Google has launched Gemini 3.8 Flash and a specialized cybersecurity model, Gemini 3.8 Flash Cyber, designed to autonomously find software vulnerabilities and help fix them.

Announced on September 2, the release marks Google's third Flash model in just six weeks. While Gemini 3.8 Flash is aimed at coding, complex reasoning and AI agent workflows, its Cyber version has a much more specific job: helping defenders identify security flaws and create patches.

What Is Gemini 3.8 Flash Cyber?

Google describes Gemini 3.8 Flash Cyber as its most capable cybersecurity model so far, with what it calls frontier-level performance in vulnerability detection and automated patching.

Cybersecurity workstation with code analysis and vulnerability monitoring screens

Image: AI-generated with ChatGPT Images 2.0

How Well Can It Find and Fix Vulnerabilities?

In testing across complex codebases covering 20 programming languages, Google says the model achieved a vulnerability discovery success rate of more than 70%.

The company is already testing it on its own software. Google says its Chrome Security team found that Gemini 3.8 Flash Cyber produced 2.6 times more correct vulnerability patches than the best larger commercial models it tested.

Google also says its Cloud Vulnerability Research team used the model to find a critical foundational vulnerability in less than two hours, a process the company says would typically take months.

AI Usage Notice: In preparing this article, AI tools were used with careful human oversight and editing. We believe in transparency regarding the use of AI in our work.
AI Usage Notice: In preparing this article, AI tools were used with careful human oversight and editing. We believe in transparency regarding the use of AI in our work.

Who Can Access Gemini 3.8 Flash Cyber?

The cyber model is not being released as a general-purpose chatbot.

Because it has more advanced cybersecurity capabilities, Google is limiting access through its new Fairwind Program, which is aimed at trusted defenders.

Government authorities, critical infrastructure operators and software maintainers are among the groups receiving prioritized access. Google says Gemini 3.8 Flash Cyber has more permissive cybersecurity safeguards than the standard model because legitimate defenders require access to a broader set of cyber capabilities.

For autonomous vulnerability remediation, Google is pairing Gemini 3.8 Flash Cyber with its CodeMender system, which is designed to help defenders find, verify and fix vulnerabilities and generate validated patches.

Looking for support around AI?

We (AImpactful 🙂) work with newsrooms, NGOs, institutions, teams, and individuals who need workshops, advisory support, or content production.

Gemini 3.8 Flash vs. Gemini 3.8 Flash Cyber

The regular Gemini 3.8 Flash, meanwhile, is more widely available and is designed for software engineering, multi-step reasoning and longer AI agent tasks. Google says the model can work through complex engineering problems autonomously and is optimized for agentic workflows.