Google released two new AI models on September 2, 2026: the all-purpose model Gemini 3.8 Flash and the specialized security variant Gemini 3.8 Flash Cyber. When automatically patching Chrome vulnerabilities, Flash Cyber delivers according to Google 2.6 times more correct fixes than the tested commercial competitor models. Access to the Cyber version is initially limited to selected authorities and infrastructure operators.
Google Cloud finds critical vulnerability in under two hours
In internal tests, the Google Cloud Vulnerability Research Team found a critical security vulnerability in a widely used software component with Flash Cyber in less than two hours – a process that, according to the company, usually takes months. On the specialized benchmark CyberGym, which measures vulnerability detection capability, the model achieves Frontier level according to Google; in the patch test CWE-Bench, the hit rate is 47.2 percent on the first attempt. The central comparison value from the announcement – the 2.6 times higher number of correct patches compared to leading commercial models for Chrome vulnerabilities – comes exclusively from Google’s own security team and is independently unverified.
The penetration testing specialized company Wiz, part of Google since 2026, reports a hit rate for Flash Cyber that is 7.5 to 9.7 percentage points higher while simultaneously having costs that are 2.3 to 5.2 times lower compared to other top models. The general model Gemini 3.8 Flash, Google’s third Flash release within six weeks, is improving particularly in programming tasks and reportedly surpasses several larger competitor models on the coding benchmark DeepSWE v1.1.
Access remains restricted to vetted defenders
The base model Gemini 3.8 Flash is now available to developers via Google AI Studio, Android Studio, the Gemini API, and the agent environment Google Antigravity, as well as through Gemini Enterprise for corporate customers and in the consumer app Gemini, in the AI mode of Google Search, and in Google Sheets. The introductory price is set at $0.75 per million input tokens and $3.75 per million output tokens until the end of 2026; after that, prices will rise to $1.50 and $7.50 respectively.
Flash Cyber, on the other hand, remains locked: access is granted only to government agencies, critical infrastructure operators, and software manufacturers that apply for Google’s new Fairwind program and are vetted. Google justifies the restriction by stating that the model operates with relaxed protective mechanisms against abuse in the cyber attack area. Interested organizations can apply directly through the Fairwind program page, according to Google; the company does not provide information on processing times or availability in Germany and the EU.
Predecessor model initiated the race for cyber defense AI
Already in July 2026, Google introduced Gemini 3.5 Flash Cyber, the first specialized security variant, which detected previously unknown vulnerabilities in tests on the V8 browser engine. The trend towards AI-supported debugging was also evident in August 2026, when Google closed 1,072 security vulnerabilities within two Chrome versions using AI agents like Gemini, Big Sleep, and CodeMender. Competitors are also ramping up: OpenAI restricts its cyber defense model GPT-5.6-Cyber in the Daybreak program to vetted partner companies and authorities, while Anthropic pursues a similar tiered release approach with its Project Glasswing program.
According to VentureBeat, the challenge remains structurally asymmetric: attackers need only one exploitable gap among millions of lines of code, while defenders must close each one. Independent security researchers outside of Google and the acquired company Wiz have not yet confirmed the published figures.
It will be crucial whether the tiered access through Fairwind actually prevents attackers from benefiting from the same capabilities that defenders are supposed to use. How many organizations Google will approve for the program and the timeline for expanding the circle remains open.


