AI Models

Google launches Gemini 3.8 Flash and a Cyber version for trusted defenders

Google introduced Gemini 3.8 Flash and Gemini 3.8 Flash Cyber, combining stronger coding and reasoning with a restricted model for vulnerability discovery and patching.

Published Updated
Google DeepMindGeminiAI Models

Google introduced Gemini 3.8 Flash and Gemini 3.8 Flash Cyber on September 2, framing the release as a step forward for long-horizon coding, agentic workflows and defensive cybersecurity. The launch comes only weeks after Gemini 3.7 Flash and keeps the same introductory price for the general Flash model: $0.75 per million input tokens and $3.75 per million output tokens until the end of 2026. Google says the new model offers stronger reasoning and coding performance without changing the speed-and-cost profile that made Flash attractive for production workloads.

Gemini 3.8 Flash is aimed at developers and enterprises that want a lower-cost model capable of sustained tool use. Google says it improves on Gemini 3.7 Flash across software engineering, agentic tasks and specialized multi-step reasoning. The company points to gains on DeepSWE v1.1 for long-horizon software engineering, Vals Finance Agent V2, Harvey’s Legal Agent Benchmark and HLE-Verified, where it reports a 54.9% score. The message is that the model is not simply a faster assistant for short prompts, but a system designed to keep working through complex tasks, call tools repeatedly and spend more reasoning effort when the task demands it.

The second version, Gemini 3.8 Flash Cyber, is more tightly controlled. Google describes it as its most capable cybersecurity model and says it is available to trusted defenders through the new Fairwind Program. It is built on the same foundational intelligence as Gemini 3.8 Flash, but tuned and deployed for vulnerability discovery and automated patching. On CyberGym, Google says the model reaches frontier-level performance in autonomous vulnerability discovery. In an internal benchmark spanning complex codebases in 20 programming languages, the company reports a success rate above 70%.

Google is emphasizing defense rather than offensive exploitation. The company says Gemini 3.8 Flash Cyber was designed to help defenders find, verify and fix vulnerabilities at speed. On CWE-Bench, an external patching benchmark run by Collinear, Google reports a pass@1 of 47.2%, close to a larger leading frontier model at 47.8%, but at substantially lower cost. It also says Chrome’s security team found that the model produced 2.6 times more correct vulnerability patches for Chrome than larger commercial models, while Wiz measured higher recall at lower cost on an internal penetration-testing benchmark.

The release also reflects how large AI labs are treating cyber capability as a special deployment category. Gemini 3.8 Flash ships with safeguards against misuse in chemical, biological, radiological, nuclear and cyber-offense domains. Gemini 3.8 Flash Cyber is more permissive for cybersecurity work, but is restricted to organizations that Google classifies as trusted defenders. Google says the models also make a significant leap in prompt-injection robustness as measured by Gray Swan, a relevant issue for agents that read untrusted documents, websites and code.

For the market, the launch puts pressure on rivals to compete not only on benchmark scores, but also on cost, access controls and operational packaging. Developers can use Gemini 3.8 Flash in Google AI Studio, the Gemini API, Android Studio, Google Antigravity, Gemini Enterprise and consumer products such as the Gemini app and AI Mode in Search. The Cyber model, however, is being treated as a more sensitive capability. That split may become increasingly common: broad access to general reasoning models, with specialized high-impact variants distributed through vetted channels.