Google’s new Gemini model is built to fight cyber threats
Google’s Gemini family just got a cybersecurity specialist. Meet Gemini 3.8 Flash Cyber and the new Gemini 3.8 Flash.
AI is getting a new job: hunting down hackers before they strike. Google has launched Gemini 3.8 Flash Cyber, a specialised version of its latest Gemini model designed for cybersecurity teams.
It arrives alongside Gemini 3.8 Flash, which Google calls its most capable Flash model yet for reasoning, coding and agentic tasks, where AI can plan, use tools and complete multiple steps with limited human input.
The timing is significant. AI is increasingly being used not just to write code, but to find weaknesses in that code and help fix them before attackers can take advantage.
Gemini 3.8 Flash Cyber is built for defenders
The cyber-focused model is aimed at trusted defenders, including government authorities, critical infrastructure operators and software maintainers. Rather than making it widely available, Google is offering access through its Fairwind Program.
Its main focus is vulnerability discovery and automated patching. In simple terms, the model can look through software for security flaws and help developers create fixes for them. Google says Gemini 3.8 Flash Cyber delivered frontier-level performance on CyberGym, a benchmark for vulnerability discovery.
In another internal test covering complex codebases across 20 programming languages, the company said the model achieved a success rate of more than 70%. The model also performed strongly on patching tasks.
On CWE-Bench, Google reported a pass@1 score of 47.2%, compared with 47.8% for a leading frontier model. Google says it achieved this at a lower cost. Pass@1 measures whether an AI gets the correct answer on its first attempt.
The tech giant says the model found 2.6 times as many correct fixes for Chrome security flaws as larger commercial AI models.
The regular Flash model is getting a wider rollout
While the cyber version is restricted, Gemini 3.8 Flash is available to a much wider audience. Developers can access it through the Gemini API, Google Antigravity, Android & AI Studio.
Businesses can use it through Gemini Enterprise, while AI Pro and Ultra subscribers get access through the Gemini app, Google Search’s AI Mode and Gemini in Google Sheets.
The model will cost $0.75 for every 1 million input tokens and $3.75 for every 1 million output tokens at its starting price, available through the end of 2026. From 2027, these rates will increase to $1.50 and $7.50, respectively.
Sam Altman's OpenAI rallies 100+ tech giants as AI cyberattack countdown begins
Google wants AI on the defensive side
There is a clear difference in how Google is positioning the two models. Gemini 3.8 Flash is designed as a general-purpose AI model for coding, reasoning and agentic work. Gemini 3.8 Flash Cyber is being given more room to operate in cybersecurity, but only for users Google has vetted.
Google says Gemini 3.8 Flash also includes safeguards against cyber misuse and other high-risk areas, including chemical, biological, radiological and nuclear threats. The bigger bet is that AI can help security teams move faster than attackers.
Finding a vulnerability is useful, but finding it and fixing it before someone exploits it could be far more valuable. For businesses, banks and public-sector organisations, that could make AI-powered cyber defence an increasingly important part of the security stack.
The challenge for Google will be making these systems powerful enough to help defenders, without giving the same capabilities to the people they are supposed to defend against.


