Dossier · Ongoing

Google's Cyber AI Models

From the first government-only release in July to the third Flash launch within six weeks in September 2026: Google's cyber AI models, tracked over time.

Since July 2026, Google has been building a dedicated model line for automated vulnerability discovery and remediation. Gemini 3.5 Flash Cyber launched within the tightly restricted CodeMender pilot for governments; with Gemini 3.8 Flash Cyber and the new Fairwind program in September 2026, the circle of eligible users grows to include critical-infrastructure operators and software makers.

The strand tracks how Google gradually shifts the balance between offensive misuse risk and defensive benefit – and how competitors like OpenAI with Daybreak and Anthropic with Project Glasswing position themselves similarly.

Timeline

  1. Google restricts new Cyber AI to governments

    The new AI model finds more vulnerabilities than Claude Opus 4.6, but remains exclusively accessible to authorities and selected partners for now.

  2. Google launches Gemini 3.8 Flash Cyber – access remains exclusive

    The new security model patches Chrome vulnerabilities more accurately than competitors, but stays limited to verified authorities for now.