Google launches Gemini 3.8 Flash and a restricted Gemini 3.8 Flash Cyber for vulnerability research
Google shipped Gemini 3.8 Flash to general availability on September 2, 2026, alongside a restricted cybersecurity-focused sibling, Gemini 3.8 Flash Cyber, aimed at vulnerability discovery and automated patching for government and critical-infrastructure operators.
What's new
Gemini 3.8 Flash is positioned as Google's fastest coding and long-horizon agentic model to date. According to Google's announcement, "3.8 Flash outperforms most larger frontier models in autonomously solving complex engineering problems end to end, only at a fraction of the cost." The model posts 54.9% on HLE-Verified, a benchmark spanning complex reasoning across STEM, humanities, and professional fields, and Google says it shows marked gains in software engineering, agentic task execution, and multi-step reasoning versus its predecessor.
Pricing for the general-release model is introductory through December 31, 2026: $0.75 per million input tokens and $3.50 per million output tokens. It is available now through Google AI Studio, the Gemini app, Google Sheets, and Gemini Enterprise.
Gemini 3.8 Flash Cyber is a separate, access-gated variant built for defensive security work. Google reports a 70%+ success rate on real-world vulnerability discovery across 20 programming languages and a 47.2% pass rate on CWE-Bench for automated patching. Unlike the general-release model, Flash Cyber is not broadly available — it ships exclusively through Google's Fairwind Program, which Google restricts to government authorities and critical-infrastructure operators.
Context
The release continues Google's rapid Flash-tier cadence: Gemini 3.7 Flash and 3.6 Flash/3.5 Flash-Lite both shipped within recent months, each iterating on coding and agentic performance while keeping costs low relative to Google's larger Pro-tier models. The Cyber variant extends a pattern of gating specialized, dual-use security capability behind vetted-access programs rather than public API keys — mirroring how other labs have restricted their own offensive/defensive security-testing models to controlled cohorts.
Google's Gemini API changelog lists the Flash 3.8 GA alongside the model's broader September 2 update, and Google AI's model-card page for 3.8 Flash documents the same benchmark figures and availability terms independently.
Why it matters
A fast, cheap model that beats larger frontier systems on end-to-end engineering tasks pressures the economics of agentic coding products: teams building autonomous dev-agent workflows get a materially lower per-task cost without giving up capability, which narrows the case for defaulting to the priciest frontier tier. The introductory pricing window running through year-end signals Google wants rapid adoption before any price normalization.
The restricted Cyber variant is arguably the more consequential signal. Frontier labs increasingly have models capable of both finding and patching real-world vulnerabilities at scale, and the industry's response — gating that capability to vetted government and infrastructure operators rather than the general API — reflects a growing consensus that autonomous vulnerability-discovery tools carry meaningful dual-use risk. How durable and enforceable that gating proves to be, as more labs field similar cyber-specialized models, is likely to remain a live policy question.
Corroborating sources
- Ai.google
https://ai.google.dev/gemini-api/docs/models/gemini-3.8-flash
- Blog
https://blog.google/innovation-and-ai/models-and-research/gemini-models/3-8-flash-and-3-8-flash-cyber/
“3.8 Flash outperforms most larger frontier models in autonomously solving complex engineering problems end to end, only at a fraction of the cost.”
- Deepmind
https://deepmind.google/models/model-cards/gemini-3-8-flash/
- Changelog
https://ai.google.dev/gemini-api/docs/changelog