering problems end to end at a fraction of the cost, and beats 3.7 Flash and other frontier models on the Vals Finance Agent V2 and Harvey Legal Agent benchmarks. It scores 54.9% on HLE-Verified, a benchmark of multi-step reasoning across STEM, humanities and professional fields. Google attributes part of the gain to the model 'working harder,' running extra reasoning steps and calling tools iteratively, which can mean using more tokens to maximize performance, especially at higher effort levels; developers who want lower token overhead can set a lower effort level or keep using 3.7 Flash, which Google says remains fully supported.

Gemini 3.8 Flash Cyber is not broadly available. Google is releasing it only to what it calls trusted defenders through a new access program named Fairwind, covering trusted government authorities, critical infrastructure operators and software maintainers, who must apply for access. On CyberGym, described as the standard industry benchmark for finding vulnerabilities, Flash Cyber shows frontier-level performance in autonomous vulnerability discovery, surpassing both Google's earlier Gemini 3.5 Flash Cyber and significantly larger frontier models. Because CyberGym covers mostly C/C++ codebases, Google also tested the model on an internal benchmark spanning 20 programming languages, where it reached a success rate exceeding 70%.

On automated patching, Google says it prioritized fixing vulnerabilities over offensive capabilities such as exploitation. On CWE-Bench, an external patching benchmark run by Collinear, Flash Cyber posted a pass@1 of 47.2%, close to an unnamed 'leading frontier model' at 47.8%, but at significantly lower cost, which Google describes as landing on the Pareto frontier. Google also cited results from teams already using the model internally: its Chrome Security team found that Flash Cyber produced 2.6 times more correct patches to Chrome vulnerabilities than the best commercial models, all of them much larger; the security firm Wiz found 7.5 to 9.7 percentage points higher recall on its internal penetration-testing benchmark at 2.3 to 5.2 times lower cost than other leading frontier models; and Google's own Cloud Vulnerability Research team used Flash Cyber to find a critical foundational vulnerability in under two hours, a task Google says usually takes months of research.

Both models carry safety mitigations under Google's Frontier Safety Framework. Gemini 3.8 Flash ships with safeguards against misuse in chemical, biological, radiological and nuclear (CBRN) domains and cyber offense, while Flash Cyber ships with a more permissive set of cybersecurity mitigations, which Google says is why it is restricted to trusted defenders rather than released broadly. Google also says the 3.8 models made a significant leap in prompt-injection robustness, as measured by the firm Gray Swan. Gemini 3.8 Flash is rolling out immediately to developers through the Gemini API, Google AI Studio and Android Studio, or through Google's Antigravity agentic workflow tool and the Stitch UI generator; to enterprises through Gemini Enterprise; and to consumers on Google AI Pro and Ultra plans through the Gemini app, AI Mode in Search, and Gemini in Sheets. Access to Flash Cyber requires applying through the Fairwind Program.

Key facts

  • Gemini 3.8 Flash keeps 3.7 Flash's introductory price ($0.75 per million input tokens, $3.75 per million output tokens) while scoring 54.9% on HLE-Verified and outperforming most larger frontier models on the DeepSWE v1.1 coding benchmark.
  • Gemini 3.8 Flash Cyber is available only through the new Fairwind Program, for trusted government authorities, critical infrastructure operators and software maintainers, and exceeds a 70% success rate on Google's internal 20-programming-language vulnerability-discovery benchmark.
  • On CWE-Bench, an external patching benchmark run by Collinear, Flash Cyber scores a 47.2% pass@1 versus 47.8% for an unnamed leading frontier model, at significantly lower cost.
  • Google's Chrome Security team reports 2.6 times more correct patches from Flash Cyber than the best commercial models, and its Cloud Vulnerability Research team found a critical vulnerability in under 2 hours, a task that usually takes months.
  • This is Google's third Flash-line release in six weeks, following Gemini 3.7 Flash three weeks earlier.

Why it matters

This is Google's third Flash-series release in six weeks, following 3.7 Flash just three weeks earlier, a pace that signals rapid iteration to keep closing the gap with costlier frontier models on coding and reasoning without raising prices. Flash Cyber addresses a structural asymmetry in cybersecurity: an attacker needs only one vulnerability while a defender must find and fix all of them. Google is positioning a dedicated model to tilt that balance toward defenders, explicitly prioritizing patching over offensive capabilities like exploitation.

Who it affects

Developers building coding agents and software-engineering tools get a more capable model at the same price, through the standard Gemini API, Google AI Studio and Android Studio, or through Google's Antigravity agentic workflow environment and the Stitch UI generator. Enterprises reach it through Gemini Enterprise, and consumers on Google AI Pro or Ultra subscriptions get it in the Gemini app, AI Mode in Search, and Gemini in Sheets. Gemini 3.8 Flash Cyber reaches a narrower group: trusted government authorities, critical infrastructure operators and software maintainers accepted into the Fairwind Program, so most developers and independent security researchers cannot use it directly.

How to use it

Gemini 3.8 Flash keeps 3.7 Flash's introductory pricing of $0.75 per million input tokens and $3.75 per million output tokens. Higher effort levels let the model use more tokens to push performance on hard tasks; developers who want lower token overhead can set a lower effort level or keep using 3.7 Flash, which Google says remains fully supported. Gemini 3.8 Flash Cyber has no published price in the announcement and is not self-serve: access requires applying through the Fairwind Program.

How solid is it

The benchmark results, DeepSWE v1.1, the Vals Finance Agent V2 and Harvey Legal Agent benchmarks, HLE-Verified, CyberGym and Google's own internal 20-language vulnerability benchmark, come from Google's own announcement, and several comparisons are made against competitors Google does not name: 'a leading frontier model,' 'other leading frontier models,' and 'the best commercial models,' which limits independent verification. Some figures do come from outside parties: CWE-Bench is run by Collinear, prompt-injection robustness was measured by Gray Swan, and the internal-use results were reported by Google's own Chrome Security and Cloud Vulnerability Research teams plus the external security firm Wiz, with Google relaying those findings rather than the parties publishing independently.

Risks and caveats

Google says Gemini 3.8 Flash ships with safeguards against misuse in chemical, biological, radiological and nuclear (CBRN) domains and cyber offense, and that Flash Cyber's more permissive cybersecurity mitigations are the reason it is restricted to trusted defenders rather than opened broadly, meaning the same capabilities that help defenders could also aid attackers if access controls fail. The announcement gives no eligibility criteria or timeline for who qualifies as a trusted defender beyond the three listed categories, no price for Flash Cyber, and no calendar date for the release beyond 'today.'