AI Security

Google opens Fairwind Program to give governments and enterprises AI cyber defense tools

Google launched the Fairwind Program, a limited-access effort that combines Gemini 3.8 Flash Cyber with CodeMender for trusted cyber defenders.

Published Updated
GoogleCybersecurityAI Security

Google launched the Fairwind Program on September 2, a limited-access initiative that gives governments, Google Cloud customers and cybersecurity partners access to its most advanced AI cyber-defense capabilities. The program combines Gemini 3.8 Flash Cyber with the CodeMender harness, aiming to help trusted defenders find, verify and fix vulnerabilities at a scale and speed that manual security teams often cannot match.

The timing matters because defenders are under pressure from two sides. Enterprise software estates keep expanding, while AI-enabled attackers can test, automate and iterate more quickly. Google describes the defender’s challenge as a trade-off between very large frontier models that may be expensive and hard to control across enterprise codebases, and smaller open-weight models that may not be strong enough for complex vulnerability remediation. Fairwind is Google’s answer to that gap: a controlled channel for advanced cyber AI focused on repair rather than exploitation.

The first step gives selected organizations access to Gemini models that can autonomously find and fix vulnerabilities. Google says CodeMender with Gemini 3.8 Flash Cyber can generate verified, deployment-ready patches in minutes, compared with the weeks that vulnerability remediation can take when handled manually. The company says the model brings specialized reasoning to code repair at a fraction of the operating cost of traditional frontier models, which is important for organizations that need to scan large codebases repeatedly rather than run isolated demonstrations.

Google is staging access around sectors it considers critical to societal resilience. Initial participants include government and national cyber authorities, critical infrastructure operators in healthcare, telecommunications, energy and financial networks, and core technology platforms whose software foundations affect many downstream users. Participating organizations must follow operational standards, including limiting access to internal cybersecurity, incident-response or penetration-testing teams and using protections such as multi-factor authentication. Google says more than 650 partners are participating globally.

The company also links Fairwind to its broader security footprint. Google says its zero-trust architecture, AI defenses and built-in security systems protect billions of accounts daily. The program is part of a wider cyber-resilience push that includes Google.org funding. Google said its latest commitment brings total cybersecurity funding to more than $100 million globally and pointed to a 2026 U.S. Cybersecurity Impact Report covering $36 million in funding for 35 cyber clinics that have provided free hands-on support to more than 1,250 hospitals, school districts and municipal utilities in the United States.

Fairwind also reflects a broader policy question around AI and cybersecurity. Advanced models can help defenders close vulnerabilities faster, but the same capabilities can be dangerous if they are used for offensive exploitation or indiscriminate scanning. Google is responding by restricting the most capable cyber model to trusted partners while allowing any Google Cloud customer to use CodeMender with publicly available models hosted on the Gemini Enterprise Agent Platform. That creates a two-tier approach: broad access to useful security automation, and tighter access to the most powerful tools. If the model works as described, the program could shorten the window between discovering a flaw and shipping a patch, which is often where real-world attacks do the most damage.